{"id":23490,"date":"2026-09-30T09:51:07","date_gmt":"2026-09-30T09:51:07","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=23490"},"modified":"2026-09-30T11:22:31","modified_gmt":"2026-09-30T11:22:31","slug":"phishing-response-protocol","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/","title":{"rendered":"Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN&#8217;s Latest Updates"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every manual step adds time to the response. It also ties up analyst capacity in work that could be spent investigating and containing real threats. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a>\u2019s latest product updates are designed around those gaps, helping teams move faster from <strong>detection to investigation, response, and proactive defense<\/strong> while keeping the evidence and context connected throughout the process. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Phishing Remains a High-Volume, High-Cost SOC Problem <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing isn\u2019t just another alert category competing for analysts\u2019 attention. In several critical industries, it shows up in <strong>more than 70% of investigations<\/strong>: ANY.RUN\u2019s 2026 data puts phishing exposure at <strong>73.4% in finance<\/strong> and <strong>72.2% in manufacturing<\/strong>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And the consequences extend far beyond the inbox. Microsoft Incident Response found that <strong>28% of the breaches it investigated started with phishing or social engineering<\/strong>, including newer techniques such as device code phishing. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The financial stakes are just as hard to ignore. In 2025, the FBI received <strong>191,561 phishing and spoofing complaints<\/strong>, while Business Email Compromise alone generated <strong>$3.05 billion in reported US losses<\/strong>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For SOC teams, that combination means high investigation volume, increasingly evasive attacks, and very little room for slow decisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finding a suspicious email or URL is only the beginning. Analysts still need to understand what happened, collect enough evidence to act, pass the case to the right team, and make sure the same threat is easier to catch next time.  <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Faster Phishing Response Looks Like <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With phishing showing up in such a large share of SOC investigations, simply putting more analyst time into every suspicious URL is not a sustainable answer. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The bigger opportunity is to cut the manual work between <strong>detection, investigation, response, and follow-up<\/strong>. That is the idea behind several of ANY.RUN\u2019s latest product updates: give analysts more of the evidence they need upfront, make the handoff easier, and turn each investigation into a starting point for proactive defense. <\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-401\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"4\"\n           data-rows=\"4\"\n           data-wpID=\"401\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell \"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:25%;                    padding:10px;\n                    \"\n                    >\n                                        Step\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell \"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:25%;                    padding:10px;\n                    \"\n                    >\n                                        SOC Goal\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell \"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:25%;                    padding:10px;\n                    \"\n                    >\n                                        ANY.RUN Capabilities\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell \"\n                                            data-cell-id=\"D1\"\n                    data-col-index=\"3\"\n                    data-row-index=\"0\"\n                    style=\" width:25%;                    padding:10px;\n                    \"\n                    >\n                                        What Improves\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        1. Accelerate Triage\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        See the full phishing attack and collect enough evidence to make a confident decision\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        <a class=\"wpdt-link-content\" style=\"color: #4BAEE3; text-decoration: underline;\" href=\"https:\/\/any.run\/cybersecurity-blog\/automatic-ssl-decryption\/\" rel=\"\" target=\"_blank\" data-cell-id=\"12\" data-link-url=\"https:\/\/any.run\/cybersecurity-blog\/automatic-ssl-decryption\/\" data-link-text=\"SSL Decryption without MITM\" data-link-target=\"true\" data-link-nofollow=\"0\" data-link-noreferrer=\"0\" data-link-sponsored=\"0\" data-link-btn-status=\"0\" data-link-btn-class=\"\" data-link-content=\"wpdt-link-content\">SSL Decryption without MITM<\/a> + <a class=\"wpdt-link-content\" style=\"color: #4BAEE3; text-decoration: underline;\" href=\"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/\" rel=\"\" target=\"_blank\" data-cell-id=\"12\" data-link-url=\"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/\" data-link-text=\"In-Browser