ANY.RUN Threat Intelligence Lookup
Automatic deploy
Supported by Filigran
Adversary & Campaign Insights
Detection & Response Enablement
Overview
The ANY.RUN Threat Intelligence Lookup connector lets SOC teams search a massive database of live attack data from 15K organizations to enrich indicators with deep behavioral context and global threat telemetry.
ANY.RUN Threat Intelligence Lookup is a searchable database of live attack data. It allows SOC and MSSP analysts to check suspicious Indicators of Compromise (IOCs), Behavior (IOBs), and Action (IOAs) against a history of active malware and phishing attacks to understand the full context of an incident. The threat database is being continuously updated with fresh intelligence backed by the ANY.RUN Interactive Sandbox's global community of 15,000 organizations and 600,000 analysts.
Key Capabilities:
- Instantly Enrich Incidents with Global Context: Query the ANY.RUN database for details on suspicious IPs, domains, hashes, and over 40 more types of indicators to see if they have been involved in real-world attacks, allowing for a more confident assessment of every alert.
- See the "How" Behind the Attack: Rather than just seeing that an indicator is "malicious", you get behavioral context that explains exactly how an attacker operates, which is vital for building a stronger defense.
- Update Your Protections Automatically: Use the intelligence you find to create new security rules and update your response playbooks directly within OpenCTI, turning global data into local security.
- Stop Breaches Before They Start: By leveraging data from 15,000 organizations, your team can identify and block emerging threats before they even target your environment.