Making Threat Intelligence Work for SOC Teams: ANY.RUN & Elastic Webinar Insights
ANY.RUN and Elastic recapped a webinar on using threat intelligence feeds inside Elastic Security workflows.
ANY.RUN published a recap of a joint webinar with Elastic on using threat intelligence in SOC workflows. CTO Dmitry Marinov and Elastic architect Tammy Torbert described feeding validated indicators from ANY.RUN into Elastic Security for alert correlation and triage. The post also promotes sandbox pivots, YARA search, and threat reports, citing use by more than 16,000 organizations and 700,000 professionals. It is a product marketing recap and does not disclose a new incident or vulnerability.
- Webinar covered using ANY.RUN threat intelligence inside Elastic Security.
- ANY.RUN cites IOC data from more than 16,000 organizations.
- The integration is pitched to speed triage and reduce manual lookups.
Full article1,088 words · extracted from any.run · click to collapse
Threat intelligence on its own is only data. Its value depends on how effectively SOC teams can turn it into action.
Simply put, this was the premise of our recent webinar.
The SOC and business impact of threat intelligence depends largely on how quickly analysts can use it to validate threats, make confident decisions, and take action.
Exploring how to make that happen was the focus of ANY.RUN‘s recent joint webinar with Elastic, “Turn Threat Intelligence Into SOC Action with ANY.RUN and Elastic Security.”
How It Went
ANY.RUN CTO Dmitry Marinov and Elastic Principal Solutions Architect Tammy Torbert came together for a live discussion on making threat intelligence work in daily SOC operations.
And we didn’t stop at theory. The webinar included interactive tasks for the audience, a live demo of the ANY.RUN Threat Intelligence and Elastic Security integration, and a Q&A session that gave us a chance to dive into even more practical questions from our viewers.
A big thank you to the Elastic team for making this session happen, and to everyone who joined us, took part, and brought great questions to the discussion!
Executive Takeaways

So, what actually makes threat intelligence useful in daily SOC work? During our discussion, we narrowed it to three things:
1. Threat Intelligence Has to Stay Relevant
Threat infrastructure changes quickly, and indicators can lose relevance just as fast.
Solution: ANY.RUN Threat Intelligence Feeds deliver continuously validated, high-confidence IOCs from real-world investigations by more than 16,000 SOC teams and 700,000 security professionals. This helps SOC teams keep detection workflows aligned with active threats.
Outcome: Earlier identification of known malicious activity, less manual IOC validation, and more analyst time for complex investigations.
2. Context Helps Analysts Make Better Decisions
An IOC match can validate suspicious activity, but analysts still need to understand what happened and how urgently they should respond.
Solution: ANY.RUN Threat Intelligence connects IOC matches to behavioral evidence from Sandbox analyses, helping analysts assess threat severity without relying on indicator matches alone.
Outcome: Faster, more confident triage, better prioritization of high-risk incidents, and fewer unnecessary escalations.
3. TI Works Better Inside Existing SOC Workflows
Manual IOC lookups, switching between systems, and moving data between sources all add time to investigations.
Solution: Integrating ANY.RUN TI Feeds with Elastic Security brings fresh IOCs into alert correlation, prioritization, and detection workflows without requiring analysts to switch between systems.
Outcome: Faster validation of suspicious activity, fewer manual investigation steps, and more analyst capacity for complex cases.
Putting It Into Practice: ANY.RUN Threat Intelligence and Elastic Security

The Threat Intelligence Feeds integration with Elastic Security brings fresh, high-confidence indicators directly into existing Elastic workflows. This helps teams:
- Identify known threats earlier by correlating Elastic security events with fresh ANY.RUN IOCs to surface malicious activity for investigation.
- Respond more confidently by prioritizing alerts based on IOC matches and threat context to guide triage decisions.
- Reduce manual investigation steps by accessing ANY.RUN indicators directly in Elastic for IOC validation, threat searches, and investigation workflows.
- Validate suspicious activity with behavioral evidence by pivoting from Elastic to related ANY.RUN Sandbox analyses when an IOC match requires deeper investigation.
The result is faster investigation of known threats, less context switching, and more analyst time for cases that require deeper analysis.
Beyond Threat Intelligence Feeds: Supporting the Investigation Lifecycle
TI Feeds are just one part of how ANY.RUN supports daily SOC workflows.
For broader threat intelligence needs, Threat Intelligence Lookup & YARA Search help analysts investigate IOCs, uncover related threats, and hunt for malware, accelerating alert enrichment and threat hunting. TI Reports provide curated intelligence on emerging threats to help teams track emerging threats and adjust investigation priorities.

When an alert requires deeper investigation, the Interactive Sandbox provides real-time visibility into threat behavior across Windows, Linux, Android, and macOS environments. API access, integrations, and Automated Interactivity help streamline repetitive analysis tasks, while team collaboration supports consistent investigation workflows across the SOC.
Together, these solutions support the investigation process from early threat detection and enrichment to in-depth behavioral analysis.
Business Impact for SOC Leaders
By bringing fresh intelligence, behavioral context, and malware analysis into existing workflows, SOC teams can:
- Reduce investigation costs through faster triage and fewer unnecessary escalations.
- Improve SOC efficiency by reducing manual work and freeing up analysts for higher-priority cases.
- Lower business risk exposure through earlier threat detection and faster, more informed response decisions.
The result is a more efficient SOC that can handle growing threats with existing resources.
About ANY.RUN
ANY.RUN provides malware analysis and threat intelligence solutions used by 700,000+ cybersecurity professionals across 16,000+ organizations, including 74 of theFortune 100.
Its Interactive Sandbox helps SOC teams safely investigate suspicious files, URLs, phishing, and malware with real-time visibility into threat behavior.
Threat Intelligence Lookup provides context from real-world investigations for threat hunting, detection, and response, while Threat Intelligence Feeds deliver fresh IOCs directly into existing security workflows.
FAQ
How can I integrate ANY.RUN Threat Intelligence Feeds with Elastic Security?
You need an active ANY.RUN plan with access to TI Feeds. If you don’t have one yet, contact us to get started. If you already have access, visit our Integrations page for setup instructions.
What can I do with ANY.RUN Threat Intelligence in Elastic Security?
Teams can use ANY.RUN indicators for IOC correlation, alert prioritization, detection, search, filtering, and dashboards. Analysts can also access related Sandbox analyses when deeper threat context is needed.
Where can I see all ANY.RUN integrations?
Visit the ANY.RUN Integrations page to explore available integrations for the Interactive Sandbox and Threat Intelligence solutions, including Elastic Security, Microsoft Sentinel, Splunk SOAR, and others.
What is the difference between TI Feeds and TI Lookup?
TI Feeds continuously deliver fresh, high-confidence IOCs into your existing security systems. TI Lookup lets analysts search and investigate indicators, uncover relationships, and access additional threat context on demand.
How does ANY.RUN generate threat intelligence?
ANY.RUN Threat Intelligence is built from real-world malware and phishing investigations conducted by more than 16,000 SOC teams and 700,000 security professionals. Indicators are validated and filtered before being delivered through TI Feeds.
When should I use the Interactive Sandbox?
Use the Interactive Sandbox when a case requires deeper behavioral analysis, additional evidence, or investigation of an unknown threat. Analysts can safely observe malicious activity in real time across Windows, Linux, Android, and macOS environments.