XXC Run
A private malware analysis lab: detonate a sample, watch processes, network and filesystem activity unfold, and keep the evidence.
A sandbox for following what a sample actually does rather than what it claims to be. A submitted file runs in an isolated guest while its process, network and filesystem activity is recorded into one connected timeline, and an interactive session lets an analyst take control of the guest desktop to click through an installer or trigger behaviour that waits for a human — Android targets included. When the session ends the evidence and recording are saved alongside a report. Private by default with encrypted sample storage; access is invite-only, managed by an administrator, with optional authenticator codes, so the public link shows a sign-in page.