ANY.RUN Sandbox Reviews (218)

Reviews

ANY.RUN Sandbox Reviews (218)

4.7
218 reviews

What do users say?

Generated using AI from real user reviews
Users consistently praise the ease of use and real-time interactivity of ANY.RUN Sandbox, which allows for effective malware analysis in a secure environment. The intuitive interface and detailed reports enhance the user experience, making it easier to identify threats quickly. However, some users note that the free version has limitations, particularly regarding analysis time.
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Dave P.
DP
Dave P.
Member of Board of Directors: APWG and APWG EU
Small-Business (50 or fewer emp.)
"Extremely Valuable Malware Metadata for Large-Scale Threat Research"
4.5/5
What do you like best about ANY.RUN Sandbox?

We submit URLs and file samples as part of our phishing, malware, and spam research at the Cybercrime Information Center, where we study how criminals acquire resources for cybercrimes. Using ANY.RUN we can augment the metadata that we gather for millions of domain names and IP addresses that we use to (1) identify resources associated with an attack or campaign, (2) identify which domain registry (TLD) operators, domain registrars, or hosting providers are exploited by cybercriminals. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

We haven't attempted to integrate the service into our analysis because of the sheer scale of our data sets and the potential cost or overhead. Review collected by and hosted on G2.com.

Response from Thomas Harris of ANY.RUN Sandbox

Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users.

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

Anurudh T.
AT
Anurudh T.
Trainee
Enterprise (> 1000 emp.)
"Safe, Isolated Environment for Testing Experimental Code"
5/5
What do you like best about ANY.RUN Sandbox?

Safe, isolated software for running code without affecting any other applications, which is a major advantage of using this application. It has proper safety measures in place, so it can be used on other systems and operated safely for testing. It also lets me run experimental code without touching the main branch.

I’ve mainly used it for testing unknown executables and safely experimenting with code without adding any of that to the main development branch. The best part of this application is being able to communicate with the virtual machine while experimenting.

Before using the application, I couldn’t open certain sites without worrying about security and potentially affecting other applications through malware or virus attacks. By using it, I feel the operating system and applications are well protected, even when working with code. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

It can behave differently than a production-based setup, for example when it’s running in a different environment or using a different database. Over time, maintaining isolated environments can also become complicated. Slow startup times and high RAM usage are drawbacks of the sandbox, and it may also limit access to certain systems.

During cybersecurity testing, I noticed that some malware samples or scripts detected they were running inside a sandbox and then limited their behavior, which made analysis harder. This limitation in real-world code has caused issues for me in that regard. Review collected by and hosted on G2.com.

Response from Thomas Harris of ANY.RUN Sandbox

Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users.

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

Parvathy S.
PS
Parvathy S.
Associate Software Engineer
Enterprise (> 1000 emp.)
"Easy Way to Analyze Suspicious Files"
3.5/5
What do you like best about ANY.RUN Sandbox?

I like the safety it provides for my device. I can see what it’s doing, and it helps me understand how threats actually work. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

It’s not suited for confidential data, since the free version makes it publicly available. It also relies heavily on internet speed. I also don’t think it can detect advanced malware. Review collected by and hosted on G2.com.

Achu S.
AS
Achu S.
Associate Software Engineer
Information Technology and Services
Enterprise (> 1000 emp.)
"Real-Time, Safer Malware Interaction in a Virtual Environment"
5/5
What do you like best about ANY.RUN Sandbox?

It’s helpful for interacting with malware safely in real time. It also lets me force the malware to reveal its actual behavior. What I like most is the real-time interactivity—it helps me run and interact with files more safely in a virtual environment. Overall, it’s good for learning as well. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

The one thing I dislike most is that the free version has limitations on certain features, so I can’t explore the platform in depth. Also, files uploaded in the free version may become publicly accessible, which could raise privacy concerns. Review collected by and hosted on G2.com.

Response from Thomas Harris of ANY.RUN Sandbox

Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users.

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

Florian K.
FK
Florian K.
Intern IT Supporter
Enterprise (> 1000 emp.)
"Simple UI and super informative analyses of URLs and files"
4.5/5
What do you like best about ANY.RUN Sandbox?

Overall, I like the website; the user interface is easy to use, the analysis of URLs and files is simple, the overview during the analysis is great, very informative and also understandable. I have never really used customer support myself, but my colleague has told me that they are relatively prompt and informative in providing assistance. I use ANY.RUN at least once a week and have never really had problems with the analyses. Implementing or adding URLs and files works very well every time, and I have never noticed any issues with uploading. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

What I like less is the resolution of the analysis, however, everything is still readable. Review collected by and hosted on G2.com.

Response from Thomas Harris of ANY.RUN Sandbox

Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users.

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

Bhatt P.
BP
Bhatt P.
Security analyst
Mid-Market (51-1000 emp.)
"The best ever sandboxing tool."
5/5
What do you like best about ANY.RUN Sandbox?

The best thing i like about any run sandboxing tool is that it provides a very accurate results and the GUI is very user friendly and easy to use.

It helps the user for easy implementation of the sandboxing.

I use this sandboxing tool very often and frequently as a part of my daily BAU. It consist of a variety of features which allows the user to analyse on ease.

Also, in case of any queries the customer support is very responsive and supportive.