Data Inspection\" data-link-target=\"true\" data-link-nofollow=\"0\" data-link-noreferrer=\"0\" data-link-sponsored=\"0\" data-link-btn-status=\"0\" data-link-btn-class=\"\" data-link-content=\"wpdt-link-content\">In-Browser Data Inspection<\/a>                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"D2\"\n                    data-col-index=\"3\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        20% less Tier 1 investigation time with faster threat validation and less manual traffic and browser reconstruction                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        2. Improve Escalation & Response\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Turn technical findings into a clear case that the next team can act on\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        <a class=\"wpdt-link-content\" style=\"color: #4BAEE3; text-decoration: underline;\" href=\"https:\/\/any.run\/cybersecurity-blog\/soc-ready-reporting\/\" rel=\"\" target=\"_blank\" data-cell-id=\"22\" data-link-url=\"https:\/\/any.run\/cybersecurity-blog\/soc-ready-reporting\/\" data-link-text=\"Tier 1 reports + AI Summary + AI Recommendations \" data-link-target=\"true\" data-link-nofollow=\"0\" data-link-noreferrer=\"0\" data-link-sponsored=\"0\" data-link-btn-status=\"0\" data-link-btn-class=\"\" data-link-content=\"wpdt-link-content\">Tier 1 reports + AI Summary + AI Recommendations <\/a>                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"D3\"\n                    data-col-index=\"3\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        30% fewer escalations and 21 minutes less MTTR per case with clearer handoffs and faster response                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        3. Move to Proactive\u00a0Defense\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Go beyond the individual incident and understand the wider threat\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        <a class=\"wpdt-link-content\" style=\"color: #4BAEE3; text-decoration: underline;\" href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookuplanding\" rel=\"\" target=\"_blank\" data-cell-id=\"32\" data-link-url=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookuplanding\" data-link-text=\"Connections in Threat Intelligence Lookup \" data-link-target=\"true\" data-link-nofollow=\"0\" data-link-noreferrer=\"0\" data-link-sponsored=\"0\" data-link-btn-status=\"0\" data-link-btn-class=\"\" data-link-content=\"wpdt-link-content\">Connections in Threat Intelligence Lookup <\/a>                    <\/td>\n                                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"D4\"\n                    data-col-index=\"3\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Faster pivoting to related infrastructure,\u00a0   retrohunting, blocking, and stronger future detection\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-401'>\ntable#wpdtSimpleTable-401{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-401 td, table.wpdtSimpleTable401 th { white-space: normal !important; }\n<\/style>\n\n\n\n\n<p class=\"wp-block-paragraph\">Each stage builds on the one before it, turning a single phishing investigation into evidence for response, escalation, and stronger future detection. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Cut the manual work from phishing response.\n\n<\/span> \n<br>\nSee how ANY.RUN helps your SOC move from alert to action. \n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=phishing-response-protocol&#038;utm_term=300926&#038;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nExplore ANY.RUN for Your SOC <\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">3 Steps from Phishing Detection to Faster Response and Stronger Defense <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For this walkthrough, we\u2019ll use a modern phishing attack with the following execution chain: <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Cloudflare CAPTCHA \u2192 Phishing document lure \u2192 Device Code Phishing (EvilTokens)<\/strong> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/malware-trends\/eviltokens\/\" target=\"_blank\" rel=\"noreferrer noopener\">EvilTokens<\/a> is a phishing-as-a-service platform that abuses Microsoft\u2019s legitimate device code authentication flow to steal session tokens and gain access to accounts. Its campaigns can combine CAPTCHA gates, redirects, legitimate cloud services, and dynamic phishing pages, which makes the attack harder to judge from the original URL alone and creates extra work for SOC analysts trying to piece together what actually happened.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The full attack is captured in this <a href=\"https:\/\/app.any.run\/tasks\/59bddc5a-ed5f-4d9b-82d8-2ca1ef0aeeda\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN sandbox session<\/a><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"637\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-sandbox-for-faster-triage-1024x637.png\" alt=\"Full EvilTokens attack chain exposed in ANY.RUN Sandbox in under a minute \" class=\"wp-image-23500\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-sandbox-for-faster-triage-1024x637.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-sandbox-for-faster-triage-300x187.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-sandbox-for-faster-triage-768x478.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-sandbox-for-faster-triage-1536x956.