September 10, 2026
ANY.RUN
The ANY.RUN integration for Splunk SOAR brings Sandbox analysis and Threat Intelligence Lookup into existing playbooks and investigation workflows. Analysts can analyze suspicious files and URLs, retrieve reports and IOCs, and enrich indicators with threat context.Built by ANY.RUN, an official Splunk PartnerSOAR On-Prem, SOAR Cloud
Platform Version: 8.7, 8.6, 8.5, 8.4, 8.0, 7.2, 7.1, 7.0
Log in to rate this app
#4 in Threat Intel
#6 in Sandbox
This integration allows you to automate suspicious file and URL analysis with ANY.RUN Interactive Sandbox to reach verdicts faster, and enrich indicators with actionable context from ANY.RUN TI Lookup within Splunk SOAR workflows. Use cases: 1. Automated Sandbox Analysis: Detonate suspicious files and URLs using individual Splunk SOAR Actions or as part of automated playbooks. Retrieve verdicts and analysis results directly within the investigation workflow. 2. IOC Enrichment & Reputation Checks: Enrich hashes, IPs, domains, and URLs with threat context and quickly check URL and IP reputation. 3. Reporting & IOC Extraction: Retrieve detailed analysis reports and extract IOCs for further investigation and automated response actions. 4. Advanced Threat Hunting: Query ANY.RUN Threat Intelligence for indicators, related infrastructure, and MITRE ATT&CK techniques to investigate related threats. 5. Interactive Investigation: Open ANY.RUN sessions to interact with samples and investigate malicious behavior in depth. This integration helps SOC teams: 1. Accelerate threat validation: Get Sandbox verdicts and threat context faster within Splunk SOAR workflows. 2. Reduce manual work: Automate analysis, enrichment, and IOC extraction through SOAR playbooks. 3. Improve investigation quality: Combine behavioral analysis, detailed reports, and threat intelligence for more informed decisions. 4. Streamline response: Turn analysis results and extracted IOCs into actionable data for investigation and response workflows.
Supported actions
- test connectivity: Validate the asset configuration for connectivity using supplied configuration
- get analysis verdict: Get the verdict of a specific analysis
- search analysis history: Get reports of a specific URL or File hash analysis from your history
- get reputation: Check URL/IP/Domain/File reputation
- get report: Get detailed JSON report for analysis
- get report stix: Get detailed STIX report for analysis
- get report misp: Get detailed MISP report for analysis
- get report html: Get detailed HTML report for analysis
- get iocs: Get list of IoCs for analysis
- detonate url windows: Detonate a URL for analysis using Windows VM
- detonate url linux: Detonate a URL for analysis using Linux VM
- detonate url android: Detonate a URL for analysis using Android VM
- detonate file windows: Detonate a file from Vault
- detonate file linux: Detonate a file from Vault
- detonate file android: Detonate a file from Vault
- get intelligence: Make a query to the ANY.RUN Threat Intelligence database using flexible searches for Indicators of Compromise (IOCs), Indicators of Attack(IOAs), and Indicators of Behavior (IOBs) to investigate and gather extensive and in-depth information on cyber threats
- delete analysis: Delete an analysis
- download pcap: Download a pcap file
Log in to report this app listing.