VYPR
researchPublished Sep 30, 2026· 1 source

ANY.RUN Enhances Sandbox for Faster Phishing Investigation

ANY.RUN has upgraded its sandbox capabilities with deeper network and browser visibility, automated reporting, and threat intelligence correlation to accelerate the investigation of sophisticated phishing threats.

Investigating phishing alerts is a complex, multi-layered process for Security Operations Center (SOC) teams. Modern phishing campaigns often employ advanced techniques such as encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, making it difficult for analysts to reconstruct the attack chain and determine its true nature. The investigation doesn't end with a verdict; it extends to evidence collection, documentation, escalation, and identifying similar patterns in other attacks. Recognizing these challenges, ANY.RUN has introduced significant enhancements to its sandbox environment designed to streamline the workflow from detection to response and threat hunting.

The scale and sophistication of phishing attacks continue to pose a significant challenge. ANY.RUN's H1 2026 Cyber Risk Report highlights the prevalence of phishing, affecting 73.4% of investigations in the financial sector and 72.2% in manufacturing. Furthermore, Microsoft Incident Response data indicates that 28% of investigated breaches originate from phishing or social engineering tactics, including newer methods like device-code phishing. The financial repercussions are substantial, with the FBI reporting over 191,000 phishing complaints in 2025 and Business Email Compromise (BEC) schemes causing billions in losses. This confluence of high alert volume and intricate attack vectors necessitates tools that can reduce manual effort without compromising analytical depth.

ANY.RUN's latest updates focus on providing deeper network and browser visibility, integrating automated reporting, and correlating threat intelligence. These features aim to reduce the manual work involved in analyzing complex attack chains, such as the EvilTokens platform, which exploits Microsoft's device-code authentication flow to steal session tokens. The goal is to empower SOC analysts to move more efficiently from initial alert triage to actionable response and proactive threat hunting, with a reported 94% of users experiencing faster threat triage.

A practical example of these enhancements in action involves a phishing campaign utilizing a multi-stage attack chain: Cloudflare CAPTCHA, followed by a phishing document lure, and culminating in device-code phishing. This specific campaign leverages EvilTokens, a phishing-as-a-service platform that abuses legitimate Microsoft authentication flows. Such techniques create significant hurdles for SOC analysts, as they can involve CAPTCHA gates, redirects, the use of legitimate cloud services, and dynamically generated phishing pages, obscuring the true malicious activity from initial observation.

ANY.RUN's sandbox allows investigators to follow the complete execution chain of such attacks. The first step in strengthening phishing defense involves accelerating triage through enhanced network and browser visibility. When a suspicious URL is analyzed in ANY.RUN's Interactive Sandbox, the Network section captures all web requests, including encrypted HTTPS traffic. The platform's SSL Decryption capability, which extracts encryption keys directly from process memory, allows for inspection of HTTPS traffic without the need for a separate Man-in-the-Middle (MITM) proxy.

Complementing network visibility, the In-Browser Data Inspection feature provides a granular view of browser activity. This includes DOM changes, HTTP requests, screenshots, and redirects, offering a comprehensive understanding of how the browser navigates the phishing flow and what modifications occur on the malicious page. By combining network and in-browser data, analysts gain a holistic view, reducing the reliance on manually piecing together disparate data sources like PCAP files, web logs, and redirect chains. This integrated approach enables Tier 1 analysts to validate suspicious URLs more rapidly and make informed decisions about case escalation.

ANY.RUN's platform aims to provide a complete picture of the attack, from initial access to the final objective. By offering deep visibility into both network communications and in-browser actions, it significantly reduces the time and manual effort required for investigation. This allows SOC teams to not only respond more effectively to individual phishing incidents but also to pivot more quickly to threat intelligence gathering, identifying related infrastructure and attacker tactics, techniques, and procedures (TTPs).

The enhancements to ANY.RUN's sandbox are designed to address the evolving landscape of phishing attacks. By providing deeper insights and automating key analytical processes, the platform empowers security teams to combat sophisticated threats more efficiently, ultimately reducing their exposure and improving their overall security posture. With 95% of SOC teams reporting faster threat investigations using ANY.RUN, these updates represent a significant step forward in phishing defense.

Synthesized by Vypr AI