---
title: ANY.RUN Sandbox Reviews
meta_title: 'ANY.RUN Sandbox Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 218 reviews by the users' company size, role or industry
  to find out how ANY.RUN Sandbox works for a business like yours.
aggregate_rating:
  rating_value: 4.7
  review_count: 218
  scale: '5'
date_modified: '2026-08-12'
parent_category:
  name: System Security
  url: https://www.g2.com/categories/system-security
---


# ANY.RUN Sandbox Reviews
**Vendor:** ANY.RUN  
**Category:** [Malware Analysis Tools](https://www.g2.com/categories/malware-analysis-tools)  
**Average Rating:** 4.7/5.0  
**Total Reviews:** 218
## About ANY.RUN Sandbox
ANY.RUN&#39;s Interactive Sandbox is a cloud-based service for in-depth malware analysis. It offers visibility into threat behavior based on interactivity that allows you to detonate threats, fine-tune analysis, and see the entire attack unfold with insights into related network activities, system processes, and TTPs in use. The environment is secure, configurable, and supports Windows, Linux, and Android. The sandbox provides SOC teams with a simple yet highly detailed way to break down cyber threats for fast decision making, investigation, and response.




## ANY.RUN Sandbox Reviews
  ### 1. Excellent interactive sandbox allowing deeper analysis of URLs and Files than traditional sandboxes.

**Rating:** 5.0/5.0 stars

**Reviewed by:** todd.cates@northpointe.com C. | Senior Information Security Analyst., Mid-Market (51-1000 emp.)

**Reviewed Date:** August 18, 2025

**What do you like best about ANY.RUN Sandbox?**

I have yet to come across another sandbox that has such a robust user interface and granular level of detail that you can interact with to truly get the full picture of the file or URL you are analyzing. The enterprise version has a SIGNIFICANT number of features that are not available in the free community version. I liked the ability to select the country you want the client URL to impersonate to circumvent geofencing restrictions on malicious URLs. Set up seemed very straight forward and really required minimal effort to take advantage of the available functions. The available automations and integrations with other security tooling is also a tremendous bonus. I utilize this tool on a daily basis and frequently integrate the reports generated in the documentation we do internally around events. My interactions with the support staff have been good and they are knowledgeable and helpful.

**What do you dislike about ANY.RUN Sandbox?**

If there was any downside, it would be that the UI can be a little intimidating. There are so many features and functions that this tool has, so there is a bit of a learning curve at first about where to find all of them. However, support staff are very helpful and with time and repetition the features become more intuitive as you use it more.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN allows us to be more thorough and detailed with our investigations of suspicious links or files. Rather than just trusting the output of integrated sandboxes with other solutions in our ecosystem, if something doesn't feel right we can submit the URL or file to ANY.RUN and view the behavior with our own eyes and make a more informed verdict around the status of the URL or file. The level of detail it provides is tremendously helpful in identifying IOCs that we can then turn into actionable steps to enhance our overall security posture.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

  ### 2. Deep Malware Visibility: Trace Every Action and Payload with Ease

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ajay K. | IT Analyst, Security, Risk and Compliance, Mid-Market (51-1000 emp.)

**Reviewed Date:** February 09, 2026

**What do you like best about ANY.RUN Sandbox?**

It helps to see every piece of action done by the malware. From dropping file to injecting code each of them can be traced. Also not only the domain and ip it’s connecting but we can also see the payload it contains such a great experience

**What do you dislike about ANY.RUN Sandbox?**

The limit of uploading max of 25mb file.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Malware analysis

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 3. Enhanced Analysis, Streamlines SOC Workflow

**Rating:** 4.0/5.0 stars

**Reviewed by:** Julian G. | Information Security Analyst

**Reviewed Date:** October 30, 2025

**What do you like best about ANY.RUN Sandbox?**

I really enjoyed the interface of ANY.RUN Sandbox, which encouraged me to continue using it and incorporate it into our SOC workflow. Switching from a virtual sandbox, I appreciated the more in-depth analysis that ANY.RUN Sandbox provides, which stands out as a valuable feature. The setup process was straightforward and hassle-free, which was a significant advantage, and I would gladly repeat the process if necessary. ANY.RUN Sandbox significantly benefits my role by allowing me to efficiently investigate incidents and phishing emails with clarity and enhanced efficiency. I particularly like the different modes of investigation available, such as investigating URLs, files, and suspicious websites, which I can tailor to fit my workflow, ultimately improving my overall processes. The software’s efficiency, which allows me to carry out my work seamlessly, is a real selling point for me, and I would consider purchasing it again for this reason.

**What do you dislike about ANY.RUN Sandbox?**

I would make the user interface a little simpler as it is kind of complicated.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN Sandbox lets me efficiently investigate incidents and phishing emails, tailoring different investigation methods into my workflow and enhancing my processes.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 4. Effortlessly Intuitive and Time-Saving Analysis Tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** Scott W.

**Reviewed Date:** October 30, 2025

**What do you like best about ANY.RUN Sandbox?**

I have been using ANY.RUN Sandbox for approximately two years, and I truly appreciate its intuitive interface, which makes it very straightforward to gain access to the tool and navigate through the features. The UI is straightforward, which makes my tasks easier and saves a lot of time, as it clearly guides how to submit files, emails, and URLs for analysis of potentially malicious content. The tool’s quick analysis capabilities are impressive, providing rapid and detailed assessments about whether something is malicious, which is crucial in my cybersecurity role. I particularly value the ability of the tool to dissect the entire lifecycle of a process, revealing network connections, HTTP requests, DNS requests, and providing detailed threat analysis. The AI-assessed summaries and IOC breakouts have been significantly beneficial from a business standpoint, offering detailed insights which enhance our forensic analysis and ability to respond quickly to cyber incidents. The setup process was pretty straightforward and I was able to quickly start using Any.Run. ANY.RUN Sandbox has proven to be very consistent in its usage compared to other options I considered, making it a reliable choice for conducting cybersecurity analysis. Additionally, its competitive pricing in the market adds to its value, making it a highly commendable tool. Overall, I rate it 10 out of 10 and have recommended it to many colleagues due to its comprehensive and easy-to-use features.

