Email Attachment Sandbox: Behavior Scoring Radar (2D)
Detonate a suspicious email attachment inside a 2D behavioral sandbox: watch scored runtime signatures (file writes, registry persistence, C2 beacons, process injection, credential access) travel to a rotatable category ring and a live radar chart while a weighted threat score drives an automated clean/suspicious/malicious verdict.
Modern email-security gateways don't just scan a suspicious attachment statically — they detonate it inside an isolated, instrumented sandbox VM and watch what it actually does at runtime. This 2D simulator renders that pipeline as a rotatable category ring: pick one of four attachment samples (a benign invoice macro, an info-stealer, a ransomware loader, or a fileless RAT), press Detonate, and watch scored behavioral events travel from the sandboxed sample out to five behavior-category nodes — File System, Registry, Network/C2, Process Injection and Credential Access — each pulsing and growing as it accumulates hits, while a live radar chart beneath the ring plots the accumulated severity per category. A weighted threat score builds on a 0–10 gauge exactly the way real dynamic-analysis engines (Cuckoo/CAPE-style signature scoring) compute it, a network-containment toggle demonstrates how a sandbox safely observes a C2 beacon without ever letting it reach a real server, and an adjustable malicious-threshold slider shows the detection trade-off security teams tune in production before the engine renders its clean / suspicious / malicious verdict. Drag inside the diagram to rotate the ring around the sample.
Detonate a suspicious email attachment inside a 2D behavioral sandbox: watch scored runtime signatures (file writes, registry persistence, C2 beacons, process injection, credential access) travel to a rotatable category ring and a live radar chart while a weighted threat score drives an automated clean/suspicious/malicious verdict.
2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install