Skip to content

Executive Summary

Phishing investigations create pressure on Security Operations Center (SOC) teams by requiring analysts to uncover hidden activity, make decisions with incomplete evidence, prepare escalations, and determine the scope of threats. Manual steps in the response process consume analyst capacity needed for threat investigation and containment. ANY.RUN’s product updates aim to resolve these gaps by providing a connected workflow, linking detection through investigation, response, and proactive defense while maintaining context throughout.
Phishing remains a high-volume, high-cost problem, affecting critical industries heavily, with exposure rates reaching 73.4% in finance and 72.2% in manufacturing according to 2026 data. Social engineering accounts for 28% of breaches investigated by Microsoft Incident Response. Financial losses are significant, with the FBI receiving over 191,561 phishing complaints in 2025 and Business Email Compromise generating $3.05 billion in reported US losses.
The solution proposed involves three interconnected steps to accelerate response: first, accelerating triage through SSL decryption and in-browser data inspection to gather evidence quickly; second, improving escalation and response via AI-powered Tier 1 reports to provide context for handover; and third, enabling proactive defense by using threat intelligence lookups to connect individual incidents to wider infrastructure. This structured approach aims to reduce manual work, decrease escalations, shorten mean time to response (MTTR), and allow for broader threat hunting across related activities.

Facts Only

* Phishing investigations require analysts to uncover hidden activity, make decisions from incomplete evidence, prepare escalations, and determine threat scope.
* Phishing exposure is 73.4% in finance and 72.2% in manufacturing in 2026 data.
* 28% of breaches investigated by Microsoft Incident Response started with phishing or social engineering, including device code phishing techniques.
* The FBI received 191,561 phishing and spoofing complaints in 2025.
* Business Email Compromise generated $3.05 billion in reported US losses in 2025.
* Step 1 (Triage) uses SSL Decryption without MITM and In-Browser Data Inspection to reduce Tier 1 investigation time by 20%.
* Step 2 (Escalation/Response) uses Tier 1 reports, AI Summary, and AI Recommendations to reduce escalations by 30% and MTTR by 21 minutes.
* Step 3 (Proactive Defense) uses Connections in Threat Intelligence Lookup to find related infrastructure for retrohunting and blocking.
* The investigation process involves inspecting network traffic (SSL Decryption), browser activity (In-Browser Data Inspection), generating AI reports, and linking indicators via threat intelligence lookups.

Full Take

The narrative frames the transition from reactive, fragmented manual investigation to a connected, evidence-driven workflow as essential for managing high-volume phishing threats effectively. The core tension lies between the immediate need for rapid containment and the need for deep contextual understanding that typically requires time-consuming, manual aggregation of data. The proposed solution leverages automation—specifically visibility enhancement (decryption/inspection), cognitive offloading (AI summarization), and relational mapping (threat intelligence lookups)—to bridge this gap.
The reliance on the three-step process suggests an inherent vulnerability in siloed security operations: when analysis moves across separate tools, the human element introduces latency and potential error at each handoff. The effectiveness hinges not just on the technical capabilities (decryption, AI) but on successfully encoding contextual understanding into actionable summaries that Tier 2 analysts can consume immediately.
The implication for operational capacity is significant: by automating context gathering and reporting, the system shifts analyst focus from low-value data reconstruction to high-value threat correlation and proactive defense. The concept of 'Connections' in Threat Intelligence Lookup suggests a shift from incident-centric analysis (what happened to this email?) to infrastructure-centric analysis (what other malicious elements are connected?). A critical question remains: does the introduction of layered abstraction—where raw sandbox data is transformed into AI summaries, then linked via TI graphs—risk obscuring the subtle, non-obvious anomalies that an expert might notice when reviewing raw artifacts? How do teams ensure this automation enhances, rather than replaces, necessary adversarial thinking during the final decision points?

From the original · Any.run Blog

Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident. Every manual step adds time to the response.
Read the full story at any.run

Sentinel — Human

Confidence

This article functions as a persuasive case study demonstrating how integrated security workflows reduce analyst workload, relying on structured narrative and specific examples rather than pure synthetic output.

Signals Detected
low severity: Moderate sentence length variance and use of specific, narrative examples (EvilTokens case) suggest human authoring.
low severity: The structure flows logically from problem identification (manual work) to solution demonstration (ANY.RUN features) and quantified impact, characteristic of persuasive business writing.
low severity: Specific quantitative metrics and direct product integration are presented in a structured way, which is typical of marketing-informed reporting, but the core narrative thread feels organic.
low severity: The inclusion of specific, self-referential data points (e.g., SANS survey numbers, specific loss figures) and detailed workflow walkthroughs suggests grounding in real reporting, though the performance claims are promotional.
Human Indicators
The text balances complex technical concepts with narrative appeal effectively, demonstrating a human drive to structure information for impact rather than pure data dumping.
The use of comparative results (e.g., 20% less time) framed within an investigative workflow feels derived from real operational experiences.
Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN’s Latest Updates | Huntaegis