Joe Sandbox Cloud is a web-based automated deep malware analysis service that executes suspicious files and URLs in a controlled environment to monitor application and operating system behavior. Hosted by Joe Security, the platform supports the analysis of threats targeting Windows, macOS, and Linux operating systems. The system captures system, network, browser, and code manipulation behavior to generate detailed analysis reports without sharing sample or analysis data with third parties.
The platform utilizes a combination of virtual and physical (bare metal) analysis machines to evaluate evasive malware and provides live interaction capabilities directly through the browser. Joe Sandbox Cloud incorporates over 2,580 generic behavior signatures, machine learning detection engines, and custom hypervisor inspection. It offers RESTful API access, threat intelligence querying, and exports intelligence data into various standard formats such as MISP, MAEC, and CybOX to support security teams in developing defense strategies.