ELSandbox
An unknown file runs outside your system
A controlled session in the native Windows Sandbox. Only a copy of the material verified by its SHA-256 checksum reaches the guest, mounted read-only — the case folder is never mapped, so not even a malicious file can reach it. The session starts from a protection profile with the clipboard, microphone, camera, printers and vGPU switched off, and the guest running in protected mode. The results folder is mounted writable only when you ask for it, and it is the only thing that comes back from the sandbox to your workstation. After the session closes you are left with a report carrying the checksums of the copy and the results, plus the session journal — the part that goes into the case file. Before it starts, ElSandbox checks whether the environment allows it at all: the Windows edition, the state of the Sandbox feature and firmware virtualisation — and it can switch that feature on. Every session gets its own working folder with separate input, control and output subfolders.
- the material copy mounted as C:\EvidLock\Input, read-only
- the case folder is never visible to the guest
- clipboard, microphone, camera, printers and vGPU switched off
- network offline, direct or through a proxy — offline by default
- Process Monitor and Wireshark added as read-only resources
- the results folder is writable only on the operator's request
- HTML report with SHA-256 checksums of the copy and results, plus the session journal
- pre-flight environment check: Windows edition, Sandbox state, virtualisation
- behaviour monitoring written to the output folder
- named proxy profiles — HTTP/HTTPS only, no credentials in the address
- session memory 4096 MB by default, never below 2048 MB
RequirementsWindows 10 version 1903 (build 18362) or newer, in the Pro, Enterprise or Education edition — Home editions have no Windows Sandbox. The Containers-DisposableClientVM feature must be enabled and firmware virtualisation available; enabling the feature needs administrator rights and a system restart.
More about this feature →