Windows Defender Antivirus can run in a sandbox on Windows 10, from version 1703 onwards.
What does this mean;
By place of Windows Defender Antivirus inside a sandbox, Microsoft makes it very difficult for malware developers to gain access to critical system features, as the sandboxed programs they are isolated from the rest of the system, having extremely limited access to memory and minimal disk resources.
Η activation ενός περιβάλλοντος implementationof restricted processes for Windows Defender Antivirus is a decision Microsoft made when too many security researchers characterized the antivirus solution as a program which can be used for attacks!
Windows Defender Antivirus uses administrator and system privileges to be able to constantly monitor and destroy malicious attacks, making it an ideal target for attackers who want a simple way to obtain administrator privileges in the victim's system.
With Windows Defender Antivirus running sandbox as the default Windows antivirus solution, Microsoft wants to be sure that those who manage to take advantage of Windows Defender security flaws will not be able to acquire system or administrator rights.
Windows Defender Antivirus and the rest of Windows Defender's Stack ATP are integrated with other Microsoft 365 security components to form the new Microsoft Threat Protection.
Although Microsoft is only opening up the Windows Defender Antivirus feature to Windows Insiders, other Windows 10 users can enable the feature with a command line orders.
Open a command-prompt window with Administrator permissions (in Windows search, write cmd and the icon to display, right-click and open as administrator). When the window opens, type the following command and press Enter:
setx / M MP_FORCE_USE_SANDBOX 1
That was when you just added another security feature to your system!
Watch the Microsoft video
https://www.youtube.com/watch?v=Xy3MOxkX_o4
___________________________
- Windows Disable unnecessary services
- Malware: Why reuse the code
- Windows 10 October 2018 the failure of telemetry