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-sandbox-for-faster-triage-2048x1274.png 2048w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-sandbox-for-faster-triage-370x230.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-sandbox-for-faster-triage-270x168.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-sandbox-for-faster-triage-740x460.png 740w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Full EvilTokens attack chain exposed in ANY.RUN Sandbox in under a minute<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Now let\u2019s follow the investigation through the three steps of the phishing response workflow. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1: Accelerate Triage with Full Attack Visibility Using SSL Decryption and In-Browser Data Inspection  <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The first problem SOC teams face is getting enough evidence to make a confident decision quickly. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That becomes harder with modern phishing, where the activity that matters may sit behind encrypted HTTPS traffic, redirects, CAPTCHA gates, scripts, and browser changes. A suspicious URL alone rarely tells the whole story. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, the first step is to expose as much of the attack as possible without forcing the analyst to reconstruct it manually across several tools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the EvilTokens case, the suspicious URL is opened in <strong>ANY.RUN\u2019s <\/strong><a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Interactive Sandbox<\/strong><\/a>. As the attack unfolds, the Network section records the web requests made by the browser, including traffic that was originally encrypted over HTTPS. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"208\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/newscreen1-1024x208.png\" alt=\"\" class=\"wp-image-23532\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/newscreen1-1024x208.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/newscreen1-300x61.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/newscreen1-768x156.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/newscreen1-370x75.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/newscreen1-270x55.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/newscreen1-740x150.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/newscreen1.png 1141w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>HTTP requests displayed inside ANY.RUN sandbox<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This shows where the phishing page connects, which resources it loads, and what happens in the background while the victim interacts with the page. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Analysts can then open the Content view to inspect individual request-response pairs and look for suspicious patterns. In this case, one of the requests is: <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GET hxxps[:\/\/]preponacrea[.]com\/est\/js\/main[.]js <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"869\" height=\"711\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Connect-preview-edited.png\" alt=\"Preview of suspicious patterns in ANY.RUN sandbox\" class=\"wp-image-23534\" style=\"aspect-ratio:1.222846484543821;width:574px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Connect-preview-edited.png 869w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Connect-preview-edited-300x245.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Connect-preview-edited-768x628.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Connect-preview-edited-370x303.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Connect-preview-edited-270x221.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Connect-preview-edited-740x605.png 740w\" sizes=\"auto, (max-width: 869px) 100vw, 869px\" \/><figcaption class=\"wp-element-caption\"><em>Preview of suspicious patterns in ANY.RUN sandbox<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This is where <a href=\"https:\/\/any.run\/cybersecurity-blog\/automatic-ssl-decryption\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>SSL Decryption without MITM<\/strong><\/a> changes the investigation. ANY.RUN extracts encryption keys directly from process memory, making HTTPS traffic available for inspection, Suricata rules, signatures, and IOC extraction, without setting up a separate MITM proxy or replacing certificates. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Network traffic, however, is only one side of the attack. The next part of the investigation happens in our newly added <a href=\"https:\/\/any.run\/cybersecurity-blog\/in-browser-data-inspection\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Browser Data<\/strong><\/a><strong> <\/strong>section.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here, analysts can follow the redirect chain leading to the phishing page and inspect what changes inside the browser as the attack progresses, including HTTP requests, DOM changes, iframes, screenshots, and other page activity. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"703\" height=\"607\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/browser-data.png\" alt=\"In-browser data inspection reveals full attack visibility into the phishing page\" class=\"wp-image-23503\" style=\"width:539px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/browser-data.png 703w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/browser-data-300x259.