Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident.
Every manual step adds time to the response. It also ties up analyst capacity in work that could be spent investigating and containing real threats.
ANY.RUN’s latest product updates are designed around those gaps, helping teams move faster from detection to investigation, response, and proactive defense while keeping the evidence and context connected throughout the process.
Phishing Remains a High-Volume, High-Cost SOC Problem
Phishing isn’t just another alert category competing for analysts’ attention. In several critical industries, it shows up in more than 70% of investigations: ANY.RUN’s 2026 data puts phishing exposure at 73.4% in finance and 72.2% in manufacturing.
And the consequences extend far beyond the inbox. Microsoft Incident Response found that 28% of the breaches it investigated started with phishing or social engineering, including newer techniques such as device code phishing.
The financial stakes are just as hard to ignore. In 2025, the FBI received 191,561 phishing and spoofing complaints, while Business Email Compromise alone generated $3.05 billion in reported US losses.
For SOC teams, that combination means high investigation volume, increasingly evasive attacks, and very little room for slow decisions.
Finding a suspicious email or URL is only the beginning. Analysts still need to understand what happened, collect enough evidence to act, pass the case to the right team, and make sure the same threat is easier to catch next time.
What Faster Phishing Response Looks Like
With phishing showing up in such a large share of SOC investigations, simply putting more analyst time into every suspicious URL is not a sustainable answer.
The bigger opportunity is to cut the manual work between detection, investigation, response, and follow-up. That is the idea behind several of ANY.RUN’s latest product updates: give analysts more of the evidence they need upfront, make the handoff easier, and turn each investigation into a starting point for proactive defense.
| Step | SOC Goal | ANY.RUN Capabilities | What Improves |
|---|---|---|---|
| 1. Accelerate Triage | See the full phishing attack and collect enough evidence to make a confident decision | SSL Decryption without MITM + In-Browser Data Inspection | 20% less Tier 1 investigation time with faster threat validation and less manual traffic and browser reconstruction |
| 2. Improve Escalation & Response | Turn technical findings into a clear case that the next team can act on | Tier 1 reports + AI Summary + AI Recommendations | 30% fewer escalations and 21 minutes less MTTR per case with clearer handoffs and faster response |
| 3. Move to Proactive Defense | Go beyond the individual incident and understand the wider threat | Connections in Threat Intelligence Lookup | Faster pivoting to related infrastructure, retrohunting, blocking, and stronger future detection |
Each stage builds on the one before it, turning a single phishing investigation into evidence for response, escalation, and stronger future detection.
3 Steps from Phishing Detection to Faster Response and Stronger Defense
For this walkthrough, we’ll use a modern phishing attack with the following execution chain:
Cloudflare CAPTCHA → Phishing document lure → Device Code Phishing (EvilTokens)
EvilTokens is a phishing-as-a-service platform that abuses Microsoft’s legitimate device code authentication flow to steal session tokens and gain access to accounts. Its campaigns can combine CAPTCHA gates, redirects, legitimate cloud services, and dynamic phishing pages, which makes the attack harder to judge from the original URL alone and creates extra work for SOC analysts trying to piece together what actually happened.
The full attack is captured in this ANY.RUN sandbox session

Now let’s follow the investigation through the three steps of the phishing response workflow.
Step 1: Accelerate Triage with Full Attack Visibility Using SSL Decryption and In-Browser Data Inspection
The first problem SOC teams face is getting enough evidence to make a confident decision quickly.
That becomes harder with modern phishing, where the activity that matters may sit behind encrypted HTTPS traffic, redirects, CAPTCHA gates, scripts, and browser changes. A suspicious URL alone rarely tells the whole story.
So, the first step is to expose as much of the attack as possible without forcing the analyst to reconstruct it manually across several tools.
In the EvilTokens case, the suspicious URL is opened in ANY.RUN’s Interactive Sandbox. As the attack unfolds, the Network section records the web requests made by the browser, including traffic that was originally encrypted over HTTPS.

This shows where the phishing page connects, which resources it loads, and what happens in the background while the victim interacts with the page.
Analysts can then open the Content view to inspect individual request-response pairs and look for suspicious patterns. In this case, one of the requests is:
GET hxxps[://]preponacrea[.]com/est/js/main[.]js

This is where SSL Decryption without MITM changes the investigation. ANY.RUN extracts encryption keys directly from process memory, making HTTPS traffic available for inspection, Suricata rules, signatures, and IOC extraction, without setting up a separate MITM proxy or replacing certificates.
Network traffic, however, is only one side of the attack. The next part of the investigation happens in our newly added Browser Data section.
Here, analysts can follow the redirect chain leading to the phishing page and inspect what changes inside the browser as the attack progresses, including HTTP requests, DOM changes, iframes, screenshots, and other page activity.

Together, SSL Decryption without MITM + In-Browser Data Inspection give the analyst both sides of the attack: what happens on the network and what happens inside the browser.

Instead of digging through hundreds of web-log entries, opening PCAPs separately, and manually rebuilding the redirect chain, Tier 1 gets the evidence needed for validation in one analysis.


