Email gateways, endpoint controls, and file-centric sandboxing remain essential layers of defense. But many of today’s phishing attacks unfold in ways they weren’t designed to fully expose.
How do you build resilience against modern phishing if it has outgrown your SOC’s investigation workflows?
Rethinking Phishing Investigations in Modern SOCs
While initial investigation workflows were designed around malicious files and processes, many modern phishing attacks, including adversary-in-the-middle (AiTM) campaigns, may leave little evidence in either.
As a result, phishing attacks can take longer to detect, investigate, and contain, increasing both operational risk and the potential business impact.
The business impact of this visibility gap is substantial: according to the FBI’s IC3 2025 report, Business Email Compromise caused $3.05 billion in reported losses in a single year, while Verizon’s 2025 Data Breach Investigations Report attributes 53% of breaches to phishing-related credential theft.
When critical stages of the attack unfold inside encrypted browser sessions, breaking them down requires SOC investigation workflows with a strong browser-level visibility level, not tools to analyze malicious files, because increasingly, there simply aren’t any.
That’s why to build resilience against modern phishing, security leaders should focus on these SOC investigation capabilities:
Step 1. Observe the Attack Through the User’s Eyes
Modern phishing often leaves little evidence in files or processes. Instead, critical evidence lives inside the browser.
The attack may consist entirely of browser interactions: a legitimate URL, trusted redirects, compromised websites, anti-analysis checks, dynamically rendered content, and finally a credential harvesting page. At no point does the attacker need to deliver a malicious file, launch a suspicious process, or exploit the endpoint.
That’s why you need another layer of phishing investigation visibility. ANY.RUN’s Interactive Sandbox lets analysts see the attack as the user experienced it.

In-browser data inspection provides a complete view of the browser session, including redirect chains, page content, DOM changes, browser events, and automatically extracted indicators.
Instead of piecing together isolated artifacts or relying on a single screenshot, analysts can follow the attack step by step and understand exactly what the user experienced.
Step 2. See Inside Encrypted Phishing Sessions
Modern phishing heavily relies on encrypted HTTPS traffic. With Microsoft’s Digital Defense Report 2025 attributing 80% of MFA bypass compromises to stolen session tokens, visibility into encrypted browser sessions has become a critical part of phishing investigations.

Automatic SSL Decryption in ANY.RUN Interactive Sandbox reveals the web content exchanged during browser sessions by extracting session keys directly from process memory, without relying on traditional man-in-the-middle techniques or certificate replacement.
As a result, detection rules can inspect the decrypted content, allowing phishing activity to be confirmed instead of disappearing into what appears to be normal encrypted traffic.
Step 3. Expand One Investigation into Threat Hunting
An investigation shouldn’t end with a verdict. Browser-level evidence becomes even more valuable when it can be operationalized.
Content from a phishing page can be converted into YARA rules and pivoted into threat intelligence to identify related samples, infrastructure, and campaigns. What begins as a single phishing alert quickly becomes an assessment of the broader threat landscape.

ANY.RUN Interactive Sandbox makes this possible by converting browser content into YARA rules that can be pivoted into TI Lookup and YARA Search. Instead of validating a single URL, analysts can threat hunt, identify related samples, infrastructure, and campaigns.
In one investigation, a YARA rule generated from a phishing page uncovered 145 related samples, turning a single alert into campaign-wide visibility:

Step 4. Operationalize Threat Intelligence

Modern SOCs turn validated threat intelligence into operational detection to ensure that new phishing campaigns can be identified as early as possible across the security stack. This reduces manual IOC management while helping analysts prioritize alerts with greater confidence.
ANY.RUN TI Feeds deliver the latest phishing indicators directly to SIEM, SOAR, TIP, EDR, and other security platforms, enabling continuous detection without disrupting existing workflows. Built on real-world threat data from 15,000+ SOC teams, the feeds provide continuously updated, analysis-backed indicators that help security teams detect and respond to emerging phishing campaigns faster.
Outcomes to Expect
The result of upgrading your SOC investigation workflow to match modern phishing threats is a more resilient phishing investigation process:
- Detect up to 5× more encrypted phishing activity by exposing attacks hidden inside HTTPS sessions.
- Expand investigations beyond the initial alert, with more than 60,000 confirmed malicious URLs added to ANY.RUN TI Lookup every month for pivoting, enrichment, and campaign discovery.
- Reduce investigation time and increase analyst confidence with decrypted HTTPS traffic, improved detection rules, and fast threat identification.
Is Your SOC Ready for Modern Phishing?
Phishing has become the primary entry point for enterprise breaches. According to IBM’s Cost of a Data Breach Report 2025, the average cost of a data breach has reached $4.8 million.
The attacks themselves are changing, too. ENISA’s Threat Landscape 2025 reports that 80% of social engineering attacks now use AI-generated phishing, making malicious messages increasingly difficult to distinguish from legitimate communications. But convincing emails are only part of the challenge.
Threat actors increasingly abuse legitimate authentication services and encrypted browser sessions. If your phishing investigations still rely primarily on files, processes, and network artifacts, your SOC is likely facing challenges such as:
- Phishing pages that appear benign because the malicious content is dynamically rendered or hidden inside encrypted sessions
- Longer investigation times as analysts manually correlate browser, network, and endpoint evidence
- Unnecessary escalations because analysts lack confidence in the available evidence
Email gateways remain an essential layer of defense, and file-centric sandboxes continue to provide valuable behavioral analysis. But when the attack itself lives inside the browser, investigation workflows need visibility there as well.
ANY.RUN Interactive Sandbox fills that investigation gap. It extends phishing analysis with browser-level visibility, encrypted session inspection, and integrated threat intelligence, helping SOC teams investigate browser-based attacks with the context and confidence needed to respond faster.
Conclusion
Building resilience against modern phishing threats requires an in-depth understanding of them. ANY.RUN helps SOC teams investigate browser-based phishing, analyze encrypted sessions, expand investigations with threat intelligence, and continuously detect emerging campaigns across the enterprise. This is what helps SOC teams investigate faster, respond with confidence, and stay ahead of modern AiTM phishing campaigns.
About ANY.RUN
ANY.RUN is a leading provider of interactive malware analysis and threat intelligence solutions that integrate seamlessly into modern SOC operations, supporting investigations from the first alert through containment and detection improvement.
Security teams use ANY.RUN Interactive Sandbox to safely analyze suspicious files and URLs, observe real attack behavior in controlled environments, extract actionable indicators, and instantly enrich findings with TI Lookup and Threat Intelligence Feeds. This unified investigation workflow reduces uncertainty, improves validation accuracy, and strengthens response consistency across the organization.
Today, more than 600,000 security professionals across 15,000+ organizations rely on ANY.RUN to accelerate investigations, strengthen detection resilience, and stay ahead of evolving phishing and malware threats.
FAQ
AiTM (Adversary-in-the-Middle) phishing intercepts authentication sessions to steal credentials and session tokens, even when MFA is enabled.
Many modern phishing attacks unfold entirely inside the browser, leaving little or no evidence in files or processes.
It allows analysts to inspect encrypted web content and identify phishing activity that would otherwise appear as normal HTTPS traffic.
Threat intelligence helps analysts pivot from a single indicator to related infrastructure, campaigns, and emerging threats for faster detection and response.
ANY.RUN combines browser-level visibility, encrypted session inspection, and integrated threat intelligence to help SOC teams investigate and respond to phishing attacks more effectively.




0 comments