Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case.

Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened. 

The investigation does not stop at the verdict. SOCs still need to collect relevant evidence, document their findings, prepare the case for escalation, and determine whether the same infrastructure or techniques appear in other attacks. 

That makes the workflow between detection, investigation, response, and threat hunting just as important as identifying the initial threat. 

ANY.RUN has introduced several capabilities aimed at reducing the manual effort involved in these investigations.

The updates combine deeper network and browser visibility, automated reporting, and threat intelligence correlation to help security teams move from initial detection to response and threat hunting more quickly. 

Why Phishing Continues to Keep SOC Analysts Busy 

The scale of phishing activity makes those investigation challenges harder to manage. Security teams are dealing with a steady stream of phishing-related alerts while attackers continue to introduce techniques that make individual incidents more difficult to analyze. 

ANY.RUN’s H1 2026 Cyber Risk Report shows phishing exposure in 73.4% of investigations in the financial sector and 72.2% in manufacturing.

Microsoft Incident Response has also found that 28% of the breaches it investigated began with phishing or social engineering, including newer techniques such as device-code phishing. 

The financial impact is equally significant. The FBI recorded 191,561 phishing and spoofing complaints in 2025, while Business Email Compromise generated $3.05 billion in reported U.S. losses. 

For SOC analysts, the result is a combination of high investigation volume and increasingly complex attack chains.

A single suspicious URL can require network analysis, browser inspection, reporting, and threat intelligence research before the case is ready to close or escalate. 

The goal is to reduce the manual work between those stages without losing the evidence and context analysts need to make decisions.
 

94% of users report faster threat triage with ANY.RUN. Give your SOC the visibility to move from phishing alerts to action faster. Improve SOC Triage

3 Steps to Strengthen Phishing Detection, Response, and Threat Defense 

To see how these steps work in practice, let’s follow a phishing campaign that uses the following attack chain: 

Cloudflare CAPTCHA → Phishing Document Lure → Device Code Phishing  

The campaign involves EvilTokens, a phishing-as-a-service platform that abuses Microsoft’s legitimate device-code authentication flow to steal session tokens and gain access to accounts. 

The technique creates several challenges for SOC analysts. It can combine CAPTCHA gates, redirects, legitimate cloud services, and dynamically generated phishing pages, meaning the activity visible at the initial URL may not reveal what happens later in the attack. 

For this walkthrough, the investigation starts with the suspicious phishing activity and follows it through three stages: triage the attack, prepare the findings for response, and pivot into threat intelligence to identify related activity. 

The complete attack is captured in an ANY.RUN sandbox session, allowing the investigation to follow the execution chain and examine the network and browser activity generated during the attack. 

ANY.RUN Sandbox reveals the complete EvilTokens attack chain in under a minute 

With the attack established, here is how the investigation can progress from the initial alert to broader threat intelligence. 

Step 1: Accelerate Phishing Triage With Network and Browser Visibility 

The first task is to establish what the suspicious URL actually does. 

In modern phishing campaigns, important evidence can be hidden behind HTTPS encryption, redirects, CAPTCHA challenges, and browser-side scripts. Looking only at the original URL may leave an analyst without enough context to make a confident decision. 

In the EvilTokens analysis, the suspicious URL is opened in ANY.RUN’s Interactive Sandbox. As the attack unfolds, the Network section records the web requests generated by the browser, including traffic that was originally encrypted over HTTPS. 

Analysts can inspect individual request and response pairs through the Content view and identify suspicious resources involved in the attack. 

One observed request is: 

GET hxxps[://]preponacrea[.]com/est/js/main[.]js 

Suspicious activity revealed in ANY.RUN Sandbox 

SSL Decryption without MITM becomes useful here. The capability extracts encryption keys directly from process memory, allowing HTTPS traffic to be inspected without deploying a separate MITM proxy or replacing certificates. 

But the network traffic is only part of the investigation. The In-Browser Data Inspection capability provides another view of the attack by allowing analysts to examine browser activity, including HTTP requests, DOM changes, iframes, screenshots, and redirects. 

In-browser inspection reveals the phishing page’s full attack activity 

For the EvilTokens campaign, this helps reveal how the browser moves through the phishing flow and what changes as the malicious page loads. 