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/browser-data-370x319.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/browser-data-270x233.png 270w\" sizes=\"auto, (max-width: 703px) 100vw, 703px\" \/><figcaption class=\"wp-element-caption\"><em>In-browser data inspection reveals full attack visibility into the phishing page<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Together, <strong>SSL Decryption without MITM + In-Browser Data Inspection<\/strong> give the analyst both sides of the attack: what happens on the network and what happens inside the browser. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"498\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/HTML-DOM-changes-1024x498.png\" alt=\"HTML DOM changes displayed inside ANY.RUN Sandbox\" class=\"wp-image-23504\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/HTML-DOM-changes-1024x498.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/HTML-DOM-changes-300x146.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/HTML-DOM-changes-768x374.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/HTML-DOM-changes-1536x747.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/HTML-DOM-changes-370x180.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/HTML-DOM-changes-270x131.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/HTML-DOM-changes-740x360.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/HTML-DOM-changes.png 1850w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>HTML DOM changes displayed inside ANY.RUN Sandbox<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Instead of digging through hundreds of web-log entries, opening PCAPs separately, and manually rebuilding the redirect chain, Tier 1 gets the evidence needed for validation in one analysis. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"717\" height=\"191\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-edited.png\" alt=\"\" class=\"wp-image-23535\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-edited.png 717w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-edited-300x80.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-edited-370x99.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-edited-270x72.png 270w\" sizes=\"auto, (max-width: 717px) 100vw, 717px\" \/><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"221\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-network-1024x221.png\" alt=\"ANY.RUN automatically decrypts traffic for Suricata analysis\" class=\"wp-image-23507\" style=\"aspect-ratio:4.63368384761248;width:724px;height:auto\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-network-1024x221.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-network-300x65.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-network-768x166.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-network-370x80.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-network-270x58.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-network-740x160.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Suricata-network.png 1147w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN automatically decrypts traffic for Suricata analysis<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<!-- Highlight Block HTML START -->\n<div class=\"window\">\n  <div class=\"window-header\">\n    <div class=\"pill\">\u261d\ufe0fStep 1 SOC outcomes:<\/div>\n  <\/div>\n  <div class=\"window-body\">\n    <ul>\n      <li>More phishing cases resolved at Tier 1<\/li>\n      <li>Higher analyst throughput without increasing headcount<\/li>\n      <li>Less time lost rebuilding browser and traffic activity<\/li>\n<li>Faster confidence on whether a case needs action <\/li>\n    <\/ul>\n  <\/div>\n<\/div>\n<!-- Highlight Block HTML END -->\n\n\n<!-- Highlight Block CSS START -->\n<style>\n  .window {\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n\n    border-radius: 4px;\n    margin: 20px auto 50px auto;\n    padding: 20px 40px;\n    line-height: 2rem;\n  }\n\n  .window-header {\n    display: flex;\n    justify-content: center;\n    margin-bottom: 20px;\n  }\n\n  .pill {\n    background-color: #fff;\n    border-radius: 20px;\n    color: #333;\n    font-weight: bold;\n    padding: 8px 32px;\nborder: 1px solid rgba(75, 174, 227, 0.32);\n  }\n\n  @media (max-width: 480px) {\n    .window {\n      padding: 10px;\n    }\n    \n    .pill {\n      font-size: 14px;\n      padding: 6px 12px;\n    }\n  }\n<\/style>\n<!-- Highlight Block CSS END -->\n\n\n\n<h3 class=\"wp-block-heading\">Step 2: Improve Escalation &amp; Response with AI-Powered Tier 1 Reports <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Confirming that a phishing attack is malicious does not finish the analyst\u2019s job. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The technical findings still need to become something another person can act on: what happened, why the activity is malicious, which indicators matter, and what should happen next. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Without that context, Tier 2 or incident response may have to reopen the original analysis, review the evidence again, and rebuild parts of the case before making a decision. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That reporting burden is still highly manual across SOCs. According to the SANS SOC Survey 2025, <strong>69% of SOCs create metrics manually or mostly manually<\/strong>, while nearly half describe the process as very time-consuming. