ANY.RUN & Microsoft Defender integration

Enrich MS Defender with threat context

Add behavioral analysis, fresh threat intelligence, and actionable IOCs to every Microsoft Defender alert. Detect evasive threats earlier and accelerate incident response with automated analysis.

Contact sales

Available integrations

Interactive Sandbox

ANY.RUN Interactive Sandbox for Microsoft Defender

Automate suspicious file and URL analysis and bring detailed behavioral context directly into Microsoft Defender.

ANYRUN Sandbox and MS Defender scheme
  • Submit files and URLs from Microsoft Defender alerts and incidents for automated analysis.

  • Receive sandbox verdicts, threat details, extracted IOCs, and a link to the analysis session.

  • Run ANY.RUN analysis with one click from Defender alerts and incidents, or automate submissions using flexible playbook rules.

  • Store discovered IOCs in the MS Defender Threat Intelligence portal for further correlation.

Use cases
Triage
Incident response
Threat hunting
Requirements

ANY.RUN Sandbox plan with API access

Threat Intelligence

ANY.RUN Threat Intelligence Feeds for Microsoft Defender

Detect active threats with a continuously updated stream of malicious IPs, domains, and URLs sourced from real-world sandbox investigations.

ANYRUN TI Feeds and MS Defender integration scheme
  • Correlate fresh threat intelligence with incoming Microsoft Defender alerts.

  • Identify high-risk activity based on indicators observed in ongoing attacks.

  • Create detection rules for proactive threat mitigation.

  • Automate threat hunting and response workflows with Microsoft Defender playbooks.

Use cases
Monitoring
Threat hunting
Requirements

ANY.RUN Threat Intelligence plan with TI Feeds access

Why integrate ANY.RUN into your SOC/MSSP stack

Eliminate context switching

Keep investigations and decision-making in one place to avoid delays and lost context.

Scale operations efficiently

Handle more threats with the same team by adding ANY.RUN’s capabilities.

Reduce MTTR, meet SLAs

Achieve faster response by unifying your security operations into a single flow.

FAQ

What is included in the ANY.RUN & Microsoft Defender integration?
How does the integration work inside Microsoft Defender workflows?
How does this integration improve daily SOC operations?
What is required to set up the integration?
Do I need additional infrastructure to use this integration?

Integrate ANY.RUN into your Microsoft Defender workflow

Reach out to request a quote or discuss your specific use case with our sales team, including security and compliance needs.

+1
Choose
I accept ANY.RUN Terms of Use
By submitting the form, I agree to allow ANY.RUN to process my contact information, contact me, and share my details with its partners in accordance with the Privacy Policy.