**What do you dislike about ANY.RUN Sandbox?**

I have not found any shortcomings with the product.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

I use ANY.RUN Sandbox to efficiently analyze suspicious files and URLs, saving time and enabling faster, educated responses to potential threats.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 5. Easy to Use, Clear Malware Insights with Strong Community Visibility

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** February 25, 2026

**What do you like best about ANY.RUN Sandbox?**

It’s easy to use, and the fact that it’s widely adopted by the community gives you a lot of visibility into malware and malicious sites. The IOCs and malware configurations are presented in a clear, well-organized format that’s simple to view and understand.

**What do you dislike about ANY.RUN Sandbox?**

No direct downsides come to mind. A more granular search of samples/URLs would be extremely useful.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Provides a good first impression of a malware or a suspicious website, therefore giving a good direction on where to start manual analysis and what to first expect of the sample.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 6. Excellent Dynamic Malware Analysis with Deep Registry and Syscall Insights

**Rating:** 4.5/5.0 stars

**Reviewed by:** Danny M. | Malware analyst, Small-Business (50 or fewer emp.)

**Reviewed Date:** March 18, 2026

**What do you like best about ANY.RUN Sandbox?**

shows me dynamic analysis and all affected registries of a malware, including what syscalls it makes and the executables nature

**What do you dislike about ANY.RUN Sandbox?**

no free linux environment for dynamic analysis

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

fast dynamic analysis of any executable, reports and iocs, also nice graphs and schemas

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 7. Quick, Reliable, and Effective for Phishing Triage

**Rating:** 5.0/5.0 stars

**Reviewed by:** Warren M. | Cyber Security Manager

**Reviewed Date:** February 12, 2026

**What do you like best about ANY.RUN Sandbox?**

I use ANY.RUN Sandbox for detonating links while triaging phishing. I appreciate having a quick and reliable environment that tells me indicators efficiently. I find it easy to use and fast, and the features are good. It's able to detonate links and files in real-time, giving me the connections it's making and telling me if there are any indicators.

**What do you dislike about ANY.RUN Sandbox?**

none at the moment

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

I use ANY.RUN Sandbox for detonating links in phishing triage, providing a quick, reliable environment that identifies indicators. It's easy to use, fast, and the real-time connections feature is beneficial.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 8. Real-Time Malware Analysis Deepens Threat Understanding

**Rating:** 4.5/5.0 stars

**Reviewed by:** Lawrence L. | Security Analyst, Small-Business (50 or fewer emp.)

**Reviewed Date:** November 25, 2025

**What do you like best about ANY.RUN Sandbox?**

Being able to observe malware behaviour in real time — file system changes, registry edits, network connections, process trees, and command execution — gives us a deeper understanding of threats targeting businesses in South Africa.

**What do you dislike about ANY.RUN Sandbox?**

The short session duration on the free plan can restrict deeper investigations, especially when dealing with malware that delays execution or requires multi-stage interaction.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Process trees, registry changes, file modifications, network traffic, MITRE ATT&CK mapping, and command execution are displayed cleanly and in real time. This helps us quickly understand the full lifecycle of malicious activity.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

If you’re experiencing any issues, don’t hesitate to reach out to us at support@any.run—we’re always here to help and will do our best to assist you! 

  ### 9. ANY.RUN Sandbox Experience

**Rating:** 4.5/5.0 stars

**Reviewed by:** Joseph U. | Security Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** July 15, 2025

**What do you like best about ANY.RUN Sandbox?**

The file and URL inspection capabilities are excellent. Being able to immediately interact with a potentially malicious file or URL right in the platform is very helpful, and the ability for the platform to provide immediate feedback of analysis helps us identify threats quicker and deploy mitigations faster. The ability to extract threat related IOCs and implement their detection in our environment helps us anticipate and block threats quicker, and provide greater insight into the exact malicious activities files and URLs perform so we can be better prepared to defend against them.

**What do you dislike about ANY.RUN Sandbox?**

Only downsides are the limitations imposed on the use of the free version of the platform. Limiting malicious file analysis to 90 seconds and malicious URL analysis to five minutes can hamper investigations depending upon how long it takes for webpages to load, or how long it takes for a file to execute. I do appreciate the ability to extend the analysis time for live file analysis, but this can only be performed a limited amount of times, and overall analysis of files and URLs is limited to a few times a day.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN Sandbox helps us diagnose potentially malicious files and URLs that our end-users receive on a daily basis, and allows us to triage them and determine if those artifacts are indeed malicious or benign. Once we receive confirmation from analysis in the Sandbox that a file or URL is malicious, we can then use the threat indicators to confirm this and can extract IOCs from the artifact to ensure no further impact is felt from end users, and we can combine this information with our existing security tools to contain these threats as quickly as possible once analysis is completed.

**Official Response from Thomas Harris:**

> Thank you for sharing your detailed feedback! We're glad to hear that our platform supports your threat detection and mitigation efforts. To overcome the limitations of the free version, we invite you to explore our paid plans, which offer extended analysis time and greater flexibility. Your insights are greatly appreciated and help us continue improving ANY.RUN to better serve your needs.

  ### 10. Powerful and Interactive Malware Analysis Tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** MOHAMED B. | SysAdmin, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 15, 2025

**What do you like best about ANY.RUN Sandbox?**

ANY.RUN stands out because of its real-time interactivity and user-friendly interface. I really appreciate how I can manually interact with malware during execution, check registry and file changes live, and download artifacts for deeper analysis. The visualization tools like network traffic flow and MITRE ATT&CK mapping also save a lot of time during investigations.

**What do you dislike about ANY.RUN Sandbox?**

Some advanced features are restricted in the free version, which limits deeper analysis in some cases. Also, the sandbox sometimes takes a little while to queue during high usage periods. More OS variety (like Android or Linux) would also be helpful for broader testing.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN helps me safely analyze suspicious files and URLs without infecting my own system. It solves the problem of needing an isolated, controlled environment to observe malware behavior in real time, which is critical for threat analysis, digital forensics, and learning. The ability to interact with the sample during execution (such as clicking buttons, entering text, etc.) gives deeper insights compared to static analysis tools. This has helped me understand how different malware families behave and improved my skills in malware reverse engineering and SOC investigations

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Great news—Android and Linux Ubuntu are already live!  We invite you to give it a try. New platforms are already in our roadmap! Stay tuned for updates, and thank you for staying with us! 

