Cybersecurity2 hrs ago

Threat Intelligence Cuts SOC Response Times by 21 Minutes, ANY.RUN Claims

ANY.RUN claims its behavioral threat intelligence cuts SOC mean time to respond by up to 21 minutes, lowers Tier 1 workload by 20% and Tier 2 escalations by 30%.

Peter Olaleru/3 min/GB

Cybersecurity Editor

TweetLinkedIn
Threat Intelligence Cuts SOC Response Times by 21 Minutes, ANY.RUN Claims
Source: CyberpressOriginal source

TL;DR: ANY.RUN claims its threat intelligence platform can reduce SOC response times by up to 21 minutes and cut Tier 1 workload by 20% while lowering Tier 2 escalations by 30%. The claim is based on data from over 600 k security professionals across 15 k+ organizations using its sandbox‑derived intelligence.

Context

Modern SOCs face alert overload, forcing analysts to spend time on manual enrichment instead of decision‑making. This delay increases dwell time and raises incident costs. Threat intelligence that supplies pre‑analyzed context can shrink the investigation loop.

Key Facts

ANY.RUN’s intelligence is built from daily sandbox analyses performed by more than 600 k analysts in over 15 k organizations worldwide. Using its TI Lookup tool, teams have reported up to a 20 % reduction in Tier 1 workload and up to a 30 % drop in Tier 2 escalations. Overall, behavioral intelligence from the platform has been linked to response‑time improvements of as much as 21 minutes per alert.

What It Means

Faster triage means threats are contained sooner, limiting dwell time and reducing the chance of credential abuse or lateral movement. Defenders should integrate ANY.RUN’s TI Feeds for real‑time IOCs, enable TI Lookup for instant context, and schedule regular TI Reports to guide threat‑hunting. Configuration steps include adding the feed to SIEM/EDR enrichment pipelines, setting up automated lookup scripts for IP/domain/hash queries, and tuning alert thresholds to reflect the reduced false‑positive rate. Watch for upcoming updates to ANY.RUN’s sandbox coverage and any new MITRE ATT&CK technique mappings they publish.

TweetLinkedIn

More in this thread

Reader notes

Loading comments...