Webinar Description
Key Takeaways
- Joint webinar from ANY.RUN and Elastic Security focusing on operationalizing threat intelligence within SOC workflows
- Addresses the challenge of keeping threat intelligence actionable as malicious infrastructure evolves
- Covers integration of indicators of compromise directly into Elastic Security for investigation and detection
- Designed for SOC analysts, threat intelligence analysts, threat hunters, detection engineers and SOC leadership
Turning Threat Intelligence into SOC Action
This webinar from ANY.RUN and Elastic Security examines a persistent challenge in security operations: translating threat intelligence into practical analyst workflows. Many SOC teams have access to threat intelligence feeds and data, but struggle to integrate that information into daily decision-making without creating additional manual workload.
The session focuses on maintaining threat intelligence relevance as attacker infrastructure shifts, a common problem when static indicator lists quickly become outdated. Presenters will demonstrate how threat context can inform alert prioritization, enabling analysts to make faster triage decisions with greater confidence.
Reducing Manual Enrichment Workflows
A significant portion of the webinar addresses the reduction of manual tasks that consume analyst time. This includes indicator of compromise lookups, enrichment processes and the context switching that occurs when analysts must move between multiple tools to gather information about a potential threat.
The presenters will cover methods for bringing fresh IOCs directly into Elastic Security, supporting both investigation and detection workflows. The goal is to make threat intelligence a scalable, integrated component of daily SOC operations rather than a separate process requiring dedicated effort.
Live Q&A with Vendor Experts
The session includes a live question and answer segment with experts from both ANY.RUN and Elastic Security, providing attendees the opportunity to discuss specific implementation challenges or workflow questions.
Who Should Attend
This webinar is intended for security operations professionals including SOC analysts, threat intelligence analysts, threat hunters, detection engineers, SOC leads and SOC managers. The content is most relevant to teams already using or considering Elastic Security who want to improve how threat intelligence supports their detection and response processes.

