Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates
Brief
Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. ANY. RUN ’s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity.
The release brings a more connected Threat Intelligence Lookup experience, broader threat coverage, and new research on active campaigns and emerging malware, giving analysts more context to investigate threats, reduce manual work, and act with greater confidence.
Product Updates
This month’s product update focuses on making threat intelligence easier to investigate and act on. Threat Intelligence Lookup now gives analysts a clearer path from a single indicator to related infrastructure, relevant observables, and the next step in the investigation.
All credited sources
Highest-trust first. Dates are the publisher's original publish time.
Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates
Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. ANY. RUN ’s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity.
The release brings a more connected Threat Intelligence Lookup experience, broader threat coverage, and new research on active campaigns and emerging malware, giving analysts more context to investigate threats, reduce manual work, and act with greater confidence.
Product Updates
This month’s product update focuses on making threat intelligence easier to investigate and act on. Threat Intelligence Lookup now gives analysts a clearer path from a single indicator to related infrastructure, relevant observables, and the next step in the investigation.
New Connections Block in TI Lookup for Faster Threat Investigation
Threat Intelligence Lookup now makes it much easier to move from a single indicator to the wider network context around it. Instead of piecing together separate results, analysts can quickly follow related observables, focus on what matters, and move from a TI query to the next investigation step with less manual work.
The Domains, IPs, and URLs tabs have also been updated to make related observables easier to explore and pivot between. Whitelisted data is hidden by default, helping analysts focus on potentially relevant activity without legitimate infrastructure crowding the results.
TI Lookup Connections bringing related observables into one investigation view
Analysts can also export filtered results in JSON , so selected observables can be reused for retrohunting, checked against SIEM/NDR data, added to blocking workflows, or passed to Detection Engineering for further action.
Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates
Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. ANY. RUN ’s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity.
The release brings a more connected Threat Intelligence Lookup experience, broader threat coverage, and new research on active campaigns and emerging malware, giving analysts more context to investigate threats, reduce manual work, and act with greater confidence.
Product Updates
This month’s product update focuses on making threat intelligence easier to investigate and act on. Threat Intelligence Lookup now gives analysts a clearer path from a single indicator to related infrastructure, relevant observables, and the next step in the investigation.
New Connections Block in TI Lookup for Faster Threat Investigation
Threat Intelligence Lookup now makes it much easier to move from a single indicator to the wider network context around it. Instead of piecing together separate results, analysts can quickly follow related observables, focus on what matters, and move from a TI query to the next investigation step with less manual work.
The Domains, IPs, and URLs tabs have also been updated to make related observables easier to explore and pivot between. Whitelisted data is hidden by default, helping analysts focus on potentially relevant activity without legitimate infrastructure crowding the results.
