Researchers Put Windows Defender in a Sandbox to Show Microsoft How It's Done

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Software experts from Trail of Bits — a well-known security R&D company — have sandboxed Windows Defender, the default antivirus solution that ships with recent Windows editions.

Sandboxing is a technical term that describes the act of running an application inside a dedicated container. These containers are usually very restricted and prevent an attacker that exploits the app from reaching the underlying operating system.

Current versions of Windows Defender aren't sandboxed
As surprisingly as it sounds, Windows Defender, a crucial part of the Windows OS does not run in a sandboxed environment by default, despite the product — in various forms and names — being part of the Windows app portfolio for 13 years.

Microsoft acquired GIANT AntiSpyware in 2004, and it used it as the starting point for the Defender app.

Other modern-day apps such as Chrome or the Java virtual machine use app containers (sandboxes) to protect users against vulnerability exploitation.

Read More. Researchers Put Windows Defender in a Sandbox to Show Microsoft How It's Done
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top