ANY.RUN is a cloud malware-analysis service built around an interactive virtual machine. Instead of waiting only for an automated report, an analyst can use the browser to click, type, open files, and change the task while system and network activity is recorded.
This review checks the product against ANY.RUN’s current official documentation as of August 30, 2026. It does not claim that Top5soft detonated malware, measured detection rates, or compared execution speed in a controlled lab.
Correction published August 30, 2026: The previous edition contained unsupported RedLine and Cobalt Strike test stories, invented scores and timing claims, conflicting and outdated prices, and generated images presented in product-interface positions. This edition removes those claims and images, replaces the score with a workflow-based verdict, and links the deciding facts to official sources.
What ANY.RUN does
ANY.RUN’s defining feature is interactive access to a cloud virtual machine. Its current feature page describes a browser-accessible environment for malware and phishing analysis, plus reporting and integration options for security teams. The official task guide says the service records processes and marks suspicious or malicious activity while the analyst interacts with the VM.
Interactivity matters when a file or website waits for input. An analyst can open an attachment, enter a known archive password, follow an approved link, or observe what appears after a prompt. That capability can add evidence that a fixed automated run would not collect.
It does not make the result complete or guaranteed. A sample can still detect the environment, wait longer than the plan timeout, require unavailable software, depend on a particular locale, or hide behavior behind an external service that is offline. The correct description is therefore “interactive analysis,” not “defeats evasive malware.”
ANY.RUN is intended for trained security work. A cloud sandbox reduces the need to execute an unknown file on a normal workstation, but analysts still need authorization, safe sample handling, and a process for protecting submitted data.
Current plans and limits
The public plan comparison now lists Community, Hunter, and Enterprise Suite. Paid prices are quote-based; the page tells buyers to contact sales. The fixed monthly prices in the previous Top5soft edition are no longer supported.
| Plan | Public price | Privacy | VM timeout | Maximum input | Selected documented features |
|---|---|---|---|---|---|
| Community | Free | Public analyses | 60 seconds | 16 MB | Interactive analysis, basic reports, personal license, selected Windows, Ubuntu, and Android environments |
| Hunter | Contact sales, billed yearly | Private analyses available | 660 seconds | 100 MB | Additional Windows environments, system process monitoring, locale selection, reboot, residential proxy, JSON and MISP exports |
| Enterprise Suite | Contact sales, billed yearly | Private analyses and team controls | 1,200 seconds | 100 MB | Team management, SSO, workspace analytics, advanced privacy controls, API task capacity, more Windows, Linux, Android, and macOS environments |
ANY.RUN says users on all plans can run unlimited public analyses, with one analysis at a time. Private Hunter analyses use a custom quota. Enterprise private analyses can be unlimited or use a custom team quota. Those limits should be checked on the account before designing a SOC workflow.
Community is a legitimate way to learn the interface with samples approved for public research. It is not a safe default for customer files, proprietary binaries, private email, or documents containing personal information. Hunter is the first current plan with private analysis, while Enterprise adds organization-level controls and integration capacity.
Plan details change. Use the table as a dated summary and confirm the official page before purchase.
Supported environments and task configuration
Environment availability depends on the plan. The current comparison includes selected Windows versions, Ubuntu 22.04.2, Android 14 ARM, Debian 12.2 ARM, Windows Server 2025, and macOS Sequoia ARM across the three tiers. It does not mean every operating system is available to every account.
ANY.RUN’s task guide describes the basic flow:
- Create a new task and provide a file or URL.
- Choose the operating system and architecture allowed by the plan.
- In advanced mode, set options such as browser, command line, locale, time limit, and network behavior.
- Check the privacy level before starting the task.
- Run the VM and interact through the browser while activity is recorded.
Network options can include HTTPS interception through a man-in-the-middle proxy, simulated networking, TOR, or a configured VPN, depending on account capabilities. These options affect the evidence. TLS interception can expose requests to the analyst, but a sample may detect the altered certificate path. A fake network can keep a task isolated, but it may also prevent behavior that requires a live command server.
The previous article said a VM boots in under ten seconds and that the complete workflow takes under fifteen minutes. No reproducible Top5soft record supports those figures, so they have been removed.
What the reports can contain
The current plan page lists process behavior graphs, MITRE ATT&CK mapping, text and SOC-oriented reports, malware configuration, script tracing, and other analysis features, with availability varying by tier. The service can also expose network and system activity while the task runs.
Exports and integrations are plan-sensitive. Hunter lists JSON and MISP exports. Enterprise lists API task capacity and task history through the API. ANY.RUN’s integrations page documents API, SDK, STIX or TAXII, and connections to security products. A January 2026 MISP integration note says results can include verdicts, extracted indicators, report links, HTML output, and mapped ATT&CK techniques.
These outputs support triage and investigation; they do not replace analyst judgment. Generic signatures can be noisy, a process tree can show correlation without proving intent, and a network indicator can belong to shared infrastructure. Preserve the task configuration and raw evidence when a decision may need to be reproduced.
