ANY.RUN
ANY.RUN provides a cloud-based interactive malware analysis sandbox and threat intelligence platform serving SOC teams, MSSPs, and enterprises globally through a community-driven model with 600,000+ analysts contributing to 50 million+ sandbox sessions.
- Company typePrivate
- Founded2017
- HeadquartersDubai, United Arab Emirates
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What ANY.RUN does
ANY.RUN operates a cloud-based interactive malware analysis and threat intelligence platform serving SOC teams, MSSPs, and enterprise security operations across financial services, telecommunications, government, retail, automotive, energy, and technology sectors. Founded in 2016 and headquartered in Dubai, UAE as ANYRUN FZCO under founder and CEO Alexey Lapshin, the platform combines three core products: an Interactive Sandbox supporting Windows, Linux, Android, and macOS (beta) with real-time behavioral analysis and browser-level visibility; Threat Intelligence Lookup providing sub-2-second searches across 50 million+ sandbox sessions using 40+ indicator parameters; and Threat Intelligence Feeds delivering continuously updated IOCs enriched with MITRE ATT&CK context, malware family labels, and sandbox-verified severity scoring.
The business runs a product-led growth motion anchored by a freemium tier that has attracted over 600,000 security analysts across 15,000+ organizations globally, with community contributions creating a self-reinforcing intelligence flywheel. Enterprise customers access SOC 2 Type II attested deployments with SSO/RBAC, dedicated API quotas, and advanced privacy controls, layered atop Hunter and Community subscription tiers with quote-based enterprise pricing. ANY.RUN has built an integration ecosystem spanning SIEM (Microsoft Sentinel, IBM QRadar), SOAR (Tines, Torq), TIP (ThreatQ, OpenCTI), and IDS/IPS (Suricata) via API, SDK, STIX/TAXII, and MISP formats.
Revenue is generated primarily through tiered recurring subscriptions across the Sandbox, TI Lookup, and TI Feeds product lines, with no external funding rounds disclosed in available sources. The company claims 74% Fortune 100 penetration, named customers including HEICO, Telefonica, GAP, Deutsche Telekom, Ryanair, McAfee, HP, TotalEnergies, Swisscom, PSA Group, Renault, AKBANK, OCBC, and UAE CERT, and 1,700+ MSSP customers globally. Operating with a team of 51-100 employees, ANY.RUN has earned recognition including two Global InfoSec Awards at RSAC 2026, placement on IT-Harvest's 2026 Cyber 150 list, G2 rating of 4.7, and Gartner Peer Insights rating of 4.8.
ANY.RUN firmographics
Firmographics- Name
- ANY.RUN
- Legal name
- ANYRUN FZCO
- Website
- https://any.run
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- ANY.RUN provides a cloud-based interactive malware analysis sandbox and threat intelligence platform serving SOC teams, MSSPs, and enterprises globally through a community-driven model with 600,000+ analysts contributing to 50 million+ sandbox sessions.
- Ownership category
- akta.pro rank
ANY.RUN industry classification
Industry- Product category
- Cybersecurity Threat Intelligence and Malware Analysis
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182), Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Attack Detection & Response for Cloud/SaaS (SOC for Cloud) (HDADAGAJ)
- akta.pro secondary industries
- Threat Intelligence Services (BPAEADAC), Security Operations Center (SOC) as a Service (BPAEADAB)
Keywords
Where ANY.RUN is headquartered
LocationHeadquarters
- HQ city
- Dubai
- HQ country
- United Arab Emirates
- HQ region
- Middle East
Offices1 record
Markets served
ANY.RUN business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- Interactive Sandbox Subscriptions: Tiered subscription plans for the Interactive Sandbox product, with plans for individuals (Community), teams (Hunter), and enterprises (Enterprise Suite). Plans differ in privacy controls, API quotas, team management features, and support levels. Free registration tier is available.
- Threat Intelligence Lookup Subscriptions: Separate subscription plans for TI Lookup with request limits and feature tiers, typically sold alongside or separately from the sandbox product.
- Threat Intelligence Feeds: Continuous IOC feed subscriptions delivered via API/SDK and STIX/TAXII, with pricing based on feed volume or organization size.
