Click here to view the original link.
I am considering scheduling a search to return if any IOCs are found from various sources I get e.g. CISA, MSISAC, EDR company, etc. I have a basic lookup:
ip,source_desc
5.252.179.169,waterisac
5.252.179.89,waterisac
I tried what I thought would work in search and then went to AI to refine it because it was returning my internal IPs not the IPs in the lookup:Links for this message:
image.png
