RFE added for enhanced IOC hunting capabilities in WebUI Query - http://www.ibm.com/developerworks/rfe/execute?use_case=viewRfe&CR_ID=123426
It would be extremely useful if the BigFix Labs ‘Client Relevance Builder’ functionality was added to WebUI (Query) so users who aren’t experts at creating relevance can build their own IOC specific queries if a template is unavailable.
The relevance builder would, as a minimum need to include File, SHA, Process, Registry, Services inspectors but the more the better.
Use case : SOC operators are hunting down an IOC but the templates provided in Query only allows for individual queries to be run. If they had the flexibility to build and search for a file with a specific hash and reg key/value, that would be a huge value add.
An example would be something like this -
exists running application “badapp.exe” AND exists file “myfile.exe” whose (sha1 of it = “9d749c3cfdc4fbacb4190e7bec892094e5a3f65a”) of folder “C:\Temp\Test” AND (exists keys “HKLM\Software\MyCompany\Test” whose (exists values whose(name of it = “IOC” AND it as string as lowercase = “True” as lowercase ) of it) of registry)
Whilst I appreciate this content can be developed manually, a client relevance builder would reduce user error, and make the process for hunting extremely flexible and easy