Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsYou can reduce the risk of analyzing a suspected zero-day exploit by first examining preserved evidence without running the sample, then—only if necessary—executing it on an isolated, disposable test system. Neither a virtual machine nor a sandbox guarantees containment, and a sample that appears inactive may be hiding its behavior.
Can you analyze malware without running it?
Often, yes. Begin with forensic examination of the affected host and its artifacts rather than deliberately allowing the suspected code to execute again. NIST distinguishes this from active analysis, in which malware is run to observe its behavior. Forensic examination can answer some questions without continuing execution on that host.
Before containment, cleanup, or other changes that could alter the evidence, follow your organization’s evidence-handling procedures. CISA recommends collecting relevant system images, memory captures, logs, samples, and indicators where appropriate, and preserving volatile evidence that could be lost or tampered with. See the CISA #StopRansomware Guide.
Forensic examination
This approach avoids intentionally running the suspected malware on the affected host. It is preferable when the available evidence can address the incident question without active execution. Preserve and review relevant artifacts under your organization’s procedures; an active compromise may warrant qualified incident-response support.
Recommended Free Tools
#1 Best Overall
Active analysis
Execution can expose behavior that static or forensic examination does not show, but it deliberately runs the sample. NIST’s guidance says: “Ideal active approaches involve an incident handler acquiring a malware sample from an infected host and placing the malware on an isolated test system.” The statement appears in NIST SP 800-83 Rev. 1, Guide to Malware Incident Prevention and Handling for Desktops and Laptops, published July 22, 2013. It describes controlled analysis—not a guarantee that isolation cannot fail.
Is a sandbox enough to safely inspect an exploit?
No. Isolation can restrict code execution and limit access to other processes or system features, but it is not proof that a sample cannot escape. MITRE ATT&CK notes that sandbox escapes and weaknesses in isolation implementations remain possible. A consumer sandbox or ordinary virtual machine should not be treated as a guaranteed containment boundary.
A suspected zero-day’s status does not make it safe to handle. If execution is necessary, use an authorized, isolated test system that is separate from production. NIST describes using a virtualized operating-system image that can be restored to a known-good state after analysis, with tools to observe processes and network connections. That setup reduces exposure; it does not eliminate it.
Check the boundary before execution
- Keep the analysis system away from production hosts, networks, credentials, and sensitive data it does not need.
- Determine what the test environment can reach, including network connections and shared resources, and limit that reach to what the investigation requires.
- Use a restorable known-good system image and suitable process and network observation tools.
- Keep evidence and analysis activities within your organization’s authorization and incident-response procedures.
Why a sample can look harmless in a lab
A sample’s behavior in one environment is not necessarily its behavior everywhere. MITRE documents techniques that check for virtual machines, sandbox artifacts, signs of user activity, or elapsed time. A sample can use those checks to delay or suppress activity during analysis.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Therefore, “nothing happened” is an observation about that run, not evidence that the sample is harmless. Interpret results alongside preserved host evidence and the analysis environment’s limitations. MITRE’s Virtualization/Sandbox Evasion (T1497) describes these evasion techniques.
Choosing an analysis approach
| Approach | Execution exposure | Isolation boundary | Evidence and observability | Key limitation |
|---|---|---|---|---|
| Forensic examination | Does not deliberately continue malware execution on the affected host. | Examines preserved host evidence rather than relying on a test-run boundary. | Can use preserved system images, memory, logs, samples, and indicators where appropriate; findings depend on the artifacts available. | May not reveal behavior that only appears during execution. |
| Active analysis | Runs the sample on an isolated test system, not in production. | Must be assessed in terms of reachable hosts, networks, data, and shared resources; isolation can have weaknesses. | Can reveal behavior when process and network activity are observed. | Sandbox or virtualization checks may conceal behavior, and isolation does not guarantee containment. |
The choice depends on the question and the evidence already available. Forensic examination avoids deliberately continuing execution on the affected host; controlled execution may reveal behavior sooner, but introduces exposure and can still produce an incomplete picture.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When to involve incident response
If the host is actively compromised, evidence may be volatile, or safe isolation and evidence handling are uncertain, coordinate with your organization’s incident-response team or qualified responders before proceeding. NIST’s Computer Security Incident Handling Guide (SP 800-61 Rev. 2) provides broader organizational context for incident handling.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →

