Scripts and configuration to prepare a Windows Sandbox environment for offline malware analysis tooling.
This repository provides:
- a host-side preinstall script to download installers into
C:\Sandbox\install - a sandbox startup script to configure Windows and install tools from that shared folder
- a
.wsbconfiguration with networking disabled and a read-only mapped host folder
Main files:
scripts/preinstall.ps1scripts/SandboxSetup.ps1conf/malware.wsb
- On the host machine, run
scripts/preinstall.ps1. - The script ensures
C:\Sandbox\installexists and downloads tool installers/packages there viawinget download. - Copy
scripts/SandboxSetup.ps1toC:\Sandbox\SandboxSetup.ps1(or adjust the.wsbif you place it elsewhere). - Start the sandbox using
conf/malware.wsb. - At logon, the sandbox auto-runs
SandboxSetup.ps1from the mapped host folder. - Inside the sandbox, tools are installed/extracted from
HostShared\installand Windows UI/system settings are adjusted for analysis.
- Windows 11 with Windows Sandbox feature enabled
C:\Sandbox\folder available on host
Run in Powershell:
powershell -ExecutionPolicy Bypass -File .\scripts\preinstall.ps1What preinstall.ps1 does:
- detects architecture (
x64,x86,arm64,arm) - installs
wingetif missing - creates
C:\Sandbox\install(safe if it already exists) - downloads these packages to
C:\Sandbox\install:- Notepad++
- Sysinternals Suite
- 7-Zip
- x64dbg
- Wireshark
- PE-bear
conf/malware.wsb uses:
NetworkingdisabledvGPUdisabled- host folder
C:\Sandbox\mapped read-only to:C:\Users\WDAGUtilityAccount\Desktop\HostShared
- auto logon command that starts
SandboxSetup.ps1 - clipboard, printer, audio, and video input disabled
System and Explorer behavior:
- enables old Windows 11 context menu style
- shows file extensions and hidden files
- enables long paths
- adjusts CI policy (
VerifiedAndReputablePolicyState) and refreshes withCiTool.exe - sets PowerShell execution policy
- enables clipboard history
- increases console scrollback
- disables spotlight wallpaper and restores default wallpaper
Context menu additions:
- Open PowerShell Here
- Open CMD Here
- Edit with Notepad++ / Open Notepad++
- New
.txtand.ps1entries in "New" context menu
Tool installation behavior:
- silent install of
.exefiles found inHostShared\install - extraction of
.zipfiles toC:\Program Files\<archive-name> - adds extracted folders to user
PATH(x64dbg handled withrelease\x64subfolder) - associates
.txtopening with Notepad++ - restarts Explorer and opens the shared folder
For the provided .wsb to work, ensure the host folder contains what the sandbox expects:
C:\Sandbox\
install\ # populated by preinstall.ps1
SandboxSetup.ps1 # copy from scripts/SandboxSetup.ps1
If SandboxSetup.ps1 is not present at C:\Sandbox\SandboxSetup.ps1, the logon command in the .wsb file cannot execute it.
- The sandbox is configured for reduced interaction (no network, no clipboard redirection).
- Mapped folder is read-only from sandbox side.
- Host still provides files to sandbox, so only place trusted setup material in
C:\Sandbox\.
MIT License. See LICENSE for details. Scripts inspired by this repository.