Book a demo call with us
Cross icon
Malware

Any run

Coming soon

An interactive online malware sandbox and threat intelligence platform used by cybersecurity analysts to safely execute and investigate suspicious files, URLs, phishing pages, and malware in isolated virtual machines.

Any run

What is ANY.RUN?

ANY.RUN is an interactive online malware sandbox that lets security analysts execute suspicious files, URLs, and phishing pages inside isolated virtual machines and observe exactly what happens in real time. Unlike traditional automated sandboxes that run a sample and return a static report, ANY.RUN is fully interactive: the analyst controls the environment during execution, can click links, open documents, interact with installers, and trigger deferred payloads that would otherwise remain dormant. Every action taken by the malware is captured and displayed live: process creation, file system changes, registry modifications, network connections, DNS queries, and API calls. The platform also extracts indicators of compromise automatically, generates MITRE ATT&CK mappings, and provides YARA rule matches, making the output immediately usable for detection and hunting. Because it runs in the cloud, no local infrastructure is required, and sessions can be shared with team members for collaborative investigation.

How does ANY.RUN work with Qevlar?

Qevlar integrates with ANY.RUN to analyze suspicious files and URLs encountered during automated investigations. When an alert involves an unknown executable, a suspicious attachment, or a potentially malicious link, Qevlar can submit it to ANY.RUN and retrieve the behavioral verdict, extracted IOCs, and ATT&CK mappings to enrich the investigation before an analyst reviews it.

Want to help your analysts focus on the most critical alerts?

Frequently asked questions

What does ANY.RUN do?

bar
bar

ANY.RUN is an interactive online malware sandbox that runs suspicious files, URLs and phishing pages inside isolated virtual machines and shows exactly what they do in real time — processes, network connections, dropped files and extracted indicators of compromise.

What can you do with ANY.RUN in Qevlar?

bar
bar

Qevlar can submit suspicious files and URLs from an alert to ANY.RUN, retrieve the behavioral verdict, extracted IOCs and MITRE ATT&CK mapping, and fold that evidence into an automated investigation — so analysts get a detonation result without leaving the case.

Do I need to detonate samples manually?

bar
bar

No. When an investigation involves an unknown attachment or link, Qevlar handles the submission and result retrieval automatically, then uses the verdict to decide whether the alert is malicious, benign or needs a closer look.

Can Qevlar use ANY.RUN findings to search the rest of my environment?

bar
bar

Yes. IOCs that ANY.RUN extracts during detonation can be pivoted across your connected SIEM, EDR and email tools to find related activity elsewhere in the estate.

Other integrations