Skip to content

Closed Key Path

ClosedKeyPath is a sandbox setting in Sandboxie Ini. It specifies path patterns for which a winning Closed rule denies new hooked registry opens or creates, including read access.

Program Name Prefix may be specified.

Example:

   .
   .
   .
   [DefaultBox]
   ClosedKeyPath=!msimn.exe,HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager

The example blocks any program other than Outlook Express (msimn.exe) from accessing the registry key containing configured email accounts for the active user account.

The value specified for ClosedKeyPath can include wildcards, although for registry keys, the use of wildcards is rarely needed. For more information on this, including examples that show the use of wildcards, see OpenFilePath. (OpenFilePath deals with files, not registry keys, but the principle of using wildcards remains the same.)

Note: For a new hooked registry open/create, a winning Closed rule is checked before the normal sandbox-copy path. The existence of a sandbox copy does not by itself bypass the rule. Already-open handles are separate; changing the rule does not imply revocation of a handle that was previously granted.

Note: Unlike the ordinary eligibility restriction on OpenKeyPath, Closed rules can apply even when the executable resides inside the sandbox. When AlwaysCloseForBoxed is active, a negated program selector does not provide its usual exemption to an executable inside the sandbox; this qualifies the example above.

Related Sandboxie Control setting: Sandbox Settings > Resource Access > Registry Access > Blocked Access

Related Sandboxie Plus setting: Sandbox Options > Resource Access > Registry > Add Reg Key > Access column > Closed