A German manufacturing company has significantly improved its handling of security alerts by transitioning to a cloud-based solution. The security team, consisting of five members, has managed to reduce investigation time by 15 minutes per alert by replacing their traditional air-gapped forensic laptop with ANY.RUN’s cloud-managed Interactive Sandbox.
Cloud Technology Revolutionizes Security Operations
Protecting around 10,000 endpoints, the team demonstrates how smaller security operations can efficiently manage enterprise-level malware and phishing threats without immediately increasing staff numbers. As noted in a case study from ANY.RUN, the manufacturer’s security team experiences a workload 22% higher than other industries, though the methodology behind this figure remains undisclosed.
The change was spearheaded by Philipp Z., the security lead at the manufacturer, whose identity remains confidential. Prior to this, the team used extended detection and response (XDR) alerts, which identified suspicious activities but lacked sufficient context for confirmation of threats.
Challenges of Previous Security Measures
Initially, the team relied on an offline forensic setup, including an Ubuntu laptop and SANS toolkit. The process was time-consuming, requiring boot-up and preparation before even beginning an investigation. The offline nature also complicated evidence transfer, with only one analyst able to access the forensic tools at any given time, causing delays especially in remote work situations.
This setup often forced analysts to treat uncertain alerts as genuine threats, resulting in unnecessary endpoint isolation and system reinstallation. Moving to ANY.RUN’s solution allowed analysts to perform investigations in a shared online workspace, streamlining access and analysis.
Benefits of the Cloud Sandbox Solution
Using ANY.RUN’s cloud platform, analysts can now submit files or URLs for analysis, interacting with a virtual environment to inspect processes and network connections. This platform supports real-time interactions, making it easier to make informed decisions quickly.
Philipp Z. noted that the new setup saves around 15 minutes per alert on average, allowing the team to handle 20 to 40 alerts daily. Additionally, the alignment between analyst decisions and the sandbox’s classifications has reached a 95% agreement rate, showcasing the effectiveness of the solution.
By eliminating repetitive setup tasks, the team is able to investigate a broader range of suspicious artifacts, transforming their security process from a hardware-focused routine to an investigative approach. This shift not only enhances security operations but also helps prevent analyst burnout, offering a significant improvement in overall security maturity.
ANY.RUN’s services are widely adopted, with more than 16,000 organizations utilizing their platform, including 74% of Fortune 100 companies. Security teams interested in exploring these capabilities can register for a trial or contact ANY.RUN for enterprise solutions.
