Geek-Guy.com

Category: release

ANY.RUN Sandbox & MISP: Confirm Alerts Faster, Stop Incidents Early 

Most SOC teams are overloaded with routine work. Tier 1 & 2 analysts spend too much time validating alerts, moving samples between tools, and chasing missing context. When integrations are weak, investigations slow down, MTTR grows, and SLAs suffer delays. That directly increases operational risk and cost for the business.   ANY.RUN has already helped teams close part of this…

Release Notes: AI Sigma Rules, Live Threat Landscape & 1,700+ New Detections

ANY.RUN is wrapping up 2025 with updates that take pressure off your SOC and help your team work faster. You can now get AI‑generated Sigma rules, track threats by industry and region, and detect new campaigns with better speed and accuracy.   Let’s see what these improvements bring to your security stack.  Product Updates  Industry & Geo Threat Landscape…

Release Notes: ANY.RUN & ThreatQ Integration, 3,000+ New Rules, and Expanded Detection Coverage 

October brought another strong round of updates to ANY.RUN, from a new ThreatQ integration that connects our real-time Threat Intelligence Feeds directly into one of the industry’s leading TIPs, to hundreds of new signatures and rules that sharpen network and behavioral detection.  With 125 new behavior signatures, 17 YARA rules, and 3,264 Suricata rules, analysts can now spot emerging threats…

Release Notes: Palo Alto Networks, Microsoft, IBM Connectors and 2,300+ Suricata Rules

September brought big updates to ANY.RUN. From four new connectors that plug our sandbox and threat intelligence straight into the world’s top SIEM and SOAR platforms, to a redesigned Threat Intelligence Lookup home screen built for speed and simplicity, your SOC now works smarter and faster than ever.   Add in 99 fresh signatures, 11 new YARA rules, and 2,322…

ANY.RUN & MS Defender: Enrich Alerts Faster, Stop Attacks Early 

Lack of context makes it hard for Security Operations Centers (SOC) to tell actual threats from false positives. ANY.RUN’s connectors for Microsoft Defender bridge this gap by automating interactive sandbox analysis and providing real-time threat intelligence for correlation.   As a result, security teams achieve faster incident resolution, reduced alert fatigue, and proactive threat detection all…

ANY.RUN & Palo Alto Networks Cortex XSOAR: Streamline SOC Workflows for Top Performance 

Swamped by incident alerts, Security Operations Centers (SOCs) struggle to quickly identify and prioritize high-risk attacks, leaving critical infrastructure exposed to ransomware and data theft. ANY.RUN’s integration with Palo Alto Networks Cortex XSOAR solves this by automating proactive sandbox analysis and threat intelligence correlation to beat alert fatigue, boost detection rates, and accelerate security workflows. …

ANY.RUN & Palo Alto Networks Cortex XSOAR: Streamline SOC Workflows for Top Performance 

Swamped by incident alerts, Security Operations Centers (SOCs) struggle to quickly identify and prioritize high-risk attacks, leaving critical infrastructure exposed to ransomware and data theft. ANY.RUN’s integration with Palo Alto Networks Cortex XSOAR solves this by automating proactive sandbox analysis and threat intelligence correlation to beat alert fatigue, boost detection rates, and accelerate security workflows. …

Release Notes: Fresh Connectors, SDK Update, and 2,200+ New Detection Rules 

August was a busy month at ANY.RUN. We expanded our list of connectors with Microsoft Sentinel and OpenCTI, added Linux Debian (ARM) support to the SDK, and strengthened detection across hundreds of new malware families and techniques. With fresh signatures, rules, and product updates, your SOC can now investigate faster, detect more threats in real time, and keep defenses sharp…

ANY.RUN & Microsoft Sentinel: Catch Emerging Threats with Real-Time Threat Intelligence

ANY.RUN now delivers Threat Intelligence (TI) Feeds directly to Microsoft Sentinel via the built-in STIX/TAXII connector. No complicated setups. No custom scripts. Only high-quality indicators of compromise (IOCs) to fortify your SOC and catch attacks early, keeping your business secure.  About the TI Feeds Connector for Microsoft Sentinel   ANY.RUN’s TI Feeds support a seamless, out-of-the-box…

