DiskCryptor v2.0.2

DiskCryptor version 2.0.2 marks the first stable release of the 2.x series, bringing together the major architectural improvements introduced in 2.0 with further performance gains, expanded ARM64 support, and important bootloader and reliability fixes. Following the initial beta releases, the new generation is now ready for stable use. Users running DiskCryptor 2.0.0 or 2.0.1 should upgrade.

All use of DiskCryptor remains at the user’s own risk. Before encrypting a volume or changing its configuration, always have a current backup on hand and verify that it can be restored. Strong encryption provides no backdoor or password reset: even a small user error, lost authentication material, damage to critical volume metadata, power loss, or hardware failure can result in permanent data loss. In the most cases recovery without backups will be impossible.

The 2.x series introduces Argon2id key derivation, providing a modern, memory-hard option for protecting volume passwords against cracking attacks. The new Version 2 volume header format adds independent key slots, allowing multiple passwords and keyfiles to unlock the same volume. Header and volume layout editors provide greater control over existing volumes, including resizing headers, managing optional backup headers, and changing relocation areas.

Optional TPM integration in the DCS bootloader enables hardware-backed authentication and unattended system unlock configurations. Together with optional Secure Boot support, it brings modern platform security features to DiskCryptor’s boot architecture. TPM and Secure Boot functionality require a DiskCryptor Pro Supporter Certificate, available from the Xanasoft web shop.

Version 2.0.2 further strengthens boot management. A new Boot Menu Lock driver prevents Windows from changing the boot order away from DCS. TPM handling has been improved by correcting the default PCR mask and adding a workaround for issues affecting some ARM64 devices. The new TpmKill option allows DCS to entirely block access to the TPM before handing control to the operating system.

The pre-boot interface now includes a full touch console, extending the on-screen keyboard support introduced in 2.0. The recovery menu has been reworked and expanded, communication between DCS modules has been redesigned, and the bootloader now accepts passwords up to the intended limit of 128 characters. Image verification for DcsLdr has been delegated to shim’s verification service, substantially reducing the size of DcsLdr.efi. New commands also allow shim to be installed or removed independently of the DCS loader.

These improvements build on USB keyfile support, a pre-boot configuration menu, and the option to install DCS on a dedicated EFI System Partition. The bootloader can also pass derived header keys directly to the Windows driver, avoiding a redundant key derivation during startup.

Encryption performance has improved by approximately 25% overall, with up to around 60% higher throughput for some ciphers. Version 2.0.2 also adds hardware cryptography support on ARM64. The broader 2.x improvements include skipping unused sectors during encryption and decryption, removing SSD chunking that reduced performance on modern drives, and an asynchronous volume processing engine that resolves low-memory deadlocks and re-encryption race conditions.

Storage protection and usability have received substantial updates as well. Optional backup headers provide additional recovery options, while RAW volume protection helps prevent accidental writes or formatting of volumes without a recognized file system. Secure desktop password entry, virtual keyfiles, integrated TPM management, password caching controls, and a reorganized interface make both everyday use and advanced configuration easier.

This final release also fixes the hibernation issue introduced in Version 1.4.0, removing the need to use the legacy handoff workaround available in 2.0.1. Further corrections address default boot-volume presets on MBR systems and unwanted status output when no prompt is enabled. It includes the earlier 2.0.1 fixes for ARM64 crashes and bootloader compatibility, volume resizing, backup-header corruption, storage-file handling, and keyslot initialization.

DiskCryptor 2.0.2 completes the transition to the new 2.x generation, combining modern key derivation, flexible authentication, improved boot security, and faster encryption with the lightweight design and control over encrypted storage that define the project.

Download: https://github.com/DiskCryptor/DiskCryptor/releases/tag/v2.0.2

Sandboxie-Plus v1.18.5 / 5.73.5 Released

This release fixes a compatibility issue that caused Chromium-based browsers and many Electron applications to crash when launched in Application Compartment boxes. The cause was incorrect hook target detection. With this fixed, desktop applications built on Electron, including Claude Desktop and similar apps, should now run more reliably in these boxes.