  ### 11. Fast, Reliable Sandbox with Excellent Multi-OS Support

**Rating:** 5.0/5.0 stars

**Reviewed by:** Harshith H. | Sec Ops Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** December 03, 2025

**What do you like best about ANY.RUN Sandbox?**

A fast and reliable sandbox that supports multiple operating systems enables more effective analysis and troubleshooting. It also provides clear DNS flow visibility, making it easier to compare behaviors across different sandbox environments and improving overall detection accuracy.

**What do you dislike about ANY.RUN Sandbox?**

At the Sandbox level, unable to copy the IOCs because the URL automatically redirects, which disrupts the extraction process.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN supports multiple OS environments, making it easier to compare behavior and understand OS-specific execution flows.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 12. Possibility to test malware without risk and study it.

**Rating:** 4.5/5.0 stars

**Reviewed by:** Tony L. | Devops, Small-Business (50 or fewer emp.)

**Reviewed Date:** February 26, 2026

**What do you like best about ANY.RUN Sandbox?**

Possibility to test malware without risk and study it.

**What do you dislike about ANY.RUN Sandbox?**

Hmm, maybe the price and that there is no option for individuals.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Test files that we do not know if they are malicious.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 13. Any.Run is a valuable tool in our cybersecurity arsenal.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Primary/Secondary Education | Enterprise (> 1000 emp.)

**Reviewed Date:** November 18, 2025

**What do you like best about ANY.RUN Sandbox?**

ANY.RUN has honestly become one of my go-to tools whenever I’m dealing with suspicious files or trying to understand what a piece of malware is actually doing. The biggest advantage is how interactive it is. Instead of waiting for a sandbox to generate a static report, you can literally watch the malware run in real time—processes spawning, network traffic, file system changes, everything. Being able to pause, click around, and dig into specific behaviors makes the analysis process much smoother and a lot faster.

Another thing I really appreciate is how clean and easy the interface is. You don’t have to fight with the tool to get the information you need. Whether you’re doing quick triage or a deeper dive, it’s laid out in a way that just makes sense. The public submissions database is also incredibly useful. I’ve been able to look up similar samples, compare behaviors, and even confirm whether something I’m seeing matches known malware families.

Customer Service has been very good.  They are quick to answer technical questions, and our account rep checks in with us regularly to go over new features and see how are liking the product.  She is receptive to criticisms where warranted, and takes that information back to her development team.

Performance has been solid across the board. Sessions spin up quickly, results appear almost instantly, and the level of detail you get is more than enough for day-to-day analysis and threat hunting. Overall, ANY.RUN has saved me a lot of time and made malware analysis far less painful. If you work in a SOC, IR, or just want a reliable sandbox with great visibility, it’s absolutely worth using.

**What do you dislike about ANY.RUN Sandbox?**

The maximum file upload size is a burden, but there are workarounds.  That really has been the only issue I have encountered.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN gives me a safe place to execute suspicious software/malware, and understand what it is doing.  There is no risk to my own systems when using ANY.RUN's virtual environment.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 14. Interactive Analysis, Redefined

**Rating:** 4.5/5.0 stars

**Reviewed by:** Rafael R. | IT Helpdesk Support, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 11, 2025

**What do you like best about ANY.RUN Sandbox?**

What I like best about ANY.RUN is how interactive and intuitive it is. Unlike traditional sandboxes, it lets me actively explore and analyze malware behavior in real time. I can easily follow network connections, file changes, and process actions without digging through logs. The visual interface makes complex data much more accessible. It feels like having a hands-on lab, but in the cloud.

**What do you dislike about ANY.RUN Sandbox?**

One thing I dislike about ANY.RUN is the limitation on analysis time and features in the free version—it can feel restrictive during deeper investigations. Sometimes, more advanced malware evades detection or doesn’t fully execute in the sandbox environment. I’ve also noticed occasional delays when the system is under heavy load. While the UI is generally great, certain areas could benefit from more customization. Still, these are relatively minor compared to its overall strengths.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN helps me quickly and safely analyze suspicious emails, especially phishing attempts I receive daily. It allows me to inspect both malicious links and attachments without risking my local environment. This saves time and adds a layer of confidence when handling potential threats. The real-time interaction is incredibly useful for seeing exactly how the payload behaves. It’s like having a secure lab available at all times, right in my browser.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us - we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 15. Powerful and intuitive malware analysis platform for professionals

**Rating:** 4.0/5.0 stars

**Reviewed by:** Mahmoud M. | Cybersecurity Researcher, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 15, 2025

**What do you like best about ANY.RUN Sandbox?**

The existent-clip synergistic analysis is perfectly game-modified. Can supervise malware conduct measure-by-measure, track web connection, register changes, and register system adjustment. The envision procedure tree and elaborated account make it easy to understand even complex menace. To appreciate the velocity and simpleness of the interface.

**What do you dislike about ANY.RUN Sandbox?**

Sometimes the free level have limitations with runtime or register size‚ and certain advanced malware circumvent analysis by find the sandbox. It would be great if more OS option or furtive environment were add in the hereafter.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN help me safely canvas and understand malicious package without infect my local system. It solve the job of postulate procure‚ insulate environment to discover malware doings in real clip. This hold significantly meliorate my efficiency in malware analysis‚ incident response‚ and turn technology undertaking‚ relieve clip and cut endangerment.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

New platforms are already in our roadmap! Stay tuned for updates, and thank you for staying with us! 

  ### 16. Helps Prevent Cyber Threats—A Must-Have for Security Teams

**Rating:** 5.0/5.0 stars

**Reviewed by:** Fern M. | Analyst, Small-Business (50 or fewer emp.)

**Reviewed Date:** April 28, 2026

**What do you like best about ANY.RUN Sandbox?**

It helps preventing cyber threats. Much needed for security team

**What do you dislike about ANY.RUN Sandbox?**

Should be made aware globally so that every company can for a dry run

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Prevent from cyber threats

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 17. Great sandbox, even on free plan (if you don't mind send public analysis)

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Small-Business (50 or fewer emp.)

**Reviewed Date:** October 30, 2025

**What do you like best about ANY.RUN Sandbox?**

Even with a free account, you can obtain impressive results. The platform is very user-friendly, and the reports it generates are excellent. It also allows you to download public malware samples. During analysis, you can extend the free analysis time from 60 seconds to 5 minutes directly from the user interface.

