{"id":21658,"date":"2026-06-16T10:11:34","date_gmt":"2026-06-16T10:11:34","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=21658"},"modified":"2026-06-16T10:15:05","modified_gmt":"2026-06-16T10:15:05","slug":"in-browser-data-inspection","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/","title":{"rendered":"The New Standard for URL Analysis: Closing Phishing\u00a0Blind\u00a0Spots\u00a0with In-Browser Data Inspection\u00a0"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Modern\u00a0URL phishing relies\u00a0on dynamic pages, credential harvesting flows, client-side scripts, and layered redirect chains. But most SOC workflows are still built around static analysis, making them blind to most of these\u00a0tactics.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=in-browser-data-inspection&amp;utm_term=160626&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> changes\u00a0this forever with\u00a0in-browser data inspection.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The&nbsp;new technology&nbsp;takes URL analysis to the next level by bringing static and dynamic analysis into one single workflow.&nbsp;Now, every phishing URL\u2019s&nbsp;behavior&nbsp;like script&nbsp;execution&nbsp;and&nbsp;redirects&nbsp;is&nbsp;visible&nbsp;to the analyst&nbsp;in&nbsp;real time,&nbsp;leaving no blind spots for attackers to exploit.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Available to all ANY.RUN users<\/strong>,\u00a0this new layer\u00a0of\u00a0URL\u00a0<a href=\"https:\/\/any.run\/cybersecurity-blog\/phishing-detection-steps-for-cisos\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing\u00a0visibility<\/a>\u00a0provides a massive\u00a0boost\u00a0for\u00a0the triage and response speed for SOC &amp; <a href=\"https:\/\/any.run\/mssp\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=in-browser-data-inspection&amp;utm_term=160626&amp;utm_content=linktomssp\" target=\"_blank\" rel=\"noreferrer noopener\">MSSP<\/a> teams, enabling them to\u00a0see and\u00a0contain\u00a0critical attacks before they become incidents.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Before vs. After:&nbsp;Fixing Slow and Painful URL Triage Process&nbsp;<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"620\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo2-1024x620.png\" alt=\"\" class=\"wp-image-21661\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo2-1024x620.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo2-300x182.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo2-768x465.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo2-1536x929.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo2-2048x1239.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo2-370x224.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo2-270x163.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo2-740x448.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN delivers complete URL phishing context within seconds<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Right now, the&nbsp;<strong>typical URL analysis process for most SOC&nbsp;and MSSP teams&nbsp;looks&nbsp;like this<\/strong>: A suspicious URL comes in, and the analyst starts assembling context.&nbsp;They scan the URL to get basic info, sandbox it to see what it does, trace redirects, inspect traffic, and still&nbsp;have to&nbsp;piece everything together manually to&nbsp;make&nbsp;a decision.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This turns every alert into a time-consuming task.&nbsp;<\/strong>Analysts spend extra time validating signals,&nbsp;escalate&nbsp;cases by default, and still risk closing malicious URLs without fully understanding their behavior.&nbsp;&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">URL Analysis with ANY.RUN:\u00a0Full\u00a0Static &amp; Dynamic URL\u00a0Context within Seconds\u00a0<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"831\" height=\"1024\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo1-831x1024.png\" alt=\"\" class=\"wp-image-21662\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo1-831x1024.png 831w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo1-243x300.png 243w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo1-768x947.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo1-1246x1536.png 1246w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo1-1662x2048.png 1662w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo1-370x456.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo1-270x333.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/unfo1-740x912.png 740w\" sizes=\"auto, (max-width: 831px) 100vw, 831px\" \/><figcaption class=\"wp-element-caption\"><em>See all URL details, DOM changes, network requests, and IOCs in one place<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">In-browser data inspection solves this friction by giving&nbsp;<strong>you the full&nbsp;static and dynamic&nbsp;URL context&nbsp;in just one click<\/strong>. The page executes in a real browser, and everything that matters, redirects, scripts, DOM changes, user-facing content, is captured and presented to you in a single view.&nbsp;No tab switching.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The result is an instant view of the attack in one place<\/strong>: How the user is redirected, what scripts drive the interaction, where data is collected, and how the phishing flow is constructed end-to-end.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The&nbsp;<strong>context<\/strong>&nbsp;that used to take up to an hour to collect is now<strong>&nbsp;delivered within seconds<\/strong>, complete with a verdict and ready for confident next-step decisions.