{"id":23628,"date":"2026-10-08T07:46:28","date_gmt":"2026-10-08T07:46:28","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=23628"},"modified":"2026-10-08T07:48:40","modified_gmt":"2026-10-08T07:48:40","slug":"ti-feeds-elastic-webinar","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/","title":{"rendered":"Making Threat Intelligence Work for SOC Teams: ANY.RUN &amp; Elastic Webinar Insights"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Threat intelligence on its own is only data. Its value depends on how effectively SOC teams can turn it into action. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Simply put, this was the premise of our recent webinar. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/any.run\/cybersecurity-blog\/threat-intelligence-for-soc\/\" target=\"_blank\" rel=\"noopener\">SOC and business impact<\/a> of threat intelligence depends largely on how quickly analysts can use it to validate threats, make confident decisions, and take action. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Exploring how to make that happen was the focus of <a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noopener\">ANY.RUN<\/a>&#8216;s recent joint webinar with Elastic, \u201cTurn Threat Intelligence Into SOC Action with ANY.RUN and Elastic Security.\u201d <\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/anyrun.webinargeek.com\/turn-threat-intelligence-into-soc-action-with-any-run-and-elastic-security?cst=blog\" target=\"_blank\" rel=\"noopener\">Watch the full webinar<\/a><\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How It Went <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">ANY.RUN CTO Dmitry Marinov and Elastic Principal Solutions Architect Tammy Torbert came together for a live discussion on making threat intelligence work in <a href=\"https:\/\/any.run\/cybersecurity-blog\/soc-maturity-with-threat-intelligence\/\" target=\"_blank\" rel=\"noopener\">daily SOC operations<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And we didn\u2019t stop at theory. The webinar included interactive tasks for the audience, a live demo of the <a href=\"https:\/\/any.run\/cybersecurity-blog\/any-run-elastic-security-integration\/\" target=\"_blank\" rel=\"noopener\">ANY.RUN Threat Intelligence and Elastic Security integration<\/a>, and a Q&amp;A session that gave us a chance to dive into even more practical questions from our viewers. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A big thank you to the Elastic team for making this session happen, and to everyone who joined us, took part, and brought great questions to the discussion! <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Executive Takeaways <\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.53-1024x576.png\" alt=\"\" class=\"wp-image-23629\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.53-1024x576.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.53-300x169.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.53-768x432.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.53-1536x864.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.53-370x208.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.53-270x152.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.53-740x416.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.53.png 1610w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Three key requirements for threat intelligence, as discussed by ANY.RUN and Elastic<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">So, what actually makes threat intelligence useful in daily SOC work? During our discussion, we narrowed it to three things:  <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Threat Intelligence Has to Stay Relevant <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Threat infrastructure changes quickly, and indicators can lose relevance just as fast. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Solution: <\/strong>ANY.RUN <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noopener\">Threat Intelligence Feeds<\/a> deliver continuously validated, high-confidence IOCs from real-world investigations by more than 16,000 SOC teams and 700,000 security professionals. This helps SOC teams keep detection workflows aligned with active threats. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Outcome: <\/strong><a href=\"https:\/\/any.run\/cybersecurity-blog\/streamline-your-soc\/\" target=\"_blank\" rel=\"noopener\">Earlier identification<\/a> of known malicious activity, less manual IOC validation, and more analyst time for complex investigations. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Context Helps Analysts Make Better Decisions <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An IOC match can validate suspicious activity, but analysts still need to understand what happened and <a href=\"https:\/\/any.run\/cybersecurity-blog\/efficient-soc-for-fast-response\/\" target=\"_blank\" rel=\"noopener\">how urgently they should respond<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Solution: <\/strong>ANY.RUN Threat Intelligence connects IOC matches to behavioral evidence from <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noopener\">Sandbox<\/a> analyses, helping analysts assess threat severity without relying on indicator matches alone. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Outcome: <\/strong>Faster, more confident triage, better prioritization of high-risk incidents, and fewer unnecessary escalations. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. TI Works Better Inside Existing SOC Workflows <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Manual IOC lookups, switching between systems, and moving data between sources all add time to investigations. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Solution:<\/strong> Integrating ANY.RUN TI Feeds with Elastic Security brings fresh IOCs into alert correlation, prioritization, and detection workflows without requiring analysts to switch between systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Outcome: <\/strong><a href=\"https:\/\/any.run\/cybersecurity-blog\/threat-intelligence-feeds-for-better-soc-performance\/\" target=\"_blank\" rel=\"noopener\">Faster validation<\/a> of suspicious activity, fewer manual investigation steps, and more analyst capacity for complex cases. <\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/any.run\/integrations\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktointegrations\" target=\"_blank\" rel=\"noopener\">Explore all ANY.RUN integrations <\/a><\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Putting It Into Practice: ANY.RUN Threat Intelligence and Elastic Security <\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.31-1-1024x573.png\" alt=\"\" class=\"wp-image-23631\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.31-1-1024x573.