ANY.RUN connectors for Opencti

Accelerate threat response in OpenCTI

Enhance OpenCTI threat intelligence platform with three dedicated ANY.RUN connectors that automate malware analysis, enrich observables with deep threat context, and deliver fresh IOCs from active threats.

Contact sales

Available connectors

Interactive Sandbox

ANY.RUN Interactive Sandbox connector for OpenCTI

Automate analysis of suspicious files and URLs to quickly determine their threat level, uncover attacker TTPs, and extract actionable IOCs.

ANY.RUN Interactive Sandbox connector to OpenCTI scheme
  • Send files or URLs for automated sandbox analysis directly from OpenCTI.

  • Leverage Automated Interactivity to move seamlessly from automated detonation to interactive investigation.

  • Enrich observables with behavioral context, malware families, MITRE ATT&CK techniques, and threat scores.

  • Extract actionable IOCs, network artifacts, and other indicators for further investigation.

Use cases
Triage
Incident response
Threat hunting
Requirements

ANY.RUN Sandbox plan with API access

Threat Intelligence

ANY.RUN Threat Intelligence Lookup connector for OpenCTI

Search through our database of millions of sandbox analyses to enrich incidents with live attack data.

TI Lookup connector to OpenCTI
  • Search and enrich indicators with TI Lookup directly from OpenCTI.

  • Retrieve malware families, campaigns and related infrastructure.

  • Pivot between connected indicators.

  • Apply collected intelligence to create detection rules, optimize playbooks, train AI models, and support incident response.

Use cases
Alert enrichment
Threat hunting
Requirements

ANY.RUN Threat Intelligence plan with TI Lookup access

ANY.RUN Threat Intelligence Feeds connector for OpenCTI

Expand threat coverage and proactive defense. Continuously enrich OpenCTI with fresh high-fidelity IOCs (IPs, domains, URLs) enriched with context from ANY.RUN’s Interactive Sandbox.

ANY.RUN TI Feeds connector for OpenCTI scheme
  • Retrieve real-time indicators from live attack investigations, including 99% unique IOCs unavailable in public feeds.

  • Keep threat intelligence continuously updated as new attacks emerge and evolve.

  • Share enriched indicators with SIEM, EDR, and other security tools to improve detection quality.

  • Support proactive defense with fresh IOCs for detection rules, playbooks, and threat hunting.

Use cases
Monitoring
Threat hunting
Requirements

ANY.RUN Threat Intelligence plan with TI Feeds access

Why integrate ANY.RUN into your SOC/MSSP stack

Eliminate context switching

Keep investigations and decision-making in one place to avoid delays and lost context.

Scale operations efficiently

Handle more threats with the same team by adding ANY.RUN’s capabilities.

Reduce MTTR, meet SLAs

Achieve faster response by unifying your security operations into a single flow.

FAQ

What is OpenCTI?
What ANY.RUN сonnectors are available for OpenCTI?
What are the most common OpenCTI use cases?
How can SOC teams use OpenCTI with ANY.RUN?
Why choose ANY.RUN Threat Intelligence for OpenCTI?
What is required to set up the integration?
Do I need additional infrastructure to use ANY.RUN connectors?

Add ANY.RUN connectors into your OpenCTI workflow

Reach out to request a quote or discuss your specific OpenCTI use case with our sales team, including security and compliance needs.

+1
Choose
I accept ANY.RUN Terms of Use
By submitting the form, I agree to allow ANY.RUN to process my contact information, contact me, and share my details with its partners in accordance with the Privacy Policy.