mdevolde/windows-sandbox-malware

Scripts and configuration to prepare a Windows Sandbox environment for offline malware analysis tooling.

★ 0Forks 0PowerShellGitHub ↗Compare
sandboxwindowswindows-sandbox

README

windows-sandbox-malware

Scripts and configuration to prepare a Windows Sandbox environment for offline malware analysis tooling.

Overview

This repository provides:

  • a host-side preinstall script to download installers into C:\Sandbox\install
  • a sandbox startup script to configure Windows and install tools from that shared folder
  • a .wsb configuration with networking disabled and a read-only mapped host folder

Main files:

  • scripts/preinstall.ps1
  • scripts/SandboxSetup.ps1
  • conf/malware.wsb

How It Works

  1. On the host machine, run scripts/preinstall.ps1.
  2. The script ensures C:\Sandbox\install exists and downloads tool installers/packages there via winget download.
  3. Copy scripts/SandboxSetup.ps1 to C:\Sandbox\SandboxSetup.ps1 (or adjust the .wsb if you place it elsewhere).
  4. Start the sandbox using conf/malware.wsb.
  5. At logon, the sandbox auto-runs SandboxSetup.ps1 from the mapped host folder.
  6. Inside the sandbox, tools are installed/extracted from HostShared\install and Windows UI/system settings are adjusted for analysis.

Prerequisites

  • Windows 11 with Windows Sandbox feature enabled
  • C:\Sandbox\ folder available on host

Host Setup

Run in Powershell:

powershell -ExecutionPolicy Bypass -File .\scripts\preinstall.ps1

What preinstall.ps1 does:

  • detects architecture (x64, x86, arm64, arm)
  • installs winget if missing
  • creates C:\Sandbox\install (safe if it already exists)
  • downloads these packages to C:\Sandbox\install:
    • Notepad++
    • Sysinternals Suite
    • 7-Zip
    • x64dbg
    • Wireshark
    • PE-bear

Sandbox Configuration

conf/malware.wsb uses:

  • Networking disabled
  • vGPU disabled
  • host folder C:\Sandbox\ mapped read-only to:
    • C:\Users\WDAGUtilityAccount\Desktop\HostShared
  • auto logon command that starts SandboxSetup.ps1
  • clipboard, printer, audio, and video input disabled

What SandboxSetup.ps1 Changes

System and Explorer behavior:

  • enables old Windows 11 context menu style
  • shows file extensions and hidden files
  • enables long paths
  • adjusts CI policy (VerifiedAndReputablePolicyState) and refreshes with CiTool.exe
  • sets PowerShell execution policy
  • enables clipboard history
  • increases console scrollback
  • disables spotlight wallpaper and restores default wallpaper

Context menu additions:

  • Open PowerShell Here
  • Open CMD Here
  • Edit with Notepad++ / Open Notepad++
  • New .txt and .ps1 entries in "New" context menu

Tool installation behavior:

  • silent install of .exe files found in HostShared\install
  • extraction of .zip files to C:\Program Files\<archive-name>
  • adds extracted folders to user PATH (x64dbg handled with release\x64 subfolder)
  • associates .txt opening with Notepad++
  • restarts Explorer and opens the shared folder

Expected Folder Layout

For the provided .wsb to work, ensure the host folder contains what the sandbox expects:

C:\Sandbox\
	install\                 # populated by preinstall.ps1
	SandboxSetup.ps1          # copy from scripts/SandboxSetup.ps1

If SandboxSetup.ps1 is not present at C:\Sandbox\SandboxSetup.ps1, the logon command in the .wsb file cannot execute it.

Security Notes

  • The sandbox is configured for reduced interaction (no network, no clipboard redirection).
  • Mapped folder is read-only from sandbox side.
  • Host still provides files to sandbox, so only place trusted setup material in C:\Sandbox\.

License

MIT License. See LICENSE for details. Scripts inspired by this repository.

Contributors

mdevolde

Issues