- Enterprise Suite Licensing: Enterprise-grade plans offering full product access, SOC 2 Type II attested security, SSO/RBAC, team API quotas, advanced privacy controls, and dedicated support for large SOC teams and MSSPs.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Free | Community (Free) - Free sandbox access with basic features and no search request limit for registered users |
| Subscription | Annual | Hunter Plan - Team collaboration features, shared presets, team API quota, and stronger privacy controls |
| Subscription | Annual | Enterprise Suite - Full product access, SOC 2 Type II compliance, SSO/MFA/RBAC, advanced privacy, dedicated support |
| Subscription | Annual | TI Lookup - Threat intelligence search with request quotas |
| Freemium | Free | 14-Day Free Trial for SOC teams |
Go-to-market motion4 records
Distribution channels6 records
Marketing channels9 records
ANY.RUN product offering
Product offeringCore offering
ANY.RUN provides a cloud-based cybersecurity platform built around an Interactive Sandbox that lets SOC teams and analysts safely detonate files and URLs across Windows, Linux, Android, and macOS virtual machines to observe real-time malicious behavior and extract IOCs. The platform adds Threat Intelligence Lookup (searchable database of 50M+ sandbox sessions) and Threat Intelligence Feeds (real-time IOC streams) sourced from a community of 600,000+ analysts, all delivered via subscription tiers and integrated with enterprise SIEM/SOAR/TIP/EDR stacks.
Product overview
ANY.RUN is a cybersecurity platform providing a unified portfolio of malware analysis and threat intelligence solutions. The core offerings include the Interactive Sandbox (cloud-based malware analysis with multi-OS support including Windows, Linux, Android, and macOS beta), Threat Intelligence Lookup (searchable database of 50M+ sandbox records with 40+ indicator types for rapid investigation), and Threat Intelligence Feeds (real-time IOC streams with 99% unique indicators sourced from 600K+ analyst community). The platform serves SOC teams, MSSPs, and enterprises across finance, healthcare, government, and technology sectors, with enterprise and MSSP-specific tiers offering advanced collaboration, automation, and compliance features.
Differentiator
Problem solved
Functional benefit
Products and services
- Interactive Sandbox
- Threat Intelligence Lookup
- Threat Intelligence Feeds
- Phishing Detection
- MSSP Solution
Quantifiable outcome
- Up to 58% more threats detected overall for users of ANY.RUN's solutions
- +16 more outcomes
Companies that use ANY.RUN
Customer profileNamed customers20 records
Ideal customer profiles3 records
ANY.RUN technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration12 records
AI capability7 records
Feature12 records
ANY.RUN partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- TorqcoreANY.RUN announced integration with Torq in June 2026 release notes. The integration enables security teams to scale triage and response within Torq's no-code automation platform by incorporating ANY.RUN's sandbox detonation and IOC extraction capabilities into automated security workflows.
- TinescoreANY.RUN launched an integration with Tines enabling security teams to validate threats faster and enrich alerts automatically within Tines workflows. The integration brings sandbox detonation, IOC extraction, and real-time threat intelligence directly into Tines, reducing manual checks and improving decision accuracy for SOC teams. The integration delivers measurable improvements including lower MTTR, higher triage accuracy, and greater capacity without additional hires.
- ThreatQ (Threat Intelligence Platform)coreANY.RUN announced integration with ThreatQ Threat Intelligence Platform, connecting malware analysis solutions to SOCs and enabling real-time threat indicators from sandbox investigations to be shared with over 15,000 organizations worldwide. The integration enriches ThreatQ's threat intelligence with ANY.RUN's behavioral analysis data.
- OpenCTIcoreOpenCTI integration enables ANY.RUN TI Feeds data to be consumed within the OpenCTI threat intelligence platform. The integration allows customers to view sandbox reports alongside threat indicators within their unified CTI workflows. Expertware, an MSSP customer, uses this integration with their SIEMBIOT platform.
- Microsoft Security Stack (Defender, Sentinel)coreANY.RUN's TI Feeds integrate with Microsoft Defender, Sentinel, and related security stack components for real-time IOC ingestion and alert enrichment. The integration is cited as a key use case for enterprise SOCs seeking to enhance Microsoft security investments with fresh, sandbox-verified threat intelligence.
- IBM QRadarcoreANY.RUN TI Feeds support integration with IBM QRadar SIEM platform, enabling security teams to enrich QRadar alerts with ANY.RUN's sandbox-verified IOCs and MITRE ATT&CK context.
- Dicker DataminorDicker Data is referenced as a CrowdStrike distributor in the APAC region in third-party MSSP news. While not a direct ANY.RUN partner mentioned in company materials, the same distribution model is applicable to ANY.RUN's MSSP growth strategy in APAC markets.
- Otsuka CorporationminorOtsuka Corporation is referenced as a CrowdStrike distributor in Japan/APAC. Contextually relevant to ANY.RUN's channel partner strategy in Asia-Pacific MSSP markets, though not explicitly cited as an ANY.RUN distributor.
Scale indicators35 records
Recent moves6 records
Expansion highlights6 records
ANY.RUN competitors and assessment
Company assessmentOthers
- Recorded Future Threat Intelligence:
- Cuckoo Sandbox: Open-source malware analysis sandbox historically used by SOC teams and researchers; many commercial offerings (including ANY.RUN) emerged as cloud-managed alternatives. Relevant adjacent tool in the same category though now eclipsed by managed cloud sandbox offerings.
