Windows Defender Gets 'Sandbox' Protection

Microsoft is beefing up Windows Defender, the built-in antivirus and antimalware security tool in Windows 10. It's now using the same sandbox technology that's used in other tools, including some major web browsers.

The concept of a sandbox is taken from the child's play area of the same name. It's a metaphor about the way the child has an area to play in freely and do what they like, but also has clearly defined boundaries. Fortunately, computer code tends to follow instructions better than a child told to stay in the sandbox.

In computing terms, the sandbox is a concept about access that software has to files, memory and other resources of the operating system. Running something in a sandbox means the relevant code is isolated from the rest of the computer.

Sandbox Isolates Code On PC

Sandboxing was originally used mainly in software testing. By running a new program or update in a sandboxed mode, developers could test the software on a real machine and operating system to see if it worked, but prevent it from causing any changes or problems with other software.

Today it's also used as a security feature. For example, browsers such as Google's Chrome run each individual tab in its own 'sandbox'. The idea is that if the user visits a compromised web page, the page isn't able to access personal data on the computer, or to access or change data that's being transferred between the computer and another website in a separate tab.

Security Tools Could Be Security Risks

Windows Defender will now run in a sandboxed mode, which eliminates a risk that may be small but has serious potential consequences. By definition, security software that scans a computer needs to have access to every file on the machine so that it can check its contents, spot any risks, and even block or isolate it. Some security software also accesses any data sent to or from the Internet in real time. (Source:

If a security tool such as Windows Defender was ever compromised, the attackers could then abuse this access and effectively have complete access and some control over a computer. While Microsoft says its never seen evidence of this happening, it has spotted and fixed some bugs with Windows Defender that could theoretically have been exploited. The sandboxing is thus acting like a backstop. (Source:

Do you rely on Windows Defender or use other security tools? Have you previously considered the risks of security software being compromised? Does the sandboxing make you feel more comfortable or is there a risk it reduces the pressure on Microsoft to spot any bugs in Windows Defender?

