An independent tool index for incident response teams
Malware analysis / EU-developed
VMRay Platform
Analyzes suspicious files, URLs and emails with layered sandbox techniques, returning behavioral findings, verdict context and extracted indicators for responders.
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts
Response workflow
Malware analysis
Developer or maintainer
VMRay GmbH
Recorded country
Germany
Product model
Commercial
Deployment
Self-hosted / SaaS
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed
What the sources establish
Origin note
VMRay says its founders developed pioneering sandbox technology during doctoral work in Bochum and founded VMRay GmbH there in 2013; the present platform has global staff and customers.
Reported capabilities
Malware and phishing sandbox analysis
Behavioral findings and extracted IOCs
Cloud or on-premises product plans
Scope and limits
Current VMRay Platform is offered through DeepResponse, FinalVerdict and TotalInsight plans; VMRay Analyzer is a discontinued legacy plan and is not a separate current entry. Product pricing/trial pages establish commercial delivery, but no full platform end-user license was publicly verified. Cloud region or sovereignty claims should not be assumed for every plan.
Inspect the research evidence 6 source observations
identity / capabilities
Official platform site describes sandbox-based malware and phishing analysis for SOC, CERT and CTI teams, with integrations and API access.
Vendor history says the founders completed doctoral work at Ruhr University Bochum on sandbox technology and founded VMRay GmbH in 2013; the company lists Bochum and Boston offices.
Vendor pricing page solicits commercial product and pricing requests; reviewed public pages did not provide complete end-user license text for the current platform.
Dated 9 April 2026 Platform 2026.2.0 release describes recursive malware analysis, improved reporting and new Cloud controls; vendor release claims are not independent effectiveness evidence.
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
VMRay's separately deployed vmray-misp-feed script periodically converts platform analysis results to MISP events. Requires VMRay API access and MISP access to the generated feed; report attachments, tags and IOC-only export are configurable.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.