Every sample runs. Nothing runs unwatched.
Threat.Zone is Malwation's malware analysis platform: submit a file or a URL, run it in the sandbox on-premise, in a private tenant or in the cloud, and read what it does.
Four operating systems, one verdict.
Windows, Linux, macOS and Android, each watched at hypervisor level with no agent inside for malware to notice.
Seen before it can hide.
Static analysis reads the file first. Then it runs, and every syscall, packet and dropped file lands in one report.
What the platform does.
Nine things, in the order a sample meets them.
-
Four operating systems
Samples run on Windows, Linux, macOS and Android. One submission, the platform picks the environment the file expects.
-
Hypervisor-level dynamic analysis
The sandbox watches from outside the machine. There is no agent inside for malware to look for, so sandbox-aware samples run as they would on a real desk.
-
Static analysis before anything runs
30 micro-analysis engines read the file first: structure, packers, signatures, strings. Config extraction pulls C2 addresses and keys; .NET deobfuscation reads through the wrapping.
-
Advanced malware traffic analysis
Every packet the sample sends from the dynamic VM is captured and filterable inside the report, the way you would read it in Wireshark.
-
URL analysis and file scanning
Submit a link as well as a file. Threat.Zone fetches what the URL serves into the sandbox, or checks the address itself against reputation feeds, WHOIS and SSL data, so the fast verdicts arrive before the deep ones.
-
Hunting with generated YARA
Each submission produces a YARA rule you can download and run against your own estate.
-
CSI: a forensic environment on demand
Pre-configured investigation machines with the tools an analyst reaches for, ready when the automated report is not enough.
-
Multi-user management
Access and licences are managed per user, so a team shares one platform without sharing one account.
-
On-premise, private tenant or cloud
Deploy inside your own perimeter, in an isolated tenant Malwation runs for you, or use the hosted platform. Same product in all three.
Submit a URL, not only a file.
Phishing starts with a link. Threat.Zone follows it for you, in the sandbox, so nobody on your side has to.
-
Fetch and analyze
Paste the address where a file is served. Threat.Zone fetches it inside the sandbox, so your organisation's IP never touches the site and any script on the page runs there, not on an analyst's desk. The download then goes through static analysis and the sandbox like any other sample.
How URL analysis works -
URL reputation and threat analysis
For links that serve no file, or serve it no longer, the address itself is checked: blacklists and threat intelligence feeds, WHOIS and SSL details, hosting and geolocation, and the campaigns the domain has been tied to. The verdict arrives with its context, not only a score.
Analyze a URL now
Where a sample can run.
Four operating systems, each a full machine. The sandbox watches every one of them from the hypervisor, so nothing inside the guest gives it away.
-
Windows
Executables, DLLs, Office documents, scripts and installers.
-
Linux
ELF binaries and shell scripts, the way they land on a server.
-
macOS
Mach-O binaries, DMG images and pkg installers.
-
Android
APKs, opened on a real Android guest.
Hypervisor The sandbox watches from underneath the guest. Nothing runs inside it, so there is nothing for a sample to find.
On-premise, private tenant or cloud, all four.
On-premise, private tenant or cloud.
The same sandbox, the same report. Only where the machines sit changes.
-
On-premise
Threat.Zone installs inside your own perimeter, on your hardware. Samples, reports and indicators never leave the network, which is what regulated environments and sensitive investigations ask for. The sandbox, static analysis and the CSI module are the same as in the cloud, run by your team with our support.
On-premise usage guide -
Private tenant
A fully isolated instance of Threat.Zone that Malwation runs for one customer: a private cloud with nothing shared. Your samples stay in your tenant, and Malwation handles hosting, updates and capacity. Built for regulated industries, secure research and threat testing that must not touch a public platform.
Ask about a private tenant -
Cloud
The hosted platform at app.threat.zone. Register, submit a file or a URL and read the report, with a free tier to start on. Plans scale from one analyst to a team, and the product is the same one that ships on-premise, so nothing changes if you move later.
Register at app.threat.zone
Threat Zone is by far my favorite malware analysis platform. Its agent-less design works very well against sandbox-aware malware. Plus, it is a cost-effective solution compared to competitors, providing top-notch quality without breaking the bank.
Questions we get asked
Does the sandbox put an agent inside the virtual machine?
No. Observation happens at the hypervisor, outside the guest. That is the reason evasive samples that stall or exit in agent-based sandboxes run to completion here.
Which operating systems can a sample run on?
Windows, Linux, macOS and Android.
Can I run Threat.Zone on-premise, inside my own network?
Yes. Threat.Zone is available on-premise, in a private tenant and in the cloud, and the product is the same in all three. On-premise, it installs on your hardware inside your perimeter, so samples and reports never leave the network.
What is a private tenant?
A fully isolated instance of Threat.Zone that Malwation hosts and runs for one customer, sometimes called a private cloud. Nothing is shared with other customers, your samples stay in your tenant, and Malwation handles updates and capacity. It suits regulated industries and research that cannot use a public platform.
Can Threat.Zone analyze a URL?
Yes. Submit a link and Threat.Zone either fetches the file it serves into the sandbox and analyzes it like any other sample, or checks the address itself against reputation feeds, WHOIS, SSL and hosting data and reports the campaigns it has been tied to.
What does static analysis return?
Findings from 30 micro-analysis engines, extracted configuration such as C2 addresses, encryption keys and protocols, and deobfuscated .NET where the sample is wrapped.
What is the CSI module?
A pre-configured forensic environment with analysis tooling, opened next to the report when you want to take a sample apart by hand.
Can I try it before talking to anyone?
Yes. Register at app.threat.zone and submit a sample. Talk to us when you want on-premise, a private tenant or a team licence.
Try it on your own samples.
Register, submit a file or a URL, read the report. Talk to us when you want it on-premise or in a private tenant.
Register now