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.31-1-300x168.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.31-1-768x430.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.31-1-1536x860.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.31-1-370x207.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.31-1-270x151.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.31-1-740x414.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Screenshot-2026-10-07-at-15.03.31-1.png 1700w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN\u2019s TI Feeds integration brings real-world threat intelligence to existing SOC workflows<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The Threat Intelligence Feeds integration with Elastic Security brings fresh, high-confidence indicators directly into existing Elastic workflows. This helps teams: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Identify known threats earlier<\/strong> by correlating Elastic security events with fresh ANY.RUN IOCs to surface malicious activity for investigation. <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/any.run\/cybersecurity-blog\/threat-intelligence-feeds-in-incident-response\/\" target=\"_blank\" rel=\"noopener\"><strong>Respond more confidently<\/strong><\/a><strong> <\/strong>by prioritizing alerts based on IOC matches and threat context to guide triage decisions.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Reduce manual investigation steps<\/strong> by accessing ANY.RUN indicators directly in Elastic for IOC validation, threat searches, and investigation workflows. <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Validate suspicious activity <\/strong>with behavioral evidence by pivoting from Elastic to related ANY.RUN Sandbox analyses when an IOC match requires deeper investigation. <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The result is faster investigation of known threats, less context switching, and more analyst time for cases that require deeper analysis. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\nUp to <span class=\"highlight\">58% more threats identified<\/span> with TI Feeds.<br>\nSee how ANY.RUN can support your SOC.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktotifeeds#contact-sales\" rel=\"noopener\" target=\"_blank\">\nTalk to ANY.RUN Experts <\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Beyond Threat Intelligence Feeds: Supporting the Investigation Lifecycle <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">TI Feeds are just one part of how ANY.RUN supports daily SOC workflows. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For broader threat intelligence needs, <a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noopener\">Threat Intelligence Lookup &amp; YARA Search<\/a> help analysts investigate IOCs, uncover related threats, and hunt for malware, accelerating alert enrichment and threat hunting. <a href=\"https:\/\/intelligence.any.run\/reports?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktotireports\" target=\"_blank\" rel=\"noopener\">TI Reports<\/a> provide curated intelligence on emerging threats to help teams track emerging threats and adjust investigation priorities. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/moresolutionsfromanyrun-1-1024x573.png\" alt=\"\" class=\"wp-image-23633\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/moresolutionsfromanyrun-1-1024x573.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/moresolutionsfromanyrun-1-300x168.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/moresolutionsfromanyrun-1-768x430.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/moresolutionsfromanyrun-1-1536x860.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/moresolutionsfromanyrun-1-370x207.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/moresolutionsfromanyrun-1-270x151.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/moresolutionsfromanyrun-1-740x414.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/moresolutionsfromanyrun-1.png 1700w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>With TI and malware analysis solutions, ANY.RUN supports SOC and MSSP teams across workflows<\/em> <\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">When an alert requires deeper investigation, the <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noopener\">Interactive Sandbox<\/a> provides real-time visibility into threat behavior across Windows, Linux, Android, and macOS environments. API access, integrations, and Automated Interactivity help streamline repetitive analysis tasks, while team collaboration supports consistent investigation workflows across the SOC. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Together, these solutions support the investigation process from early threat detection and enrichment to in-depth behavioral analysis. <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\nReduce threat exposure with a <span class=\"highlight\">14-second MTTD<\/span>.<br>\nExplore how ANY.RUN can improve your SOC performance.&nbsp;\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=ti-feeds-elastic-webinar&#038;utm_term=81026&#038;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nContact us <\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Business Impact for SOC Leaders <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">By bringing fresh intelligence, behavioral context, and malware analysis into existing workflows, SOC teams can: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Reduce investigation costs <\/strong>through faster triage and fewer unnecessary escalations. <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Improve SOC efficiency <\/strong>by reducing manual work and freeing up analysts for higher-priority cases. <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Lower business risk exposure<\/strong> through earlier threat detection and faster, more informed response decisions. <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The result is a more efficient SOC that can handle growing threats with existing resources. