German Manufacturer Boosts Security Efficiency with Cloud Sandbox
A German manufacturer significantly reduced security alert response times by replacing an air-gapped forensic laptop with ANY.RUN's cloud-managed Interactive Sandbox, improving efficiency for its five-person security team protecting 10,000 endpoints.

A five-person security team at an unnamed German manufacturer has cut a reported 15 minutes from each alert investigation after replacing an air-gapped forensic laptop with ANY.RUN’s cloud-managed Interactive Sandbox. The team protects approximately 10,000 endpoints and 10,000 users across office systems and servers, illustrating how smaller security operations centers can scale enterprise malware and phishing triage without immediately adding specialist headcount. The deployment comes as manufacturing security teams contend with unusually heavy operational pressure, with workloads in the sector reportedly 22% higher than in other major industries.
Before the change, extended detection and response (XDR) alerts could identify suspicious activity but did not always provide enough behavioral context to determine whether a file or URL was genuinely malicious. Analysts relied on an offline Ubuntu laptop, a virtualized FLARE VM, and the SANS forensic toolkit. Retrieving the device, booting it, entering encryption keys, and preparing the virtual machine consumed five to 10 minutes before investigation even began. The air gap also complicated evidence transfer, with analysts moving samples by USB and sometimes having to enter complex URLs manually. Crucially, only one analyst could use the laptop at headquarters at any time, and remote work, which comprised roughly 25% of its schedule, removed access altogether.
The friction forced selective triage: uncertain detections were often treated as true positives, prompting endpoint isolation, wiping, and cloud reinstallation even when deeper analysis might have cleared the alert. This led to wasted resources and potential disruption for legitimate activities. The manufacturer moved file and URL analysis into ANY.RUN’s private, cloud-managed sandbox, giving office and remote analysts access to the same isolated workspace.
Instead of preparing physical hardware, an analyst can now submit a suspicious file or paste a link, interact with the live virtual machine, and inspect processes, network connections, system changes, indicators, and triggered detection rules. ANY.RUN describes the platform as supporting real-time interaction, including typing, scrolling, clipboard access, and file transfer, while keeping analyses private under eligible plans. For daily triage, the team uses the platform’s visual verdict and process tree to make containment decisions, and downloads reports for audit and compliance review, preserving the reasoning behind actions months after an incident.
Philipp Z., the manufacturer’s security lead, stated that eliminating laptop retrieval and VM preparation saves a median of 15 minutes per alert, separate from additional analysis-time reductions. The team now processes 20 to 40 tasks daily and targets 2.5 minutes from a dangerous alert to the isolation of the affected device. They also track agreement between analyst decisions and the sandbox’s true-positive or false-positive classification, reporting a 95% agreement rate.
One investigation highlighted the value of behavioral context. XDR detected a suspicious Windows shortcut file executing on an endpoint, which the team immediately isolated. Historical activity linked the file to a web download and then to an email carrying an apparently harmless PDF. Inside the document, a link led to a password-protected ZIP archive; the password appeared only as text in the PDF, preventing email filters and static antivirus tools from inspecting the encrypted payload. Detonating the chain in ANY.RUN reproduced the sequence from Outlook to Microsoft Edge and finally malware execution. Matching that process tree with endpoint telemetry gave investigators the context needed to identify the originating message, search other mailboxes, and remove it organization-wide.
The operational benefit extends beyond faster verdicts. Removing repetitive setup work lets analysts examine more suspicious artifacts rather than choosing only a small subset, while interactive execution turns triage into an investigative task instead of a hardware-management routine. Philipp described burnout prevention as a priority and called the transition from a manually operated laptop to distributed, repeatable analysis a major improvement in security maturity. For management, the clearest return is analyst time reclaimed per incident and the ability of five specialists to support an enterprise-scale footprint.
ANY.RUN states its services are used by more than 16,000 organizations and 74% of Fortune 100 companies. Its enterprise controls include SSO, MFA, role-based access, SOC 2 Type II attestation, and encrypted client-data handling. Organizations seeking private deployment features, integrations, and commercial terms can contact ANY.RUN enterprise sales.