It also fixes how Sandboxie handles File IDs queried through fsutil. These IDs are now inverted consistently with File IDs returned through other methods (#5612).

Sandboxie Plus 1.18.5 is primarily a maintenance and usability release, with the most visible improvements affecting INI editing and completion behavior while also tightening shell notification routing and addressing several smaller issues reported since the previous release.

Download: https://github.com/sandboxie-plus/Sandboxie/releases/tag/v1.18.5

ShadowFreeze 1.0.5 Released – First Final Release

I am pleased to announce the release of ShadowFreeze 1.0.5, the first final release of ShadowFreeze.

ShadowFreeze is a Windows disk virtualization and system-freezing solution designed to protect a system volume by redirecting changes into an overlay. While protection is active, applications and Windows continue to see and use the system normally, but modifications are kept separate from the original disk state. After discarding the overlay and rebooting, the system returns to its previous state.

Unlike a traditional sandbox, ShadowFreeze operates at the storage layer and can therefore protect the complete Windows installation rather than individual applications. The underlying, unmodified disk state can also be mounted separately when required, allowing files to be accessed or deliberately modified outside the active virtualized view.

The 1.0.x development and testing cycle concentrated heavily on filesystem correctness, persistence, recovery behavior, and compatibility with modern storage configurations. This included fixes for FAT32, exFAT and ReFS handling, overlay resume and persistence, metadata integrity, race conditions and deadlocks, as well as support for native 4K-sector drives.

Version 1.0.5 marks the point at which ShadowFreeze is considered ready for normal use rather than being an experimental preview. This release disables the remaining debug logging code and includes the latest version of the integrated disk toolbox.

As with any software operating directly on storage devices and filesystem data, maintaining a current and verified backup of important data is strongly recommended. ShadowFreeze is intended to make system experimentation, testing and recovery significantly easier, but it should not be considered a replacement for proper backups.

Thank you to everyone who tested the early builds and reported issues. The feedback during the 1.0 development cycle helped uncover and resolve a substantial number of edge cases that would otherwise have been very difficult to reproduce.

Download: https://shadowfreeze.com/Downloads/ShadowFreeze/ShadowFreeze-v1.0.5.exe

Task Explorer v2.0.0 Released

Task Explorer 2.0 is a major release introducing native Linux support and remote system monitoring.

Task Explorer is now available natively for Linux on both x64 and ARM64. The Linux version includes Wine integration, allowing Task Explorer to expose additional Windows-specific information for Wine processes, including Windows process names and PIDs, handles, windows and tokens.

The second major addition is remote monitoring through the new TaskServer and TaskRemote components. Task Explorer can now connect to and monitor remote Windows and Linux systems, including cross-platform connections, and multiple machines can be monitored simultaneously. Machine selection and cluster-mode controls have been added directly to the toolbar to make working with multiple systems easier. Remote access includes secure authentication, encrypted credential storage and automatic discovery of TaskServer instances on the local network. Remote monitoring requires a Task Explorer supporter certificate, available from the Xanasoft store at xanasoft.com.

On Windows, Task Explorer 2.0 also introduces optional Window Agents that allow windows belonging to other user sessions to be enumerated and controlled. The built-in Windows security object editor has been replaced with a custom permissions editor.

Under the hood, much of Task Explorer has been reorganized around a new system abstraction layer that allows local Windows, local Linux and remote systems to be handled through the same interfaces. PHlib has also been updated to version 4.0.26241. These architectural changes provide the foundation for further expansion of Task Explorer's cross-platform and remote-management capabilities.

Download: https://github.com/DavidXanatos/TaskExplorer/releases/tag/v2.0.0

Sandboxie-Plus v1.18.4 Released

This release focuses primarily on refinements to SandMan’s INI editor, shell notification handling, and several smaller reliability fixes.

