Security teams in the manufacturing sector face persistent operational demands. Recent ANY.RUN data shows their workloads are roughly 22% higher than those in other major industries.
To get an insider’s view on how teams navigate these industry demands, we sat down with Philipp Z., Security Lead at a leading German manufacturer. He shared how replacing complex manual analysis with ANY.RUN’s Interactive Sandbox helped his team accelerate incident response by 15 minutes per case, eliminate tedious routines, and strengthen their overall security posture.
Customer Profile: Protecting a Large-Scale Industrial Footprint with a Small, Agile Team
Philipp’s company has a massive computer network with 10,000 devices and 10,000 users, including both office computers and servers. To protect this huge system, they don’t use a massive security department. Instead, everything is run by a quick, flexible team of just five professionals.
Our responsibilities include proactive hardening and reactive response. When alerts appear in our XDR system, we analyze them, react quickly, and execute our security procedures like immediately isolating devices or pushing cloud reinstalls. It is a massive footprint, and we have to handle it dynamically.
Philipp Z., Security Lead
They split their focus between two main jobs: stopping threats early and responding quickly. When security alerts pop up in their monitoring system, they immediately jump in to contain and inspect the problem. When things are quiet, they work with other IT teams to upgrade the company’s overall defenses.
The Challenge: Forensic Laptop Bottleneck and Selective Triage
Before switching to ANY.RUN, the German company ran into major delays because of how they analyzed threats. Their XDR was great at flagging potential dangers, but it couldn’t show them how a file or URL actually behaved in real time.
It’s less burnout and also less work in general. The hassle of just booting the different machine, going to the VM, entering any encryption keys… it just was tedious work. It was not rewarding work or any fun work…
Philipp Z., Security Lead
To safely analyze potential malware and phishing, the team had to use a single dedicated laptop kept completely offline. This machine ran a host Ubuntu operating system, which housed a virtualized Flare VM and the SANS forensic toolkit.
While this setup was functional, it introduced problems:
- Long Setup Time: Physically retrieving the laptop, booting up, entering multiple keys, and configuring VMs ate up 5 to 10 minutes of critical triage time before analysis could start.
- Risky Manual Data Transfer: Being fully air-gapped made moving data tedious and risky. Analysts had to manually copy files via USB or type complex URLs by hand.
- Single-User Access: As a single physical laptop at HQ, only one analyst could use it at a time, creating immediate backlogs during concurrent alerts.
This setup created an even bigger issue when the team started working from home. Analysts spent about 25% of their time working remotely. If a threat hit on a remote day, workers could not use the office laptop at all, leaving dangerous security gaps.
Before, we were carefully selecting the stuff that we really want to analyze, because it was just so much work, and for everything else, it was easier to just assume true positive.
Philipp Z., Security Lead
On top of that, testing just one file took so much time and effort that the five-person team could only check a tiny fraction of their alerts. They had to constantly pick and choose which suspicious files to inspect and which ones to skip completely.
Since they couldn’t check every alert, the team had to assume the worst every time. Whenever a suspicious file popped up, they would disconnect the user’s computer and completely wipe it, reinstalling everything from scratch. While this brute-force method kept the network safe, it dumped a huge amount of extra work on the IT staff and left employees unable to work for hours.
The Solution: Building a Scalable, Cloud-Managed Interactive Triage Workspace
To break free from the constraints of physical hardware and manual setup times, the company needed an enterprise-grade solution for triaging files and URLs that was completely isolated, cloud-managed, and accessible from anywhere. They found the answer in ANY.RUN’s Interactive Sandbox.
During my time as a student, I was able to experience the platform first hand. The usability is great, the options that you have are great… And of course, as an enterprise, the pricing is also great.
Philipp Z., Security Lead
ANY.RUN fit the company’s security team needs perfectly, giving them a safe, central workspace without any of the old setup headaches:
- Complete Safety and Privacy: The sandbox runs entirely in a private cloud, kept totally separate from the company’s main network. Analysts can open dangerous files and links with zero risk of spreading malware, infecting their own computers, or exposing sensitive data.
