Sandboxie Plus


Sandboxie Plus — Free Download. Sandbox isolation

Sandboxie Plus creates isolated environments on Windows to run applications separately from the host system. It prevents permanent changes to files, registry, and system settings by redirecting operations into a sandbox. The software supports 32-bit and 64-bit Windows NT-based operating systems. It provides controlled testing of untrusted programs, secure web browsing, and privacy protection for browsing history, cookies, and cached temporary files. A snapshot manager allows restoring any sandbox to a previous state. The program includes a network firewall per sandbox using Windows Filtering Platform, encrypted sandbox storage with AES, and privacy mode to protect user data from unauthorized access.

5.0(1 ratings)
File size: 23.7 MB
The latest version of Sandboxie Plus is: 5.73.4
Operating system: Windows
Languages: English
Price: $0.00 USD (Open Source (GPL-3.0) and Freemium)
  • Snapshot Manager. Takes a complete copy of any sandbox at a specific moment. This image can be restored later to return the sandbox to its exact previous state. The feature is used for testing software configurations, recovering from unwanted changes, or comparing system behavior before and after application installation. Snapshots include files, registry modifications, and sandbox settings. Restoration can be performed while processes are stopped or during sandbox maintenance operations.
  • Maintenance Menu. Provides direct control over the Sandboxie driver and service from the user interface. Users can install, uninstall, start, or stop core components without using command-line tools. This menu is available when the driver fails to load or when switching between different modes of operation. It simplifies troubleshooting by giving visual feedback about the status of system-level components.
  • Portable Mode. Allows extracting all program files to a selected directory without installing system services permanently. The portable version can be launched from removable media or a local folder. Configuration data remains in the same directory, making it possible to carry settings between computers. This mode does not require administrator privileges for initial extraction but may need them for driver loading.
  • Block Access to Windows Components. Adds UI options to prevent sandboxed processes from accessing printer spooler and clipboard. This control limits data leaks from inside the sandbox to shared Windows resources. Users can disable clipboard reading or writing separately, and block print jobs from untrusted applications. The setting applies per sandbox and can be adjusted without editing configuration files manually.
  • Start/Run and Internet Access Restrictions. Provides more detailed customization for process execution and network availability. Users can define which programs are allowed to start inside a sandbox and which external resources they can reach. Internet access can be restricted by address, port, or protocol. This granularity supports scenarios where only specific web services or local servers should be available to sandboxed software.
  • Privacy Mode Sandboxes. Protects user data from illegitimate access by preventing sandboxed processes from reading sensitive locations. These include user profile folders, documents, and other personal directories unless explicitly allowed. The mode reduces the risk of data theft by malware that executes inside the sandbox. Access requests are blocked before they reach the host file system.
  • Security Enhanced Sandboxes. Restricts the availability of syscalls and endpoints to sandboxed processes. This limits the attack surface available to malicious software. The configuration can disable specific system calls or network endpoints that are not required for the application to function. Such restrictions make exploitation of vulnerabilities more difficult.
  • Global Hotkeys. Assigns keyboard shortcuts to suspend or terminate all processes running in any sandbox. A single key combination can immediately freeze activity or close all boxed programs. This feature is used for emergency response when a sandboxed application becomes unresponsive or behaves unexpectedly. Hotkeys are configurable through the settings interface.
  • Network Firewall Per Sandbox. Implements a firewall for each sandbox using Windows Filtering Platform. Rules can allow or block network traffic based on direction, address, and port. Unlike global firewall settings, this firewall applies only to processes inside a specific sandbox. It enables isolated network policy testing and prevents unauthorized communication from untrusted applications.
  • Search Function for Settings. Provides a search field within Global Settings and Sandbox Options. Users can type keywords to filter and locate configuration entries quickly. The search operates across all sections, including advanced settings that are normally hidden. Matching items are highlighted, reducing the time needed to find specific parameters in large configuration sets.
  • Import/Export Sandboxes to 7z Files. Allows saving sandbox configurations and contents to compressed 7z archives. The archive can be transferred to another computer and imported to recreate the same sandbox environment. This feature supports backup, migration, and sharing of sandbox setups. Both the settings and the data inside the sandbox are included in the export.
  • Windows Start Menu Integration. Adds sandbox entries to the Windows Start menu. Users can launch applications directly inside a selected sandbox from the menu. Shortcuts can be created for specific programs or entire sandbox groups. This integration removes the need to open the main Sandboxie Plus window to start a sandboxed application.
  • Browser Compatibility Wizard. Creates templates for web browsers that are not officially supported. The wizard analyzes the browser executable and generates configuration rules to improve isolation and functionality. This includes settings for cache, cookies, and process handling. Users can run newer or less common browsers inside a sandbox with reduced manual configuration.
  • Vintage View Mode. Reproduces the graphical appearance of the original Sandboxie Control interface. Users familiar with older versions can switch to this mode for a consistent visual experience. The mode changes window layout, icons, and color scheme while retaining all new functionality. It is a cosmetic option that does not affect security or compatibility.
  • Troubleshooting Wizard. Assists users in diagnosing problems with sandbox operation. The wizard asks a series of questions about symptoms and then suggests specific steps or configuration changes. It can check driver status, service state, and common misconfigurations. The output helps resolve issues without searching through documentation manually.
  • Add-on Manager. Extends functionality through additional components installed separately. Users can browse, enable, or disable add-ons from within the interface. Add-ons may provide new templates, language packs, or specialized tools. This system keeps the core application lean while allowing optional features to be added when needed.
  • Protection Against Host. Prevents sandboxed processes from taking screenshots or capturing host screen content. This protection reduces the ability of malicious software to record visual information from outside the sandbox. The setting is enforced at a low level and cannot be bypassed by standard graphical APIs.
  • Trigger System. Performs actions when a sandbox goes through different stages such as initialization, start, termination, or file recovery. Users define triggers for each stage and assign actions like running a script, showing a message, or deleting specific files. This automation supports custom workflows and integration with external tools.
  • Process Sandboxing Control. Allows a process to run outside the sandbox while forcing its child processes to be sandboxed. This split mode is used for parent applications that must access host resources but spawn untrusted child processes. Configuration is per process and can be combined with other restrictions.
  • Force SOCKS5 Proxy. Automatically directs network traffic from selected programs through a user-provided SOCKS5 proxy. The proxy address and authentication can be set for each sandbox. This feature is used to hide real IP addresses or to test network applications through different geographic locations.
  • DNS Control. Blocks or redirects DNS queries from sandboxed processes. Users can specify which domains are resolved to alternative addresses or denied entirely. This control operates before the query reaches the host DNS resolver. It is useful for filtering unwanted domains or redirecting traffic to local servers.
  • Memory Usage Limits. Limits the amount of memory space a single process in the sandbox can occupy and the total memory space all processes can use together. These limits prevent a runaway application from exhausting system resources. Users can also limit the total number of sandboxed processes per box.
  • Token Creation Mechanism. Uses a completely different token creation method from the pre-open-source Sandboxie version. This makes sandboxes more independent in the system and reduces conflicts with host security mechanisms. The new token system improves compatibility with modern Windows versions and services.
  • Encrypted Sandbox. Provides an AES-based data storage solution for sandbox contents. Files written inside the sandbox are encrypted before being stored on the host drive. The encryption key can be tied to the user account or a separate password. This protects data even if the host disk is accessed outside Windows.
  • Unique Identifier Prevention. Prevents sandboxed programs from generating unnecessary unique identifiers in the normal way. Some applications create hardware-based IDs or other fingerprints that could be used for tracking. This feature blocks or randomizes such identifiers to reduce tracking and improve privacy.
  • Internal INI Editor. An integrated editor for Sandboxie configuration files that provides visual hints and tooltips. As users type settings, the editor displays information about valid values and their effects. This reduces syntax errors and helps discover available options. The editor supports search and context-aware autocompletion.
  • External Text Editor Configuration. Allows users to select an external text editor instead of the system default for editing INI files. The configured editor is launched from within Sandboxie Plus when configuration files need manual changes. This is useful for users who prefer editors with specific features like syntax highlighting or version control integration.
  • Border Alpha Transparency Control. Adjusts the alpha transparency of the colored border drawn around sandboxed windows. Users can make the border more or less visible depending on their preference. The setting applies globally or per sandbox and helps identify which windows are running inside an isolated environment.
  • Custom UAC Dialog. Provides a custom User Account Control dialog for sandboxed processes that request elevation. Users can choose to fake permission, grant real permission, or cancel the elevation attempt. This gives control over how sandboxed applications interact with Windows security prompts.
  • Modern Icons. Uses updated icon sets throughout the interface while allowing old-school icons in certain places. Users can switch between icon styles for different elements. The visual update improves recognition of functions without changing the underlying behavior of the program.
  • User Interface Font Change. Allows changing the font used in the Sandboxie Plus interface. Users can select from installed system fonts and adjust size. This customization improves readability on different display configurations and personal preferences.
  • Custom Colors and Icons for Sandboxes. Assigns custom colors or icons to individual sandboxes or groups of sandboxes. Visual markers help distinguish multiple sandboxes at a glance. The settings appear in the main list and on window borders if enabled.