ANY.RUN & Microsoft Sentinel: Catch Emerging Threats with Real-Time Threat Intelligence

ANY.RUN now delivers Threat Intelligence (TI) Feeds directly to Microsoft Sentinel via the built-in STIX/TAXII connector. No complicated setups. No custom scripts. Only high-quality indicators of compromise (IOCs) to fortify your SOC and catch attacks early, keeping your business secure.  About the TI Feeds Connector for Microsoft Sentinel   ANY.RUN’s TI Feeds support a seamless, out-of-the-box…

ANY.RUN & Microsoft Sentinel: Catch Emerging Threats with Real-Time Threat Intelligence

ANY.RUN now delivers Threat Intelligence (TI) Feeds directly to Microsoft Sentinel via the built-in STIX/TAXII connector. No complicated setups. No custom scripts. Only high-quality indicators of compromise (IOCs) to fortify your SOC and catch attacks early, keeping your business secure.  About the TI Feeds Connector for Microsoft Sentinel   ANY.RUN’s TI Feeds support a seamless, out-of-the-box…

Release Notes: QRadar SOAR App, TI Lookup Free Access, and 2,900+ New Detection Rules

July brought powerful new updates to help your SOC catch threats faster, reduce manual effort, and make more confident decisions, right inside your existing workflows. From fresh integrations to better detection coverage, these changes are built to support your team every step of the way.  In this update:  New IBM QRadar SOAR integration to automate investigations and speed…

Release Notes: QRadar SOAR App, TI Lookup Free Access, and 2,900+ New Detection Rules

July brought powerful new updates to help your SOC catch threats faster, reduce manual effort, and make more confident decisions, right inside your existing workflows. From fresh integrations to better detection coverage, these changes are built to support your team every step of the way.  In this update:  New IBM QRadar SOAR integration to automate investigations and speed…

Release Notes: QRadar SOAR App, TI Lookup Free Access, and 2,900+ New Detection Rules

July brought powerful new updates to help your SOC catch threats faster, reduce manual effort, and make more confident decisions, right inside your existing workflows. From fresh integrations to better detection coverage, these changes are built to support your team every step of the way.  In this update:  New IBM QRadar SOAR integration to automate investigations and speed…

Detect ARM Malware in Seconds with Debian Sandbox for Stronger Enterprise Security 

ANY.RUN’s Interactive Sandbox provides SOC teams with the fastest solution for analyzing and detecting cyber threats targeting Windows, Linux, and Android systems. Now, our selection of VMs has been expanded to include Linux Debian 12.2 64-bit (ARM).   With the rapid rise of ARM-based malware, the sandbox helps businesses tackle this threat through proactive analysis and…

Turn Alert Noise into Threat Insights without Leaving QRadar SOAR with ANY.RUN 

IBM QRadar SOAR is a go-to platform for incident response. To make things faster and easier for SOCs to use this powerful tool with ANY.RUN’s services, we built an official app. Now you can seamlessly launch different playbooks directly inside SOAR to streamline threat analysis, speed up investigations, and reduce Mean Time to Respond (MTTR)…

Release Notes: Detonation Actions, Enhanced QR Extraction, and 1,400+ New Detection Rules 

We’ve packed June with updates designed to make your day-to-day analysis faster, clearer, and easier than before. Whether you’re just getting started or deep into reverse engineering every day, these improvements are here to save you time and help you catch more threats.  In this update:  Real-time Detonation Action hints that guide you through the…

Simplify Threat Analysis and Boost Detection Rate with Detonation Actions 

Threat analysis is a complex task that demands full attention, especially during active incidents, when every second counts. ANY.RUN’s Interactive Sandbox is designed to ease that pressure with an intuitive interface and fast threat detection.   Our new feature, Detonation Actions, takes this further by highlighting detonation steps during analysis. When a specific action is needed…

Simplify Threat Analysis and Boost Detection Rate with Detonation Actions 

Threat analysis is a complex task that demands full attention, especially during active incidents, when every second counts. ANY.RUN’s Interactive Sandbox is designed to ease that pressure with an intuitive interface and fast threat detection.   Our new feature, Detonation Actions, takes this further by highlighting detonation steps during analysis. When a specific action is needed…

