But, what are the rootkit methods which are used by Sandboxie and are not used by AVs, MemProtect, and popular security software?
MemProtect isn't doing anything rootkit-like.
Third-party AVs occassionally use rootkit-like techniques in 2019 but not to the excess that Sandboxie does. There are times when there's no viable alternate to API hooking and the pro's outweigh the con's... but Sandboxie is excused because there are better designs it could be following. Third-party AVs have been taking a hit from companies like Microsoft, Firefox and Google anyway - needless to say, the rootkit-like techniques in third-party AVs are beginning to decrease as they are put under the microscope. Sandboxie could be hooking a guest environment but instead they are hooking the host environment, even when you're running hardware capable of handling all of the virtualization overhead without breaking a sweat.
For the record, many third-party AVs do a lot of stupid things. It's why I don't use any third-party AVs. Google and Firefox have a pattern of disliking third-party AVs due to the stupid things they often do.
It's over-kill to use a design like a hypervisor when you only need to monitor a few APIs, but when you need to literally isolate a program to prevent it from damaging the host, that'd be ideal for a hypervisor.
Sandboxie could use VirtualBox engine like Avast do and there's even the ability to reverse-engineer and leverage Hyper-V APIs (it's legal under interoperability purposes in the UK and U.S) but they aren't even trying any of this. They do not even need to do all of the work themselves to change the design to make it up to scratch with modern sandbox systems. Sandboxie is living a life of 2010 in 2019 and SOPHOS aren't going to do a thing about it, because Sandboxie is too dead for SOPHOS to care less.
It's clear that SOPHOS does not really care about Sandboxie either. Sandboxie does not have a lot of attention from them, it's left ditched on the side roads... and even the spokesman on the forum called Barbara doesn't know about many important things, like a proper channel for reporting critical vulnerabilities. That in itself is a big problem.
I do not know why SOPHOS bought Sandboxie in the first place.