2021-03-17 03:29 AM
I am looking for any possible way to search of huge list of Malicious hashes in one go for all file in Endpoint hybrid. I know there is one way to search for one hash at a time.
2021-03-21 08:57 AM
Couple ways I do it, one is with SOAR, and use a playbook to launch a load of the hashes and then a query back to the specific concentrators or decoders creating alerts when finding the specific use case. Other way I know is to build a app rule with the specific query and then carve from there. I think RSA recommends this in the hunting process as well for malicious indicators.