A sandbox is an isolated environment in which untrusted code runs with strictly limited access to the rest of the system, so that anything it does cannot harm the host.
Two meanings of “sandbox”
Application sandbox. Browsers, mobile operating systems and many desktop programs run risky code in a restricted process. In Chrome, each web page is rendered in a sandboxed process that cannot read your files directly; iOS and Android give every app its own sandbox. To take over a device, attackers therefore need a chain: one bug to run code inside the sandbox and a second one – a sandbox escape – to break out. Such chains are the typical winning entries at Pwn2Own.
Analysis sandbox. Security teams and products “detonate” suspicious files and links in a disposable virtual machine and watch what happens: which files are created, which registry keys change, which servers are contacted. Mail gateways, EDR platforms and open-source tools such as CAPE rely on this to reveal the real payload of malware.
Sandbox evasion
Malware authors know about sandboxes. Their code checks for signs of a virtual machine or analysis tools, waits for minutes before acting, requires mouse movement or a reboot, or only activates for specific countries. Combined with obfuscation, these tricks let samples look harmless during automated analysis.
Best practices
- Keep browsers and operating systems updated – sandbox escapes are patched regularly.
- Open untrusted attachments in isolated environments such as Windows Sandbox or a dedicated VM.
- Do not rely on sandbox verdicts alone; combine them with behavioural detection on endpoints.