Architectural Evaluation of Virtualization and Sandbox Technologies for Custom MCP-Driven Autonomous Malware Analysis
Background Autonomous malware analysis requires moving beyond static, predefined containment environments. Modern malware actively fingerprints its execution context, checking CPUID leaves, measuring execution time with RDTSC, and probing for virtualization-specific hardware devices [6, 13]. Traditional sandboxing methodologies rely on a one-size-fits-all containerization approach, which typically embeds an agent inside the guest OS to monitor API calls and system behavior [1, 12]. This in-guest presence provides a highly visible artifact for evasive malware to detect and subvert. ...