&nbsp;<\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\nAnalyze\u00a0<span class=\"highlight\">any suspicious URL<\/span> with ANY.RUN\u00a0\n<br>\nSee how it compares to <span class=\"highlight\">your usual\u00a0analysis flow<\/span>\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/app.any.run\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=in-browser-data-inspection&#038;utm_term=160626&#038;utm_content=linktoservice\" rel=\"noopener\" target=\"_blank\">\nLaunch analysis\n<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Why Existing URL&nbsp;Investigation&nbsp;Approaches Fall Short&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many security solutions still lack the&nbsp;<strong>dynamic browser-level visibility&nbsp;<\/strong>needed to clearly understand how a phishing attack unfolds in real time, resulting in critical gaps:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Analysts may see a screenshot of the final page, but not the full path that led to it: redirects, scripts,\u00a0iframe\u00a0activity, and intermediate page states\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Limited visibility into the forms, content, and user-facing elements the victim\u00a0actually saw\u00a0and interacted with\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Missing context around DOM changes, injected content, and dynamically loaded elements during page execution\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Reliance on static page analysis instead of a dynamic, step-by-step view of real browser behavior\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Lack of automatically collected DOM history that allows analysts to inspect page changes across different execution stages\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>No visibility into browser activity preceding WAF alerts or application logs\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Without browser-level inspection, critical evidence can remain hidden from investigators.&nbsp;As a result, analysts often need to combine multiple tools and data sources to fully understand a single URL.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Operational Impact&nbsp;of Visibility Gaps&nbsp;for&nbsp;Security Teams&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">These visibility gaps create several operational challenges for SOC teams:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Fragmented Workflow:\u00a0<\/strong>Reconstructing webpage behavior across multiple tools and data sources slows investigations, increases manual effort, and delays response.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Inefficient Resource Management:<\/strong>\u00a0When analysts lack sufficient evidence to classify a URL confidently, potentially benign links are often escalated to senior team members, consuming valuable resources.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Phishing Analysis\u00a0Gap:\u00a0<\/strong>Solutions focused on file or <a href=\"https:\/\/any.run\/cybersecurity-blog\/how-to-analyze-malicious-network-traffic\/\" target=\"_blank\" rel=\"noreferrer noopener\">network activity<\/a> may miss critical phishing context, leaving analysts without sufficient browser-level evidence.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">As phishing attacks continue to rise, security teams need faster and more reliable ways to investigate suspicious URLs.&nbsp;In-browser&nbsp;data&nbsp;inspection closes this visibility gap by introducing a new layer of&nbsp;webpage-level investigation&nbsp;evidence.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Beyond URL Scanning: Full Browser Visibility for Phishing Investigations&nbsp;<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/In-Browser-Data-Inspection-2-1024x576.png\" alt=\"\" class=\"wp-image-21674\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/In-Browser-Data-Inspection-2-1024x576.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/In-Browser-Data-Inspection-2-300x169.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/In-Browser-Data-Inspection-2-768x432.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/In-Browser-Data-Inspection-2-1536x864.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/In-Browser-Data-Inspection-2-2048x1152.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/In-Browser-Data-Inspection-2-370x208.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/In-Browser-Data-Inspection-2-270x152.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/In-Browser-Data-Inspection-2-740x416.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Functionality and impact delivered by ANY.RUN surpasses what most solutions offer<\/em>&nbsp;<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">As phishing and browser-based threats continue to grow in both&nbsp;volume&nbsp;and sophistication,&nbsp;it\u2019s&nbsp;time for&nbsp;SOC and MSSP&nbsp;teams to upgrade their&nbsp;operations to match&nbsp;the reality of modern attacks.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Available to all ANY.RUN users, in-browser data inspection introduces an investigation layer missing from many security operations today.&nbsp;Unlike workflows that force analysts to piece together evidence across&nbsp;multiple&nbsp;tools, ANY.RUN provides dynamic, in-depth browser visibility, making URL investigations faster, clearer, and more reliable.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This&nbsp;<strong>new investigation&nbsp;layer&nbsp;<\/strong>enables SOC analysts to:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Instantly\u00a0validate, enrich, and prioritize phishing threats using evidence that often\u00a0remains\u00a0hidden in conventional URL analysis workflows\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Reduce uncertainty during investigations with direct visibility into what happens during execution\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Reveal the complete attack chain, including redirects, executed scripts,\u00a0iframes, and dynamically loaded content\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Track browser and DOM changes across every stage of page execution\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Gather the evidence\u00a0required\u00a0for fast triage, escalation, and response from a single investigation workflow\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Access threat intelligence\u00a0required\u00a0for detection engineering, <a href=\"https:\/\/any.run\/cybersecurity-blog\/threat-hunting-for-soc-and-mssp\/\" target=\"_blank\" rel=\"noreferrer noopener\">hunting<\/a>, and campaign analysis\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">All without leaving the\u00a0<a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=in-browser-data-inspection&amp;utm_term=160626&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">sandboxing<\/a> interface.