ANY.RUN

Web · Windows · Mac · Linux · Android · iPhone · API

Freedom report

Three barsScore 6.7

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely6 of 6 device platforms
  • DocumentedPlans, terms and facts published

ANY.RUN is a cloud service for interactive malware analysis and threat intelligence aimed at security teams. Analysts can submit a file or link and inspect its behavior, indicators of compromise, tactics, techniques, and triggered detection rules. Its browser-based sandbox provides a virtual machine that analysts can control in real time. ANY.RUN says virtual machines start in under 10 seconds and reports are ready in 40 seconds. Windows, macOS, Linux, and Android analysis environments are supported, with availability depending on the plan. The free Community plan costs 0.00 USD per free and includes Windows 10 64-bit, Windows 7 32-bit, Android 14 64-bit ARM, and Ubuntu 22.04.2 64-bit environments. It has a 60-second VM timeout and a 16 MB maximum input file size. The service also offers API and SDK access, network traffic analysis, and IOC extraction. Listed integrations include Microsoft Defender, Microsoft Sentinel, OpenCTI, SentinelOne, Splunk, Cortex XSOAR, and IBM QRadar. ANY.RUN says its threat intelligence draws on millions of sandbox investigations into malware and phishing threats; SOC teams can try premium features with a 14-day trial.

Who it is for

ANY.RUN suits security teams that need to inspect suspicious files or links in an interactive sandbox. Its Enterprise Suite is presented for SMBs, enterprise companies, MSSPs, and government agencies.

What is good

  • Interactive browser sandbox supports real-time VM control
  • Analysis includes indicators, tactics, techniques, and detection rules
  • API and SDK access are available
  • 14-day trial advertised for SOC teams

What to know first

  • Community plan has a 60-second VM timeout
  • Community plan limits input files to 16 MB
  • Analysis environment availability varies by plan

Freedom251 review

ANY.RUN: the full review

ANY.RUN combines interactive sample analysis with threat-intelligence and integration options. The Community plan has short VM and file-size limits, so check whether its scope fits your analysis needs.

Overview

ANY.RUN is a cloud-based malware analysis and threat intelligence platform for security teams. It suits analysts who need to inspect suspicious files or links while interacting with the sample’s virtual machine, rather than relying only on a static report. The Community plan makes it possible to start free, but its short analysis window and small file cap make it a limited fit for demanding investigations.

Analysts can submit a file or URL and examine behavior, indicators of compromise, tactics and techniques, and detection rules triggered during analysis. The browser-based sandbox allows real-time interaction with its virtual machine. ANY.RUN says machines start in under 10 seconds and reports are ready in 40 seconds; those stated speeds may matter to teams triaging samples quickly.

ANY.RUN says its threat intelligence draws on data from millions of sandbox investigations into live malware and phishing threats. The company dates the product idea to 2016, names Aleksey Lapshin as its founder, and is headquartered in Dubai, United Arab Emirates.

Key features

  • Interactive analysis: Analysts can interact with a running sample in the browser-based virtual machine. That makes the sandbox useful for observing behavior that depends on actions inside the environment.
  • Investigation output: Analysis can surface IOCs, tactics and techniques, and triggered detection rules. This gives security teams several kinds of evidence to review in one workflow.
  • Environment options: The sandbox supports Windows, macOS, Linux, and Android analysis, with availability varying by plan. The Community plan includes Windows 10 64-bit, Windows 7 32-bit, Android 14 64-bit (ARM), and Ubuntu 22.04.2 64-bit.
  • Integrations and formats: Connectors include Microsoft Defender, Microsoft Sentinel, OpenCTI, SentinelOne, Splunk, Cortex XSOAR, and IBM QRadar. API and SDK access, plus STIX/MISP support for integrations, give teams routes to connect analysis with existing security workflows.
  • Security and access: ANY.RUN states that it has SOC 2 Type II compliance and supports SAML 2.0 single sign-on and configurable multi-factor authentication, features relevant to organizations managing analyst access.

Pricing

ANY.RUN uses a freemium model, with a free plan and a 14-day free trial advertised for SOC teams to try products with premium features. The Community plan is 0.00 USD per free, billed forever. It includes a 60-second VM timeout and a 16 MB maximum input file size. That is a useful no-cost starting point, but the brief runtime and file cap can rule it out for larger samples or investigations that need longer observation.

Hunter has custom pricing, billed yearly at an individual price. It provides 70% of sandbox functionality, a 660-second VM timeout, a 100 MB maximum file size, and private analyses. It is the step up for individuals who need substantially more runtime, larger samples, or privacy, while accepting that it does not include the full sandbox feature set.