- Distributed and Remote-Ready: Being cloud-managed, ANY.RUN is accessible from any location. Whether the team is working in the office or from home during their remote office rotations, they have identical access to deep behavioral analysis.
- Fast, Interactive Triage: The team created a quick, simple workflow. When users report suspicious emails or potential phishing links, analysts simply copy the link, paste it into ANY.RUN, interact with the live virtual machine to observe behavior, and receive a definitive verdict in seconds.
While the immediate visual verdict in ANY.RUN is sufficient for the team’s rapid daily triage, documenting these investigations is critical for compliance. The team relies on ANY.RUN’s comprehensive reporting feature for audit support.
The verdict is usually enough for our daily analyst work. We download the report for archival stuff, and if the compliance department wants to have a review at our work… Two or three months later, someone wants to ask, ‘Hey, why did you decide on this specific case?’ I don’t know, I have had a thousand cases in the meantime, so I have to look at the report. And then I say, ‘Okay, this is why we responded like that.
Philipp Z., Security Lead
ANY.RUN proved so effective that the company gave licenses to two Exchange email admins. Strict filters often quarantine normal emails, which used to drag security analysts away from major threats. Now, email admins safely test held files and links in ANY.RUN’s Interactive Sandbox themselves, quickly releasing clean messages without wasting the security team’s time.
SOC Results: Shrinking Response Times and Fueling Analyst Engagement
The biggest quick win after starting with ANY.RUN was how much faster the team could process security alerts. By cutting out all the manual steps of setting up a physical laptop and configuring virtual machines, the team now saves an average of 15 minutes on every single alert they investigate.
In median, I think we were able to take 15 minutes from every alert response, just by using ANY.RUN, without anything else, without the analysis time and the time it saves us. Just by being able to look at the process tree, just the whole starting VM pointing stuff there alone per incident, 15 minutes. Which is a lot if you are time-critical…
Philipp Z., Security Lead
These time savings directly help the team take fast action against serious security threats. The company maintains an impressive response goal of just 2.5 minutes from the moment a dangerous alert goes off to completely locking down the affected device.
By making threat analysis almost instant and easy, ANY.RUN gives the five-person team the extra power they need to handle heavy workloads. Instead of making risky compromises or guessing which alerts matter, the team can now easily check every single suspicious link, reported email, or flagged file that comes their way.
Before, we were carefully selecting the stuff that we really want to analyze, because it was just so much work, and for everything else, it was easier to just assume true positive. But now, we just like to put anything we deem suspicious into ANY.RUN and have a look… My team is handling 20, 30, 40 tasks per day, so it is good at scale.
Philipp Z., Security Lead
To ensure the integrity of their triage, Philipp’s team actively tracks a key performance indicator, KPI agreement rate with ANY.RUN’s true/false positive classifications. Currently, it stands at 95%, showing total confidence in their threat determinations.
In an industry with high workloads and tedious tasks, repetitive workflows regularly lead to professional exhaustion. Introducing ANY.RUN has directly improved the team’s daily work environment.
ANY.RUN just makes the job fun, because you just point the VM, you can explore it, you can try to see what happens if you execute the malware, and then dig deeper from the process tree… It is definitely a good addition to the team, because SOC burnout is very much a threat that I want to prevent in my team.
Philipp Z., Security Lead
By removing the non-rewarding and exhausting physical chores of the legacy system, the job has once again become an engaging, investigative experience. Analysts are now empowered to safely and interactively explore how threats operate, digging deep into process trees and visual execution paths.
How ANY.RUN Helped Detect an Encrypted Multi-Stage Email Threat
A good example of ANY.RUN’s hands-on value happened when the team had to investigate a complex attack designed to exploit the blind spots of automated security.
The incident began when their XDR system flagged a suspicious shortcut (.lnk) file being opened on a computer. Following strict protocol, the analyst immediately isolated the machine to stop any potential threat from spreading while they investigated.
Using the computer’s history logs, they traced the file back to a web download, which led them back to an incoming email. To uncover the full, multi-stage delivery architecture, the analyst detonated the suspicious email from the XDR in ANY.RUN’s Interactive Sandbox. The analysis revealed the following attack chain:
- The Vector: The spear-phishing email contained a benign-looking PDF attachment.