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of relying solely on network logs or file traces, the&nbsp;new inspection method&nbsp;allows you to&nbsp;see&nbsp;<strong>all&nbsp;browser activity<\/strong>&nbsp;observed&nbsp;on the webpage, including forms, content, DOM changes, scripts, and&nbsp;redirects.&nbsp;This provides direct access to behavioral insights and&nbsp;evidence&nbsp;that&nbsp;often&nbsp;remain&nbsp;unavailable in&nbsp;URL analysis and&nbsp;sandboxing workflows.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unlike workflows that require analysts to manually reconstruct browser activity from multiple data sources, in-browser data inspection&nbsp;consolidates&nbsp;browser telemetry, page content, behavioral evidence, and threat intelligence into a single investigation experience.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This allows teams to move from <a href=\"https:\/\/any.run\/cybersecurity-blog\/safebrowsing-extension\/\" target=\"_blank\" rel=\"noreferrer noopener\">URL analysis <\/a>to confident decisions faster, with less effort and greater visibility.\u00a0The result is <a href=\"https:\/\/any.run\/cybersecurity-blog\/triage-analyst-guide\/\" target=\"_blank\" rel=\"noreferrer noopener\">accelerated triage<\/a>, more\u00a0validated\u00a0escalations, stronger detections, and <a href=\"https:\/\/any.run\/cybersecurity-blog\/efficient-soc-for-fast-response\/\" target=\"_blank\" rel=\"noreferrer noopener\">more efficient <\/a>security operations.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Change the Way You Investigate Phishing with In-Browser Data Inspection&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In-browser data inspection changes how phishing investigations are performed.&nbsp;By delivering&nbsp;dynamic&nbsp;browser visibility within ANY.RUN&#8217;s Interactive Sandbox, it helps SOC and MSSP teams investigate threats faster, reduce uncertainty, and make more confident incident response&nbsp;decisions.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of piecing together screenshots, redirects, page content, browser artifacts, and external intelligence from multiple tools, analysts receive a complete browser-level investigation within a single workflow.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To start&nbsp;your investigation<strong>,&nbsp;<\/strong>simply&nbsp;open the&nbsp;<strong>Browser Data&nbsp;<\/strong>tab to access a complete, dynamic&nbsp;view of the web&nbsp;page&nbsp;execution.&nbsp;It&#8217;s&nbsp;available within every URL analysis in ANY.RUN&#8217;s Interactive Sandbox.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/app.any.run\/tasks\/9ad891af-11b7-4e0d-a600-f3c8b594875b\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=in-browser-data-inspection&amp;utm_term=160626&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">View analysis<\/a>\u00a0<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"485\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-11.42.23-1024x485.png\" alt=\"\" class=\"wp-image-21665\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-11.42.23-1024x485.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-11.42.23-300x142.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-11.42.23-768x364.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-11.42.23-1536x727.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-11.42.23-2048x970.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-11.42.23-370x175.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-11.42.23-270x128.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-11.42.23-740x350.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Phishing analysis inside ANY.RUN\u2019s Interactive Sandbox. Browser Data tab\u00a0<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\">Understand the Attack Flow&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The<strong>&nbsp;Browser Data&nbsp;<\/strong>within&nbsp;ANY.RUN&#8217;s Interactive&nbsp;Sandbox&nbsp;provides&nbsp;the entire&nbsp;web page execution&nbsp;tree, from&nbsp;initial&nbsp;URL to the final&nbsp;page view,&nbsp;featuring all redirects and activated&nbsp;iframes.&nbsp;Color highlights and tags&nbsp;point to the pages responsible for triggering&nbsp;detections.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Investigation outcome:&nbsp;<\/strong>Accelerate triage and escalation decisions&nbsp;by gaining an immediate overview of the dynamic attack flow and&nbsp;identifying&nbsp;the most relevant stages for further analysis.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"366\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image6-1024x366.png\" alt=\"\" class=\"wp-image-21666\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image6-1024x366.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image6-300x107.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image6-768x274.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image6-1536x549.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image6-370x132.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image6-270x96.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image6-740x264.