Retrace

Web · Windows · Mac · Linux · Android · Self-hosted · API

Freedom report

Three barsScore 6.7

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely5 of 6 device platforms
  • DocumentedPlans, terms and facts published

Retrace is an AI-powered malware analysis platform built around interactive sandboxes for Windows, macOS, Linux and Android virtual machines. Each sample runs in a disposable virtual machine separate from the user's laptop. During execution, Retrace records file writes, registry activity, network packets and process spawns. Its AI copilot answers questions using the sandbox trace and cites specific events, techniques or captured files. Each detonation is matched against the user's full sandbox corpus for similarity and malware-family evidence. AI answers can be exported as Markdown, PDF or STIX 2.1 bundles. The free Community plan includes public analyses, a standard execution queue, web access and basic report export. Public analyses expose results, events, behavioral data, screenshots and detection results to all service users. Team adds private submissions, priority queueing, REST API access, team management and audit logging. Enterprise inference runs on-premises, while Sovereign deployments are air-gapped. The service is designed for legitimate security research, malware analysis, incident response and threat intelligence.

Who it is for

Retrace is intended for security researchers, malware analysts, incident responders and threat-intelligence teams. Teams handling sensitive samples may consider the private-submission or sovereign deployment options.

What is good

  • Disposable virtual machines isolate each sample.
  • Captures file, registry, network and process activity.
  • Copilot cites events, techniques and captured files.
  • Exports include Markdown, PDF and STIX 2.1.
  • Team tier includes private submissions and REST API access.

What to know first

  • Community analyses are public to all service users.
  • Community plan uses a standard execution queue.
  • API keys must remain confidential.
  • Documented rate limits and fair-use guidelines apply.

Freedom251 review

Retrace: the full review

Retrace combines sandbox telemetry, corpus matching and cited AI answers, with different options for public or private analysis. Users should consider the visibility of Community analyses and follow the API limits and fair-use guidelines.

Retrace is a malware-analysis platform for researchers and security teams examining suspicious files across operating systems. Its evidence-linked AI and corpus matching make it a strong fit for investigations that need behavioral context as well as a report. The free tier is useful for public work, but private or tightly controlled analysis calls for a paid tier.

Overview

Samples run in disposable virtual machines rather than on the analyst’s laptop, with Windows, macOS, Linux, and Android environments. Retrace captures file writes, registry activity, network packets, and process spawns, giving investigations several kinds of observed behavior to examine. Its AI copilot answers questions against that trace and cites events, techniques, or captured files, a practical way to connect a summary to supporting evidence.

Each detonation is also matched against the user’s sandbox corpus for similarity and family evidence. Answers can be exported as Markdown, PDF, or STIX 2.1 bundles for MISP and other threat-intelligence platforms. That combination supports analysis and reporting in one workflow, though the cited behavior still needs analyst interpretation.

Key features

  • Interactive, isolated execution: Disposable virtual machines keep sample execution separate from a user’s laptop. Multi-OS coverage suits researchers investigating behavior across Windows, macOS, Linux, and Android.
  • Behavioral telemetry and indicators: File, registry, network, and process records provide a useful basis for investigating activity; Retrace also supports network traffic analysis and IOC extraction.
  • Evidence-linked AI: The copilot’s citations let analysts check which captured events, techniques, or files support an answer. This is more useful for investigation than a summary without trace references, but it is not a substitute for reviewing the evidence.
  • Corpus matching and export: Similarity and family evidence draw on the user’s full sandbox corpus. Markdown, PDF, and STIX 2.1 exports give teams options for documentation and sharing with MISP or other threat-intelligence platforms.
  • Private and sovereign deployment: Team adds private submissions and operational controls; Enterprise offers dedicated hardware, optional UK, EU, or US data residency, SSO/SAML, and custom retention. Sovereign deployments are air-gapped and keep sample bytes, IOCs, and tool calls within the customer’s infrastructure.

Pricing

Retrace uses a freemium model. Community costs 0.00 USD per free and includes Community feed access, a standard execution queue, web interface, basic report export, and unlimited public analyses. It is the entry point for public research, but unlimited analyses do not make the results private or the queue priority-based.

