Urgent.News

What's breaking now, across thousands of outlets.

Tech

15 Minutes Saved Per Alert: How a Lean German Manufacturer Protects 10,000 Endpoints with ANY.RUN

See how a five-person SOC uses ANY.RUN to investigate threats across 10,000 devices, save 15 minutes per alert, and scale malware triage.

15 Minutes Saved Per Alert: How a Lean German Manufacturer Protects 10,000 Endpoints with ANY.RUN

Security teams within the manufacturing industry confront demanding operational requirements, with recent ANY.RUN data indicating that their workloads are roughly 22% higher than those in other major sectors. To provide an insider perspective on how teams navigate these challenges, we interviewed Philipp Z., Security Lead at a prominent German manufacturer.

He explained that by replacing complex manual analysis with ANY.RUN's Interactive Sandbox, his team was able to accelerate incident response by 15 minutes per case, eliminate tedious routines, and enhance their overall security posture.

Philipp's company manages a vast computer network comprising 10,000 devices and 10,000 users, including both office computers and servers. Unlike many companies, they operate with a lean security team of just five professionals responsible for both proactive hardening and reactive response. When security alerts appear in their XDR system, the team immediately analyzes them, takes swift action, and follows security protocols such as isolating devices or initiating cloud reinstalls. This massive footprint requires dynamic handling.

The company divided their focus into two primary tasks: early threat detection and quick incident response. Upon receiving security alerts in their monitoring system, the team immediately responds to contain and investigate the issue. When operations are calm, they collaborate with other IT teams to bolster the company's defenses.

Prior to adopting ANY.RUN, the German company faced significant delays due to forensic laptop bottlenecks and selective triage processes. Their XDR could identify potential threats but lacked real-time visibility into file or URL behavior. To safely examine questionable files and URLs, they relied on a single dedicated offline laptop equipped with a virtualized Flare VM and the SANS forensic toolkit.

While functional, this setup introduced several issues: long setup times, risky manual data transfers, and limited access for remote workers. Consequently, the team often assumed files to be malicious and performed brute-force remediation, such as wiping and reinstalling affected devices, which caused significant disruptions for IT staff and employees.

To overcome these challenges, the company transitioned to ANY.RUN's Interactive Sandbox. Philipp, who previously experienced the platform during his student years, praised its usability, options, and enterprise pricing. ANY.RUN provided a safe, centralized workspace free from the old setup hassles: complete safety and privacy through a private cloud environment, remote-ready accessibility from any location, and fast, interactive triage capabilities.

Analysts could quickly copy suspicious links into ANY.RUN, observe file behavior in real-time, and receive a definitive verdict within seconds. Although the immediate visual verdict was sufficient for daily triage, the team utilized ANY.RUN's reporting feature for compliance documentation. This streamlined workflow allowed them to triage alerts more efficiently, leaving no time wasted on tedious tasks and ensuring a robust security posture without compromising on response time.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Tech

More from Wednesday 16 September →