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image6.png 1845w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>HTTP Requests tab within\u00a0Browser\u00a0Data section. ANY.RUN\u2019s Interactive Sandbox<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Detailed&nbsp;<strong>HTTP&nbsp;Requests<\/strong>&nbsp;data&nbsp;provides complete visibility into redirects, requests, and responses generated during page execution.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Investigation outcome:&nbsp;<\/strong>Improve threat validation and detection engineering&nbsp;by reconstructing redirect chains and collecting evidence for IDS detections and network-based hunting rules.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Analyze Browser-Level Behavior&nbsp;<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"495\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image2-1024x495.png\" alt=\"\" class=\"wp-image-21667\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image2-1024x495.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image2-300x145.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image2-768x371.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image2-1536x742.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image2-370x179.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image2-270x130.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image2-740x357.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image2.png 1849w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>URL Details\u00a0displays\u00a0related context and screenshots. ANY.RUN\u2019s Interactive Sandbox<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Explore&nbsp;browser-level telemetry,&nbsp;including triggered signatures, domain, URL, and IP statistics, as well as&nbsp;rendered&nbsp;screenshots of the analyzed page.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Investigation outcome:&nbsp;<\/strong>Improve threat validation and detection engineering&nbsp;by reconstructing redirect chains and collecting evidence for IDS detections and network-based hunting rules.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To see which code fragments were added to the DOM after the page loaded, go to the HTML DOM Changes tab\u00a0for\u00a0<a href=\"https:\/\/any.run\/cybersecurity-blog\/five-common-malware-evasion-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">deobfuscation<\/a>. It will reveal what static analysis misses:\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/app.any.run\/tasks\/586505b8-897f-4e2f-b520-e4eecf31d453\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=in-browser-data-inspection&amp;utm_term=160626&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">View analysis<\/a>\u00a0<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"413\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-16-at-09.58.05-1-1024x413.png\" alt=\"\" class=\"wp-image-21669\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-16-at-09.58.05-1-1024x413.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-16-at-09.58.05-1-300x121.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-16-at-09.58.05-1-768x310.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-16-at-09.58.05-1-1536x619.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-16-at-09.58.05-1-2048x826.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-16-at-09.58.05-1-370x149.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-16-at-09.58.05-1-270x109.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-16-at-09.58.05-1-740x298.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>The green lines show\u00a0the new code which was added to the DOM after the page\u00a0loaded.\u00a0ANY.RUN\u2019s Interactive Sandbox<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">In-browser data inspection\u00a0captures the\u00a0<a href=\"https:\/\/app.any.run\/tasks\/586505b8-897f-4e2f-b520-e4eecf31d453?w=6a2b3e90017aef632e2c2b93&amp;t=dom\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=in-browser-data-inspection&amp;utm_term=160626&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">fully rendered and interactive state of the page<\/a>, allowing the analyst to see the actual behavior, including hidden forms, redirects, and user interaction logic that were impossible to understand statically.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Investigation outcome:&nbsp;<\/strong>Strengthen threat hunting and detection engineering&nbsp;by&nbsp;identifying&nbsp;phishing elements, reconstructing the loading process, and extracting behavioral artifacts.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Expand the Investigation Beyond the Initial Sample&nbsp;<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"366\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image7-1024x366.png\" alt=\"\" class=\"wp-image-21670\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image7-1024x366.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image7-300x107.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image7-768x274.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image7-1536x549.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image7-370x132.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image7-270x96.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image7-740x264.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/image7.png 1845w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Track all related indicators in a dedicated tab. ANY.RUN\u2019s Interactive Sandbox<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Collected&nbsp;<strong>Indicators&nbsp;<\/strong>include URLs, domains, IP addresses, and hashes of web content associated with the analyzed page.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Investigation outcome:&nbsp;<\/strong>Expand investigations&nbsp;beyond a single sample by developing pivoting hypotheses and uncovering attacker-controlled infrastructure.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Content extracted from web page snapshots can&nbsp;also&nbsp;be used to create custom hunting and detection rules backed by ANY.RUN Threat Intelligence.