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noopener\">ANY.RUN<\/a> provides malware analysis and threat intelligence solutions used by 700,000+ cybersecurity professionals across 16,000+ organizations, including 74 of theFortune 100. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noopener\">Interactive Sandbox<\/a> helps SOC teams safely investigate suspicious files, URLs, phishing, and malware with real-time visibility into threat behavior. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noopener\">Threat Intelligence Lookup<\/a> provides context from real-world investigations for threat hunting, detection, and response, while <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noopener\">Threat Intelligence Feeds<\/a> deliver fresh IOCs directly into existing security workflows. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ <\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1791444559016\"><strong class=\"schema-faq-question\">Can I watch the full ANY.RUN and Elastic webinar? <\/strong> <p class=\"schema-faq-answer\">Yes, the recording is <a href=\"https:\/\/anyrun.webinargeek.com\/turn-threat-intelligence-into-soc-action-with-any-run-and-elastic-security?cst=blog\" target=\"_blank\" rel=\"noopener\">available on demand<\/a>. <\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1791444564585\"><strong class=\"schema-faq-question\">How can I integrate ANY.RUN Threat Intelligence Feeds with Elastic Security? <\/strong> <p class=\"schema-faq-answer\">You need an active ANY.RUN plan with access to TI Feeds. If you don\u2019t have one yet, <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktotifeedslanding#contact-sales\" target=\"_blank\" rel=\"noopener\">contact us<\/a> to get started. If you already have access, visit our <a href=\"https:\/\/any.run\/integrations\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktointegrations\" target=\"_blank\" rel=\"noopener\">Integrations<\/a> page for setup instructions. <\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1791444574134\"><strong class=\"schema-faq-question\">What can I do with ANY.RUN Threat Intelligence in Elastic Security? <\/strong> <p class=\"schema-faq-answer\">Teams can use ANY.RUN indicators for IOC correlation, alert prioritization, detection, search, filtering, and dashboards. Analysts can also access related Sandbox analyses when deeper threat context is needed. <\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1791444584736\"><strong class=\"schema-faq-question\">Where can I see all ANY.RUN integrations? <\/strong> <p class=\"schema-faq-answer\">Visit the ANY.RUN <a href=\"https:\/\/any.run\/integrations\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktointegrations\" target=\"_blank\" rel=\"noopener\">Integrations<\/a> page to explore available integrations for the Interactive Sandbox and Threat Intelligence solutions, including Elastic Security, Microsoft Sentinel, Splunk SOAR, and others. <\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1791444591244\"><strong class=\"schema-faq-question\">What is the difference between TI Feeds and TI Lookup? <\/strong> <p class=\"schema-faq-answer\">TI Feeds continuously deliver fresh, high-confidence IOCs into your existing security systems. TI Lookup lets analysts search and investigate indicators, uncover relationships, and access additional threat context on demand. <\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1791444599566\"><strong class=\"schema-faq-question\">How does ANY.RUN generate threat intelligence? <\/strong> <p class=\"schema-faq-answer\">ANY.RUN Threat Intelligence is built from real-world malware and phishing investigations conducted by more than 16,000 SOC teams and 700,000 security professionals. Indicators are validated and filtered before being delivered through TI Feeds. <\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1791444604617\"><strong class=\"schema-faq-question\">When should I use the Interactive Sandbox? <\/strong> <p class=\"schema-faq-answer\">Use the Interactive Sandbox when a case requires deeper behavioral analysis, additional evidence, or investigation of an unknown threat. Analysts can safely observe malicious activity in real time across Windows, Linux, Android, and macOS environments. <\/p> <\/div> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>Threat intelligence on its own is only data. Its value depends on how effectively SOC teams can turn it into action. Simply put, this was the premise of our recent webinar. The SOC and business impact of threat intelligence depends largely on how quickly analysts can use it to validate threats, make confident decisions, and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":23636,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[81],"tags":[57,10,78],"class_list":["post-23628","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-integrations-connectors","tag-anyrun","tag-cybersecurity","tag-threat-intelligence"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>From\u00a0Threat Intelligence\u00a0to\u00a0SOC Action | ANY.RUN &amp; Elastic\u00a0<\/title>\n<meta name=\"description\" content=\"Explore key insights from ANY.RUN and Elastic on making threat intelligence actionable across daily SOC workflows.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ANY.RUN\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/\"},\"author\":{\"name\":\"ANY.RUN\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"Making Threat Intelligence Work for SOC Teams: ANY.RUN &amp; Elastic Webinar Insights\",\"datePublished\":\"2026-10-08T07:46:28+00:00\",\"dateModified\":\"2026-10-08T07:48:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/\"},\"wordCount\":1183,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Webinar-w-Elastic-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\",\"threat intelligence\"],\"articleSection\":[\"Integrations &amp; connectors\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#respond\"]}]},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/\",\"name\":\"From\u00a0Threat Intelligence\u00a0to\u00a0SOC Action | ANY.RUN & Elastic\u00a0\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Webinar-w-Elastic-scaled.png\",\"datePublished\":\"2026-10-08T07:46:28+00:00\",\"dateModified\":\"2026-10-08T07:48:40+00:00\",\"description\":\"Explore key insights from ANY.RUN and Elastic on making threat intelligence actionable across daily SOC workflows.