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">30% fewer escalations. MTTR reduced by 21 mins per case. \n\n<\/span> \n<br>\nGet more capacity from your existing SOC team. \n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\n Increase SOC Capacity<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<p class=\"wp-block-paragraph\">At this stage, the goal is to move from technical analysis to a <strong>response-ready decision<\/strong> without writing the case from scratch. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the EvilTokens analysis, <a href=\"https:\/\/any.run\/cybersecurity-blog\/soc-ready-reporting\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Tier 1 reports<\/strong><\/a> bring the key findings into one structured view. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/report\/59bddc5a-ed5f-4d9b-82d8-2ca1ef0aeeda\/summary\/tier1?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">See the Tier 1 report for this analysis<\/a> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"153\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-TI-report-1024x153.png\" alt=\"Tier 1 report for the EvilTokens phishing analysis\" class=\"wp-image-23492\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-TI-report-1024x153.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-TI-report-300x45.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-TI-report-768x115.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-TI-report-370x55.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-TI-report-270x40.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-TI-report-740x111.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/ANY.RUN-TI-report.png 1102w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Tier 1 report for the EvilTokens phishing analysis<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The report gives the next responder the information needed to quickly understand the case, including: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The analysis verdict and relevant threat or campaign tags <\/li>\n\n\n\n<li>An <strong>AI Summary<\/strong> explaining what happened during the session <\/li>\n\n\n\n<li>Key IOCs and technical events that can support blocking or hunting <\/li>\n\n\n\n<li><strong>AI Recommendations<\/strong> with actions the team can consider next <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of translating raw sandbox output into another incident summary by hand, the analyst gets a ready-to-share view of the case. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"680\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/AI-summary-1024x680.png\" alt=\"AI summary generated for EvilTokens attack\" class=\"wp-image-23493\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/AI-summary-1024x680.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/AI-summary-300x199.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/AI-summary-768x510.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/AI-summary-370x246.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/AI-summary-270x179.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/AI-summary-740x491.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/AI-summary.png 1106w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>AI summary generated for EvilTokens attack<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">For Tier 1, that makes it easier to answer the three questions that matter before escalation: <strong>What happened? Why is it malicious? What should happen next?<\/strong> <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"333\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/key-iocs-from-tier-1-report-1024x333.png\" alt=\"Key IOCs that support blocking or hunting the phishing attack\" class=\"wp-image-23494\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/key-iocs-from-tier-1-report-1024x333.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/key-iocs-from-tier-1-report-300x98.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/key-iocs-from-tier-1-report-768x250.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/key-iocs-from-tier-1-report-370x120.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/key-iocs-from-tier-1-report-270x88.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/key-iocs-from-tier-1-report-740x241.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/key-iocs-from-tier-1-report.png 1122w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Key IOCs that support blocking or hunting the phishing attack<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The same context can then be passed to Tier 2, IR, or an MSSP customer without asking them to start from the raw analysis again. <\/p>\n\n\n\n<!-- Highlight Block HTML START -->\n<div class=\"window\">\n  <div class=\"window-header\">\n    <div class=\"pill\">\u261d\ufe0fStep 2  SOC outcomes:<\/div>\n  <\/div>\n  <div class=\"window-body\">\n    <ul>\n      <li>Fewer unnecessary Tier 1 \u2192 Tier 2 escalations<\/li>\n      <li>More senior analyst time preserved for complex incidents<\/li>\n      <li>Clearer handoffs with evidence already packaged<\/li>\n      <li>Shorter path from investigation to containment<\/li>\n    <\/ul>\n  <\/div>\n<\/div>\n<!-- Highlight Block HTML END -->\n\n\n<!