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"863\" height=\"389\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imagea.png\" alt=\"\" class=\"wp-image-21671\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imagea.png 863w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imagea-300x135.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imagea-768x346.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imagea-370x167.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imagea-270x122.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imagea-740x334.png 740w\" sizes=\"auto, (max-width: 863px) 100vw, 863px\" \/><figcaption class=\"wp-element-caption\"><em>YARA rule built based on Browser\u00a0Data. ANY.RUN\u2019s TI Lookup &amp; YARA Search<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">In this example, a YARA rule created from a single phishing page\u00a0identified\u00a0145 related samples\u00a0within\u00a0<a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=in-browser-data-inspection&amp;utm_term=160626&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Lookup &amp; YARA Search<\/a>:\u00a0<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"540\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imageb-1024x540.png\" alt=\"\" class=\"wp-image-21672\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imageb-1024x540.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imageb-300x158.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imageb-768x405.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imageb-1536x810.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imageb-370x195.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imageb-270x142.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imageb-740x390.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/imageb.png 1572w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>YARA rule browsing results. ANY.RUN\u2019s TI Lookup &amp; YARA Search<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>Investigation outcomes:<\/strong>&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Expand visibility beyond a single URL or alert\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Validate threat hunting hypotheses with browser-level evidence\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Assess the scale of an attack campaign\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Develop resilient detections based on attacker tooling and\u00a0page artifacts\u00a0<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Turning Powerful Visibility into Stronger Security Outcomes&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">By combining interactive sandboxing, full browser-level visibility, and threat intelligence sourced from over 15,000 security teams, ANY.RUN transforms URL investigations from fragmented, manual analysis into fast, evidence-based decision-making.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Through&nbsp;eliminating&nbsp;visibility gaps and reducing the need for disconnected tools, security teams can improve outcomes across the entire investigation workflow:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Faster triage and fewer unnecessary escalations:<\/strong>\u00a0With immediate access to browser-level evidence, Tier 1 analysts can\u00a0validate\u00a0suspicious URLs faster and escalate fewer benign cases, improving\u00a0productivity\u00a0and reducing pressure on senior teams.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Smoother handoff and incident response:\u00a0<\/strong>When escalation is\u00a0required, Tier 2 analysts receive a complete evidence package rather than disconnected indicators, accelerating validation and reducing MTTR.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Stronger detection engineering:\u00a0<\/strong>Browser telemetry provides a new source of intelligence for building custom detections, hunting hypotheses, and phishing signatures based on real-world attack behavior.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Structured reporting:\u00a0<\/strong>Built-in <a href=\"https:\/\/any.run\/cybersecurity-blog\/soc-ready-reporting\/\" target=\"_blank\" rel=\"noreferrer noopener\">SOC-ready reports <\/a>transform complex investigations into decision-ready intelligence, simplifying triage, escalation, response, and stakeholder communication.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For enterprises and MSSPs, these operational improvements translate into faster investigations, more efficient use of analyst resources, stronger phishing defenses, and the ability to scale security operations without proportionally increasing workload.&nbsp;<\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\nThe new <span class=\"highlight\">phishing detection standard<\/span> in your SOC\n<br>\nEliminate phishing blind spots with <span class=\"highlight\">full browser visibility<\/span>\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=in-browser-data-inspection&#038;utm_term=160626&#038;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nContact us\n<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In-browser data inspection closes a critical visibility gap in modern phishing investigations.&nbsp;With it,&nbsp;SOC analysts and threat hunters can investigate phishing attacks directly inside ANY.RUN without manually extracting web content from traffic captures, reconstructing redirect chains, or comparing raw page source against the content&nbsp;rendered&nbsp;in the browser.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead, all browser-level evidence is collected, correlated, and presented within a single investigation environment,&nbsp;helping enterprise security teams investigate threats faster and respond with greater confidence.