ANY.RUN pitches SOC threat intelligence amid alert overload
ANY.RUN promotes sandbox feeds, lookup, and an Elastic integration as US SOCs average 2,566 daily alerts.
ANY.RUN is promoting intelligence-led monitoring for SOC and MSSP teams, pairing Interactive Sandbox feeds of malicious IPs, domains, and URLs in STIX/TAXII—drawn from more than 700,000 analysts—with behavioral lookup and YARA testing that it says returns first matches against millions of samples in under five seconds. Those feeds are described as flowing into SIEM, EDR, and SOAR tools such as Microsoft Sentinel and Google SecOps, while Threat Intelligence Lookup covers registry changes, command lines, JA3 fingerprints, and MITRE ATT&CK-mapped TTPs, and a Moonrise trojan analysis is cited as an indicator source. Citing a 2026 Optiv, Palo Alto Networks, and Ponemon report, ANY.RUN says organizations average 2,566 alerts a day, 52% saw volume rise, 46% lack staff, and 36% of alerts are still investigated manually; a SANS survey found 24% of leaders cite missing enterprise-wide visibility as the top SOC barrier. The same coverage cites 73.4% phishing exposure in finance in 2026 and FBI 2025 figures of about $3.05 billion in business-email-compromise losses and 191,561 complaints, which one source calls phishing complaints and another phishing and spoofing complaints, plus tactics such as fake CAPTCHAs, fingerprinting, QR codes, geofencing, and token theft. ANY.RUN claims 20% less Tier-1 time and 30% fewer escalations, and a later webinar recap with Elastic says validated indicators can feed Elastic Security; the company cites use by more than 16,000 organizations and 700,000 professionals and discloses no new incident or vulnerability.
- ANY.RUN Threat Intelligence Feeds deliver malicious IPs, domains, and URLs in STIX/TAXII to SIEM, EDR, and SOAR tools such as Microsoft Sentinel and Google SecOps, drawn from its Interactive Sandbox and more than 700,000 analysts.
- Threat Intelligence Lookup covers registry changes, command lines, JA3 fingerprints, and MITRE ATT&CK-mapped TTPs; YARA Search is said to return first matches against millions of samples in under five seconds, with a Moonrise trojan…
- A 2026 Optiv, Palo Alto Networks, and Ponemon report cited by ANY.RUN says organizations average 2,566 alerts a day, 52% saw volume rise, 46% lack staff, and 36% of alerts are still investigated manually.
- A SANS survey found 24% of leaders name missing enterprise-wide visibility as the top SOC barrier; ANY.RUN also cites 73.4% phishing exposure in finance in 2026.
- FBI 2025 figures cited are 191,561 complaints—called phishing by one source and phishing and spoofing by another—and about $3.05 billion in business-email-compromise losses.
- Evasive phishing tactics described include fake CAPTCHAs, fingerprinting, QR codes, geofencing, and token theft.
- ANY.RUN claims 20% less Tier-1 investigation time and 30% fewer escalations.
- An Oct. 8 webinar recap with Elastic, featuring CTO Dmitry Marinov and Elastic architect Tammy Torbert, pitches feeding validated indicators into Elastic Security; ANY.RUN cites more than 16,000 organizations and discloses no new incident…
Coverage timelineoldest first · each row is one article
- · 2d agoFrom Telemetry to Defense: How SOC and MSSP Leaders Can Build Intelligence-Led Threat Monitoring
Cyber Security News· 18
ANY.RUN promotes intelligence-led SOC monitoring using sandbox feeds, behavioral lookup, and YARA rule testing.
- · 1d ago5 Critical Pain Points of Modern US SOCs and How to Solve Them
ANY.RUN· 18
ANY.RUN outlines five US SOC pain points and pitches its sandbox to cut manual alert investigation.
- · 1d agoAlert Overload, Tool Sprawl and Evasive Phishing: The 5 Bottlenecks Slowing Down US SOCs
Cyber Security News· 32