-- Highlight Block CSS START -->\n<style>\n  .window {\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n\n    border-radius: 4px;\n    margin: 20px auto 50px auto;\n    padding: 20px 40px;\n    line-height: 2rem;\n  }\n\n  .window-header {\n    display: flex;\n    justify-content: center;\n    margin-bottom: 20px;\n  }\n\n  .pill {\n    background-color: #fff;\n    border-radius: 20px;\n    color: #333;\n    font-weight: bold;\n    padding: 8px 32px;\nborder: 1px solid rgba(75, 174, 227, 0.32);\n  }\n\n  @media (max-width: 480px) {\n    .window {\n      padding: 10px;\n    }\n    \n    .pill {\n      font-size: 14px;\n      padding: 6px 12px;\n    }\n  }\n<\/style>\n<!-- Highlight Block CSS END -->\n\n\n\n<h3 class=\"wp-block-heading\">Step 3: Move to Proactive Defense with Threat Intelligence <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Closing the original phishing alert solves the immediate incident. It does not tell the SOC how far the threat extends. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers rotate domains, IPs, and other infrastructure quickly, which means individual IOCs can lose value fast. Once the threat is confirmed, the next step is to look for patterns that can reveal related activity and support hunting, blocking, and new detections. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the EvilTokens case, the sandbox analysis already gives analysts a useful starting point: the HTTP endpoints used during the device code phishing flow. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example: <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\/api\/device\/start <br>\/api\/device\/status\/ <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These patterns can be taken into <strong>ANY.RUN\u2019s <\/strong><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Threat Intelligence Lookup<\/strong><\/a> to find other analyses where the same behavior appears. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/intelligence.any.run\/analysis\/lookup?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookup#{%22query%22:%22url:%5C%22\/api\/device\/start%5C%22%20and%20url:%5C%22\/api\/device\/status\/%5C%22%22,%22dateRange%22:180}\" target=\"_blank\" rel=\"noreferrer noopener\">View the EvilTokens query in TI Lookup<\/a> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But finding matching analyses is only the first step. The new <strong>Connections<\/strong> view brings the network artifacts from those results together and shows how URLs, domains, IPs, and other indicators relate to one another. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"488\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-connections-1-1024x488.png\" alt=\"Connections view showing related EvilTokens infrastructure inside ANY.RUN\u2019s Threat Intelligence Lookup\" class=\"wp-image-23495\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-connections-1-1024x488.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-connections-1-300x143.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-connections-1-768x366.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-connections-1-1536x732.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-connections-1-370x176.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-connections-1-270x129.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-connections-1-740x353.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/TI-connections-1.png 1842w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Connections view showing related EvilTokens infrastructure inside ANY.RUN\u2019s Threat Intelligence Lookup<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Instead of comparing indicators across separate results one by one, analysts can pivot through the relationships and move from <strong>a single IOC to a testable hypothesis about related infrastructure<\/strong>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is especially useful for retrohunting in SIEM or NDR data and for passing relevant findings to detection engineering. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Connections also help analysts distinguish useful indicators from shared infrastructure. An IP associated with Cloudflare, for example, may appear in a malicious analysis but should not automatically become a blocking candidate. Filters help narrow the view to the relationships that matter and reduce the risk of pushing noisy or widely shared infrastructure into production defenses. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"429\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Threat-landscape-1024x429.png\" alt=\"Wider threat landscape demonstrated inside Threat Intelligence\" class=\"wp-image-23496\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Threat-landscape-1024x429.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Threat-landscape-300x126.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Threat-landscape-768x322.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Threat-landscape-1536x643.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Threat-landscape-370x155.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Threat-landscape-270x113.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Threat-landscape-740x310.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Threat-landscape.png 1843w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Wider threat landscape demonstrated inside Threat Intelligence<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Lookup<\/a> also adds context around the wider threat landscape, including geography and targeted industries, which can support threat hunting, research, and reporting. <\/p>\n\n\n\n<!