ANY.RUN Sandbox
Automatic deploy
Supported by Filigran
Detection & Response Enablement
Overview
The ANY.RUN Sandbox connector lets SOC teams detonate and analyze suspicious files or URLs in a safe virtual environment directly from OpenCTI to uncover real-time malware & phishing behavior.
ANY.RUN Sandbox is an interactive malware & phishing analysis solution that provides safe, cloud-based virtual environments for executing and observing suspicious artifacts. It provides your team with the ability to detonate artifacts in cloud-based virtual environments (Windows, Linux, Android, and macOS), get a conclusive verdict on the threat, and safely see exactly how malware or phishing behaves in real time.
Key Capabilities:
- Launch Automated Analysis Directly from OpenCTI: Instead of manually moving files, you can trigger a deep analysis of suspicious artifacts right from your dashboard, which saves time and keeps your team focused on critical tasks.
- Uncover Hidden Threats by Automating Clicks and Tasks: The connector handles time-consuming manual actions, like solving CAPTCHAs or opening email attachments, to ensure you see the final stage of an attack that might otherwise stay hidden.
- Turn Technical Logs into Actionable Clarity: It automatically pulls details like malicious network traffic and registry changes into your OpenCTI records, giving you instant visibility into threat behavior without any manual data entry.
- Accelerate Response with Faster Triage: By receiving detailed, automated reports immediately, your analysts can move from detecting a threat to isolating it much faster, significantly shortening your overall time to respond.