Email Attachment Sandbox Detonation
Detonate a suspicious email attachment inside a live 3D sandbox: watch its runtime behavior (file writes, registry persistence, C2 beacons, process injection, credential access) accumulate into a weighted threat score and trigger an automated verdict.
Modern email-security gateways don't just scan a suspicious attachment statically — they detonate it inside an isolated, instrumented sandbox VM and watch what it actually does at runtime. This simulator renders that pipeline in 3D: pick one of four attachment samples (a benign invoice macro, an info-stealer, a ransomware loader, or a fileless RAT), press Detonate, and watch scored behavioral events travel from the sandboxed file out to five behavior-category nodes — File System, Registry, Network/C2, Process Injection and Credential Access — each pulsing and growing as it accumulates hits. A weighted threat score builds live on a 0–10 gauge exactly the way real dynamic-analysis engines (Cuckoo/CAPE-style signature scoring) compute it, a network-containment toggle demonstrates how a sandbox safely observes a C2 beacon without ever letting it reach a real server, and an adjustable malicious-threshold slider shows the detection trade-off security teams tune in production before the engine renders its clean / suspicious / malicious verdict.
Detonate a suspicious email attachment inside a live 3D sandbox and watch its runtime behavior — file writes, registry persistence, C2 beacons, process injection, credential access — accumulate into a weighted threat score that drives an automated clean/suspicious/malicious verdict.
3D · Three.js / WebGL renderer · 60 FPS target · runs fully client-side, no install