The SandMan INI editor has received a substantial auto-completion overhaul. Completion candidates are now ranked using context-aware semantic matching and fuzzy matching, while metadata is synchronized independently for each editor instance. Refreshes are also deferred during rapid typing or deletion to reduce unnecessary updates and improve responsiveness.

The completion popup itself has also been refined. Candidate tooltips no longer retain stale information while editing, Template and TemplateReject entries now show only the relevant setting-name information, and large description tooltips have been adjusted to avoid jumping unnecessarily between sides or obscuring completion candidates.

Shell notification handling has also been updated. UseShellNotifyIconProxy remains enabled by default when OpenWinClass=* is configured, preserving the behavior required by these sandboxes, while other sandboxed processes now use direct routing by default unless proxying is explicitly enabled. To make troubleshooting this behavior easier, low-noise SbieTrace logging has been added for Shell_NotifyIconW calls. The trace records the notification message, icon identity using either NIF_GUID/GUID or HWND/uID, and whether the effective route was direct or through the proxy.

A problem with shortcuts created from SandMan’s File Panel has been fixed. Previously, the “Create Shortcut” action did not set a working directory, causing sandboxed applications to inherit SandMan’s current directory. Programs relying on relative paths could consequently fail to locate their data files. Shortcuts created through the File Panel now receive the appropriate working directory.

This release additionally fixes an incorrect return type in SbieSvc and corrects archive path cleaning behavior.

Sandboxie Plus 1.18.4 is primarily a maintenance and usability release, with the most visible improvements affecting INI editing and completion behavior while also tightening shell notification routing and addressing several smaller issues reported since the previous release.

Download: https://github.com/sandboxie-plus/Sandboxie/releases/tag/v1.18.4

ShadowFreeze v1.0.3

ShadowFreeze keeps your PC in a known-good state. You take a snapshot of a disk partition — or your
whole Windows system drive — and from that moment on every change is written to a temporary shadow
instead of the real disk. When you reboot (or unfreeze on demand), all of those changes vanish and the
partition returns exactly to how it was at the moment you froze it.

Now with fully signed driver, still in beta though try at your own risk.

Download: https://shadowfreeze.com/Downloads/ShadowFreeze-v1.0.3.exe

And the website is also ready: https://shadowfreeze.com/

Sandboxie-Plus v1.18.3

Sandboxie-Plus 1.18.3 is a maintenance release focused primarily on stability, usability, and compatibility improvements across SandMan, Start.exe, and the tracing subsystem.

The standalone SandMan trace monitor now provides a visible Cleanup Trace Log action, making it easier to clear accumulated trace data directly from the monitor.

Several issues in the SandMan user interface have been addressed. Changes made to the File Migration action dropdown are now correctly preserved when clicking Apply or OK while the editor still has keyboard focus. The File Panel and Browse Files views have also been improved when deleting files or folders: expanded directory states are retained, and the interface now restores the selection, keyboard focus, and scroll position to the nearest remaining item instead of unexpectedly resetting the view.

The trace logging subsystem received a number of stability and state-management fixes. Crashes and stale entries that could occur when clearing the Trace Log while both integrated and standalone trace views were open have been resolved. The standalone Trace Logging controls now correctly reflect the actual monitor state and no longer inadvertently disable logging when the monitor window is closed. When closing the standalone monitor while tracing remains active, Sandboxie now offers the choice to stop logging and clear the log, disable logging while retaining the existing log data, or leave logging running in the background.

Start.exe autorun handling has been made more robust. It now correctly handles oversized registry values, applies proper bounds to shortcut paths, supports paginated Startup directories, and dynamically allocates launch command lines instead of relying on fixed-size buffers. These changes improve reliability in systems with unusually large or complex autorun configurations.

This release also restores compatibility with Firefox 154 in Standard Isolation mode.