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=in-browser-data-inspection&amp;utm_term=160626&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> helps SOC teams, MSSPs, and enterprises investigate cyber threats faster through interactive malware analysis and threat intelligence.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its cloud-based <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=in-browser-data-inspection&amp;utm_term=160626&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> enables security teams to safely analyze suspicious files, URLs, and emails in real time,\u00a0observe\u00a0attack behavior as it unfolds, and collect actionable evidence for rapid response.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN&#8217;s <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=in-browser-data-inspection&amp;utm_term=160626&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence<\/a> solutions provide\u00a0additional\u00a0context around threats, infrastructure, and attacker activity, helping organizations enrich investigations, streamline security workflows, and improve threat detection. Together, these capabilities enable faster triage, more informed decision-making, and more efficient security operations at scale.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ&nbsp;<\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1781601200148\"><strong class=\"schema-faq-question\"><strong>What is\u00a0in-browser\u00a0data\u00a0inspection?<\/strong>\u00a0<\/strong> <p class=\"schema-faq-answer\">In-browser data inspection\u00a0is a new ANY.RUN capability that collects and displays browser-level activity during URL analysis, including page content, forms, scripts, redirects, screenshots, and DOM modifications.\u00a0<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1781601207221\"><strong class=\"schema-faq-question\"><strong>How does\u00a0in-browser data inspection\u00a0improve phishing analysis?<\/strong>\u00a0<\/strong> <p class=\"schema-faq-answer\">It provides visibility into what\u00a0actually happens\u00a0inside the browser, helping analysts\u00a0identify\u00a0phishing forms, deceptive content, redirect chains, and other browser-based attack techniques that may not be visible through network or file analysis alone.\u00a0<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1781601213356\"><strong class=\"schema-faq-question\"><strong>What browser data can analysts investigate in ANY.RUN?<\/strong>\u00a0<\/strong> <p class=\"schema-faq-answer\">Analysts can examine page content,\u00a0rendered\u00a0screenshots, forms, scripts, DOM changes, redirects, URLs, domains, IP addresses, and other browser-level artifacts collected during URL execution.\u00a0<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1781601219442\"><strong class=\"schema-faq-question\"><strong>How does\u00a0in-browser data inspection\u00a0help SOC teams?<\/strong>\u00a0<\/strong> <p class=\"schema-faq-answer\">By providing immediate access to browser-level evidence, it reduces manual investigation effort, improves triage accuracy, minimizes unnecessary escalations, and accelerates incident response.\u00a0<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1781601234880\"><strong class=\"schema-faq-question\"><strong>Can\u00a0in-browser data inspection\u00a0be used for threat hunting?<\/strong>\u00a0<\/strong> <p class=\"schema-faq-answer\">Yes. Analysts can use collected indicators, page artifacts, and browser telemetry to pivot across related infrastructure, investigate phishing campaigns, and develop threat hunting hypotheses.\u00a0<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1781601246590\"><strong class=\"schema-faq-question\"><strong>How can browser inspection data improve threat detection?<\/strong>\u00a0<\/strong> <p class=\"schema-faq-answer\">Security teams can use content extracted from analyzed web pages to create custom detection rules and hunting signatures, including YARA rules, to\u00a0identify\u00a0related threats and phishing campaigns.\u00a0<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1781601252624\"><strong class=\"schema-faq-question\"><strong>Is\u00a0in-browser data inspection\u00a0available in ANY.RUN Interactive Sandbox?<\/strong>\u00a0<\/strong> <p class=\"schema-faq-answer\">Yes.\u00a0In-browser data inspection\u00a0is available within URL analyses in ANY.RUN&#8217;s Interactive Sandbox through the Browser Data tab.\u00a0<\/p> <\/div> <\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Modern\u00a0URL phishing relies\u00a0on dynamic pages, credential harvesting flows, client-side scripts, and layered redirect chains. But most SOC workflows are still built around static analysis, making them blind to most of these\u00a0tactics.\u00a0 ANY.RUN changes\u00a0this forever with\u00a0in-browser data inspection.\u00a0 The&nbsp;new technology&nbsp;takes URL analysis to the next level by bringing static and dynamic analysis into one single workflow.&nbsp;Now, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":21664,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9],"tags":[57,10,34],"class_list":["post-21658","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-service-updates","tag-anyrun","tag-cybersecurity","tag-malware-analysis"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ANY.RUN Sets a New Standard for URL Analysis<\/title>\n<meta name=\"description\" content=\"See how full browser visibility transforms URL analysis, helping analysts investigate phishing threats with confidence.