Replies: 1 comment
-
You could use an Elastalert rule and query back since the beginning of your data , you could technically develop a Sigma rule, and have Playbook convert it for you, or you could use a simple bash script to create your ad-hoc query for you with something like the following:
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi all,
I have a list of SHA256 (134 of them) that I need to search for. What's the best way to do that, manually will take forever.
Thanks
Monah
Beta Was this translation helpful? Give feedback.
All reactions