-- Highlight Block HTML START -->\n<div class=\"window\">\n  <div class=\"window-header\">\n    <div class=\"pill\">\u261d\ufe0fStep 3: SOC outcomes<\/div>\n  <\/div>\n  <div class=\"window-body\">\n    <ul>\n      <li>Each investigation produces intelligence the SOC can reuse<\/li>\n      <li>Faster discovery of related infrastructure and attack activity<\/li>\n      <li>More IOCs available for hunting, blocking, and enrichment<\/li>\n      <li>Broader detection coverage beyond the original incident<\/li>\n    <\/ul>\n  <\/div>\n<\/div>\n<!-- Highlight Block HTML END -->\n\n\n<!-- Highlight Block CSS START -->\n<style>\n  .window {\n    background: rgba(32, 168, 241, 0.1);\n    border: 1px solid rgba(75, 174, 227, 0.32);\n    border-radius: 4px;\n    margin: 20px auto 50px auto;\n    padding: 20px 40px;\n    line-height: 2rem;\n  }\n\n  .window-header {\n    display: flex;\n    justify-content: center;\n    margin-bottom: 20px;\n  }\n\n  .pill {\n    background-color: #fff;\n    border-radius: 20px;\n    color: #333;\n    font-weight: bold;\n    padding: 8px 32px;\n    border: 1px solid rgba(75, 174, 227, 0.32);\n  }\n\n  @media (max-width: 480px) {\n    .window {\n      padding: 10px;\n    }\n\n    .pill {\n      font-size: 14px;\n      padding: 6px 12px;\n    }\n  }\n<\/style>\n<!-- Highlight Block CSS END -->\n\n\n\n<h3 class=\"wp-block-heading\">What One Phishing Investigation Can Deliver with ANY.RUN\u2019s New Capabilities <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Starting with a single phishing URL, the SOC can get much more than a malicious verdict. In this case, the investigation produced: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Complete picture of the attack:<\/strong> The execution chain, decrypted HTTP requests and responses, redirect path, and browser changes observed as the phishing page loaded. <\/li>\n\n\n\n<li><strong>Response-ready Tier 1 report:<\/strong> The verdict, key findings, IOCs, AI-generated summary and recommendations, and the context needed for escalation and response. <\/li>\n\n\n\n<li><strong>Wider view of the threat:<\/strong> Related analyses, infrastructure, and connections that help analysts understand how far the activity extends beyond the original URL. <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Without these capabilities, the same investigation could require separate traffic analysis, browser inspection, threat intelligence research, and incident reporting, with analysts moving findings between each stage themselves. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That difference becomes much more important at scale. When a SOC or CSIRT handles hundreds or thousands of incidents, time spent rebuilding context for every case quickly adds up. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Business Impact of Faster Phishing Response <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Faster phishing response is not only an analyst productivity win. It directly affects SOC capacity, escalation costs, and how long the business stays exposed to a confirmed threat. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN customers have reported <strong>20% less Tier 1 investigation time, 30% fewer Tier 1-to-Tier 2 escalations, and 21 minutes cut from MTTR<\/strong>. For security leaders, that means more cases handled by the existing team, less senior analyst time spent on routine work, and faster containment when an attack is real. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With updates such as SSL Decryption and In-Browser Data Inspection, Tier 1 reports with AI insights, and Connections in TI Lookup, it becomes easier to carry the same investigation from triage to response and proactive defense without adding more manual steps. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Bring faster phishing response into your SOC.\n\n<\/span> \n<br>\nGive your team the visibility and context they need to act sooner.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\n Build a Faster SOC Workflow<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a> provides interactive malware analysis and threat intelligence solutions used by 700,000+ cybersecurity professionals across 16,000+ organizations worldwide, including 64% of the Fortune 500. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a> helps SOC teams safely investigate suspicious files, URLs, phishing pages, and malware while watching the attack unfold in real time. Analysts can inspect browser activity, decrypted network traffic, processes, redirects, and other behavior to validate threats faster and collect evidence for response. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN\u2019s <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Lookup<\/a> turns data from real-world sandbox investigations into context for threat hunting, detection, and incident response. Analysts can pivot from individual indicators to related infrastructure and activity, while <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=phishing-response-protocol&amp;utm_term=300926&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Feeds<\/a> continuously deliver newly observed IOCs into existing security systems. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident. Every manual step adds time to the response. It also ties up analyst capacity [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":23510,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4],"tags":[57,10],"class_list":["post-23490","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-lifehacks","tag-anyrun","tag-cybersecurity"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>3-Step Phishing Response with ANY.RUN\u2019s New Product Updates<\/title>\n<meta name=\"description\" content=\"See how ANY.RUN\u2019s latest product updates help SOC teams investigate phishing, improve escalation, and turn confirmed incidents into proactive defense.