The "Enrich Case with File Analysis in ANY.RUN Sandbox" workflow template automates the process of analyzing file attachments from Torq Cases using the ANY.RUN interactive sandbox. This workflow is designed for security analysts to streamline threat intelligence enrichment and case management. It extracts and submits case attachments for analysis, retrieves detailed reports, and updates the case with critical security insights, including threat levels, scores, and behavioral tags. If the analysis identifies malicious or suspicious activity, the workflow further enriches the case by attaching detailed HTML reports and Indicators of Compromise (IoCs), enhancing the organization's incident response capabilities.
Use Cases
Case Management , Endpoint Detection and Response (EDR) , Threat Intelligence Enrichment
Workflow Breakdown
Lists case attachments and prompts the analyst to select a file.
Generates an attachment download link, submits the file to ANY.RUN Sandbox, and attaches the live sandbox link to the case.
Polls ANY.RUN until the analysis completes, then retrieves the report and extracts IoCs (IPs, URLs, file hashes).
Updates the case with a note containing threat level, scores, and behavioral tags from the sandbox verdict.
If the verdict is malicious or suspicious, runs parallel actions to attach the HTML report and (when IoCs exist) attach an IOC.csv to the case.
Vendors
Utils, ANY.RUN, Torq Cases
Workflow Output
Enrichment summary containing the analysis report details and extracted IoCs.