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ANY.RUN\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/\"},\"author\":{\"name\":\"ANY.RUN\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"The New Standard for URL Analysis: Closing Phishing\u00a0Blind\u00a0Spots\u00a0with In-Browser Data Inspection\u00a0\",\"datePublished\":\"2026-06-16T10:11:34+00:00\",\"dateModified\":\"2026-06-16T10:15:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/\"},\"wordCount\":2373,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Next-Level-of-Phishing-Detection-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\",\"malware analysis\"],\"articleSection\":[\"Service Updates\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#respond\"]}]},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/\",\"name\":\"ANY.RUN Sets a New Standard for URL Analysis\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Next-Level-of-Phishing-Detection-scaled.png\",\"datePublished\":\"2026-06-16T10:11:34+00:00\",\"dateModified\":\"2026-06-16T10:15:05+00:00\",\"description\":\"See how full browser visibility transforms URL analysis, helping analysts investigate phishing threats with confidence.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601200148\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601207221\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601213356\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601219442\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601234880\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601246590\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601252624\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Next-Level-of-Phishing-Detection-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Next-Level-of-Phishing-Detection-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"in-browser data inspection\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Service Updates\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/service-updates\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"The New Standard for URL Analysis: Closing Phishing\u00a0Blind\u00a0Spots\u00a0with In-Browser Data Inspection\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"caption\":\"ANY.RUN\"},\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/author\\\/a-bespalova\\\/\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601200148\",\"position\":1,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601200148\",\"name\":\"What is\u00a0in-browser\u00a0data\u00a0inspection?\u00a0\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"In-browser data inspection\u00a0is a new ANY.RUN capability that collects and displays browser-level activity during URL analysis, including page content, forms, scripts, redirects, screenshots, and DOM modifications.\u00a0\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601207221\",\"position\":2,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601207221\",\"name\":\"How does\u00a0in-browser data inspection\u00a0improve phishing analysis?\u00a0\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It provides visibility into what\u00a0actually happens\u00a0inside the browser, helping analysts\u00a0identify\u00a0phishing forms, deceptive content, redirect chains, and other browser-based attack techniques that may not be visible through network or file analysis alone.\u00a0\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601213356\",\"position\":3,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601213356\",\"name\":\"What browser data can analysts investigate in ANY.RUN?\u00a0\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Analysts can examine page content,\u00a0rendered\u00a0screenshots, forms, scripts, DOM changes, redirects, URLs, domains, IP addresses, and other browser-level artifacts collected during URL execution.\u00a0\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601219442\",\"position\":4,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601219442\",\"name\":\"How does\u00a0in-browser data inspection\u00a0help SOC teams?\u00a0\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"By providing immediate access to browser-level evidence, it reduces manual investigation effort, improves triage accuracy, minimizes unnecessary escalations, and accelerates incident response.\u00a0\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601234880\",\"position\":5,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601234880\",\"name\":\"Can\u00a0in-browser data inspection\u00a0be used for threat hunting?\u00a0\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. Analysts can use collected indicators, page artifacts, and browser telemetry to pivot across related infrastructure, investigate phishing campaigns, and develop threat hunting hypotheses.\u00a0\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601246590\",\"position\":6,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601246590\",\"name\":\"How can browser inspection data improve threat detection?\u00a0\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Security teams can use content extracted from analyzed web pages to create custom detection rules and hunting signatures, including YARA rules, to\u00a0identify\u00a0related threats and phishing campaigns.\u00a0\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601252624\",\"position\":7,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/in-browser-data-inspection\\\/#faq-question-1781601252624\",\"name\":\"Is\u00a0in-browser data inspection\u00a0available in ANY.RUN Interactive Sandbox?\u00a0\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes.\u00a0In-browser data inspection\u00a0is available within URL analyses in ANY.RUN's Interactive Sandbox through the Browser Data tab.\u00a0\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ANY.RUN Sets a New Standard for URL Analysis","description":"See how full browser visibility transforms URL analysis, helping analysts investigate phishing threats with confidence.