
ANY.RUN
Summary
ANY.RUN is a cloud-based malware analysis and threat intelligence service for security teams. Analysts can submit a file or link and inspect sample behavior, indicators of compromise, tactics, techniques, and detection rules triggered during analysis. Its browser-based sandbox lets analysts interact with a virtual machine in real time. Windows, macOS, Linux, and Android environments are supported, with availability depending on the plan. The free Community plan includes Windows 10 64-bit, Windows 7 32-bit, Android 14 64-bit ARM, and Ubuntu 22.04.2 64-bit environments, with a 60-second virtual-machine timeout and a 16 MB maximum input file size. The service also provides API and SDK access, network traffic analysis, IOC extraction, and STIX/MISP support for integrations. Listed connectors include Microsoft Defender, Microsoft Sentinel, Splunk, and IBM QRadar. ANY.RUN says its threat intelligence draws on millions of sandbox investigations into malware and phishing threats. A 14-day trial is advertised for SOC teams. Listed security provisions include SOC 2 Type II compliance, SAML 2.0 single sign-on, and configurable multi-factor authentication.
Who it is for
ANY.RUN is aimed at security teams that need to inspect suspicious files or links in an interactive sandbox. Its Enterprise Suite is presented for SMBs, large companies, MSSPs, and government agencies.
What is good
- Interactive browser sandbox for real-time analysis
- Accepts files and links for inspection
- API and SDK access are available
- Includes network traffic analysis and IOC extraction
What to know first
- Community VM timeout is 60 seconds
- Community input files are limited to 16 MB
- Environment availability varies by plan
Everything Xiaomi review
ANY.RUN: the full review
ANY.RUN offers interactive sample analysis alongside threat intelligence and integrations. The free Community plan has explicit time and file-size limits, while a 14-day trial is available for SOC teams.
Overview
ANY.RUN is a cloud-based malware analysis and threat intelligence service for security teams. Analysts can submit a file or link and inspect its behavior, indicators of compromise, tactics and techniques, and detection rules activated during analysis. The browser-based sandbox runs a virtual machine analysts can interact with while a sample is running.
ANY.RUN says its virtual machines start in under 10 seconds and reports are ready in 40 seconds. These are the provider’s stated timings. The company dates the product idea to 2016, identifies Aleksey Lapshin as its founder, and lists its headquarters in Dubai, United Arab Emirates.
For readers comparing tools in this area, see our guides to Malware Analysis Sandboxes and Sandbox Software.
Key features
- Interactive sample analysis: Upload files or submit links to observe sample behavior in a browser-based virtual machine and interact with its environment in real time.
- Investigation details: Analysis can surface indicators of compromise, tactics and techniques, and the detection rules triggered by a sample.
- Threat intelligence: ANY.RUN says its intelligence uses data from millions of sandbox investigations into live malware and phishing threats.
- Integrations and API: API and SDK access are available. The integrations directory lists connectors for Microsoft Defender, Microsoft Sentinel, OpenCTI, SentinelOne, Splunk, Cortex XSOAR, and IBM QRadar, along with STIX/MISP support for integrations.
- Security controls: ANY.RUN states that it has SOC 2 Type II compliance and supports SAML 2.0 single sign-on and configurable multi-factor authentication.
Supported analysis environments include Windows, macOS, Linux, and Android, with availability depending on plan. Community includes Windows 10 64-bit, Windows 7 32-bit, Android 14 64-bit (ARM), and Ubuntu 22.04.2 64-bit. The published Community limits are a 60-second virtual machine timeout and a maximum input file size of 16 MB.
Pricing
ANY.RUN uses a freemium model. Its Community plan is free at 0.00 USD, billed forever. Hunter and Enterprise Suite are billed yearly with individual pricing; no prices are listed for either.
| Plan | Price and term | Listed details |
|---|---|---|
| Community | 0.00 USD per free, billed forever | 60-second VM timeout; 16 MB maximum file size; listed Windows, Android, and Ubuntu environments. |
| Hunter | Price not listed; billed yearly, individual price | 70% of sandbox functionality; 660-second VM timeout; 100 MB maximum file size; private analyses. |
| Enterprise Suite | Price not listed; billed yearly, individual price | 100% of sandbox functionality; 1,200-second VM timeout; 1,500+ API tasks per month; premium support; private analyses. |
ANY.RUN also advertises a 14-day free trial for SOC teams, with premium features. The trial is separate from the forever-free Community plan. Availability and features vary by plan.
Platforms
ANY.RUN lists Android, iOS, Linux, macOS, web, and Windows platforms, as well as API access. The sandbox supports Windows, macOS, Linux, and Android analysis environments, subject to plan availability. The service is deployed in the cloud.