- The Redirect: Inside the PDF was a malicious link directing the user to download an external archive.
- The Stealth Layer: This external archive was an encrypted, password-protected ZIP file. Critically, the decryption password was only displayed as text within the PDF attachment itself.
Because the ZIP archive was encrypted, automated mail gateway filters and static antivirus scanners were unable to parse or inspect the files hidden inside.
Looking at the process tree, we could clearly see the progression from Outlook to Edge, and finally to the malware execution. This process tree allowed us to visually confirm that the exact execution path we observed on our employee’s endpoint was mirrored safely inside the ANY.RUN virtual machine.
Philipp Z., Security Lead
This precise match gave the team absolute certainty that they had identified the exact source of the infection. Without ANY.RUN, the phishing email would have remained active on the mail server, posing an active threat of lateral forwarding or secondary infection.
An antivirus alert for us is not the end of a report, but the start… The email wasn’t automatically removed because the context was missing from the email to the finally malicious execution chain. Without the ANY.RUN analysis, we supposedly would not have been able to remove the email, so maybe it would have been forwarded or used to execute on another device.
Philipp Z., Security Lead
Equipped with the full context from ANY.RUN, the SOC team systematically searched for and purged the malicious email from all other user mailboxes across the organization.
It’s such a perfect example that I have saved the active ANY.RUN analysis link for internal training. It shows the team, from start to finish, exactly how an infection path moves from an email to a web-downloaded encrypted archive, and finally to a payload executing on the device.
Philipp Z., Security Lead
Business Value: Hard ROI and a Leap in Cybersecurity Maturity
Deploying ANY.RUN delivered an immediate Return on Investment (ROI) and a leap in operational maturity.
For a lot of C-suite or manager people that just look at the numbers, it’s hard to get a clean return on investment number, because IT security just costs something… But for me personally, I think the biggest indicator that really works is just the time. If you have a look at the time that a SOC analyst costs, and just look at the numbers for the time saved per incident, you can directly get a good return number.
Philipp Z., Security Lead
Instead of being forced to hire additional highly specialized analysts to handle an escalating threat landscape, the existing 5-person team seamlessly absorbs a massive enterprise workload, completely stabilizing labor costs while keeping the company secure.
Beyond the financial metrics, ANY.RUN has catalyzed a profound shift in the company’s internal security posture, representing a significant jump in maturity.
For us internally, it definitely was a big jump in maturity, going from a small team that handles these incidents manually with a laptop, to handling incidents cleanly, timely, and at scale. You can’t put a price tag on usability, but it’s just so much easier now.
Philipp Z., Security Lead
The security team has evolved from a small group reacting slowly through manual, localized workflows into a highly efficient, distributed operation capable of investigating enterprise-level threats at scale.
By providing a lightning-fast sandbox that analysts actually enjoy using, the firm has built a more resilient, highly motivated, and burnout-free defensive unit.
Ultimately, ANY.RUN gives the German manufacturer the technical agility to respond to threats effectively, protecting both their physical operations and their standing as a trusted global industrial partner.
Conclusion
For this German manufacturer, managing a footprint of 10,000 endpoints with a team of only five colleagues required a highly efficient way to analyze daily security threats. Replacing their manual, physical forensic laptop with ANY.RUN streamlined this process, saving a median of 15 minutes of setup and analysis time per alert. This practical optimization has allowed the compact team to comfortably handle 20 to 40 tasks daily, prevent analyst burnout, and support a jump in the team’s internal operational maturity.
We would like to extend our sincere thanks to Philipp Z. for sharing his team’s experience and showing how a lean team can successfully keep a large enterprise footprint secure.
About ANY.RUN
ANY.RUN is a leading provider of interactive malware analysis and threat intelligence solutions trusted by more than 16,000 organizations worldwide, including 74% of the Fortune 100.
Its Interactive Sandbox and Threat Intelligence solutions help SOC teams analyze suspicious files and URLs, uncover malicious behavior, enrich investigations with actionable context, and connect related activity across infrastructure and campaigns.
This helps security teams reduce investigation time, lower MTTD and MTTR, and contain threats before business impact grows.