**What do you dislike about ANY.RUN Sandbox?**

They restrict Free mode analysis to Windows 10, even though the software actually supports multiple Windows versions, as well as Ubuntu and Debian Linux distributions, and Android 14.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

This is a great tool for quickly and easily gaining visibility into malware behavior and obtaining additional IOCs. It streamlines the process, making it much more efficient to analyze threats and gather the necessary indicators.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 18. A powerful analytics tool with an easy-to-use interface

**Rating:** 4.5/5.0 stars

**Reviewed by:** Awad R. | Cyber Security Analyst, Small-Business (50 or fewer emp.)

**Reviewed Date:** February 20, 2026

**What do you like best about ANY.RUN Sandbox?**

I love the interface and ease of use in ANY.RUN Sandbox, where I can easily view logs and see traffic more easily. The setup process was very easy and interactive.

**What do you dislike about ANY.RUN Sandbox?**

When I try to download the backup file to my device and analyze it, it is not complete.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN Sandbox dynamically analyzes malware samples and easily analyzes the network. The interface and ease of use enable me to easily view logs and clearly monitor the network.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

If you’re experiencing any issues, don’t hesitate to reach out to us at support@any.run—we’re always here to help and will do our best to assist you! 

  ### 19. Perfect for Beginners Guided Experience Makes Analysis Easy

**Rating:** 5.0/5.0 stars

**Reviewed by:** Rochana R. | Security Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** November 17, 2025

**What do you like best about ANY.RUN Sandbox?**

If you’re new, you don’t need to be a hardcore reverser the platform walks you through, making it less intimidating

**What do you dislike about ANY.RUN Sandbox?**

Some phishing sites or advanced threats might not load properly in the sandbox, so you can’t always see exactly what a victim would

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

There’s no need to build your own malware lab, it runs in the cloud, saving you time, money, and a lot of hardware headaches.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

If you’re experiencing any issues, don’t hesitate to reach out to us at support@any.run—we’re always here to help and will do our best to assist you! 

  ### 20. Intuitive, Interactive Malware Analysis That Boosts Collaboration and Productivity

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** October 31, 2025

**What do you like best about ANY.RUN Sandbox?**

What I like best about ANY.RUN Sandbox is its intuitive and interactive interface that allows real-time visibility into malware behavior, network activity, and process execution. It makes dynamic analysis fast, visual, and highly effective, enabling analysts to interact directly with samples and quickly identify threats. I also value how the platform promotes collaboration and knowledge sharing within the security community through public submissions and detailed reports, helping professionals stay ahead of emerging threats while improving productivity and learning.

**What do you dislike about ANY.RUN Sandbox?**

Some advanced features and longer analysis times are only available in the paid plans, which can limit deeper investigations for free users or can have a smoll paid plan.. poc 10 days.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN Sandbox solves the challenge of quickly analyzing and understanding malware behavior in a secure, interactive environment. It provides real-time visibility into processes, files, and network activity, making threat detection and response much faster and more accurate. The platform also enhances collaboration by allowing analysts to share results and insights, improving overall efficiency, knowledge, and incident response capabilities.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 21. Easy to use sandbox for professionals

**Rating:** 4.5/5.0 stars

**Reviewed by:** Jeff N. | Cyber Security Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** November 19, 2025

**What do you like best about ANY.RUN Sandbox?**

The ANY.RUN sandbox is easy to use.  Simply upload your file and you can watch it run.

**What do you dislike about ANY.RUN Sandbox?**

The only thing I don't like about ANT.RUN is the public information.  It would be nice if others didn't see my files.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN Sandbox allows anybody to evaluate malware and suspicious files, URL's and executables.  The evaluation provides information to allow us to make additional decisions.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 22. A whole lab in the cloud and on the go

**Rating:** 5.0/5.0 stars

**Reviewed by:** Jacob H. | Senior Cybersecurity engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 15, 2025

**What do you like best about ANY.RUN Sandbox?**

I love the fact that within minutes of receiving an alert, we can send a sample to Any.Run, and begin analyzing it.  The process is easy, and gives a wealth of information and saves us the hassle of running our own lab to do the same work but at 3x the cost and time.

**What do you dislike about ANY.RUN Sandbox?**

The only downsides are the lack of mobile sandboxing simulation for malware just used on phones and tablets.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Any.Run removes the need for our own lab environment and allows us to do triage and investigation as well as training our analysts in a safe environment.  There are also API hooks to make it a streamlined process to handle alerts.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 23. Exceptional Domain Analysis for Security Insights

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Small-Business (50 or fewer emp.)

**Reviewed Date:** November 26, 2025

**What do you like best about ANY.RUN Sandbox?**

The analysis of suspicious domains is very helpful, as it allows me to determine whether a domain appears unusual or legitimate. Any run is also really easy to use. I use ANY.RUN everytime I want to inspect a domain.

**What do you dislike about ANY.RUN Sandbox?**

The analysis process can be a bit slow at times, and occasionally, I notice that some suspicious websites redirect traffic to Google in order to bypass the sandbox.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

This tool makes it much easier to analyze websites, as I no longer have to open a virtual machine just to see what suspicious sites look like.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 24. Good tool for peace of mind

**Rating:** 5.0/5.0 stars

**Reviewed by:** Chris B. | Information Security Operations Lead, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 22, 2025

**What do you like best about ANY.RUN Sandbox?**

I like the ability to run in an isolated environment that helps determine if a file or site has malicious intent. It is very easy to navigate the menus to get things going.  I have yet to try the paid version, luckily for us there are only a few occasions in a given month that I am asked to review a file or site.

**What do you dislike about ANY.RUN Sandbox?**

The time limit on the free account is a little too short, even though it can be extended.  It's just a bit frustrating to have to reset it every few seconds, which takes away from what your trying to accomplish.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Allows me to view a webpage or file without risking any business assets.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 25. Unmatched Depth and Power in Cloud Sandbox Analysis

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Utilities | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 03, 2025

**What do you like best about ANY.RUN Sandbox?**

I've both used and built a number of such sandboxes over my career.  The Any.run sandbox offers a depth of analysis I have yet to find.

