![Verified User in Financial Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Financial Services")
UF

Verified User in Financial Services

Enterprise (\> 1000 emp.)

4/29/2025

More Options
- 

"A Must-Have Tool for Threat Analysts"

5/5

What do you like best about ANY.RUN Sandbox?

We really appreciate how the interactive sandbox allows for real-time engagement with malware samples, particularly those that require user interaction to fully detonate. The user interface is clean and intuitive, making it easy to navigate and work through analyses efficiently.

The detailed reporting significantly speeds up the process of compiling findings, and the addition of AI-driven reporting provides deeper insights without the need for constant manual investigation.

Having access to the Proof of Concept (PoC) version also highlighted the full potential of the platform, offering expanded operating system support and a broader set of capabilities that enhance threat analysis even further. Review collected by and hosted on G2.com.

What do you dislike about ANY.RUN Sandbox?

Overall, the platform performs very well, but one improvement area would be expanding the flexibility for simulating different user behaviors or system states during a detonation. In some cases, malware that relies on very specific conditions or timing might require a bit more manual intervention to fully observe its behavior. It’s a minor point that Any.Run is constantly tweaking, but more advanced automation or customization options would make an already strong platform even better. Review collected by and hosted on G2.com.

What problems is ANY.RUN Sandbox solving and how is that benefiting you?

ANY.RUN helps us quickly see how malware behaves by giving us an interactive sandbox where we can manually trigger actions, like clicking and typing, to fully execute the malware. This makes it much easier to catch behaviors that wouldn’t show up in a basic automated analysis. While it covers most use cases very well, for highly specialized or environment-sensitive malware, we sometimes need more advanced setups — but for everyday malware analysis and investigation, it saves us a lot of time and gives us detailed reports we can trust. Review collected by and hosted on G2.com.

Show More

Response from Thomas Harris of ANY.RUN Sandbox

[Editedit](https://www.g2.com/survey_responses/any-run-sandbox-review-11099365/official_response/edit)

Thank you so much for your thoughtful and detailed review, we truly appreciate your support and feedback!

We're especially glad to hear that the interactive sandbox, intuitive UI, and AI-driven reporting are making a real difference in your workflow. It's always rewarding to know that ANY.RUN is helping analysts like you work more efficiently and with greater insight.

Regarding your comment on simulating different user behaviors, great point! We wanted to highlight that ANY.RUN already includes an "Automated Interactivity (ML)" feature that helps simulate user actions during detonation. You can read more about how it works and how to activate certain automated interaction scenarios in this post: https://any.run/cybersecurity-blog/automated-interactivity-stage-two/

We’re also actively working on expanding this functionality: upcoming releases will support even more behavior scenarios and introduce enhanced visualization of automated actions to give you a clearer picture of what’s happening under the hood.

Thanks again for your feedback and for being part of the ANY.RUN community!

Current UserValidated ReviewerSource: Organic

See what 217 reviewers think of ANY.RUN Sandbox

4.7 out of 5 · Verified reviews from real users

[
Read all reviews
](https://www.g2.com/products/any-run-sandbox/reviews)