It runs. We watch from outside.

A malware sandbox at hypervisor level: the sample gets a real machine and no company. Every action is recorded from underneath the guest, where malware cannot look.

Lives inside Threat.Zone
  1. Behaviour, as it happens.

    Processes, files, registry and network are captured in real time while the sample runs. The report reads like a recording of the machine, not a summary of it.

  2. No agent inside. No false negatives from evasion.

    Observation happens at the hypervisor, outside the guest. There is nothing inside the virtual machine for sandbox-aware malware to detect, so it runs as it would on a real desk instead of stalling.

  3. A forensic bench, ready.

    The CSI module opens a pre-configured investigation environment next to the report. The analyst takes the sample apart by hand without standing up separate tooling.

  4. One platform, many analysts.

    Multi-user management gives each analyst their own access and licence. A team shares one platform without sharing one account.

Threat.Zone

Sandboxing is the dynamic half of Threat.Zone, on-premise, in a private tenant or in the cloud. Submit a file or a URL and read what it does.

See Threat.Zone

On-premise, private tenant or cloud.

The same sandbox, the same report. Only where the machines sit changes.

  1. On-premise

    Threat.Zone installs inside your own perimeter, on your hardware. Samples, reports and indicators never leave the network, which is what regulated environments and sensitive investigations ask for. The sandbox, static analysis and the CSI module are the same as in the cloud, run by your team with our support.

    On-premise usage guide
  2. Private tenant

    A fully isolated instance of Threat.Zone that Malwation runs for one customer: a private cloud with nothing shared. Your samples stay in your tenant, and Malwation handles hosting, updates and capacity. Built for regulated industries, secure research and threat testing that must not touch a public platform.

    Ask about a private tenant
  3. Cloud

    The hosted platform at app.threat.zone. Register, submit a file or a URL and read the report, with a free tier to start on. Plans scale from one analyst to a team, and the product is the same one that ships on-premise, so nothing changes if you move later.

    Register at app.threat.zone

Questions we get asked

What is a malware sandbox?

An isolated machine where a suspicious file or URL is opened on purpose so its behaviour can be recorded: the processes it starts, the files and registry keys it touches, the network connections it makes. The verdict comes from what the sample did, not from what it looks like.

What does hypervisor-level sandboxing change?

Agent-based sandboxes put a monitoring program inside the guest, and evasive malware looks for it and stops. A hypervisor-level sandbox records from underneath the virtual machine, so there is nothing inside for the sample to find and it runs to completion.

Which operating systems does the sandbox run?

Windows, Linux, macOS and Android, each a full machine. Threat.Zone picks the environment the file expects, or you choose it at submission.

Can the sandbox run on-premise?

Yes. Threat.Zone, and the sandbox inside it, deploys on-premise inside your perimeter, in a private tenant that Malwation runs for you alone, or in the cloud at app.threat.zone. All four guest operating systems are available in each.

Can I submit a URL instead of a file?

Yes. Threat.Zone fetches whatever the link serves into the sandbox and analyzes it there, so your own network never touches the site. Links that serve no file get a reputation and threat analysis of the address itself.

The Agent mascot, calm

Submit a sample. Read what it does.

Register at app.threat.zone and run your first file today. Talk to us when you want on-premise, a private tenant or a team licence.

Register now