Simplify Threat Analysis and Boost Detection Rate with Detonation Actions 

Threat analysis is a complex task that demands full attention, especially during active incidents, when every second counts. ANY.RUN’s Interactive Sandbox is designed to ease that pressure with an intuitive interface and fast threat detection.   Our new feature, Detonation Actions, takes this further by highlighting detonation steps during analysis. When a specific action is needed…

Simplify Threat Analysis and Boost Detection Rate with Detonation Actions 

Threat analysis is a complex task that demands full attention, especially during active incidents, when every second counts. ANY.RUN’s Interactive Sandbox is designed to ease that pressure with an intuitive interface and fast threat detection.   Our new feature, Detonation Actions, takes this further by highlighting detonation steps during analysis. When a specific action is needed…

Integrate Threat Intelligence Feeds via TAXII Protocol 

ANY.RUN’s Threat Intelligence Feeds (TI Feeds) provide security teams with exclusive intel on threats targeting 15,000 companies worldwide. With TAXII protocol, you can safely and easily reinforce your company’s proactive detection with TI Feeds.   Why Use TAXII for TI Feeds?  TAXII (Trusted Automated eXchange of Indicator Information) allows for swift and comfortable delivery of threat…

Integrate Threat Intelligence Feeds via TAXII Protocol 

ANY.RUN’s Threat Intelligence Feeds (TI Feeds) provide security teams with exclusive intel on threats targeting 15,000 companies worldwide. With TAXII protocol, you can safely and easily reinforce your company’s proactive detection with TI Feeds.   Why Use TAXII for TI Feeds?  TAXII (Trusted Automated eXchange of Indicator Information) allows for swift and comfortable delivery of threat…

Integrate Threat Intelligence Feeds via TAXII Protocol 

ANY.RUN’s Threat Intelligence Feeds (TI Feeds) provide security teams with exclusive intel on threats targeting 15,000 companies worldwide. With TAXII protocol, you can safely and easily reinforce your company’s proactive detection with TI Feeds.   Why Use TAXII for TI Feeds?  TAXII (Trusted Automated eXchange of Indicator Information) allows for swift and comfortable delivery of threat…

Integrate Threat Intelligence Feeds via TAXII Protocol 

ANY.RUN’s Threat Intelligence Feeds (TI Feeds) provide security teams with exclusive intel on threats targeting 15,000 companies worldwide. With TAXII protocol, you can safely and easily reinforce your company’s proactive detection with TI Feeds.   Why Use TAXII for TI Feeds?  TAXII (Trusted Automated eXchange of Indicator Information) allows for swift and comfortable delivery of threat…

Release Notes: TAXII Support for TI Feeds, New Sandbox Onboarding, and 900+ Detection Rules 

We’ve packed May with updates to make your experience smoother and your threat detection even sharper. Whether you’re just getting started or knee-deep in malware every day, these changes are here to save you time and give you better insights.  In this update:  A brand-new onboarding tutorial in the sandbox to guide you step by…

Release Notes: TAXII Support for TI Feeds, New Sandbox Onboarding, and 900+ Detection Rules 

We’ve packed May with updates to make your experience smoother and your threat detection even sharper. Whether you’re just getting started or knee-deep in malware every day, these changes are here to save you time and give you better insights.  In this update:  A brand-new onboarding tutorial in the sandbox to guide you step by…

Release Notes: TAXII Support for TI Feeds, New Sandbox Onboarding, and 900+ Detection Rules 

We’ve packed May with updates to make your experience smoother and your threat detection even sharper. Whether you’re just getting started or knee-deep in malware every day, these changes are here to save you time and give you better insights.  In this update:  A brand-new onboarding tutorial in the sandbox to guide you step by…

Release Notes: TAXII Support for TI Feeds, New Sandbox Onboarding, and 900+ Detection Rules 

We’ve packed May with updates to make your experience smoother and your threat detection even sharper. Whether you’re just getting started or knee-deep in malware every day, these changes are here to save you time and give you better insights.  In this update:  A brand-new onboarding tutorial in the sandbox to guide you step by…