Sandboxie Plus isolates apps from the host system to prevent persistent changes. Every file operation and registry modification is redirected into a contained space. The program is used for testing software, browsing the web, and opening email attachments without risk to the main operating system. Network traffic can be restricted per sandbox, and snapshot restoration returns environments to earlier states. Memory and process limits prevent resource exhaustion by isolated applications.
The application includes encrypted storage, privacy protection against data reading, and prevention of screenshot capture by sandboxed processes. A trigger system automates actions during sandbox lifecycle events. Configuration is managed through a built-in INI editor with context-aware autocompletion. Sandboxes can be exported to 7z archives and imported on other computers. Portable mode supports running from removable media.
Development of Sandboxie Plus continues with regular releases that address reliability and shell notification handling. The interface provides direct control over driver and service components. Users can block access to Windows resources such as printer spooler and clipboard. A browser compatibility wizard generates templates for unsupported web browsers. The software supports 32-bit and 64-bit Windows NT-based operating systems.
| Instant sandbox state capture for reliable rollback | Restore previous system image after failed configuration |
| Graphical control over kernel driver lifecycle operations | Visual feedback for service installation and startup failures |
| Extract runtime binaries without permanent system integration | Carry isolated environment on removable storage media |
| Restrict sandboxed access to shared Windows clipboard resources | Block print spooler interaction from untrusted processes |
| Granular egress filtering by protocol address and port | Define per-box executable launch and network policies |
| Prevent reading of user profile and document directories | Deny sensitive filesystem paths before host access |
| Reduce kernel attack surface via syscall restrictions | Disable unused network endpoints for sandboxed processes |
| Single keystroke suspension of all boxed activity | Emergency terminate all isolated processes immediately |
| WFP-based per-sandbox network traffic inspection | Isolated firewall policies for direction-based filtering |
| Keyword filter locates advanced configuration parameters quickly | Highlight matching entries across hidden settings sections |
| Compress sandbox state into portable 7z archives | Migrate full isolated environment between host machines |
| Direct launch isolated applications from Start menu | Create per-program shortcuts for boxed execution |
| Generate isolation templates for unsupported browser binaries | Auto-configure cache and cookie handling rules |
| Reproduce legacy Sandboxie Control interface aesthetics | Switch visual theme without altering security behavior |
| Interactive diagnostic questionnaire for sandbox malfunctions | Automated driver and service state verification |
| Modular extension system for optional feature installation | Enable language packs and specialized templates separately |
| Block host screen capture from inside sandbox | Low-level enforcement preventing visual data leakage |
| Automate actions during sandbox lifecycle transitions | Run scripts on initialization termination or recovery |
| Parent runs natively while children get sandboxed | Split execution for host-dependent untrusted spawners |
| Force selected applications through SOCKS5 tunnel | Mask real IP or test geo-specific routing |