ANY.RUN Enhances SOC Efficiency with Threat Intelligence Lookup Tool
ANY.RUN's new Threat Intelligence Lookup (TI Lookup) aims to reduce Security Operations Center (SOC) triage time and analyst burnout by providing contextualized threat intelligence.

Security Operations Centers (SOCs) are constantly battling alert fatigue and analyst burnout, often exacerbated by the time-consuming process of investigating Indicators of Compromise (IOCs). A single suspicious IP address, domain, or file hash can initiate an investigation, but understanding the full context—such as associated threats, malware, infrastructure, and attack techniques—requires sifting through multiple disparate sources. This fragmented approach significantly slows down triage and threat hunting.
To address these challenges, ANY.RUN has introduced its Threat Intelligence Lookup (TI Lookup) tool. This feature aims to streamline SOC workflows by consolidating critical threat context. TI Lookup connects individual IOCs with related threats, infrastructure, malware behavior, and MITRE ATT&CK techniques, providing analysts with a more comprehensive understanding of potential security incidents.
The core innovation lies in integrating interactive sandbox data with threat intelligence. While a simple reputation check might flag an IOC as malicious, an interactive sandbox investigation reveals how that indicator behaves in practice. ANY.RUN's sandbox data provides details on processes, network connections, file drops, and registry changes, offering behavioral context that is crucial for understanding broader attack patterns. This allows analysts to not only identify threats but also to trace their activities and understand their modus operandi.
ANY.RUN's TI Lookup allows analysts to search using over 30 parameter types, including hashes, IP addresses, domains, URLs, process information, registry data, and TTPs. This versatility supports both alert investigation and proactive threat hunting. For instance, an analyst can start with an IOC from a SIEM alert and trace related activity, or a threat hunter can begin with a specific behavior or technique to discover associated threats, even when attackers change their infrastructure.
The tool draws upon a vast dataset, with contributions from over 16,000 SOCs and 700,000 analysts through public analyses and shared anonymized threat data. This collective intelligence enriches the platform, providing analysts with real-world examples of how threats behave and interact with indicators.
Furthermore, TI Lookup can be augmented by ANY.RUN's TI Feeds and TI Reports. TI Feeds deliver continuously updated lists of malicious IPs, domains, and URLs enriched with sandbox context, helping identify emerging threats. TI Reports offer expert-curated research on recent threats, providing broader context around malware, campaigns, and APT activity. Together, these components create a robust ecosystem for threat intelligence consumption.
By consolidating IOC context, behavioral data, and curated research, ANY.RUN's TI Lookup significantly reduces the time and effort required for alert triage and threat investigation. This not only improves the efficiency of SOC teams but also helps mitigate the pervasive issue of analyst burnout by making their work more manageable and impactful.
The platform's ability to link isolated indicators to actionable intelligence shortens the path from detection to understanding, enabling faster response times and more effective security postures against evolving cyber threats.