|
Run a single query.
|
Select Single query, enter a file hash, IP address, domain, or URL in the search field, then submit the
query. The result is added to the Query history table.
|
|
Run a bulk query.
|
Select Bulk query to validate multiple objects at once.
-
Click Download sample file to get the CSV template.
-
Fill in the objects following the sample format, then upload the file. You can query
up to 1,000 IoCs per CSV file.
-
Bulk queries are processed asynchronously. After processing completes, the queried
objects appear in Query history, where you can review results and apply response actions.
|
|
Review query results.
|
The Query history table lists every previously queried object. Each entry includes the following information:
-
Object: The queried indicator value, for example a file hash, IP address, domain, or URL.
Click the object to view detailed information.
-
Object type: The type of the queried object, for example File MD5, File SHA-1, File SHA-256,
IP address, Domain, or URL
-
Detection name: The TrendAI™ detection name assigned to the object, if TrendAI™ has determined the object to be malicious and covers it with a detection. Displays
a dash if no detection exists.
-
Sandbox analysis: The Sandbox Analysis result for the object, if the object has been analyzed. Displays a dash if the object
has not been submitted.
-
Associated threats: The number of known threats, emerging threats or threat actors, associated with
the object. Click the number to view the associated threats.
-
Third-party insights: Detection results from third-party intelligence sources, shown as a ratio, for example
33/74 for the number of sources flagging the object as malicious out of the total
sources queried
-
Last query time: The date and time the object was most recently queried, in YYYY-MM-DD HH:MM:SS format.
Results are sorted by this column by default.
|
|
Filter the Query history table.
|
Select options to display objects with specific criteria:
|
|
Export the Query history table.
|
Click Export to download the table contents as a CSV file.
|
|
Apply response actions to one or more objects.
|
Select the check box next to one or more objects to display the action toolbar:
-
Create report and sweep: Creates a custom intelligence report from the selected objects and starts a sweep
of your environment for matches.
-
Type a Report name.
-
Optionally, select Extract domain, file SHA-1, file SHA-256, IP address, and URL objects then add them
to the Suspicious Object List to also add the extracted objects to the Suspicious Object List. Selecting this option displays additional settings:
-
Risk level: Select the risk level to assign to the extracted objects.
-
Select the action to apply for each detected object type: Domain, File SHA-1, File SHA-256, IP address, and URL.
-
Expiration: Select whether the extracted objects automatically expire from the Suspicious Object
List after a specified number of days, or never expire.
-
Click Submit.
A confirmation message displays when the report is created and the sweep starts. If
report creation or sweeping fails, refresh the page and try again.
-
Query in XDR Data Explorer: Opens XDR Data Explorer to search your environment's activity data for the selected objects.
-
Send to Sandbox: Submits the selected URL objects to Sandbox Analysis for analysis in a secure virtual environment. Only URL objects support this action.
-
Add to block list: Adds the selected objects to the Suspicious Object List for detection and response by connected products.
-
Delete: Removes the selected entries from Query history.
|