In a major update aimed at revolutionizing the way cybersecurity professionals tackle threats, ANY.RUN has unveiled its redesigned Threat Intelligence (TI) Lookup platform.
The latest update introduces an enhanced home screen that integrates the powerful MITRE ATT&CK matrix, complete with interactive features, actionable insights, and connections to real-world malware samples and signatures.
The new features are set to help analysts, researchers, and incident responders streamline their workflows and respond to threats with greater precision and confidence.
The centerpiece of the redesigned TI Lookup is its fully interactive MITRE ATT&CK matrix, now displayed prominently on the home screen. This matrix doesn’t just present theoretical frameworks for tactics and techniques—it bridges the gap between these concepts and practical, real-world threat data.
Whether you’re a malware analyst, incident responder, or simply a researcher looking to understand attack patterns, the new dashboard is a highly functional tool designed to simplify complex threat intelligence tasks.
Collect threat intel on the latest malware and phishing attacks with TI Lookup – Get Upto 3 Free Licences
One of the primary goals of the redesign is to turn the MITRE ATT&CK matrix into a hands-on tool for analysts. Instead of just listing tactics and techniques, the enhanced platform connects these elements to detection data, attack patterns, and malware families.
For instance, by analyzing the Phishing technique (T1566) within the Initial Access phase of the MITRE ATT&CK matrix, users can explore sub-techniques like spearphishing links, spearphishing attachments, and more. Each entry provides detailed signatures and examples pulled from real-world analysis sessions, offering invaluable insights into how attackers operate.
To help analysts prioritize critical threats, the redesigned TI Lookup introduces a color-coded filtering system for MITRE ATT&CK techniques:
Users can refine their view by toggling specific categories on or off, making it easier to focus on the most pressing threats.
For example, when analyzing spearphishing links, users can drill down into associated URLs, domains, and other Indicators of Compromise (IOCs).
The revamped platform seamlessly integrates with ANY.RUN’s cloud-based interactive sandbox, allowing users to analyze malware samples in-depth. With one click, users can jump from the TI Lookup dashboard to a sandbox session, where they can observe malware behavior in real time and analyze its overall attack structure.
This integration ensures analysts have all the tools they need to not only understand threats but also respond effectively.
To illustrate the power of the new platform, consider the Spearphishing Links sub-technique within the MITRE ATT&CK matrix. Clicking on this entry reveals detailed information, including:
According to the ANY.RUN report, By studying these insights, analysts can create tailored detection rules, enhance their defenses, and develop detailed reports for stakeholders. For example, they might uncover a phishing campaign leveraging malicious URLs embedded in emails, then use this information to prevent future attacks.
The updated TI Lookup also features a dedicated search function for deeper exploration of threats. Users can search for specific techniques, malware families, or IOCs and access a wealth of actionable intelligence, including:
For instance, searching for “Suspicious URL” might reveal phishing campaigns, malicious payloads, or other threats, providing analysts with the context needed to improve their defenses.
The new features in TI Lookup are designed to address some of the most pressing challenges in cybersecurity:
ANY.RUN is a leading provider of interactive cybersecurity tools, including its popular Threat Intelligence Lookup and YARA Search services. Known for their speed and precision, these tools empower analysts to stay ahead of emerging threats by providing detailed insights into malware behavior and attack patterns.
Explore the redesigned Threat Intelligence Lookup today and experience firsthand how these updates can revolutionize your approach to cybersecurity.
Whether you’re defending against phishing attacks, studying persistence techniques, or analyzing lateral movement, TI Lookup provides everything you need to stay ahead.
Sign Up Intelligence Lookup for Fast Threat Investigations - Get Upto 3 Free Licences
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…