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/","twitter_misc":{"Written by":"ANY.RUN","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/"},"author":{"name":"ANY.RUN","@id":"https:\/\/any.run\/"},"headline":"The New Standard for URL Analysis: Closing Phishing\u00a0Blind\u00a0Spots\u00a0with In-Browser Data Inspection\u00a0","datePublished":"2026-06-16T10:11:34+00:00","dateModified":"2026-06-16T10:15:05+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/"},"wordCount":2373,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Next-Level-of-Phishing-Detection-scaled.png","keywords":["ANYRUN","cybersecurity","malware analysis"],"articleSection":["Service Updates"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#respond"]}]},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/","url":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/","name":"ANY.RUN Sets a New Standard for URL Analysis","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Next-Level-of-Phishing-Detection-scaled.png","datePublished":"2026-06-16T10:11:34+00:00","dateModified":"2026-06-16T10:15:05+00:00","description":"See how full browser visibility transforms URL analysis, helping analysts investigate phishing threats with confidence.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601200148"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601207221"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601213356"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601219442"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601234880"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601246590"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601252624"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Next-Level-of-Phishing-Detection-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/06\/Next-Level-of-Phishing-Detection-scaled.png","width":2560,"height":1243,"caption":"in-browser data inspection"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Service Updates","item":"https:\/\/any.run\/cybersecurity-blog\/category\/service-updates\/"},{"@type":"ListItem","position":3,"name":"The New Standard for URL Analysis: Closing Phishing\u00a0Blind\u00a0Spots\u00a0with In-Browser Data Inspection\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"ANY.RUN","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","caption":"ANY.RUN"},"url":"https:\/\/any.run\/cybersecurity-blog\/author\/a-bespalova\/"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601200148","position":1,"url":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601200148","name":"What is\u00a0in-browser\u00a0data\u00a0inspection?\u00a0","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"In-browser data inspection\u00a0is a new ANY.RUN capability that collects and displays browser-level activity during URL analysis, including page content, forms, scripts, redirects, screenshots, and DOM modifications.\u00a0","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601207221","position":2,"url":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601207221","name":"How does\u00a0in-browser data inspection\u00a0improve phishing analysis?\u00a0","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"It provides visibility into what\u00a0actually happens\u00a0inside the browser, helping analysts\u00a0identify\u00a0phishing forms, deceptive content, redirect chains, and other browser-based attack techniques that may not be visible through network or file analysis alone.\u00a0","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601213356","position":3,"url":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601213356","name":"What browser data can analysts investigate in ANY.RUN?\u00a0","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Analysts can examine page content,\u00a0rendered\u00a0screenshots, forms, scripts, DOM changes, redirects, URLs, domains, IP addresses, and other browser-level artifacts collected during URL execution.\u00a0","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601219442","position":4,"url":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601219442","name":"How does\u00a0in-browser data inspection\u00a0help SOC teams?\u00a0","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"By providing immediate access to browser-level evidence, it reduces manual investigation effort, improves triage accuracy, minimizes unnecessary escalations, and accelerates incident response.\u00a0","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601234880","position":5,"url":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601234880","name":"Can\u00a0in-browser data inspection\u00a0be used for threat hunting?\u00a0","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes. Analysts can use collected indicators, page artifacts, and browser telemetry to pivot across related infrastructure, investigate phishing campaigns, and develop threat hunting hypotheses.\u00a0","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601246590","position":6,"url":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601246590","name":"How can browser inspection data improve threat detection?\u00a0","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Security teams can use content extracted from analyzed web pages to create custom detection rules and hunting signatures, including YARA rules, to\u00a0identify\u00a0related threats and phishing campaigns.\u00a0","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601252624","position":7,"url":"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/#faq-question-1781601252624","name":"Is\u00a0in-browser data inspection\u00a0available in ANY.RUN Interactive Sandbox?\u00a0","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes.\u00a0In-browser data inspection\u00a0is available within URL analyses in ANY.RUN's Interactive Sandbox through the Browser Data tab.\u00a0","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/21658","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=21658"}],"version-history":[{"count":14,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/21658\/revisions"}],"predecessor-version":[{"id":21691,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/21658\/revisions\/21691"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/21664"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=21658"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=21658"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=21658"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}