Question Does Sandboxie Plus Support Advanced Security Tweaks in Windows 11?

Please provide comments and solutions that are helpful to the author of this topic.

a090

Level 2
Thread author
Mar 26, 2023
67
This is a question for @DavidXanatos, as he is the only one who will have the knowledge to be able to answer this.

Does Sandboxie Plus operate well under some rather “extreme” virtualization-based tweaks and other security measures? I’m talking about things like:

1. Core Isolation (Memory Integrity) + Secure Boot
2. Kernel-mode Hardware-enforced Stack Protection
3. LSA Protection
4. Firmware Protection

I don’t plan on doing anything crazy with Sandboxie. No testing apps or installing them within sandboxes. Just running my Brave browser sandboxied and completely locked down (so nothing can access my PC from the internet while surfing sandboxied Brave). I will subscribe to get the additional features for Sandboxie Plus. Device is Windows 11.

Questions:

1. Will Sandboxie crash or have unforseen issues with those additional Windows’ security tweaks enabled?

I’m assuming Sandboxie uses some kind of driver that may or may not be compatible with those tweaks. Any insight you can provide is most appreciated, David.

2. Does Sandboxie Plus support Brave browser or are there incompatibilities?

Chromium based browsers are supposedly already sandboxed, but I’m not sure if that will cause conflicts when trying to sandbox again using Sandboxie Plus. Does Brave run well in Sandboxie Plus when locked down, or does it cause glitches / instability.

Many thanks in advance!
 
  • Like
Reactions: Trident

DavidXanatos

From Sandboxie Plus
Verified
Developer
May 4, 2020
22
Hello

1. Should be working there were bugs reported in the past and fixed the latest version should be fine.
2. Since many builds it is supported and processes using these mechanism work just fine.
3. There should be no problems with that
4. Also nothing here that could cause issues imho.

1. Will Sandboxie crash or have unforseen issues with those additional Windows’ security tweaks enabled?

It should not

2. Does Sandboxie Plus support Brave browser or are there incompatibilities?

Last I tested it worked fine.

Chromium based browsers are supposedly already sandboxed, but I’m not sure if that will cause conflicts when trying to sandbox again using Sandboxie Plus. Does Brave run well in Sandboxie Plus when locked down, or does it cause glitches / instability.

It works fine, what may not work are some GPU acceleration features.

Also given how sandboxie operates some of chromium's sand-boxing is not in effect when run under sandboxie, but then it should not be needed, its a trade of.
When ran in a App Compartment Type box (green icon), chromium own Sandboxing is fully effective, plus it gets a good amount of extra protection from sandboxies driver. Also in a green box GPU acceleration should work just fine.

An App Compartment Type box combined with DropAdminRights and Chromiums own sandbox is a very good way of running such browsers.

Cheers
David
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top