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ANY.RUN\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/\"},\"author\":{\"name\":\"ANY.RUN\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN&#8217;s Latest Updates\",\"datePublished\":\"2026-09-30T09:51:07+00:00\",\"dateModified\":\"2026-09-30T11:22:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/\"},\"wordCount\":2059,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Phishing-Response-Protocol-3-Essential-Steps-from-Detection-to-Proactive-Defense-for-Every-SOC-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\"],\"articleSection\":[\"Cybersecurity Lifehacks\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/\",\"name\":\"3-Step Phishing Response with ANY.RUN\u2019s New Product Updates\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Phishing-Response-Protocol-3-Essential-Steps-from-Detection-to-Proactive-Defense-for-Every-SOC-scaled.png\",\"datePublished\":\"2026-09-30T09:51:07+00:00\",\"dateModified\":\"2026-09-30T11:22:31+00:00\",\"description\":\"See how ANY.RUN\u2019s latest product updates help SOC teams investigate phishing, improve escalation, and turn confirmed incidents into proactive defense.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Phishing-Response-Protocol-3-Essential-Steps-from-Detection-to-Proactive-Defense-for-Every-SOC-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Phishing-Response-Protocol-3-Essential-Steps-from-Detection-to-Proactive-Defense-for-Every-SOC-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"Phishing Response Protocol- 3 Essential Steps\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/phishing-response-protocol\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity Lifehacks\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/lifehacks\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN&#8217;s Latest Updates\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"caption\":\"ANY.RUN\"},\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/author\\\/a-bespalova\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"3-Step Phishing Response with ANY.RUN\u2019s New Product Updates","description":"See how ANY.RUN\u2019s latest product updates help SOC teams investigate phishing, improve escalation, and turn confirmed incidents into proactive defense.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/","twitter_misc":{"Written by":"ANY.RUN","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/"},"author":{"name":"ANY.RUN","@id":"https:\/\/any.run\/"},"headline":"Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN&#8217;s Latest Updates","datePublished":"2026-09-30T09:51:07+00:00","dateModified":"2026-09-30T11:22:31+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/"},"wordCount":2059,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Phishing-Response-Protocol-3-Essential-Steps-from-Detection-to-Proactive-Defense-for-Every-SOC-scaled.png","keywords":["ANYRUN","cybersecurity"],"articleSection":["Cybersecurity Lifehacks"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/","url":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/","name":"3-Step Phishing Response with ANY.RUN\u2019s New Product Updates","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Phishing-Response-Protocol-3-Essential-Steps-from-Detection-to-Proactive-Defense-for-Every-SOC-scaled.png","datePublished":"2026-09-30T09:51:07+00:00","dateModified":"2026-09-30T11:22:31+00:00","description":"See how ANY.RUN\u2019s latest product updates help SOC teams investigate phishing, improve escalation, and turn confirmed incidents into proactive defense.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Phishing-Response-Protocol-3-Essential-Steps-from-Detection-to-Proactive-Defense-for-Every-SOC-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/Phishing-Response-Protocol-3-Essential-Steps-from-Detection-to-Proactive-Defense-for-Every-SOC-scaled.png","width":2560,"height":1243,"caption":"Phishing Response Protocol- 3 Essential Steps"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/phishing-response-protocol\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity Lifehacks","item":"https:\/\/any.run\/cybersecurity-blog\/category\/lifehacks\/"},{"@type":"ListItem","position":3,"name":"Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN&#8217;s Latest Updates"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"ANY.RUN","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","caption":"ANY.RUN"},"url":"https:\/\/any.run\/cybersecurity-blog\/author\/a-bespalova\/"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23490","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=23490"}],"version-history":[{"count":25,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23490\/revisions"}],"predecessor-version":[{"id":23541,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23490\/revisions\/23541"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/23510"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=23490"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=23490"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=23490"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}