Automatic sandbox - an option to virtualize FS/REG

CIS’s ‘automatic sandbox’ concept that sandboxes unrecognized file is cool.
but it doesn’t virtualize filesystem/registry, some garbages may be created by various software.
it will be good to have an option to turn on/off the FS/REG virtualization when automatically sandboxing the application.
as always, I’m enjoying a benevolent influence of COMODO products. thanks in advance.

[attachment deleted by admin]

I doubt Comodo will be able to release anything quite like Sandboxie. However, it would be rather amazing if they did.

+1

+1

Definitely something that needs to be added.

They also need to add the security context selection menu that is currently on the Execution Control Tab. This sets the security context for all sandboxed programs.

I would like to be able to run sandboxed apps with full privileges as well, and just rely on virtualization and D+ for protection. Some apps don’t run properly with limited rights.

+1
AUTO SANBOX NEEDS TO BE A SANBOX!!
recently they add the “partially limited” but a sanbox dont need any kind of limit, because its vittualised
so i think auto sanbox need to virtualise all thinks fron unreconised files and when moved to safe files move the files also (the virtualised folder must be in same partition were the file should be)

+1

-1

I don’t think so… sorry, the auto-sandbox will make impossible to work if it virtualizes everything… You won’t be able to run your programs (as a lot of them aren’t in the whitelist yet).

The full sandbox is the on demand one.
The automatic sandbox is for protection and need to be lighter, not full.

I do think it should be disabled by default, for the reasons given by Tech, but I still think there should be an setting to allow full virtualization of files that are automatically sandboxed.

A complain of another user… today…
https://forums.comodo.com/defense-sandbox-help-cis/how-do-i-remove-and-keep-a-program-out-of-sandbox-t62615.0.html;msg442266#msg442266

+1

Definitely this is a feature that needs to be added.

I voted +1 so :-TU

recently i was testing avast pro because the sanbox feature it have was somehow atractive
i discovered it implement some features i was asking here for comodo sanbox
the main one is if a app on disk F: is sanboxed then his files will go to F: also (or in the same partition it should be). :-TU thats a point in favour
but it is only on-deman and forced, i was hoping it were somehow automatic, this makes this sambox only a bundled software who came with the antivirus. :-TD thats a drawback
i noticed it saves the files in F:## aswSnx private storage\ but while avast is installed you cannot get there and automatically deletes all changes, which is bad :-TD but comodo keep the files without any way in the interface to delete it, this is bad also.
but i liked a lot the righ clic shell to mark a file to be forced always :-TU its a simple detail but well recived
this get me the idea for a good auto-REAL sanbox wicht will no have problems interacting with programs not sanboxed and still with a hight security lvl like an on-deman sanbbox, but this is not the place to write it so i will leave it for later.
i think these are only 2 antivirus who offer something selft called sanbox, i remember a video from languy99 while testing another antivirus wicht virtalised the apps also but i dont remember the name, if someone can refresh my memory i wan to test it also.

Nice! +1

CIS's 'automatic sandbox' concept that sandboxes unrecognized file is cool. but it doesn't virtualize filesystem/registry, some garbages may be created by various software. [b]it will be good to have an option to turn on/off the FS/REG virtualization when automatically sandboxing the application[/b].

+1

I really want to see this option integrated in the automatic sandbox by CIS.