Sandbox
Definition
An isolated execution environment, typically a virtual machine, where a malware sample runs under full instrumentation. The sandbox logs all system calls, file operations, network traffic, and process activity while preventing the sample from reaching production infrastructure.
- Typical implementation
- Virtual machine
- Logged activity
- System calls, file ops, network traffic, processes
- Purpose
- Isolate malware from production infrastructure
- Field
- Dynamic malware analysis
Common questions
Why do analysts run malware dynamically in a sandbox instead of only reading its code statically?+
Static analysis can be defeated by packing, obfuscation, or encryption that hides the code's real behaviour, while actually executing the sample under instrumentation reveals what it does at runtime, such as which files it touches or which servers it contacts.
How can malware detect and evade a sandbox environment?+
Some samples check for virtual-machine artefacts, unusual hardware signatures, absence of typical user activity, or a lack of network latency, and if detected they suppress malicious behaviour or exit early to avoid being fully analysed.
What is a key limitation of sandbox-based analysis for an investigator?+
A sandbox only captures behaviour actually triggered during the observation window, so malware with time-delayed, environment-specific, or command-triggered payloads may never reveal its full functionality within a single run.
Related terms
- API Hooking
- A monitoring technique in which the sandbox intercepts calls the malware makes to operating-system API functions. Each intercepted call is logged with...
- Behavioural Analysis
- The examination of what a program does at runtime rather than what its code says at rest. Behavioural analysis captures the actual...
- Evasion Detection
- Malware logic that checks whether the execution environment is a real host or an analysis sandbox. Checks may query hardware identifiers, count...
- MITRE ATT&CK Mapping
- The process of classifying observed malware behaviours against the MITRE ATT&CK framework's taxonomy of adversary tactics and techniques. Sandbox platforms increasingly produce...
- Network Indicator
- A network-based artefact produced by malware at runtime, such as a DNS query, an IP address contacted, an HTTP request path, a...