Interactive Sandbox
ANY.RUN Interactive Sandbox for Microsoft Defender
Automate suspicious file and URL analysis and bring detailed behavioral context directly into Microsoft Defender.

Submit files and URLs from Microsoft Defender alerts and incidents for automated analysis.
Receive sandbox verdicts, threat details, extracted IOCs, and a link to the analysis session.
Run ANY.RUN analysis with one click from Defender alerts and incidents, or automate submissions using flexible playbook rules.
Store discovered IOCs in the MS Defender Threat Intelligence portal for further correlation.
Use cases
Requirements
ANY.RUN Sandbox plan with API access

