A SOC team of just five professionals safeguarded their company’s infrastructure from a multi-stage email attack using in-depth browser visibility and full-scale attack detonation. What the Initial Alert Suggested The security team’s XDR system flagged a suspicious shortcut (.lnk) file being opened. The encryption technique further obscured the connection between the original email and the malicious files within the archive, making it difficult to trace the full execution chain through automated inspection.
Another PDF file analyzed within ANY.RUN revealed that the process tree in the Interactive Sandbox allowed the team to trace the email to the browser and ultimately to malware execution.
Any.Run's sandbox allows for deeper investigation, enabling the team to trace back endpoint activity to its source and take immediate action against the malicious email. Deploying in a private cloud, the secure and adaptable virtual environment doesn’t require extra setup and lets analysts observe threat behavior and uncover complete attack chains in just seconds. Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort.
To ensure consistent triage results, Philipp’s team tracks a key KPI: the rate at which analysts agree with ANY.RUN’s true- and false-positive classifications. For the German manufacturer, integrating ANY.RUN’s Interactive Sandbox into daily SOC investigations resulted in less manual effort, faster incident response, and more context for confident security decisions.











