

This is what I do. I have a VM for torrents and a VM sandbox to check stuff that I’m concerned about. At the host level I disable any type of sharing with the host, no copy paste, no sharing disks, nothing. The VM only gets the storage I assign to it and once I validate then I’ll detach and mount it to the host.
I use Hyper-V because I run server 2022 and it’s free. Hyper-V allows you to disable any host resource sharing in the VM settings.
On my sandbox VM I’ll scan the files then install and scan, then run the software and scan. I use both defender and I think malwarebytes. It’s a lot of extra work for no gain, but I’d rather be too careful than risk installing malware.