Finally, an initialization issue affecting sandboxed processes that already carry an AppContainer token has been fixed.

Download: https://github.com/sandboxie-plus/Sandboxie/releases/tag/v1.18.3

Sandboxie-Plus v1.18.2

Sandboxie Plus 1.18.2 / 5.73.2 is a maintenance and usability update that brings several refinements to SandMan, improves compatibility with recent Windows Insider builds, and fixes a number of long-standing UI and driver-related issues.

Sandboxed-window borders have gained new outside-border modes, allowing the configured border to be drawn outside the application frame. For maximized and snapped windows, the new BorderInsideMaximized=y option, enabled by default, automatically moves the border and label inside the window so they remain visible.

SandMan now remembers manually expanded and collapsed process-tree branches across refreshes and restarts. The Auto Expand Tree option has been adjusted accordingly and now acts as the default only for items without an explicitly remembered state. Sandbox groups are likewise kept in their chosen expanded or collapsed state more reliably.

A new global BoxAliasDisplayMode allows display-only aliases to be used for sandbox names throughout SandMan, Start.exe, window titles, borders, tooltips, recovery logs, and messages, while the actual sandbox name continues to be used internally for paths and operations. Imported sandbox archives can optionally restore their saved aliases as well.

The tray menu can now provide a literal search field for quickly filtering sandboxes and groups, and automatic sandbox cleanup gained an option to restore either the active or the default snapshot after deletion. Snapshot management and refresh controls have also been integrated into the relevant settings.

Trace Log handling has been improved so automatic scrolling no longer fights manual navigation. Scrolling away from the bottom now pauses auto-scroll and presents an in-list control for resuming it.

This release also updates DynData and restores driver compatibility with the latest Windows Insider builds, including validation against Windows build 29634.

Among the fixes are corrected File Panel column persistence, more reliable open-handle reporting, improved file sorting, proper Recycle Bin deletion of expanded directory trees, and a fix for registry hive log files such as RegHive.LOG1 and RegHive.LOG2 being incorrectly treated as descendants of RegHive. Several character-versus-byte buffer size issues affecting shortcuts, window class names, configuration reads, driver-log retrieval, and icon-path IPC handling have also been corrected.

ApiTrace has been reworked to avoid stack exhaustion on Cygwin and other environments using unusually small or alternate stacks, while retaining legacy event ordering and stack capture. Stack symbol resolution has also been improved by retrying unresolved addresses after process discovery and refreshing the DbgHelp module list when necessary.

Finally, the release fixes an issue where SandMan could unnecessarily offer to install the DbgHelp add-on when it was already present, as well as a ConfidentialBox=y elevation problem that could leave the user stuck on a black screen.

Download: https://github.com/sandboxie-plus/Sandboxie/releases/tag/v1.18.2

ShadowFreeze UNSIGNED Beta v1.0.0

I'm excited to finally share the first public preview of ShadowFreeze, a new lightweight disk virtualization tool for Windows.

ShadowFreeze allows you to freeze partitions, redirect all changes into a temporary overlay, and return the system to its original state with a simple reboot. The project aims to provide a modern, actively maintained alternative to classic disk-freezing solutions, while adding new capabilities and long-term support.

This is still a very early preview intended for enthusiasts and experienced testers. The core functionality is already usable, but many features are still under development and there has only been limited testing on different hardware and Windows versions.

Important Warning

The current preview build includes an unsigned kernel driver and installer. As a result, it can only be used on systems with Windows Test Signing enabled.

This build should not be installed on a production machine. Although it has worked well in my testing so far, it is still an early development build and may contain serious bugs that could lead to data loss or an unbootable system.

Please make sure you have a recent backup. Ideally, use a virtual machine or a dedicated test system.

I'm looking forward to your feedback, bug reports, and suggestions. Your testing will help shape ShadowFreeze into a reliable replacement for existing disk-freezing solutions.

Happy testing!

Download: https://shadowfreeze.com/downloads/