Privacy: public is not private
The most important ANY.RUN setting is task visibility. The official plan FAQ says public submissions and reports are available to all users and may be used for research and cybersecurity intelligence. It explicitly warns against uploading personal or confidential third-party data in public mode.
Private analyses are available with Hunter and Enterprise Suite. ANY.RUN says private-analysis data is kept confidential, while anonymized malicious artifacts or activity may be used to improve detection with permission. The enterprise privacy guide describes four visibility levels: public, anyone with the link, team-only, and private to the user. Enterprise controls can restrict team members to approved task types.
“Anyone with the link” is not a confidentiality boundary if the link is forwarded or logged. Public analysis is intentionally discoverable. Before upload, organizations should classify the sample, confirm that the account can enforce the required visibility, and document deletion or retention settings.
ANY.RUN’s task guide also describes an optional AI-report feature. It says enabling that feature sends task-related data for report generation, can be disabled for privacy reasons, and is limited to public tasks in the documented workflow. Teams should verify the current implementation and their data-processing requirements before enabling it.
Strengths and limitations
Documented strengths
- Browser-based interaction can collect behavior triggered by analyst input.
- Current plans cover multiple Windows, Linux, Android, and macOS environments, with availability depending on tier.
- Reports can combine process, network, indicator, and ATT&CK-oriented views.
- Hunter introduces private analysis for an individual professional.
- Enterprise adds team privacy controls, SSO, API capacity, and workspace management.
- Community provides a free path for approved public research and learning.
Important limitations
- Community tasks are public and have a 60-second timeout and 16 MB input limit.
- Paid pricing is not published as a fixed amount, making budget comparison less direct.
- A cloud VM cannot reproduce every victim environment or guarantee that evasive behavior appears.
- Private analysis requires a paid plan and a correctly configured task.
- Results still require interpretation and may contain incomplete or ambiguous signals.
- API, export, operating-system, timeout, and team features vary by tier.
The strongest reason to choose ANY.RUN is the interactive workflow. The strongest reason to pause is data sensitivity: selecting the wrong visibility can expose the sample and its report to the community.
Alternatives by workflow
The corrected file scanner comparison separates reputation, sandbox, and sanitization workflows rather than pretending they produce the same answer.
VirusTotal is useful when the first question is whether a hash, URL, or file already has broad reputation context. Its public and licensed private workflows produce different sharing and analysis behavior.
Hybrid Analysis is a public community service powered by Falcon Sandbox. It is suited to samples approved for public automated analysis, not confidential content.
Filescan.io offers another online analysis workflow with its own limits and privacy terms. Verify those current terms before upload.
MetaDefender Cloud focuses on multiscanning, Deep CDR, DLP, sandboxing, and policy-driven API processing. It is a different fit for organizations building controlled file-ingestion pipelines.
Dangerzone does not investigate malware behavior. It locally rebuilds supported documents as PDFs, which can be a better answer when a recipient only needs to read an untrusted document without cloud submission.
Who should use ANY.RUN
ANY.RUN fits malware analysts, incident responders, threat researchers, and SOC teams that need to interact with a cloud task while system and network evidence is collected. Community is appropriate for learning and public research with non-confidential samples. Hunter is the relevant starting tier when an individual analyst requires private tasks. Enterprise is aimed at teams that need policy enforcement, shared workspaces, SSO, integrations, and larger task capacity.
It is not a general-purpose antivirus and should not be presented as a one-click declaration that a file is safe. Non-specialists handling an unexpected attachment should follow their organization’s incident process rather than uploading customer or personal data to a public task.
Verdict: ANY.RUN offers a distinctive and well-documented interactive analysis model. Its value depends less on a numerical score than on three operational questions: does the available VM match the suspected target, is the timeout sufficient, and is the task visibility appropriate for the data?
Frequently asked questions
Is ANY.RUN free?
Yes. The Community plan is free and supports public analyses. The current plan page lists a 60-second VM timeout and a 16 MB maximum input file for that tier.
Are Community submissions private?
No. ANY.RUN says public submissions and reports are available to other users and may support research and threat intelligence. Hunter and Enterprise Suite provide private analyses.
What is the current Hunter price?
ANY.RUN does not publish a fixed Hunter price on the current plan page. It lists individual pricing billed yearly and directs buyers to contact sales. Old $99, $199, or $299 monthly figures should not be treated as current.
Can ANY.RUN guarantee detection of evasive malware?
No. Interaction can trigger behavior that a fixed run might miss, but samples can still detect the environment, exceed the timeout, require unavailable dependencies, or remain inactive.
Does ANY.RUN support Android, Linux, and macOS?
The current plan table includes Android and Linux environments, with exact versions depending on tier. macOS Sequoia ARM is listed under Enterprise Suite. Confirm the account’s available VM list before relying on a platform.