- More phishing cases resolved at Tier 1
- Higher analyst throughput without increasing headcount
- Less time lost rebuilding browser and traffic activity
- Faster confidence on whether a case needs action
Step 2: Improve Escalation & Response with AI-Powered Tier 1 Reports
Confirming that a phishing attack is malicious does not finish the analyst’s job.
The technical findings still need to become something another person can act on: what happened, why the activity is malicious, which indicators matter, and what should happen next.
Without that context, Tier 2 or incident response may have to reopen the original analysis, review the evidence again, and rebuild parts of the case before making a decision.
That reporting burden is still highly manual across SOCs. According to the SANS SOC Survey 2025, 69% of SOCs create metrics manually or mostly manually, while nearly half describe the process as very time-consuming.
At this stage, the goal is to move from technical analysis to a response-ready decision without writing the case from scratch.
For the EvilTokens analysis, Tier 1 reports bring the key findings into one structured view.
See the Tier 1 report for this analysis

The report gives the next responder the information needed to quickly understand the case, including:
- The analysis verdict and relevant threat or campaign tags
- An AI Summary explaining what happened during the session
- Key IOCs and technical events that can support blocking or hunting
- AI Recommendations with actions the team can consider next
Instead of translating raw sandbox output into another incident summary by hand, the analyst gets a ready-to-share view of the case.

For Tier 1, that makes it easier to answer the three questions that matter before escalation: What happened? Why is it malicious? What should happen next?

The same context can then be passed to Tier 2, IR, or an MSSP customer without asking them to start from the raw analysis again.
- Fewer unnecessary Tier 1 → Tier 2 escalations
- More senior analyst time preserved for complex incidents
- Clearer handoffs with evidence already packaged
- Shorter path from investigation to containment
Step 3: Move to Proactive Defense with Threat Intelligence
Closing the original phishing alert solves the immediate incident. It does not tell the SOC how far the threat extends.
Attackers rotate domains, IPs, and other infrastructure quickly, which means individual IOCs can lose value fast. Once the threat is confirmed, the next step is to look for patterns that can reveal related activity and support hunting, blocking, and new detections.
In the EvilTokens case, the sandbox analysis already gives analysts a useful starting point: the HTTP endpoints used during the device code phishing flow.
For example:
/api/device/start
/api/device/status/
These patterns can be taken into ANY.RUN’s Threat Intelligence Lookup to find other analyses where the same behavior appears.
View the EvilTokens query in TI Lookup
But finding matching analyses is only the first step. The new Connections view brings the network artifacts from those results together and shows how URLs, domains, IPs, and other indicators relate to one another.

Instead of comparing indicators across separate results one by one, analysts can pivot through the relationships and move from a single IOC to a testable hypothesis about related infrastructure.
This is especially useful for retrohunting in SIEM or NDR data and for passing relevant findings to detection engineering.
Connections also help analysts distinguish useful indicators from shared infrastructure. An IP associated with Cloudflare, for example, may appear in a malicious analysis but should not automatically become a blocking candidate. Filters help narrow the view to the relationships that matter and reduce the risk of pushing noisy or widely shared infrastructure into production defenses.

Threat Intelligence Lookup also adds context around the wider threat landscape, including geography and targeted industries, which can support threat hunting, research, and reporting.
- Each investigation produces intelligence the SOC can reuse
- Faster discovery of related infrastructure and attack activity
- More IOCs available for hunting, blocking, and enrichment
- Broader detection coverage beyond the original incident
What One Phishing Investigation Can Deliver with ANY.RUN’s New Capabilities
Starting with a single phishing URL, the SOC can get much more than a malicious verdict. In this case, the investigation produced:
- Complete picture of the attack: The execution chain, decrypted HTTP requests and responses, redirect path, and browser changes observed as the phishing page loaded.
- Response-ready Tier 1 report: The verdict, key findings, IOCs, AI-generated summary and recommendations, and the context needed for escalation and response.
- Wider view of the threat: Related analyses, infrastructure, and connections that help analysts understand how far the activity extends beyond the original URL.
Without these capabilities, the same investigation could require separate traffic analysis, browser inspection, threat intelligence research, and incident reporting, with analysts moving findings between each stage themselves.
That difference becomes much more important at scale. When a SOC or CSIRT handles hundreds or thousands of incidents, time spent rebuilding context for every case quickly adds up.
The Business Impact of Faster Phishing Response
Faster phishing response is not only an analyst productivity win. It directly affects SOC capacity, escalation costs, and how long the business stays exposed to a confirmed threat.
ANY.RUN customers have reported 20% less Tier 1 investigation time, 30% fewer Tier 1-to-Tier 2 escalations, and 21 minutes cut from MTTR. For security leaders, that means more cases handled by the existing team, less senior analyst time spent on routine work, and faster containment when an attack is real.
With updates such as SSL Decryption and In-Browser Data Inspection, Tier 1 reports with AI insights, and Connections in TI Lookup, it becomes easier to carry the same investigation from triage to response and proactive defense without adding more manual steps.
About ANY.RUN
ANY.RUN provides interactive malware analysis and threat intelligence solutions used by 700,000+ cybersecurity professionals across 16,000+ organizations worldwide, including 64% of the Fortune 500.
Its Interactive Sandbox helps SOC teams safely investigate suspicious files, URLs, phishing pages, and malware while watching the attack unfold in real time. Analysts can inspect browser activity, decrypted network traffic, processes, redirects, and other behavior to validate threats faster and collect evidence for response.
ANY.RUN’s Threat Intelligence Lookup turns data from real-world sandbox investigations into context for threat hunting, detection, and incident response. Analysts can pivot from individual indicators to related infrastructure and activity, while Threat Intelligence Feeds continuously deliver newly observed IOCs into existing security systems.




0 comments