Forum Discussion

Deleted's avatar
Deleted
Aug 25, 2022

Searching for all IOC's or different types in all logs(?) and maybe via file for import?

Hi everyone!

I am sure there have been similar questions, but sadly, I am not really finding anything of clear and specific enough to implement in any practical way.

 

I would like to:

  1. Scan for IOC's.
    1. These IOC's can be multiple types (Hashes (MD5, SHA1,SHA256), IP's, url's, or files etc)

  2. Scan for them in all relevant systems/Tables. (I have available: Alerts,Apps/Identities,Email & Collaboration, Devices, Threat & Vul. Management)

  3. Potentially also, rather than copy/paste into the query-editor, can it be done by placing into a file (any-type such as txt or csv for example), and then reference that in the query to obtain the many types of IOC's???

Thanks in advance you guru's!

2 Replies

Resources