Sandboxie was originally developed by Ronen Tzur and released in 2004. The program was later acquired by Invincea in 2013 and then by Sophos in 2017. Sophos continued development under the name Sandboxie and eventually released the source code as open source in 2020. After the source code became available, the community forked the project and David Xanatos began developing Sandboxie Plus as a modern branch. The original Sandboxie Classic remains available with the older interface, while Sandboxie Plus receives new features and updates. The software is written primarily in C and C++ with the user interface based on the Qt framework.

Alternatives to Sandboxie Plus:

Kudu Cleaner — Free Download. System cleanup

Kudu Cleaner

Kudu Cleaner is a free, open-source system maintenance suite offering over fifteen built-in tools for Windows, macOS, and Linux.
Price: Free   Size: 121.8 MB   Version: 3.1.0   OS: Windows, Mac OS, Linux
Aerium Browser — Free Download. Private fast browsing

Aerium Browser

Aerium Browser is a free web client for Android, Windows, and Linux engineered for speed, strict privacy, and minimal system resource consumption.
Price: Free   Size: 121 MB   Version: 152.0.7977.64   OS: Windows, Linux, Android
Argente Utilities — Free Download. System suite

Argente Utilities

Argente Utilities is a full-featured maintenance suite that cleans, optimizes and protects your system with a wide variety of tools.
Price: Free   Size: 60.1 MB   Version: 3.0.9.5   OS: Windows