**What do you dislike about ANY.RUN Sandbox?**

Really, not much.  As a cloud tool it is subject to all of the associated "someone else's computer" issues, but other than that it is wildly powerful and simple to use.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Really no problems at this time.  Our group uses it to do both quick and dirty analysis of potentially malicious sites, as well as deeper dives into known, compromised items.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 26. Great tool, use it regularly!

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Government Administration | Enterprise (> 1000 emp.)

**Reviewed Date:** September 24, 2025

**What do you like best about ANY.RUN Sandbox?**

Our team has been looking for a comprehensive sandboxing tool for a few years now, and after finding ANY.RUN and using their free plan for a little while, we picked up an Enterprise subscription and immediately noticed the benefits. Being able to run sandboxes for longer and the ability to make them private are two big standouts. Now we use ANY.RUN on a regular basis in our environment when analyzing websites and emails. All in all, a great tool. Highly recommend it.

**What do you dislike about ANY.RUN Sandbox?**

Their threat intelligence is still in its infancy. Best used in combination with other TI services.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Analyzing risky websites and suspicious emails in a safe environment without having to worry about putting our own systems at risk.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 27. Intuitive, exact, and detailed

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** February 12, 2026

**What do you like best about ANY.RUN Sandbox?**

The interface is very intuitive and the results are presented very accurately, comprehensively, and clearly.

**What do you dislike about ANY.RUN Sandbox?**

When exporting the results, additional formats would be helpful.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

We must quickly see and find out whether a file or an email is actually harmful and what changes have been made. Any.Run helps us a lot with this.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 28. A Must-Have for Real-Time Malware Analysis!

**Rating:** 5.0/5.0 stars

**Reviewed by:** CEMAL A. | M.Computer Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** July 16, 2025

**What do you like best about ANY.RUN Sandbox?**

ANY.RUN is an outstanding sandbox platform that brings together all the tools needed for effective malware analysis. Its real-time interactive analysis capability sets it apart from traditional static solutions, allowing you to observe malware behavior as it unfolds.

The user interface is clean and intuitive, and the detailed reports are extremely valuable for both technical and non-technical users. Features like MITRE ATT&CK mapping, IOC extraction, network traffic inspection, and interactive command-line access make deep analysis straightforward and efficient.

It’s a reliable solution for anyone looking to investigate suspicious files, gather threat intelligence, or validate IOCs. I use it regularly and highly recommend it to colleagues in the cybersecurity field.

**What do you dislike about ANY.RUN Sandbox?**

While ANY.RUN offers a convenient and interactive environment for malware analysis, there are several areas where the platform could be improved.

The biggest downside is the limited system configuration flexibility—users cannot easily simulate more diverse environments (e.g., different OS builds, regional settings, or enterprise-like setups). Additionally, for advanced users, some of the network analysis capabilities feel too basic, and deeper packet inspection options are missing unless you upgrade.

Another concern is the pricing model. The free version is very limited, and the paid tiers can be expensive for small teams or individual researchers.

Overall, ANY.RUN is useful for quick analyses and educational purposes, but for more advanced, in-depth investigations, other solutions may offer better customization and depth.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN helps solve the challenge of quickly and safely analyzing potentially malicious files or URLs in a controlled environment. Its real-time interactive sandbox allows me to observe malware behavior, such as file system changes, process activity, and network communication, without putting production systems at risk.

This benefits me by significantly reducing investigation time, improving threat detection accuracy, and making it easier to extract IOCs for further defense and response actions. It also enhances collaboration within my team by providing clear visual reports that are easy to share and interpret.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

New platforms are already in our roadmap! Stay tuned for updates, and thank you for staying with us! 

  ### 29. ANY.RUN Makes Malware Analysis Fast and Interactive

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Retail | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 15, 2025

**What do you like best about ANY.RUN Sandbox?**

I really appreciate ANY.RUN’s interactive approach to sandboxing. Unlike traditional sandboxes that just give you static reports, ANY.RUN lets me actually interact with the environment in real time — clicking through windows, running commands, and observing live behavior. This makes it so much easier to track down malicious actions, registry changes, dropped files, and network connections. The intuitive visual process tree is also a huge plus for quickly understanding how malware executes.

**What do you dislike about ANY.RUN Sandbox?**

Overall, I’m very satisfied, but there are a few areas that could improve. Sometimes large or heavily obfuscated samples take longer to analyze, which slows down workflows. I’d also like to see deeper integrations with more threat intelligence feeds or automatic enrichment to speed up investigations even more. Lastly, while the UI is very user-friendly, advanced users might want even more granular control over the sandbox environment and simulation settings.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN helps me quickly understand what suspicious files or URLs actually do in a safe, controlled environment. Instead of spending hours manually reverse engineering or reading static indicators, I can run the sample interactively and see its real behavior in minutes. This speeds up malware analysis, supports faster incident response, and helps me build stronger detection rules. It’s also great for creating reports or sharing clear visual evidence with other teams.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. Stay tuned for updates, and thank you for staying with us! 

  ### 30. Pro Mode Makes Analysis Easy with Full Domain, Hash, and IP Visibility

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Enterprise (> 1000 emp.)

**Reviewed Date:** February 17, 2026

**What do you like best about ANY.RUN Sandbox?**

What I like the best is the pro mode where I can see every domains, hashes and IP addresses during an analysis.

**What do you dislike about ANY.RUN Sandbox?**

The only downside is the time limit on the analysis.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

I can safely analyse malwares and phishing campaigns

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 31. Secure interface and intuitive design: very useful and easy to use

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Consumer Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** March 12, 2026

**What do you like best about ANY.RUN Sandbox?**

INTERFACE AND SECURITY, EASY TO USE DESIGN

**What do you dislike about ANY.RUN Sandbox?**

NONE UNTIL NOW HAS BEEN VERY USEFUL AND EASY TO USE

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

REVIEW SUSPICIOUS EMAILS WITH MALICIOUS LINKS OR FILES

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 32. Any.Run Sandboxing breeds confidence

**Rating:** 5.0/5.0 stars

**Reviewed by:** Matthew L. | IT Support Consultant, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 22, 2025

**What do you like best about ANY.RUN Sandbox?**

Any.Run has halted many attacks and provided confidence in the handling of phishing and other malicious Emails and their attachments.

The ability to detonate potential threats in a non-production environment in a breadth of different software platforms is also a great bonus feature.

