arXiv · 2608.30383
Using Hyper-V Sockets for Real-time Data Extraction from a Malware Analysis Sandbox
Abstract
We present how Hyper-V sockets can be used as a real-time communication channel for a malware analysis sandbox. We show that, compared to WinSock TCP sockets, Hyper-V sockets are not subject to TCP/IP-layer blocking and are not enumerated by common TCP connection listing tools. We compare the throughput of the two communication channels as a function of buffer size.
Explore related subjects
Keep this discovery
István-Attila Császár, Radu-Marian Portase, Adrian Coleşa, Adrian Groza. 2026-08-31. Using Hyper-V Sockets for Real-time Data Extraction from a Malware Analysis Sandbox. https://doi.org/10.1109/aqtr70159.2026.11577802
Cite the original work for its findings. Save a collection to share your selection of sources.
Discover connections
Connections use source metadata and explicit phrase matches, not verified experimental comparisons.