Enterprise Suite also has custom pricing, billed yearly at an individual price. It includes 100% of sandbox functionality, a 1,200-second VM timeout, 1,500+ API tasks per month, premium support, and private analyses. That package is aimed at teams needing full functionality, API capacity, and support. The Enterprise Suite is presented for SMBs, enterprise companies, MSSPs, and government agencies. The advertised 14-day trial gives SOC teams a way to evaluate premium features before choosing a plan.

Platforms

ANY.RUN is a cloud deployment accessed through the web, with analysis environments spanning Windows, macOS, Linux, and Android subject to plan availability. Its platform coverage also includes API access and Android, iOS, Linux, macOS, web, and Windows. The gap between broad platform coverage and plan-specific sandbox environments is worth checking against the systems a team needs to analyze.

Who it's for

ANY.RUN is best suited to security analysts and teams that need interactive malware or phishing investigation, threat-intelligence context, and connections to established security products. Its longer timeouts, private analyses, and API allowance make paid tiers more appropriate for regular operational use. The Community plan is better for trying the workflow or handling small, short analyses than for teams with larger files or longer-running samples.

For technical support, ANY.RUN gives the address [email protected]; sales, demo, and trial inquiries go to [email protected].

Pros and cons

  • Pro: Real-time VM interaction adds behavioral context beyond simply submitting a file or link and receiving a report.
  • Pro: Analysis can bring together IOCs, tactics, techniques, and detection rules, while integrations and API/SDK access support security workflows.
  • Pro: The free plan is billed forever at 0.00 USD per free, and the 14-day trial offers SOC teams a premium-feature evaluation period.
  • Con: Community limits analysis to a 60-second VM timeout and 16 MB files, which constrains longer investigations and larger samples.
  • Con: Hunter offers only 70% of sandbox functionality, so moving beyond Community does not automatically mean full feature access.
  • Con: Hunter and Enterprise Suite use custom pricing, billed yearly at an individual price, so their costs require a quote.

Alternatives

  • Retrace is a reasonable alternative for users who want a free Community tier with unlimited public analyses, a standard execution queue, a web interface, and basic report export.
  • Hatching Triage may suit organizations that need volume-based licensing, with packages starting at 500 analyses per day and scaling toward 50,000 per day, plus bespoke enterprise volumes.
  • Malwagon is worth considering for a tightly limited free scan: three scans per source address per day, Windows 10 22H2, no internet egress, and public reports.
  • CAPE Sandbox fits readers seeking free, open-source software with a self-hosted setup rather than a cloud deployment.
  • Hybrid Analysis offers a free community service with 30 file uploads per month and a 100 MB maximum upload size.
  • Detonate is another freemium option for web and Linux.
  • ReversingLabs Cloud Sandbox may fit users who want a feature preview capped at five sample uploads per day, with full access available at additional cost.
  • Bitdefender Total Security is a paid alternative with a free plan and trial, covering Android, iOS, macOS, and Windows; its Total Security Individual plan is 59.99 USD per year (billed First year price; plus applicable sales tax; 5 devices · 1 account).

For broader comparisons, see Malware Analysis Sandboxes and Sandbox Software.

Verdict

Choose ANY.RUN if your security work benefits from interactive sample analysis, threat-intelligence context, and integrations with tools such as Microsoft Sentinel, Splunk, or QRadar. The main reason to look elsewhere is the mismatch between Community’s 60-second, 16 MB limits and more demanding analysis needs, compounded by custom pricing on the yearly paid plans. For teams that can use the longer timeouts and private analysis, it is a focused option; for light or occasional use, start with Community or compare alternatives with different free-tier limits.

ANY.RUN plans and pricing

All plans
Community Free forever Windows 10 64-bit · Windows 7 32-bit · Android 14 64-bit (ARM) · Ubuntu 22.04.2 64-bit · 60 sec VM timeout · 16 MB max file size any.run · 29 Sept 2026
Hunter Not published billed yearly; individual price 70% of sandbox functionality · 660 sec VM timeout · 100 MB max file size · private analyses any.run · 29 Sept 2026
Enterprise Suite Not published billed yearly; individual price 100% of sandbox functionality · 1,200 sec VM timeout · 1,500+ API tasks/mo · premium support · private analyses any.run · 29 Sept 2026

Compared on malware analysis sandboxes

Free plan
Yes
URL analysis
Yes
API access
Yes
Network traffic analysis
Yes
IOC extraction
Yes
File size limit
100 MB
Deployment model
cloud

Best ANY.RUN alternatives

See all 20