Advice Request Thoughts on Windows Sandbox?

Please provide comments and solutions that are helpful to the author of this topic.

Stenographers

Level 2
Thread author
Nov 11, 2022
48
Or any alternatives that would work on Linux?

Windows Sandbox is a feature of Windows that gives you a disposable VM to use for checking out suspicious links or software. Personally I don't investigate malware samples on Windows anyway, but I'm not sure if I fully trust Windows Sandbox to keep my computer safe if it did execute malware. My reasoning is that it shares some resources with the host system, like copy / paste, in the sake of convenience. These little holes it pokes between the VM and the host make me uncomfortable.
 
  • Like
Reactions: Gandalf_The_Grey

struppigel

Super Moderator
Verified
Staff Member
Well-known
Apr 9, 2020
667
I would not trust it either. Worms can still spread to devices that are connected via the network. Clipboard data can be leaked too.
I use VMRay and VirtualBox on Linux. Do not add the Guest Addons or similar convenience features for the malware VM because they will do the same thing and, e.g., expose the clipboard or allow file exchange via copy and pasting from host to VM and back which is a security risk.
 

upnorth

Level 68
Verified
Top Poster
Malware Hunter
Well-known
Jul 27, 2015
5,458
I wouldn't recommend use Windows sandbox for malware testing, as it exist much better options. Today even free online platforms works faster for a quick test of urls and software. Automatic also much more safe.

Microsoft always had the good intention to help and supply their users with fast and easy options, but it's impossible to compete with all 3rd party vendors. Paint, great basic option, but for real professionals, not really. The list goes on with backup solutions etc etc.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top