Partner Tool
Share:

ThreatBook OneSandbox

Free cloud malware sandbox — detonate a suspicious file and read the behaviour, not just a verdict

Opens at s.threatbook.com — external site, RECATOOLS doesn't host this tool.
Free public tier No install APAC-based vendor
ThreatBook OneSandbox logo
Free
Public web tier
File + URL
Submission types
Behavioural
Dynamic analysis report
Intel-linked
Cross-referenced verdicts
What it does

Shows what a sample does, not just whether it's known-bad.

A hash lookup only tells you if a file has been seen before. A sandbox shows you what it actually does, which is what you need to know for a new, targeted, or repacked sample that signature-matching will miss.

Isolated detonation

Samples run in a disposable environment, letting you observe their behaviour without risking an endpoint.

Full behavioural trace

Processes, dropped files, registry and filesystem changes, and persistence attempts are recorded as the sample executes.

Network + C2 destinations

Domains and addresses the sample reaches for are captured and checked against ThreatBook intelligence.

Intelligence cross-reference

The report connects findings to known malware families and actor infrastructure, putting raw telemetry into context.

Nested content

Archives and embedded objects are unpacked so a payload cannot hide one layer down.

Analyst-readable report

Written to be pasted into a ticket — the evidence trail, not only a score.

Advertisement
After features · AD-W1 Responsive · Post-feature engagement
Detection Pipeline

From submission to a report you can act on

STAGE 1
Submit
Upload a file or paste a URL into the web console
STAGE 2
Static triage
Format, structure and known-signature checks before execution
STAGE 3
Detonate
The sample runs in an isolated, monitored environment
STAGE 4
Observe behaviour
Processes, files, registry and persistence recorded live
STAGE 5
Capture network
Callback domains and addresses logged and resolved
STAGE 6
Correlate intel
Indicators matched against ThreatBook threat intelligence
STAGE 7
Report
A behavioural write-up with the supporting evidence
Deployment

Three ways to get it running

Tier 02

Commercial plans

Higher submission volume and richer output for teams doing this daily.

  • Greater capacity
  • Team access
  • Pricing on request
Tier 03

On-premises appliance

For samples that must never leave your own network.

  • Local detonation
  • Sensitive-sample handling
  • Contact the vendor
Advertisement
After deployment · AD-W2 Responsive
Regional presence

APAC offices & coverage

Same-jurisdiction threat-intel for ASEAN and East Asian compliance frameworks.

🇸🇬 Singapore 🇭🇰 Hong Kong 🇨🇳 China 🇦🇪 United Arab Emirates
FAQ

Common questions

Is OneSandbox really free?

There is a free public web tier you can use without a commercial agreement — submit a file or URL and read the report. Higher-volume commercial plans and an on-premises option exist; pricing for those is not published, so ask us for a quote.

How is this different from a hash lookup?

Reputation lookups tell you if a sample is already known; a sandbox shows you what it does. This is the critical distinction for new threats designed to evade signatures.

Should I upload confidential files to a cloud sandbox?

Treat any cloud submission as a disclosure. Documents holding customer data, credentials or trade secrets should go to an on-premises sandbox instead — that is exactly what the on-prem option exists for. Ask us if you need that deployment.

How does it relate to ThreatBook's other products?

The sandbox uses the same threat intelligence that underpins ThreatBook CTI, TDP and OneSEC. The sandbox is for analysing a single unknown sample; the platforms are for applying that intelligence at scale.

Does RECATOOLS get paid to list OneSandbox?

We earn no per-click fee for this listing and our editorial coverage is independent. For full disclosure: RECASYS is an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor, so it earns revenue if you buy a commercial licence through us — the same relationship disclosed on our other ThreatBook listings.

Independently reviewed by RECATOOLS editorial on 16 Aug 2026. Listings are based on the vendor's public documentation; we don't accept payment for inclusion.
Disclosure: RECASYS is an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor. We may earn revenue if you buy a commercial licence through us. This does not affect the editorial assessment above, and any free tier stays free regardless of how you reach it.
Authorized reseller

Need pricing, a demo, or the full brochure?

Tell us about your environment and our team will get back to you with ThreatBook licensing, a guided demo, or the product brochure — usually within one business day.

Handled by RECASYS, an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor for the region. Enquiries are copied to their sales desk. No obligation — your details are used only to answer you.

Prefer email? Write to [email protected]
Spam-protected · no account needed · see our Privacy Policy for how enquiries are handled.

Analyse a suspicious file now

The public sandbox is free to use — no account needed to start.

Open the sandbox
Related on RECATOOLS

Explore related tools & intelligence

Hand-picked RECATOOLS pages relevant to malware analysis and incident response.

Related News

You may be interested in these recent stories from our newsroom.

View all news →
Related

More Cybersecurity Tools