| name | performing-dynamic-analysis-with-any-run |
| description | Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes. Activates for requests involving interactive sandbox analysis, cloud-based malware detonation, real-time behavioral observation, or ANY.RUN usage. . Use when working with performing dynamic analysis with any run. |
| domain | cybersecurity |
| tags | ["malware","dynamic-analysis","sandbox","ANY.RUN","interactive-analysis"] |
| subdomain | malware-analysis |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| d3fend_techniques | ["File Metadata Consistency Validation","Application Protocol Command Analysis","Identifier Analysis","Content Format Conversion","Message Analysis"] |
| nist_csf | ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"] |
Performing Dynamic Analysis With Any Run
Overview
Cybersecurity skill for performing dynamic analysis with any run. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"performing dynamic analysis with any run"
-
"Performs interactive dynamic malware analysis using the ANY"
-
Interactive malware analysis is needed where the analyst must click dialogs, enter credentials, or navigate installer screens
-
Rapid cloud-based sandbox analysis without maintaining local sandbox infrastructure
-
Malware requires user interaction to proceed past anti-sandbox checks (document macros requiring "Enable Content")
-
Sharing analysis results with team members via public or private task URLs
-
Comparing behavior across different OS versions (Windows 7, 10, 11) available in ANY.RUN
Do not use for highly sensitive samples that cannot be uploaded to cloud services; use an on-premises sandbox like Cuckoo instead.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- ANY.RUN account (free community tier or paid subscription at https://any.run)
- Modern web browser with WebSocket support for interactive session streaming
- Sample file ready for upload (max 100 MB for free tier, 256 MB for paid)
- Understanding of the sample type to select appropriate execution environment
- VPN or secure network for accessing ANY.RUN portal during analysis sessions
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: ) -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}