ANY.RUN pitches threat intelligence to speed SOC triage and showcases its sandbox at RootedCON Valencia 2026
ANY.RUN promoted its interactive sandbox, TI Lookup, and Feeds as a way to cut SOC triage time and Tier 1 workload, both in product coverage and at RootedCON Valencia on September 18, 2026.
Two reports describe ANY.RUN's marketing of its interactive sandbox and threat-intelligence products rather than a new security incident. Coverage from Cyber Security News (September 22, 2026) highlights TI Lookup, which searches more than 30 parameters — including hashes, IPs, domains, URLs, processes, registry data, YARA and Suricata rules, and MITRE ATT&CK techniques — across six months of interactive sandbox data. The company cites intelligence contributed by 16,000 SOCs and roughly 700,000 analysts, claims 99% unique IOCs with near-zero false positives and 58% more threats found, supports delivery via API, SDK, and STIX/TAXII, and says contextual intelligence can reduce Tier 1 SOC workload by up to 20%. ANY.RUN's own announcement (September 25, 2026) adds that it exhibited at RootedCON Valencia on September 18, 2026, demonstrating sandbox execution of files, URLs, and phishing payloads, and pitching Lookup and Feeds for SOC and MSSP investigations. In that announcement the company states it serves more than 16,000 organizations and 700,000 professionals and is SOC 2 Type II certified. The two reports agree on the scale figures; one frames them as SOCs and analysts, the other as organizations and professionals.
- TI Lookup searches 30-plus parameters across six months of interactive sandbox data, including hashes, IPs, domains, URLs, processes, registry data, YARA and Suricata rules, and ATT&CK techniques.
- ANY.RUN cites intelligence contributions from 16,000 SOCs/organizations and about 700,000 analysts/professionals (figures consistent across both reports).
- Vendor claims: 99% unique IOCs, near-zero false positives, and 58% more threats found.
- Feeds are delivered via API, SDK, and STIX/TAXII for detection and blocking.
- Company says contextual threat intelligence can cut Tier 1 SOC workload by up to 20%.
- ANY.RUN exhibited at RootedCON Valencia on September 18, 2026, demoing sandbox execution of files, URLs, and phishing payloads.
- ANY.RUN states it is SOC 2 Type II certified.
- Both reports are vendor product marketing; neither discloses a new incident or vulnerability.
Coverage timelineoldest first · each row is one article
- · 4d agoScaling SOC Capabilities: How Threat Intelligence Cuts Triage Time and Burnout
Cyber Security News· 16
ANY.RUN promotes threat-intelligence lookup and feeds to speed SOC triage and cut alert fatigue.
- · 2d agoANY.RUN at RootedCON Valencia 2026: Where Cybersecurity Meets the Next Wave of AI
ANY.RUN· 16
ANY.RUN showcased its interactive sandbox and threat intelligence to SOC teams at RootedCON Valencia 2026.