Start exploring malware analysis with essential tools and limited dynamic sandboxing.
- Windows 7 x64
- Windows 10 x64
Transparent pricing designed to fit your requirements.
Start exploring malware analysis with essential tools and limited dynamic sandboxing.
Ideal for cybersecurity researchers who need deeper analysis tools and more flexibility.
Designed for threat hunters and analysts handling high volume and advanced scenarios.
Organization plan for teams of researchers and security operations teams.
Dedicated infrastructure, custom service levels, and white-glove onboarding for larger teams.
Contact salesCompare features to easily choose the plan that fits your team’s needs, whether you're starting small or scaling fast.
Organization Plan for team of malware hunters
$400 $330/month (per seat) $400/month (per seat)
Get StartedDedicated infrastructure, custom SLAs, and white-glove onboarding
Custom Custom Custom
Contact Us| Features | Free $0/month $0/month Billed annuallyBilled monthly Start for Free | Researcher $199/month $250/month Billed annuallyBilled monthly Get Started | Hunter $399/month $450/month Billed annuallyBilled monthly Get Started | Organization $330/month $400/month Billed annuallyBilled monthly Get Started | Enterprises Custom Custom Billed annuallyBilled monthly Contact Us |
|---|---|---|---|---|---|
| Size Maximum file size you can upload per submission. | 16 MB | 32 MB | 650 MB | 1 GB | 4 GB |
| Extensions File types you can submit for analysis. | All Extensions | All Extensions | All Extensions | All Extensions | All Extensions |
| API Limit Monthly request quota for the public API. | 500 | Custom | |||
| Concurrent Limit How many analyses can run at the same time. | 1 | 1 | 1 | 1 | Custom |
| Daily Limit How many submissions you can send per day. | 50 | 250 | 500 | 500 | Custom |
| Re-Analyze Submission Run a submission again with a different configuration or scan type — no need to re-upload. | |||||
| Additional Files Download the artifacts an analysis produces: dropped files, memory dumps, and extracted payloads from dynamic, static, and emulation runs. | |||||
| Download Sample Re-download the original submitted sample whenever you need it. | |||||
| Html Report Download a self-contained HTML report summarizing the full analysis — verdict, indicators, and behavior — in one shareable file. | |||||
| PDF Report Export polished PDF reports of your analysis results, ready to attach to tickets, cases, or incident reviews. | |||||
| STIX 2.1 Report Export indicators and observables as a STIX 2.1 bundle that drops straight into your TIP, SIEM, or SOAR tooling. | |||||
| Queue Priority While sending submissions, you will be in the upper priority level | |||||
| Commercial Usage Use Threat.Zone results in your commercial products, services, and client work. | |||||
| Export Submission Export any part of a submission — reports, network captures, and analysis data — file by file. | |||||
| Private Submission Keep submissions visible only to you and your workspace — never listed publicly. | |||||
| Custom VPN You will receive a custom OpenVPN configuration from us | |||||
| Network Configs Route sandbox traffic through your own WireGuard, OpenVPN, or proxy configuration during dynamic analysis. | |||||
| Start Arguments Launch samples with custom command-line arguments to reach code paths that only trigger with specific flags. | |||||
| Pre-Script Run your own preparation script inside the sandbox before the sample executes — stage files, tweak settings, simulate a victim environment. | |||||
| Run Command Execute your own commands inside the sandbox VM for hands-on investigation. | |||||
| Scan Duration Extension Extend a running dynamic analysis on the fly when a sample needs more time to detonate. | |||||
| MCP Support Connect Threat.Zone to AI agents, IDEs, and automation over the Model Context Protocol — included on every plan with API access. |