Sandbox Shenanigans pt.1 - The Windows Sandbox Abuse

Windows Sandbox is a disposable, lightweight VM baked into every Pro/Enterprise install - flip on one optional feature and you get a throwaway Windows box with Defender off by default and optional folder mappings into the host. Genuinely useful for detonating a suspicious attachment. Also, structurally, a gift to anyone trying to hide from your EDR: the payload runs somewhere your host telemetry can’t see.