Emerging players
- PhishTank: Community-driven phishing URL verification database with free lookup APIs. Adjacent to ANY.RUN's phishing detection capabilities but with narrower scope (URL-only, no behavioral analysis); competes for some of the same free-tier threat intelligence demand.
- ThreatConnect Threat Intelligence Platform: Commercial TIP that aggregates and operationalizes threat intelligence feeds, similar to ANY.RUN's TI Lookup and TI Feeds. Overlaps in TI consumption but does not offer an interactive sandbox, making it complementary in some stacks and competitive in TI spending.
Broad incumbents
- Kaspersky Threat Intelligence Portal: Established cybersecurity vendor offering file, URL, and domain reputation lookups alongside paid sandbox analysis. Comparable to ANY.RUN's TI Lookup and TI Feeds, competing primarily in the analyst research and triage segment.
Direct peers
- Triage: Cloud-based malware analysis sandbox offering static and dynamic analysis with IOC extraction, similar to ANY.RUN's Interactive Sandbox product. Targets the same SOC analyst and threat researcher user base with comparable workflow.
- Hybrid Analysis (Falcon Sandbox): CrowdStrike-owned cloud-based malware sandbox with community-driven threat intelligence, comparable in product structure to ANY.RUN's Interactive Sandbox. Direct peer competing for security analyst workflows, now backed by a major endpoint security incumbent.
- VirusTotal: Google-owned multi-engine malware analysis and threat intelligence platform offering free and enterprise sandbox and lookup services. Direct competitor with overlapping sandbox detonation, IOC lookup, and community-contributed intelligence; competing for the same SOC analyst workflows.
- URLScan.io: Free and paid URL and domain scanning service with sandbox-style browser analysis, screenshot capture, and community-driven threat intelligence. Comparable to ANY.RUN's phishing-focused URL sandbox capabilities and overlapping analyst community.
- Joe Sandbox: Deep malware analysis sandbox offering Windows, Linux, macOS, Android, and iOS detection with behavior reports and YARA rule generation. Closely competes with ANY.RUN on interactive analysis depth, multi-OS coverage, and enterprise SOC use cases.
Market position
Strengths1 record
Weaknesses1 record
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
ANY.RUN social profiles
Digital presenceANY.RUN compliance and trust
Trust signalCompliance2 records
ANY.RUN financial estimates
Financial estimateRevenue estimate
Valuation estimate
ANY.RUN leadership team
Management profileNumber of profiles
Profiles1 record
ANY.RUN funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ANY.RUN M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ANY.RUN
What does ANY.RUN do?
ANY.RUN provides a cloud-based cybersecurity platform built around an Interactive Sandbox that lets SOC teams and analysts safely detonate files and URLs across Windows, Linux, Android, and macOS virtual machines to observe real-time malicious behavior and extract IOCs. The platform adds Threat Intelligence Lookup (searchable database of 50M+ sandbox sessions) and Threat Intelligence Feeds (real-time IOC streams) sourced from a community of 600,000+ analysts, all delivered via subscription tiers and integrated with enterprise SIEM/SOAR/TIP/EDR stacks.
Is ANY.RUN a public or private company?
ANY.RUN is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was ANY.RUN founded?
ANY.RUN was founded in 2017. It employs 51 to 100 people.
Where is ANY.RUN based?
ANY.RUN is headquartered in Dubai, United Arab Emirates, in the Middle East region.
How does ANY.RUN make money?
Four revenue lines are on record. Interactive Sandbox Subscriptions are the primary driver. The others are threat Intelligence Lookup Subscriptions, threat Intelligence Feeds and enterprise Suite Licensing.
Who are ANY.RUN's main competitors?
Others on record are Recorded Future Threat Intelligence and Cuckoo Sandbox. Emerging players are PhishTank and ThreatConnect Threat Intelligence Platform. Kaspersky Threat Intelligence Portal is listed as a broad incumbent. Direct peers are Triage, Hybrid Analysis (Falcon Sandbox), VirusTotal, URLScan.io and Joe Sandbox.
Does ANY.RUN have an API?
Yes. ANY.RUN provides API and SDK integration for connecting its malware analysis and threat intelligence services with security stacks. The API enables automated submission of suspicious files and URLs for analysis, real-time IOC ingestion, and integration with SIEM, SOAR, TIP, and EDR platforms. Supports STIX/TAXII format for machine-readable threat data. Developer documentation is at any.run/api-documentation.
What industry is ANY.RUN in?
ANY.RUN's product category is Cybersecurity Threat Intelligence and Malware Analysis. Its primary akta.pro industry code is HDADAGAJ, Attack Detection & Response for Cloud/SaaS (SOC for Cloud), with a secondary code of BPAEADAC, Threat Intelligence Services. Its NAICS code is 5182 and its SIC code is 7372.