Thanks for sharing a very interesting project!
Windows already supports other sandboxing techniques, such as AppContainer isolation and Low Integrity Level isolation that can also be used for sandboxing of untrusted processes.
It would be nice if you could document how hyperlight compares against these other approaches, and provide some guidance on when hyperlight excel, and when traditional "process level" sandboxing is usually preferred?
Thanks for sharing a very interesting project!
Windows already supports other sandboxing techniques, such as AppContainer isolation and Low Integrity Level isolation that can also be used for sandboxing of untrusted processes.
It would be nice if you could document how hyperlight compares against these other approaches, and provide some guidance on when hyperlight excel, and when traditional "process level" sandboxing is usually preferred?