The product is very easy to use, with drag & drop / copy & paste functionality.

**What do you dislike about ANY.RUN Sandbox?**

N / A.  It does the job perfectly by removing guesswork.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Any.run has allowed me to verify whether or not a risky Email or link contains genuine threats, and therefore how to approach it with my Clients in case a User has actioned the payload.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 33. An essential tool for malware analysis

**Rating:** 5.0/5.0 stars

**Reviewed by:** Wally algenis G. | Analista de ciberseguridad, Information Technology and Services, Small-Business (50 or fewer emp.)

**Reviewed Date:** June 10, 2025

**What do you like best about ANY.RUN Sandbox?**

I have used ANY.RUN for several months as part of my malware analysis and cybersecurity testing tasks. The interface is intuitive, highly interactive, and allows obtaining real-time results with a great level of detail. What I value most is the ability to control the environment as if it were a real desktop, which facilitates tracking the malware's behavior minute by minute.

Additionally, the active community and technical support of ANY.RUN make the experience even more reliable. It is an essential tool for researchers, security analysts, and incident response teams.

✅ Interactive
✅ Detailed reports
✅ Fast and easy to use

**What do you dislike about ANY.RUN Sandbox?**

How efficient it is to analyze URL sha 255 and its potential threat analysis

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Analyze URL and malicious links

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts are invaluable to us - we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 34. Impressive Experience—Absolutely Love It!

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Media Production | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 31, 2025

**What do you like best about ANY.RUN Sandbox?**

The user-friendly interface made navigation straightforward, even for those less tech-savvy. The real-time analysis feature was invaluable, enabling us to identify and address potential threats quickly. The detailed reports provided comprehensive insights, aiding our decision-making process.

**What do you dislike about ANY.RUN Sandbox?**

If a user forgets to mark their analysis as private, the uploaded file and its behavioral analysis may be published publicly.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN’s interactive sandbox allows analysts to simulate user actions (e.g., clicking links, entering passwords) to detonate malware fully.

Analysts get full execution chains, network activity, and malware configurations instantly.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 35. Easy, Interactive, and Perfect for Quick Analyses

**Rating:** 5.0/5.0 stars

**Reviewed by:** Leonora M. | CyberSecurity Consultant, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 30, 2025

**What do you like best about ANY.RUN Sandbox?**

This software is easy to use and highly interactive. It is also quite handy when you need to perform quick analyses.

**What do you dislike about ANY.RUN Sandbox?**

I enjoy every aspect of any run and look forward to seeing it improve even more. Hehe.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Analysing phishing mails, processes and stuff like that

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 36. Intuitive & Best for quick response. Top tools for cases like incident responses.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Small-Business (50 or fewer emp.)

**Reviewed Date:** July 22, 2025

**What do you like best about ANY.RUN Sandbox?**

I love the information I could collect on ANY.RUN Sandbox. With me, the most valuable things are network connections of the sample, as well as their behaviors. This could provide overviews of the sample before I look in-depth into it. I haven't used a lot features related to report like MITRE ATT&CK mappings, but sure, they are good also. ANY.RUN also has helped me a lot during my incident response case, where I can quickly understand behaviors of the sample and react accordingly.

**What do you dislike about ANY.RUN Sandbox?**

I think ANY.RUN Sandbox is fine enough for an interactive sandbox. I didn't have tried premium version and I am satisfied with current free tier.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

I think ANY.RUN solve the problem of building a malware sandbox, allow people to investigate their samples quickly. It is totally fit my case.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 37. Time-Saving IOC Extraction That Delivers Clean Results

**Rating:** 5.0/5.0 stars

**Reviewed by:** Vijay G. | Information Security Analyst Intern, Enterprise (> 1000 emp.)

**Reviewed Date:** November 17, 2025

**What do you like best about ANY.RUN Sandbox?**

The IOC extraction. It saves me a ton of time by pulling clean, useful indicators without any extra noise.

**What do you dislike about ANY.RUN Sandbox?**

Sometimes the analysis can feel a bit slow or hangs with heavier samples, which breaks the workflow.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

It helps me quickly analyze suspicious files and URLs, extract IOCs instantly, and speed up my incident response without digging through raw logs or running risky samples locally.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

If you’re experiencing any issues, don’t hesitate to reach out to us at support@any.run—we’re always here to help and will do our best to assist you!

  ### 38. Using ANY.RUN in a typical SMB workplace

**Rating:** 5.0/5.0 stars

**Reviewed by:** Paul D. | IT Manager &amp; Offensive Security Pentester, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 15, 2025

**What do you like best about ANY.RUN Sandbox?**

The ease to test unknown links and files that are received via emails is invaluable in maintaining the company security against malicous actors.

**What do you dislike about ANY.RUN Sandbox?**

The shear complexity is a bonus, but can also be confusing at times.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

As a small/Medium business, we are constantly receiving emails with files and/or links that could be malicous. With the use of ANY.RUN, I'm able to verify if the link/file is malicous or not, and then pass that onto my colleagues, knowing that they will not click or open something they shouldn't.

**Official Response from Thomas Harris:**

> Thank you so much for sharing your experience! We're thrilled to hear that ANY.RUN is helping you keep your organization secure by verifying suspicious files and links.

Your feedback truly means a lot to us—it helps guide our improvements and inspires us to keep delivering the best experience possible. 

  ### 39. Clear and visual threat analysis, ideal for investigations

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Small-Business (50 or fewer emp.)

**Reviewed Date:** December 01, 2025

**What do you like best about ANY.RUN Sandbox?**

The software provides clear insights into the threats present in the domains being searched. Additionally, it allows you to visualize the pages and interact with them, which is very helpful for analysis.

**What do you dislike about ANY.RUN Sandbox?**

I haven't found anything that I dislike. However, sometimes I feel that the interaction time is too brief.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

This application eliminates the need to install an additional virtual machine on the device, as it already includes its own. It allows me to analyze and test the domains and IPs I need without the risk of infection.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 40. Real-Time Interactive Malware Analysis with an Intuitive UI

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** February 02, 2026

**What do you like best about ANY.RUN Sandbox?**

Any run allows interact with Malware live, As it is a realtime interactive analysis solution. UI is very intuitive

**What do you dislike about ANY.RUN Sandbox?**

I don’t have any as we didnt come acrross anything negative yet

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN is an interactive, cloud-based sandbox that helps address the challenges of slow, static, or evasive malware analysis by making the process more responsive and practical.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users.

