An interactive online malware sandbox and threat intelligence platform used by cybersecurity analysts to safely execute and investigate suspicious files, URLs, phishing pages, and malware in isolated virtual machines.

ANY.RUN is an interactive online malware sandbox that lets security analysts execute suspicious files, URLs, and phishing pages inside isolated virtual machines and observe exactly what happens in real time. Unlike traditional automated sandboxes that run a sample and return a static report, ANY.RUN is fully interactive: the analyst controls the environment during execution, can click links, open documents, interact with installers, and trigger deferred payloads that would otherwise remain dormant. Every action taken by the malware is captured and displayed live: process creation, file system changes, registry modifications, network connections, DNS queries, and API calls. The platform also extracts indicators of compromise automatically, generates MITRE ATT&CK mappings, and provides YARA rule matches, making the output immediately usable for detection and hunting. Because it runs in the cloud, no local infrastructure is required, and sessions can be shared with team members for collaborative investigation.
Qevlar integrates with ANY.RUN to analyze suspicious files and URLs encountered during automated investigations. When an alert involves an unknown executable, a suspicious attachment, or a potentially malicious link, Qevlar can submit it to ANY.RUN and retrieve the behavioral verdict, extracted IOCs, and ATT&CK mappings to enrich the investigation before an analyst reviews it.
ANY.RUN is an interactive online malware sandbox that runs suspicious files, URLs and phishing pages inside isolated virtual machines and shows exactly what they do in real time — processes, network connections, dropped files and extracted indicators of compromise.
Qevlar can submit suspicious files and URLs from an alert to ANY.RUN, retrieve the behavioral verdict, extracted IOCs and MITRE ATT&CK mapping, and fold that evidence into an automated investigation — so analysts get a detonation result without leaving the case.
No. When an investigation involves an unknown attachment or link, Qevlar handles the submission and result retrieval automatically, then uses the verdict to decide whether the alert is malicious, benign or needs a closer look.
Yes. IOCs that ANY.RUN extracts during detonation can be pivoted across your connected SIEM, EDR and email tools to find related activity elsewhere in the estate.