We’ve just subscribed to the Community threat which details a number of IOCs related to the Chrysalis backdoor i.e. Notepad++.
While I know this monitors ingested logs and alerts for anything new that comes in matching these IOCs, does it also look over historical logs to check for any matches too?