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 41. It is a good sandbox but it can be improved

**Rating:** 4.0/5.0 stars

**Reviewed by:** Gibs S. | Cybersecurity analyst, Restaurants, Enterprise (> 1000 emp.)

**Reviewed Date:** June 11, 2025

**What do you like best about ANY.RUN Sandbox?**

The option that allows you to fully interact with the sandbox, both to see the processes outside the environment and connections is very efficient.

**What do you dislike about ANY.RUN Sandbox?**

The problem is that sometimes it takes a long time to start the environment and sometimes it blocks some pages and does not allow to perform the corresponding tests.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

I had a relatively critical incident a couple of months ago, I managed to get the malware we had out of control inside the company and with Any.Run I managed to find a manual remediation method and also hashes and identify the malware as “amadey”.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us - we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

  ### 42. Any.Run is a Secure Sandbox

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 14, 2025

**What do you like best about ANY.RUN Sandbox?**

can detonate any website or files within contained sandbox

**What do you dislike about ANY.RUN Sandbox?**

Have to open settings menu to delete old sessions. Additional clicks feel unnecessary

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Allows us to detonate files within a virtual environment without worrying about its affecting anything in the "real world"

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 43. Fast, Responsive Environment Setup That Delivers

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Higher Education | Enterprise (> 1000 emp.)

**Reviewed Date:** November 16, 2025

**What do you like best about ANY.RUN Sandbox?**

The configuration of the environment is really well put together, fast and responsive to spin up a session.

**What do you dislike about ANY.RUN Sandbox?**

There isn’t much that I dislike about this product, but I have noticed that it can become unresponsive for brief periods (on rare occasions).

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

Our team primarily concentrates on analyzing malware and malicious emails.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

If you’re experiencing any issues, don’t hesitate to reach out to us at support@any.run—we’re always here to help and will do our best to assist you! 

  ### 44. Best first step in malware analysis

**Rating:** 5.0/5.0 stars

**Reviewed by:** Matías  C. | Cibersecurity Analyst, Small-Business (50 or fewer emp.)

**Reviewed Date:** June 11, 2025

**What do you like best about ANY.RUN Sandbox?**

When I was a newbie, I was drawn to it for its intuitive graphical interface and extensive analysis capabilities, providing a comprehensive scan of how malware works on different operating systems and a summary of its behavior. It's now part of my everyday malware analysis toolkit.

**What do you dislike about ANY.RUN Sandbox?**

I would add the option to run AnyRun as a local client on computers with a monthly license, so that you can scan the behavior of malware in your own sandbox. However, there is nothing I dislike at the moment.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

dynamic malware analysis in controlled environments

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us - we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 45. Easy, intuitive, and secure

**Rating:** 5.0/5.0 stars

**Reviewed by:** Brian C. | Information Security Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 15, 2025

**What do you like best about ANY.RUN Sandbox?**

Intuitive and easy-to-use interface, with interactive file and URL analysis, AI-assisted TTP detection, MITRE ATT&CK mapping, IOC extraction, and detailed reports. Cloud-based execution speeds up incident response.

**What do you dislike about ANY.RUN Sandbox?**

The lack of an offline version prevents use in air-gapped environments. English-only interface may hinder adoption by international or multilingual teams.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

With ANY.RUN, we regularly analyze suspicious links and files, identifying relevant IOCs and TTPs. This data supports security policy adjustments and enhances awareness campaigns with real-world examples.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We're glad to hear that our platform is supporting your organization’s analysis and response efforts. Your feedback is incredibly valuable and helps us continue improving the service to better meet the needs of our users. We truly appreciate your input!

  ### 46. Amazing tools for check malware behavior

**Rating:** 4.0/5.0 stars

**Reviewed by:** Josue C. | Technical Support Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** August 14, 2025

**What do you like best about ANY.RUN Sandbox?**

ANY.RUN Sandbox stands out for its interactive, real-time malware analysis, allowing users to pause, resume, and interact with samples to better understand malicious behavior quickly and effectively.

**What do you dislike about ANY.RUN Sandbox?**

Nothing for the moment. But in moment have some laggy.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

The platform quickly delivers indicators of compromise (IOCs) and detailed threat reports, enabling security teams to respond to incidents faster and more accurately.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

If you’re experiencing any issues, don’t hesitate to reach out to us at support@any.run—we’re always here to help and will do our best to assist you! 

  ### 47. A Must-Have Tool for Threat Analysts

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** April 29, 2025

**What do you like best about ANY.RUN Sandbox?**

We really appreciate how the interactive sandbox allows for real-time engagement with malware samples, particularly those that require user interaction to fully detonate. The user interface is clean and intuitive, making it easy to navigate and work through analyses efficiently. 

The detailed reporting significantly speeds up the process of compiling findings, and the addition of AI-driven reporting provides deeper insights without the need for constant manual investigation. 

Having access to the Proof of Concept (PoC) version also highlighted the full potential of the platform, offering expanded operating system support and a broader set of capabilities that enhance threat analysis even further.

**What do you dislike about ANY.RUN Sandbox?**

Overall, the platform performs very well, but one improvement area would be expanding the flexibility for simulating different user behaviors or system states during a detonation. In some cases, malware that relies on very specific conditions or timing might require a bit more manual intervention to fully observe its behavior. It’s a minor point that Any.Run is constantly tweaking, but more advanced automation or customization options would make an already strong platform even better.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN helps us quickly see how malware behaves by giving us an interactive sandbox where we can manually trigger actions, like clicking and typing, to fully execute the malware. This makes it much easier to catch behaviors that wouldn’t show up in a basic automated analysis. While it covers most use cases very well, for highly specialized or environment-sensitive malware, we sometimes need more advanced setups — but for everyday malware analysis and investigation, it saves us a lot of time and gives us detailed reports we can trust.

**Official Response from Thomas Harris:**

> Thank you so much for your thoughtful and detailed review, we truly appreciate your support and feedback!
 
We're especially glad to hear that the interactive sandbox, intuitive UI, and AI-driven reporting are making a real difference in your workflow. It's always rewarding to know that ANY.RUN is helping analysts like you work more efficiently and with greater insight.
 
