Community Threats and Historical Logs

We’ve just subscribed to the Community threat which details a number of IOCs related to the Chrysalis backdoor i.e. Notepad++.

While I know this monitors ingested logs and alerts for anything new that comes in matching these IOCs, does it also look over historical logs to check for any matches too?

It does not, in order to do so you would need to leverage log search

David

FYI we have a webinar coming up on this topic tomorrow

https://www.brighttalk.com/webcast/10457/661975

David