Joe Sandbox is a threat analysis platform that inspects files, emails, and URLs across Windows, macOS, Linux, and Android operating systems. It performs static, dynamic, hybrid, and execution graph analysis, utilizing machine learning and generative AI to evaluate potential threats. The system supports execution on both virtual machines and physical bare-metal hardware to analyze evasive behaviors. Its purpose is to detect cyber threats and phishing attacks by evaluating execution behavior and processing suspicious artifacts.
The platform employs proprietary hardware virtualization, emulation, and API hooking to monitor user and kernel-mode activity. It gathers static and dynamic function traces from various file formats, including PE, MSI, and PowerShell scripts, to evaluate application behavior. An integrated machine learning component analyzes Windows API calls and static file data for signatureless threat identification, which is complemented by matching observed behaviors against integrated Yara, Sigma, and proprietary behavior signatures. The analysis generates threat verdicts and detailed indicators of compromise, and it allows analysts to interact manually with threats in real-time.