ANY.RUN outlines three SOC steps for phishing response
ANY.RUN is promoting sandbox updates and a three-step SOC workflow for phishing investigations, using an EvilTokens device-code campaign.
ANY.RUN is promoting sandbox updates and a three-step SOC workflow meant to speed phishing investigations, covering triage, AI-assisted escalation, and threat-intelligence pivoting. Highlighted capabilities include HTTPS or SSL decryption without a separate MITM proxy, in-browser request and DOM inspection, AI summaries and recommendations or automated reporting, and threat-intel lookup and correlation. The walkthrough follows an EvilTokens phishing-as-a-service chain that uses a CAPTCHA—identified as Cloudflare by one source—a document lure, and Microsoft’s device-code flow to steal session tokens. ANY.RUN cites phishing in 73.4% of finance or financial-sector investigations and 72.2% of manufacturing investigations; sources disagree on whether that window is 2026 generally or H1 2026. Both cite FBI figures of 191,561 complaints in 2025 and $3.05 billion in reported U.S. business-email-compromise losses, though one source describes the complaints as phishing and the other as phishing and spoofing.
- ANY.RUN published a product guide promoting a three-step SOC phishing workflow: triage, AI-assisted escalation, and threat-intelligence pivoting.
- Highlighted features include SSL/HTTPS decryption without a separate MITM proxy, in-browser request and DOM inspection, AI summaries and recommendations or automated reporting, and Threat Intelligence Lookup.
- Phishing appeared in 73.4% of finance investigations and 72.2% of manufacturing investigations; one source dates this to 2026 and the other more specifically to H1 2026.
- Cited FBI figures are 191,561 phishing complaints in 2025—one source says phishing and spoofing—and $3.05 billion in reported U.S. business-email-compromise losses.
- The walkthrough uses an EvilTokens device-code phishing chain after a CAPTCHA (Cloudflare in one report) and a document lure that abuses Microsoft authentication to steal session tokens.
Coverage timelineoldest first · each row is one article
- · 1d agoPhishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN’s Latest Product Updates
ANY.RUN· 30
ANY.RUN promotes three SOC steps for faster phishing response using new sandbox and reporting features.
- · 1d agoPhishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
Cyber Security News· 28
ANY.RUN pitched sandbox updates that speed phishing triage, using an EvilTokens device-code campaign as the example.