Who it's for
ANY.RUN is intended for security teams investigating suspicious files and links, reviewing sample behavior, or using threat intelligence and sandbox results in wider security workflows. Its Enterprise Suite is presented for SMBs, enterprise companies, managed security service providers, and government agencies. API and SDK access, integrations, and STIX/MISP support may also suit teams that need to connect analysis to other security tools.
The limits matter when choosing a plan: Community allows 60 seconds per virtual machine run and files up to 16 MB, while the listed Hunter and Enterprise Suite limits are 660 seconds and 100 MB, and 1,200 seconds and 1,500+ API tasks per month, respectively.
Pros and cons
Pros
- Interactive browser-based analysis of files and links.
- Analysis includes behavior, indicators of compromise, tactics and techniques, and triggered detection rules.
- A free Community plan is available, and a separate 14-day trial is advertised for SOC teams.
- API and SDK access, named integrations, and STIX/MISP support are listed.
- ANY.RUN states SOC 2 Type II compliance and support for SAML 2.0 and configurable multi-factor authentication.
Cons
- Community is limited to a 60-second VM timeout and 16 MB maximum input file size.
- Prices for Hunter and Enterprise Suite are not listed; both use individual yearly pricing.
- Supported environments and functionality depend on the plan.
Alternatives
Other options in related security categories include Retrace, Hatching Triage, Malwagon, CAPE Sandbox, and Hybrid Analysis. For broader security product comparisons, consider Bitdefender Total Security, Zscaler Private Access, or CrowdStrike Falcon Pro.
Verdict
ANY.RUN combines interactive sandbox analysis with threat intelligence, integration options, and API access. The free Community plan offers a way to start, but its timeout and file-size limits are modest relative to the higher tiers described. Teams considering Hunter or Enterprise Suite should weigh their environment, analysis-duration, privacy, and API needs against the individual yearly pricing, which is not published. The advertised trial gives SOC teams 14 days to try premium features before choosing.
ANY.RUN plans and pricing
All plansCompared on malware analysis sandboxes
Facts
- Product
- ANY.RUN provides interactive malware analysis and threat intelligence solutions for security teams.any.run · 29 Sept 2026
- Analysis
- Users can upload a file or submit a link to inspect sample behavior, indicators of compromise, tactics, techniques, and triggered detection rules.any.run · 29 Sept 2026
- Interactive sandbox
- The sandbox runs in a browser and lets analysts interact with a virtual machine in real time.any.run · 29 Sept 2026
- Analysis speed
- ANY.RUN says its virtual machines start in under 10 seconds and reports are ready in 40 seconds.any.run · 29 Sept 2026
- Supported environments
- The sandbox supports Windows, macOS, Linux, and Android analysis environments, with availability varying by plan.any.run · 29 Sept 2026
- Threat intelligence
- ANY.RUN says its threat intelligence uses data from millions of sandbox investigations into live malware and phishing threats.any.run · 29 Sept 2026
- Integrations
- The integrations directory lists connectors for Microsoft Defender, Microsoft Sentinel, OpenCTI, SentinelOne, Splunk, Cortex XSOAR, and IBM QRadar.any.run · 29 Sept 2026
- API and formats
- ANY.RUN offers access through API and SDK and lists STIX/MISP support for integrations.any.run · 29 Sept 2026
- Security
- ANY.RUN states that it has SOC 2 Type II compliance and supports SAML 2.0 single sign-on and configurable multi-factor authentication.any.run · 29 Sept 2026
- Trial
- ANY.RUN advertises a 14-day free trial for SOC teams to try its products with premium features.any.run · 29 Sept 2026
- Support
- The contact page lists [email protected] for technical support and [email protected] for sales, demo, and trial inquiries.any.run · 29 Sept 2026
- Intended users
- The Enterprise Suite is presented for SMBs, enterprise companies, MSSPs, and government agencies.any.run · 29 Sept 2026
- Notable limits
- The Community plan allows a 60-second VM timeout and a maximum input file size of 16 MB.any.run · 29 Sept 2026
- Company history
- ANY.RUN's about page says the idea for the product dates to 2016 and names Aleksey Lapshin as its founder.any.run · 29 Sept 2026
Company
- Founded
- 2016any.run · 23 Sept 2026
- Headquarters
- Dubai, United Arab Emiratesany.run · 23 Sept 2026
Best ANY.RUN alternatives
See all 12Where it ranks on Everything Xiaomi
Is ANY.RUN yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- any.run· checked 29 Sept 2026
- any.run/features/· checked 29 Sept 2026
- any.run/integrations/· checked 29 Sept 2026
- any.run/compliance/· checked 29 Sept 2026
- any.run/contacts/· checked 29 Sept 2026
- any.run/plans/· checked 29 Sept 2026
- any.run/about-us/· checked 29 Sept 2026


