VMRay
German malware and phishing sandbox that uses hypervisor-level monitoring instead of in-guest agents, aimed at SOC teams and MSSPs.
Visit Website ↗ + Add to CompareOverview
VMRay builds a detonation-based sandbox for dynamic analysis of malware and phishing samples, used by SOC analysts, threat intel teams, and MSSPs to understand what a suspicious file or URL actually does before it reaches a production environment. Its core technical bet is hypervisor-level monitoring: rather than installing an agent inside the guest virtual machine being watched, VMRay observes execution from below the operating system, which makes it harder for malware to detect it is being analyzed and alter its behavior to evade detection, a known weakness of many agent-based sandboxes.
The company was founded in Bochum, Germany in 2013 by Dr. Carsten Willems and Dr. Ralf Hund, academic researchers who had published on hypervisor-driven virtual machine introspection before commercializing the approach. VMRay’s early development was backed in part by German government innovation funding before it moved to institutional venture capital.
VMRay closed two Series B rounds in quick succession, one led by Tikehau Ace Capital in December 2022 and another led by Digital+ Partners in January 2023, funding that the company has used to expand engineering and its go-to-market focus on MSSPs and government customers, the latter sold in the US through Carahsoft.
Innovation Matrix Assessment
VMRay has extended its detonation-based sandbox from pure malware analysis into phishing analysis and government-channel distribution via Carahsoft, a steady cadence of expansion for a specialist platform rather than a fast-moving new entrant.
Hypervisor-level introspection is a technically substantive capability: monitoring execution from below the guest OS avoids installing an in-guest agent that malware can fingerprint, a real architectural advantage over many agent-based sandboxes.
Two Series B rounds closed within about a month of each other (Tikehau Ace Capital in December 2022, Digital+ Partners in January 2023) show recent, real investor interest, though reported total funding figures vary across press sources.
Agentless, hypervisor-based monitoring is a genuine technical departure from the in-guest-agent design most competing sandboxes rely on, directly addressing a known sandbox-evasion weakness rather than iterating on the same approach.
No independent third-party evaluation (e.g., MITRE-style testing) of VMRay's detection or evasion-resistance claims was found; the available evidence is vendor and funding-round press describing customers as "some of the world's most valuable corporations" without named case studies.
Automated malware and phishing triage remains a core SOC and threat-intel workflow, and VMRay's MSSP-focused packaging fits the growing trend of security teams outsourcing detection engineering to managed providers.
Why CISOs Should Care
SOC and threat-intel teams that need to know what a suspicious file or URL actually does, without tipping it off that it's being watched, get hypervisor-level visibility that in-guest-agent sandboxes can't match.
What Makes It Different
Hypervisor-based introspection instead of an in-guest monitoring agent, reducing the sandbox-evasion blind spot that affects many competing dynamic-analysis tools.
The Matrix Verdict
58/100 — INCREMENTAL INNOVATOR
A technically credible, recently well-funded malware and phishing analysis specialist with a real architectural differentiator, though independent efficacy evidence beyond vendor and funding-round press is limited.
Editorial Note: Claims vs. Verified Findings
Reported Series B totals differ across outlets (SecurityWeek reported $10M in January 2023; tech.eu reported $34M in December 2022 for what appears to be a related round), so exact cumulative funding is unclear from available press. Customer-quality claims ("the world's most valuable corporations") are vendor/partner-sourced and not independently named or verified.
Sources
Alternatives to VMRay
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Reality Defender
Deepfake and synthetic media detection company offering real-time detection across voice, video, image, and text for enterprises and…