ABUSE POLICY
Acceptable use guidelines for 0x12DarkSandbox
Operator
0x12DarkSandbox is operated by 0x12 Dark Development, a sole trader registered in Spain. This platform provides automated malware analysis services for security research and professional use.
Last updated: May 2026 · Governing law: Kingdom of Spain / European Union
Permitted Uses
The following activities are explicitly welcomed on this platform:
- Malware research and behavioral analysis
- Incident response — analysis of suspicious files from your own infrastructure
- Penetration testing of systems you own or have written authorization to test
- SOC and threat intelligence operations
- Academic and educational research on malware
- AV/EDR vendor testing and detection research
- Red team analysis of custom payloads against authorized targets
Prohibited Uses
The following uses are prohibited and may result in immediate account suspension:
- Submitting samples with the intent to refine or deploy them against systems you do not own or have no authorization to access
- Using analysis results to actively attack third-party systems or infrastructure
- Attempting to escape or compromise the sandbox infrastructure
- Creating multiple accounts to circumvent service limits or the free credit system
- Automated bulk submission intended to degrade platform performance for other users
- Any use that violates applicable Spanish law or EU regulations, including Computer Fraud directives
Sample Submissions
We accept all file types for analysis purposes, including live malware, functional ransomware, samples with active C2 communication, and other high-risk binaries. The platform is designed for exactly this use case and imposes no blanket restrictions on sample content.
The determining factor is intent: submitting a sample to understand its behavior is permitted; submitting a sample to improve it for deployment against unauthorized targets is not.
Submitted binaries are permanently deleted from our infrastructure immediately after analysis completes. Analysis results and metadata (hashes, detections, telemetry) are retained as part of your job history.
Enforcement
0x12 Dark Development reserves the right to suspend or terminate any account, at any time, with or without prior notice. No refund of unused credits is guaranteed in cases of policy violation. Enforcement decisions are at the sole discretion of the operator.
We do not proactively report users to law enforcement agencies. See below regarding legally compelled disclosures.
Law Enforcement Cooperation
As an operator subject to Spanish and EU law, 0x12 Dark Development will cooperate with legally binding requests from competent authorities — including court orders, judicial warrants, and formal requests from Spanish law enforcement (Policía Nacional, Guardia Civil) or equivalent EU bodies — when required to do so by law.
We will not voluntarily disclose user data to any authority absent a valid legal requirement.
Data Retention After Suspension
Upon account suspension for policy violations, associated account data — including submitted samples, analysis results, and account metadata — is retained for 7 days, after which it is permanently deleted. This retention window exists solely to support potential legal review or internal dispute resolution.
Contact
To report abuse, suspicious activity, or policy violations:
For general support, use the support ticket system.