Together, the two capabilities give analysts visibility across both sides of the investigation: what the browser communicates with and what happens inside the browser itself. 

That can reduce the need to manually piece together PCAP data, web logs, screenshots, and redirect chains before reaching a verdict. Tier 1 analysts can validate suspicious URLs faster and determine whether a case can be resolved or needs to be escalated.
 

95% of SOC teams speed up threat investigations with ANY.RUN. Move from phishing alerts to actionable response faster. Explore ANY.RUN
 

Step 2: Turn the Investigation into a Response-Ready Case 

Once the activity has been confirmed as malicious, the next challenge is communicating the findings. 

The analyst needs to explain what happened, why the activity is malicious, which indicators are relevant, and what the next team should do.

Without that context, Tier 2 or incident response may have to return to the original investigation and reconstruct the evidence before taking action. 

The EvilTokens analysis can be turned into a structured Tier 1 report, bringing the key findings together in one place.

The report includes the analysis verdict, relevant threat and campaign tags, key IOCs, technical events, an AI Summary, and AI Recommendations.  View the Tier 1 report for this analysis. 

Tier 1 report summarizing the EvilTokens phishing attack 

The AI Summary provides a condensed explanation of what happened during the session, while the recommendations give the responding team potential next actions to consider. 

AI-generated summary of the EvilTokens phishing attack 

For an analyst, this means the investigation does not have to end as a collection of raw sandbox findings. The evidence can be packaged into a format that another analyst can quickly understand and act on.

That becomes particularly useful when a case moves from Tier 1 to Tier 2, incident response, or an MSSP customer. 

Key IOCs identified for attack detection and threat hunting 

The broader benefit is reducing the amount of time analysts spend translating technical findings into another incident summary and giving the next responder the context needed to continue the investigation.
 

The original phishing case can also provide a starting point for a wider investigation. 

Attackers can rotate domains, IP addresses, and other infrastructure, so closing one malicious URL does not necessarily establish whether related activity exists elsewhere. 

In the EvilTokens analysis, the observed HTTP endpoints provide useful behavioral indicators for further investigation: 

/api/device/start 

/api/device/status/ 

Analysts can take these patterns into ANY.RUN Threat Intelligence Lookup (TI Lookup) and search for other analyses where the same behavior has appeared. 

See the EvilTokens query in TI Lookup 

The new Connections view adds context by showing relationships between network artifacts such as URLs, domains, IP addresses, and other indicators.

This allows analysts to move beyond checking individual IOCs and instead investigate how different pieces of infrastructure may be connected. 

Connections view reveals related EvilTokens infrastructure in ANY.RUN’s TI Lookup 

That distinction is important during threat hunting. An IP associated with a malicious analysis may belong to shared cloud or CDN infrastructure and therefore may not be an appropriate blocking candidate.

Relationship context and filtering can help analysts separate potentially useful indicators from infrastructure that is widely shared. 

The results can then support retrohunting, SIEM and NDR investigations, detection engineering, and blocking decisions. 

Threat Intelligence Lookup also provides additional context around the wider threat activity, including geography and targeted industries, giving analysts more information to determine whether related activity is relevant to their environment. 

ANY.RUN’s TI Lookup provides visibility into the wider threat landscape 

What These Steps Mean for Phishing Response 

Following the EvilTokens campaign through the three stages shows how a single phishing investigation can deliver more than a malicious verdict.

The same evidence can continue to support the investigation as the case moves from triage to response and threat hunting. 

For SOC analysts, the workflow provides: 

  • Faster phishing triage: Encrypted traffic and browser activity can be examined together, giving analysts more context to validate suspicious URLs and understand the attack chain. 
  • Clearer incident response: Investigation findings can be consolidated into a structured report with the verdict, IOCs, technical evidence, AI-generated summary, and recommendations for the next responder. 
  • Broader threat visibility: Observed IOCs and attack patterns can be used to search for related activity and uncover connections between domains, URLs, IPs, and other infrastructure. 

The result is a more continuous path from phishing detection to response and proactive defense, with less need for analysts to rebuild investigation context at each stage. 

30% fewer Tier 1-to-Tier 2 escalations. Give analysts the context they need to investigate phishing faster. Power Up Your SOC 

The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster  appeared first on Cyber Security News.