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444559016\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444564585\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444574134\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444584736\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444591244\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444599566\"},{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444604617\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Webinar-w-Elastic-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Webinar-w-Elastic-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"ANY.RUN Elastic webinar\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Integrations &amp; connectors\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/integrations-connectors\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Making Threat Intelligence Work for SOC Teams: ANY.RUN &amp; Elastic Webinar Insights\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"caption\":\"ANY.RUN\"},\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/author\\\/a-bespalova\\\/\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444559016\",\"position\":1,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444559016\",\"name\":\"Can I watch the full ANY.RUN and Elastic webinar?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes, the recording is <a href=\\\"https:\\\/\\\/anyrun.webinargeek.com\\\/turn-threat-intelligence-into-soc-action-with-any-run-and-elastic-security?cst=blog\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">available on demand<\\\/a>. \",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444564585\",\"position\":2,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444564585\",\"name\":\"How can I integrate ANY.RUN Threat Intelligence Feeds with Elastic Security?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"You need an active ANY.RUN plan with access to TI Feeds. If you don\u2019t have one yet, <a href=\\\"https:\\\/\\\/any.run\\\/threat-intelligence-feeds\\\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktotifeedslanding#contact-sales\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">contact us<\\\/a> to get started. If you already have access, visit our <a href=\\\"https:\\\/\\\/any.run\\\/integrations\\\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktointegrations\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">Integrations<\\\/a> page for setup instructions. \",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444574134\",\"position\":3,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444574134\",\"name\":\"What can I do with ANY.RUN Threat Intelligence in Elastic Security?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Teams can use ANY.RUN indicators for IOC correlation, alert prioritization, detection, search, filtering, and dashboards. Analysts can also access related Sandbox analyses when deeper threat context is needed. \",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444584736\",\"position\":4,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444584736\",\"name\":\"Where can I see all ANY.RUN integrations?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Visit the ANY.RUN <a href=\\\"https:\\\/\\\/any.run\\\/integrations\\\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktointegrations\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">Integrations<\\\/a> page to explore available integrations for the Interactive Sandbox and Threat Intelligence solutions, including Elastic Security, Microsoft Sentinel, Splunk SOAR, and others. \",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444591244\",\"position\":5,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444591244\",\"name\":\"What is the difference between TI Feeds and TI Lookup?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"TI Feeds continuously deliver fresh, high-confidence IOCs into your existing security systems. TI Lookup lets analysts search and investigate indicators, uncover relationships, and access additional threat context on demand. \",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444599566\",\"position\":6,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444599566\",\"name\":\"How does ANY.RUN generate threat intelligence?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"ANY.RUN Threat Intelligence is built from real-world malware and phishing investigations conducted by more than 16,000 SOC teams and 700,000 security professionals. Indicators are validated and filtered before being delivered through TI Feeds. \",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444604617\",\"position\":7,\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/ti-feeds-elastic-webinar\\\/#faq-question-1791444604617\",\"name\":\"When should I use the Interactive Sandbox?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Use the Interactive Sandbox when a case requires deeper behavioral analysis, additional evidence, or investigation of an unknown threat. Analysts can safely observe malicious activity in real time across Windows, Linux, Android, and macOS environments. \",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"From\u00a0Threat Intelligence\u00a0to\u00a0SOC Action | ANY.RUN & Elastic\u00a0","description":"Explore key insights from ANY.RUN and Elastic on making threat intelligence actionable across daily SOC workflows.