Forensic and Retrospective Search
Searching through months or years of event data to find an indicator match can be a time consuming and resource-intensive process. Anomali Search provides the turbosearch operator that is purpose-built to rapidly search through large datasets and identify malicious indicators in your events that were logged in the past. This operator is ideal for examining event data across large time spans such as the last 7 days, 30 days, or up to 90 days.
When Schema RBAC is active for your organization, the schema filters in your assigned roles determine which data this feature returns. An eventlog filter limits your results to only the eventlog data your role permits, and an OCSF filter limits your results to only the OCSF data your role permits. If a query runs against a schema for which your role has no filter assigned, the query returns a forbidden error. For details, see Role-Based Access Control for Schemas.
Note: Similar to all search operations on Security Analytics, the turbosearch operator searches events that fall within the data retention policy associated with your subscription license. See Anomali Search Data Retention Policy to understand how your data is retained over time in the Anomali platform.
Use cases
You can use the turbosearch operator for the following applications:
-
Forensic or retrospective searches
-
Threat hunting
-
Needle in a haystack scenarios
See the turbosearch operator documentation for more information on its syntax and the different threat indicator types it supports.