Verified User in Financial Services
UF
Enterprise (> 1000 emp.)
"A Must-Have Tool for Threat Analysts"
5/5
What do you like best about ANY.RUN Sandbox?

We really appreciate how the interactive sandbox allows for real-time engagement with malware samples, particularly those that require user interaction to fully detonate. The user interface is clean and intuitive, making it easy to navigate and work through analyses efficiently.

The detailed reporting significantly speeds up the process of compiling findings, and the addition of AI-driven reporting provides deeper insights without the need for constant manual investigation.

Having access to the Proof of Concept (PoC) version also highlighted the full potential of the platform, offering expanded operating system support and a broader set of capabilities that enhance threat analysis even further. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

Overall, the platform performs very well, but one improvement area would be expanding the flexibility for simulating different user behaviors or system states during a detonation. In some cases, malware that relies on very specific conditions or timing might require a bit more manual intervention to fully observe its behavior. It’s a minor point that Any.Run is constantly tweaking, but more advanced automation or customization options would make an already strong platform even better. Review collected by and hosted on G2.com.

Response from Thomas Harris of ANY.RUN Sandbox

Thank you so much for your thoughtful and detailed review, we truly appreciate your support and feedback!

We're especially glad to hear that the interactive sandbox, intuitive UI, and AI-driven reporting are making a real difference in your workflow. It's always rewarding to know that ANY.RUN is helping analysts like you work more efficiently and with greater insight.

Regarding your comment on simulating different user behaviors, great point! We wanted to highlight that ANY.RUN already includes an "Automated Interactivity (ML)" feature that helps simulate user actions during detonation. You can read more about how it works and how to activate certain automated interaction scenarios in this post: https://any.run/cybersecurity-blog/automated-interactivity-stage-two/

We’re also actively working on expanding this functionality: upcoming releases will support even more behavior scenarios and introduce enhanced visualization of automated actions to give you a clearer picture of what’s happening under the hood.

Thanks again for your feedback and for being part of the ANY.RUN community!

See what 217 reviewers think of ANY.RUN Sandbox

4.7 out of 5 · Verified reviews from real users

Read all reviews