The logic of sandboxing (containment) over outright blocking is rooted in Business Continuity and Threat Intelligence. While blocking an "Unknown" file is more restrictive, it frequently results in false positives that halt legitimate work. Containment allows a file to execute in a virtualized state where it can be observed and verdicted without risking the host system, effectively eliminating the "patient zero" problem while maintaining productivity.
Blocking or allowing to run within a hardened container depends upon the mandate which governs the system. If the system is a:
NURO
SCS
GRS
NGA
DI
JIO
NCF
DSTL
system, as a limited subset of IC/'CI agencies, then 100% whitelitsting is required. As in the "absolutte" definition of whitelisting. Translation= Block ALL by Default, Allow Only AFTER An Extensive Vetting Process by Exception:
A. Identified
B. Documented
C. Vetted initially and continuously
E. Monitored continuously
F. Protected from modification
G. Audited 24/7
H. Other stuff
Software is really just a collection of
artifacts that together make a program run. Some are executable, some are configuration, some are data, and some are supporting resources. There’s no single “official” complete list because different platforms use different components, but you can map out the full landscape of what software is typically made of.
The fact that an object has been published and signed my Microsoft and resides in C:\Windows\System?? matters not a jot.
There are many tools used to perform what is required and they work well, but human eyeballs are mandated the final verdicts.
Since this is all about playing with civilian meatspace security software I will leave it at that.
For MT and lesser types, Melih figured out that a virtual container solves almost the full extent of human behaviors that are dangerous. He performed what Charlie Munger figured out but applied to cybersecurity:
Charlie Munger used the term “Lollapalooza” to describe situations where multiple psychological biases act together, reinforcing one another so strongly that they produce extreme, irrational, and often disastrous human behavior.