tech from europe

Joe Sandbox

🇨🇭 CH · Free plan · paid from Credit based (~$5,000 / 5,200 CHF annually)/yr

Deep malware and phishing analysis across Windows, macOS, Linux and Android

EU hostedGDPRFree planISO 27001
Joe Sandbox is a Swiss malware analysis platform for automated deep inspection of files, URLs, emails and documents. It uses a custom hypervisor for evasion-resistant analysis, supports multi-OS detonation and integrates with SIEM, SOAR and XDR systems. A free community tier is available.

Replaces

Joe Sandbox is sought as a European alternative to:

Features

Multi-Platform & Dynamic Execution

  • Executes files, URLs, and emails in isolated environments across Windows, macOS, Linux, Android, and iOS
  • Supports virtual machines and bare-metal hardware to defeat sandbox evasion
  • Covers Windows 7, 10, 11, macOS (VMs and native Apple Silicon/Intel), Ubuntu, CentOS

Live Interaction & Web Automation

  • Remote in-browser interaction for manual navigation of complex attacks
  • Automated web browsing, clipboard monitoring, and form/CAPTCHA handling
  • Screenshot and video recording of analysis sessions

AI & Agentic Reverse Engineering

  • Joe Reverser: LLM-driven reverse engineering assistant
  • Joe Sandbox AI and ML for autonomous payload deobfuscation and execution tracing
  • AI-generated analysis and chat reports

Deep Code Analysis & Decompilation

  • Hybrid Code Analysis (HCA) and Hybrid Decompilation (HDC) to reconstruct C-equivalent source code
  • Hypervisor-based system call tracing
  • Execution Graph Analysis (EGA)

Network & Traffic Inspection

  • Deep URL analysis and SSL/TLS man-in-the-middle decryption
  • Exposure of encrypted command-and-control (C2) traffic
  • Localized Internet Anonymization (LIA) for country-specific traffic routing

Detection Rules & Threat Intelligence

  • Custom and built-in YARA, Sigma, and Suricata/Snort rules
  • Joe Sandbox View search engine for threat hunting against IOCs and API artifacts
  • Automatic MITRE ATT&CK mapping

Exporting & Reporting

  • Human-readable executive summaries (HTML, PDF)
  • Machine-readable data feeds (JSON, XML, MISP, MAEC, unpacked binaries, PCAPs, dropped files, memory dumps)

Pricing

Cloud Basic
Free per month
  • 1 user account
  • 10–15 analyses per month
  • Up to 2 minutes of Live Interaction
  • Publicly shared samples and results
Cloud Light
Credit based (~$5,000 / 5,200 CHF annually) per year
  • 1 user account
  • 50 non-expiring analysis credits
  • Private analyses
  • Windows analysis, Joe Reverser access
Cloud Pro
On request per month or year
  • 5+ user accounts
  • Private analyses
  • Up to 30 minutes of Live Interaction
  • Multi-OS support (Windows, macOS, Linux)
Cloud Enterprise
On request custom
  • Unlimited users
  • High-volume capacity (from 200 analyses/day)
  • Single-tenant infrastructure options
  • Dedicated support

Exact prices for Cloud Light, Cloud Pro, and Cloud Enterprise are not publicly published; quotes available on request.

EU Trust Profile

What we verified against public sources, last checked 2026-09-17. Every point links to its evidence.

  • EU data residencyGermany and Switzerland

    All data centers are located in Europe.

    Evidence
  • Data Processing Agreement (DPA)

    Public DPA available for Joe Sandbox Cloud Pro.

    Evidence
  • Public sub-processor list

    List of sub-processors included in Appendix II of the DPA.

    Evidence
  • Trust center / security page

    Dedicated Security and Privacy page covering compliance, data protection, and infrastructure.

    Evidence
  • ISO 27001

    Company and infrastructure are ISO 27001 certified.

    Evidence
  • Self-hosting available

    On-premises deployment options available (e.g., Joe Sandbox Desktop, Complete, Ultimate, X, Linux).

    Evidence
  • Documented data exportJSON, XML, PDF

    Export of analysis data, IOCs, screenshots, and reports via web UI and REST API.

    Evidence

We list only what we could verify against a public source on the check date. A point that is absent was not established either way — it is not a finding against the vendor. The vendor's own information prevails.

Work at Joe Sandbox?

This badge is free for every vendor we list and has no bearing on the order of any list. It is issued on the basis of a verified European headquarters (CH) and the compliance points we checked against public sources — the date on it is the date we last checked.

Joe Sandbox — verified European company on tech-from-europe.euJoe Sandbox — verified European company on tech-from-europe.eu

Embed code

<a href="https://tech-from-europe.eu/product/joe-sandbox"><img src="https://tech-from-europe.eu/badge/joe-sandbox.svg" alt="Joe Sandbox — verified European company on tech-from-europe.eu" height="164"></a>

Plain HTML: an SVG served from our domain, with no JavaScript, no cookies and no tracking of your visitors. Add ?style=card for the wide variant, or swap .svg for .png where a CMS refuses SVG. Whether you nofollow the link is your call — we do not check.

Claiming the profile with a work email gets you the artwork as PNG, a form for correcting anything we got wrong, and a note whenever we re-check you.

Claim this profile →

Something wrong on this page? Write to hello@tech-from-europe.eu with a public link and we will re-check it.

Reviews

Recurring themes, synthesized from public reviews across portals.

What users value

  • Comprehensive hybrid analysis (static, dynamic, behavioral)
  • Granular reports with MITRE ATT&CK mapping, Sigma rules, and IOC extraction
  • Detects sophisticated and evasive malware via bare-metal and hypervisor-level analysis
  • Multi-OS coverage (Windows, macOS, Linux, Android)
  • Live interactivity during payload detonation with forensic evidence capture
  • Extensive API connectivity for SIEM, SOAR, EDR, and MISP integration

Where users see room to improve

  • · High pricing with limited public transparency
  • · Steep learning curve and complexity for non-specialists
  • · Strict trial and account validation requirements

Integrations

Microsoft Defender for EndpointCrowdStrikeSentinelOneKasperskySophosTrend MicroESETFortinet (FortiClient)MalwarebytesG DATAAvastAVGPalo Alto Networks Cortex XSOARSplunk (Phantom / SOAR)Rapid7 InsightConnectSwimlaneThreatConnectExabeam+10

Feature, pricing and integration details are based on web research (as of 2026-09-17), without guarantee, errors are possible. The vendor's website prevails.