Executive Summary
Phishing investigations create pressure on Security Operations Center (SOC) teams by requiring analysts to uncover hidden activity, make decisions with incomplete evidence, prepare escalations, and determine the scope of threats. Manual steps in the response process consume analyst capacity needed for threat investigation and containment. ANY.RUN’s product updates aim to resolve these gaps by providing a connected workflow, linking detection through investigation, response, and proactive defense while maintaining context throughout.
Phishing remains a high-volume, high-cost problem, affecting critical industries heavily, with exposure rates reaching 73.4% in finance and 72.2% in manufacturing according to 2026 data. Social engineering accounts for 28% of breaches investigated by Microsoft Incident Response. Financial losses are significant, with the FBI receiving over 191,561 phishing complaints in 2025 and Business Email Compromise generating $3.05 billion in reported US losses.
The solution proposed involves three interconnected steps to accelerate response: first, accelerating triage through SSL decryption and in-browser data inspection to gather evidence quickly; second, improving escalation and response via AI-powered Tier 1 reports to provide context for handover; and third, enabling proactive defense by using threat intelligence lookups to connect individual incidents to wider infrastructure. This structured approach aims to reduce manual work, decrease escalations, shorten mean time to response (MTTR), and allow for broader threat hunting across related activities.
Facts Only
* Phishing investigations require analysts to uncover hidden activity, make decisions from incomplete evidence, prepare escalations, and determine threat scope.
* Phishing exposure is 73.4% in finance and 72.2% in manufacturing in 2026 data.
* 28% of breaches investigated by Microsoft Incident Response started with phishing or social engineering, including device code phishing techniques.
* The FBI received 191,561 phishing and spoofing complaints in 2025.
* Business Email Compromise generated $3.05 billion in reported US losses in 2025.
* Step 1 (Triage) uses SSL Decryption without MITM and In-Browser Data Inspection to reduce Tier 1 investigation time by 20%.
* Step 2 (Escalation/Response) uses Tier 1 reports, AI Summary, and AI Recommendations to reduce escalations by 30% and MTTR by 21 minutes.
* Step 3 (Proactive Defense) uses Connections in Threat Intelligence Lookup to find related infrastructure for retrohunting and blocking.
* The investigation process involves inspecting network traffic (SSL Decryption), browser activity (In-Browser Data Inspection), generating AI reports, and linking indicators via threat intelligence lookups.
Full Take
The narrative frames the transition from reactive, fragmented manual investigation to a connected, evidence-driven workflow as essential for managing high-volume phishing threats effectively. The core tension lies between the immediate need for rapid containment and the need for deep contextual understanding that typically requires time-consuming, manual aggregation of data. The proposed solution leverages automation—specifically visibility enhancement (decryption/inspection), cognitive offloading (AI summarization), and relational mapping (threat intelligence lookups)—to bridge this gap.
The reliance on the three-step process suggests an inherent vulnerability in siloed security operations: when analysis moves across separate tools, the human element introduces latency and potential error at each handoff. The effectiveness hinges not just on the technical capabilities (decryption, AI) but on successfully encoding contextual understanding into actionable summaries that Tier 2 analysts can consume immediately.
The implication for operational capacity is significant: by automating context gathering and reporting, the system shifts analyst focus from low-value data reconstruction to high-value threat correlation and proactive defense. The concept of 'Connections' in Threat Intelligence Lookup suggests a shift from incident-centric analysis (what happened to this email?) to infrastructure-centric analysis (what other malicious elements are connected?). A critical question remains: does the introduction of layered abstraction—where raw sandbox data is transformed into AI summaries, then linked via TI graphs—risk obscuring the subtle, non-obvious anomalies that an expert might notice when reviewing raw artifacts? How do teams ensure this automation enhances, rather than replaces, necessary adversarial thinking during the final decision points?
From the original · Any.run Blog
Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident. Every manual step adds time to the response.Read the full story at any.run
Sentinel — Human
This article functions as a persuasive case study demonstrating how integrated security workflows reduce analyst workload, relying on structured narrative and specific examples rather than pure synthetic output.