It also provide various integration features to implement with our day-to-day tools for on the go use. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

The only thing i dislike is while entering a base-64 URL it gives an error for incorrect URL. Review collected by and hosted on G2.com.

Response from Thomas Harris of ANY.RUN Sandbox

Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users.

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

Aubin H.
AH
Aubin H.
Cybersecurity Expert
Enterprise (> 1000 emp.)
"Interactive & Efficient Malware Analysis with ANY.RUN"
4.5/5
What do you like best about ANY.RUN Sandbox?

I use ANY.RUN Sandbox primarily for interactive malware analysis and I appreciate the deep visibility it provides into malware behavior without the overhead of maintaining my own sandbox infrastructure. I like the real-time interactive VM control, which lets analysts reproduce user behavior and malware actions as if it were a real endpoint. The features of interactive analysis, real-time process monitoring, network analysis, and IOC extraction are key because they combine visibility and interaction, making analysis faster and more accurate. The initial setup of ANY.RUN Sandbox was very easy, as it's a cloud-based solution that required minimal configuration, enabling us to start analyzing samples quickly without complex deployment. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

The interface can feel crowded on very noisy or long-running analyses, and it can take time to find a specific event. Review collected by and hosted on G2.com.

Response from Thomas Harris of ANY.RUN Sandbox

Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users.

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

SA
Syed Zaid A.
Information Security Analyst
Mid-Market (51-1000 emp.)
"Transforms Malware Analysis with Real-Time Visibility"
5/5
What do you like best about ANY.RUN Sandbox?

ANY.RUN has become one of the most valuable tools in my malware analysis workflow. The interactive sandbox is incredibly fast, intuitive, and gives me real-time visibility into process behavior, network traffic, file system actions, and registry modifications—all in one place. The fact that I can interact with the malware live (click buttons, enter text, browse folders) sets it apart from traditional static sandboxes.

The preconfigured analysis environments save a lot of time, and the ability to pivot into deeper analysis—like unpacking, process tree visualization, and network IOCs—is extremely helpful. Their public submissions database is also a great resource when hunting emerging threats.

What I Like Most:

Real-time interactive analysis

Beautiful and clear process tree visualization

Rich metadata and automatic extraction of IOCs

Easy to use even for junior analysts

Great for SOC, DFIR, and malware research Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

Would love to see even more OS/Browser versions in interactive mode

Heavy samples sometimes take a bit longer to load—but still faster than many alternatives Review collected by and hosted on G2.com.

Response from Thomas Harris of ANY.RUN Sandbox

Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users.

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

JV
Jose V.
"Real-Time Interactive Analysis, with Areas for Improvement"
4/5
What do you like best about ANY.RUN Sandbox?

I use ANY.RUN Sandbox to review suspicious links and files related to phishing. I like it because the analysis is interactive and in real-time, which means I can see what's happening as it runs and not just wait for a final report. That helps me a lot to quickly understand if something is malicious. Additionally, the initial setup was quite simple, as registering and accessing the platform didn't take much time. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

Sometimes the free version falls a bit short, especially in analysis time or in some advanced features. They could extend the analysis time a bit. It would also help to have some advanced features enabled in a limited way, to better test them before moving to a paid plan. Review collected by and hosted on G2.com.

Response from Thomas Harris of ANY.RUN Sandbox

Thank you for sharing your insights and experiences! We truly appreciate your feedback, as it helps us continuously improve ANY.RUN and make it even better for our users.

Your thoughts and suggestions are invaluable to us—we take note of every detail and are always working on enhancements. Stay tuned for updates, and thank you for being a part of our community!

Siddhalingesh B.
SB
Siddhalingesh B.
Information Security Analyst
"Streamlined Malicious URL and File Analysis"
4.5/5
What do you like best about ANY.RUN Sandbox?

I really like the fact that ANY.RUN Sandbox generates a permanent report link after completing a run. This makes it easy for me to check reports later. I enjoy how the link opens a full interactive report, allowing an easy view of the process tree, network traffic, and IOCs. The ability to customize privacy settings is great. Public link option lets anyone view the analysis, while the private option restricts access to only me and my team. I like the ability to share the interactive report like a read-only, which is ideal for soft reviews and incident tickets. I appreciate the export feature that offers analysis results in multiple formats like HTML, JSON, and MSP, making it really easy for us to extract reports and share with our internal team. I find the initial setup very easy, just need to create a profile on the ANY.RUN website and it's ready for use. It's a breeze to use for my day-to-day operations. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

Sometimes, when uploading internal documents, there's no option to turn off the VirusTotal upload. This can be problematic because it involves internal, highly sensitive client data. Having the ability to disable the VirusTotal upload for sample analysis would be very helpful. Review collected by and hosted on G2.com.

Response from Thomas Harris of ANY.RUN Sandbox

Thank you for sharing your insights and experience with us! We truly appreciate your feedback — it helps us continuously improve ANY.RUN and make it even better for our users.

Please note that ANY.RUN does not upload user samples to VirusTotal. This functionality is not available on the platform, which is why there is no option to enable or disable it. All uploaded samples remain within the privacy mode selected for the analysis. If private mode is chosen, the data remains fully private according to the selected privacy settings and is not shared externally.

If you have any specific concerns regarding the handling of sensitive data, please feel free to contact our support team at support@any.run.