You have found a hash-based indicator of compromise (IOC) in an intelligence report and want to determine if the program has run in your environment. Which search would provide all of the process’ executions over the timeframe specified?
If you have a hash-based indicator of compromise (IOC) and want to determine if the corresponding program has executed in your environment, searching by hash is the most direct and effective method.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
NastyNutsu
2 months agoalanalanalan
7 months, 2 weeks ago[Removed]
9 months, 1 week agoTech_Amit
10 months, 4 weeks agogr23
1 year, 1 month agoSunaperi
1 year, 4 months ago