Regarding your comment on simulating different user behaviors,  great point! We wanted to highlight that ANY.RUN already includes an "Automated Interactivity (ML)" feature that helps simulate user actions during detonation. You can read more about how it works and how to activate certain automated interaction scenarios in this post: https://any.run/cybersecurity-blog/automated-interactivity-stage-two/
 
We’re also actively working on expanding this functionality: upcoming releases will support even more behavior scenarios and introduce enhanced visualization of automated actions to give you a clearer picture of what’s happening under the hood.
Thanks again for your feedback and for being part of the ANY.RUN community!

  ### 48. The best method to identify malware

**Rating:** 5.0/5.0 stars

**Reviewed by:** aymara c. | Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** February 05, 2025

**What do you like best about ANY.RUN Sandbox?**

What I like most about ANY RUN is that I have access to a controlled and secure environment at no additional cost, and I use it to perform analysis of possible security events.

We can also view in detail the processes and services executed during the scan emulation.

It is very easy to use, implementing its tools is very didactic, in case I could not perform a scan, the support contacts have always been available to resolve any of my questions.

In my area of ​​work, the daily use of ANY RUN is very useful, since there are many cases of phishing reports that we must investigate.

If you are looking for a new tool to help you easily integrate with your work requirements, this is your best option since it is very easy to integrate into cybersecurity

**What do you dislike about ANY.RUN Sandbox?**

I have not yet found any negative points in using the tool, although like all Any Runs it seeks to automate its system on a daily basis.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

detects, investigates, and monitors cybersecurity threats

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 49. ANY.RUN as the best option for sandboxing

**Rating:** 5.0/5.0 stars

**Reviewed by:** PUVENDRAN P. | IT Security, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 10, 2025

**What do you like best about ANY.RUN Sandbox?**

very helpful, especially the public analysis. detailed information. managed to actually mitigate a Lumma Stealer attempt thanks to any.run. I use it all the time for analysis as its my go to tool for sandboxing. Its very straightforward, where u can just submit the link and watch it in action.

**What do you dislike about ANY.RUN Sandbox?**

The AI features on analysis can be improved, such as the summary.

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

ANY.RUN is a sandbox product that has helped mitigate so many infostealer attacks, mainly Lumma Stealer and Poweshell Attacks. Its realtime analysis is very beneficial.

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts and suggestions are invaluable to us - we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 

  ### 50. my favorite sandbox <3

**Rating:** 5.0/5.0 stars

**Reviewed by:** הדר . | SOC Analyst , Small-Business (50 or fewer emp.)

**Reviewed Date:** June 11, 2025

**What do you like best about ANY.RUN Sandbox?**

As a soc analyst, this tool saves my life during shifts or even when investigating URLs and files for family and friends,
That's my first option to investigate any time, the software is super easy to understand and puts out any important info 
the IOC super true 
I love this platform!

**What do you dislike about ANY.RUN Sandbox?**

The 5 minutes of free use, but except that it's handled

**What problems is ANY.RUN Sandbox solving and how is that benefiting you?**

as i said previos, the sandbox helping me alot with finding malicious files, solving phising attacks and finding out a bad domains and URLs

**Official Response from Thomas Harris:**

> Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users. 

Your thoughts are invaluable to us - we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community! 


## ANY.RUN Sandbox Discussions
  - [What is Any.Run used for?](https://www.g2.com/discussions/what-is-any-run-used-for) - 1 comment

- [View ANY.RUN Sandbox pricing details and edition comparison](https://www.g2.com/products/any-run-sandbox/reviews?focus_review=9510957&page=2&product_id=any-run&section=pricing&secure%5Bexpires_at%5D=2026-08-14+23%3A44%3A39+-0500&secure%5Bsession_id%5D=0dcfd9fa-b729-4e46-b4f7-2321f55311a5&secure%5Btoken%5D=ba82d642c87ca88421ff626285744a0ee4c5583cc3f87420e20c251aff36b5d3&format=llm_user)
## ANY.RUN Sandbox Integrations
  - [Blink](https://www.g2.com/products/blink-ops-blink/reviews)
  - [D3 Security](https://www.g2.com/products/d3-security/reviews)
  - [FortiSOAR](https://www.g2.com/products/fortisoar/reviews)
  - [Google Chronicle Security Operations](https://www.g2.com/products/google-chronicle-security-operations/reviews)
  - [Logsign Unified SO Platform](https://www.g2.com/products/logsign-unified-so-platform/reviews)
  - [Microsoft Defender for Endpoint](https://www.g2.com/products/microsoft-defender-for-endpoint/reviews)
  - [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)
  - [OpenCTI by Filigran](https://www.g2.com/products/opencti-by-filigran/reviews)
  - [Palo Alto Networks Cortex XSOAR](https://www.g2.com/products/palo-alto-networks-cortex-xsoar/reviews)
  - [Rapid7 Security Services](https://www.g2.com/products/rapid7-security-services/reviews)
  - [Splunk SOAR (Security Orchestration, Automation and Response)](https://www.g2.com/products/splunk-soar-security-orchestration-automation-and-response/reviews)
  - [Sumo Logic](https://www.g2.com/products/sumo-logic/reviews)
  - [Swimlane](https://www.g2.com/products/swimlane/reviews)
  - [ThreatConnect TI Ops](https://www.g2.com/products/threatconnect-ti-ops/reviews)
  - [ThreatQ](https://www.g2.com/products/threatq/reviews)
  - [Tines](https://www.g2.com/products/tines/reviews)
  - [Torq AI SOC Platform](https://www.g2.com/products/torq-ai-soc-platform/reviews)

## ANY.RUN Sandbox Features
**Detection**
- Malware Detection

**Analysis**
- Malware Evaluation
- Sandboxing
- Threat Intelligence
- File Analysis

**Generative AI**
- AI Text Summarization

## Top ANY.RUN Sandbox Alternatives
  - [Intezer](https://www.g2.com/products/intezer-intezer/reviews) - 4.5/5.0 (187 reviews)
  - [VirusTotal](https://www.g2.com/products/virustotal/reviews) - 4.7/5.0 (33 reviews)
  - [Hybrid Analysis](https://www.g2.com/products/hybrid-analysis/reviews) - 4.4/5.0 (12 reviews)