Team has custom pricing and includes private submissions, priority queueing, REST API access, team management, and audit logging. It is the more appropriate choice when confidentiality, team coordination, or queue priority matters. Enterprise also has custom pricing and adds a multi-tenant workspace, dedicated hardware, UK, EU, or US data residency on request, SSO/SAML, and custom data retention.

Sovereign has custom pricing and is aimed at organizations that need an air-gap-compatible deployment, full data sovereignty, custom hardware support, unlimited throughput, and a dedicated account manager. Support is provided according to plan tier. API users must keep keys confidential, respect documented rate limits, and ensure automated bulk submissions follow fair-use guidelines.

Platforms

Retrace supports web access, an API, and Android, Linux, macOS, and Windows platforms. Its sandbox environments cover Windows, macOS, Linux, and Android virtual machines, so the listed platform range aligns with its multi-OS analysis focus.

Who it's for

Retrace is designed for legitimate security research, malware analysis, incident response, and threat intelligence. Community suits analysts whose work can be public; teams handling sensitive samples should consider Team or a higher tier because analyses marked public expose results, events, behavioral data, screenshots, and detection results to all service users.

Enterprise is a better fit for organizations that need dedicated hardware, identity controls, retention options, or regional data residency. Sovereign is for customers requiring an air-gapped environment and full data sovereignty. Retrace is less suitable when private analysis is essential but a custom-priced tier is outside the budget.

Pros and cons

  • Pro: AI answers cite trace evidence, giving analysts a route to verify the basis for an answer.
  • Pro: Corpus matching and multiple report export formats connect investigation with family comparison and downstream reporting.
  • Pro: Deployment choices range from public Community analysis to private, dedicated, and air-gapped options.
  • Con: Community analyses can expose extensive behavioral and detection data to all service users, making it unsuitable for sensitive samples.
  • Con: Team, Enterprise, and Sovereign have custom pricing, so their costs cannot be compared from a published figure.
  • Con: Community uses a standard queue and basic report export, giving up the priority queue and broader controls in Team and above.

Alternatives

Malware Analysis Sandboxes is a useful place to compare the category. Choose ANY.RUN if you want a freemium alternative with a free trial and listed Windows, Android, and Ubuntu environments. Malwagon may suit users looking for a free scan tier capped at three scans per source address per day, with no internet egress and public reports.

Choose CAPE Sandbox if open-source software and a self-hosted setup are the priority. Hybrid Analysis offers a free community service capped at 30 file uploads per month and a 100 MB maximum upload size. Bitdefender Total Security is a paid endpoint-security alternative rather than a sandbox comparison: its listed Individual plan is 59.99 USD per year, billed at the first-year price, for five devices and one account.

Hatching Triage may fit organizations seeking volume-based licensing, with packages starting at 500 analyses per day and scaling toward 50,000 per day. ReversingLabs Cloud Sandbox offers a feature preview limited to five samples per day, with full access at additional cost. Zscaler Private Access is a paid private-access product, not a malware-analysis sandbox substitute.

Verdict

Retrace is a strong choice for security researchers and incident-response or threat-intelligence teams that want multi-OS behavior capture, corpus comparisons, and AI answers tied to trace evidence. Community is best reserved for work that can be public; choose a higher tier when privacy, priority, or infrastructure controls matter. Look elsewhere if those controls are essential but custom pricing does not fit.

Retrace plans and pricing

All plans
Community Free Community feed access · Standard execution queue · Web interface · Basic report export · Unlimited public analyses retrace.cloud · 1 Oct 2026
Enterprise Not published Multi-tenant workspace · UK, EU or US data residency on request · Dedicated hardware · SSO/SAML · Custom data retention retrace.cloud · 1 Oct 2026
Team Not published Private submissions · Priority queueing · REST API access · Team management · Audit logging retrace.cloud · 1 Oct 2026
Sovereign Not published Air-gap compatible · Unlimited throughput · Full data sovereignty · Custom hardware support · Dedicated account manager retrace.cloud · 1 Oct 2026

Compared on malware analysis sandboxes

Free plan
Yes
URL analysis
Yes
API access
Yes
Network traffic analysis
Yes
IOC extraction
Yes

Best Retrace alternatives

See all 20