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/","twitter_misc":{"Written by":"ANY.RUN","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/"},"author":{"name":"ANY.RUN","@id":"https:\/\/any.run\/"},"headline":"Making Threat Intelligence Work for SOC Teams: ANY.RUN &amp; Elastic Webinar Insights","datePublished":"2026-10-08T07:46:28+00:00","dateModified":"2026-10-08T07:48:40+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/"},"wordCount":1183,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Webinar-w-Elastic-scaled.png","keywords":["ANYRUN","cybersecurity","threat intelligence"],"articleSection":["Integrations &amp; connectors"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#respond"]}]},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/","url":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/","name":"From\u00a0Threat Intelligence\u00a0to\u00a0SOC Action | ANY.RUN & Elastic\u00a0","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Webinar-w-Elastic-scaled.png","datePublished":"2026-10-08T07:46:28+00:00","dateModified":"2026-10-08T07:48:40+00:00","description":"Explore key insights from ANY.RUN and Elastic on making threat intelligence actionable across daily SOC workflows.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444559016"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444564585"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444574134"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444584736"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444591244"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444599566"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444604617"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Webinar-w-Elastic-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/10\/Webinar-w-Elastic-scaled.png","width":2560,"height":1243,"caption":"ANY.RUN Elastic webinar"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Integrations &amp; connectors","item":"https:\/\/any.run\/cybersecurity-blog\/category\/integrations-connectors\/"},{"@type":"ListItem","position":3,"name":"Making Threat Intelligence Work for SOC Teams: ANY.RUN &amp; Elastic Webinar Insights"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"ANY.RUN","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","caption":"ANY.RUN"},"url":"https:\/\/any.run\/cybersecurity-blog\/author\/a-bespalova\/"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444559016","position":1,"url":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444559016","name":"Can I watch the full ANY.RUN and Elastic webinar?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes, the recording is <a href=\"https:\/\/anyrun.webinargeek.com\/turn-threat-intelligence-into-soc-action-with-any-run-and-elastic-security?cst=blog\" target=\"_blank\" rel=\"noopener\">available on demand<\/a>. ","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444564585","position":2,"url":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444564585","name":"How can I integrate ANY.RUN Threat Intelligence Feeds with Elastic Security?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"You need an active ANY.RUN plan with access to TI Feeds. If you don\u2019t have one yet, <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktotifeedslanding#contact-sales\" target=\"_blank\" rel=\"noopener\">contact us<\/a> to get started. If you already have access, visit our <a href=\"https:\/\/any.run\/integrations\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktointegrations\" target=\"_blank\" rel=\"noopener\">Integrations<\/a> page for setup instructions. ","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444574134","position":3,"url":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444574134","name":"What can I do with ANY.RUN Threat Intelligence in Elastic Security?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Teams can use ANY.RUN indicators for IOC correlation, alert prioritization, detection, search, filtering, and dashboards. Analysts can also access related Sandbox analyses when deeper threat context is needed. ","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444584736","position":4,"url":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444584736","name":"Where can I see all ANY.RUN integrations?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Visit the ANY.RUN <a href=\"https:\/\/any.run\/integrations\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=ti-feeds-elastic-webinar&amp;utm_term=81026&amp;utm_content=linktointegrations\" target=\"_blank\" rel=\"noopener\">Integrations<\/a> page to explore available integrations for the Interactive Sandbox and Threat Intelligence solutions, including Elastic Security, Microsoft Sentinel, Splunk SOAR, and others. ","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444591244","position":5,"url":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444591244","name":"What is the difference between TI Feeds and TI Lookup?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"TI Feeds continuously deliver fresh, high-confidence IOCs into your existing security systems. TI Lookup lets analysts search and investigate indicators, uncover relationships, and access additional threat context on demand. ","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444599566","position":6,"url":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444599566","name":"How does ANY.RUN generate threat intelligence?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"ANY.RUN Threat Intelligence is built from real-world malware and phishing investigations conducted by more than 16,000 SOC teams and 700,000 security professionals. Indicators are validated and filtered before being delivered through TI Feeds. ","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444604617","position":7,"url":"https:\/\/any.run\/cybersecurity-blog\/ti-feeds-elastic-webinar\/#faq-question-1791444604617","name":"When should I use the Interactive Sandbox?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Use the Interactive Sandbox when a case requires deeper behavioral analysis, additional evidence, or investigation of an unknown threat. Analysts can safely observe malicious activity in real time across Windows, Linux, Android, and macOS environments. ","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=23628"}],"version-history":[{"count":6,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23628\/revisions"}],"predecessor-version":[{"id":23643,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23628\/revisions\/23643"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/23636"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=23628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=23628"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=23628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}