Hello,
I would like suggestions regarding how to put together a query to find MD5 hashes.
There is a built-in query called Processes matching SHA-256 hashes in the last 30 days (below), but I would like to search for MD5 hashes not SHA-256, since that were the only values that was provided to me as IOCs. Thank you.
WITH split(sha) AS (
SELECT value
FROM
JSON_EACH('["' || REPLACE(REPLACE('$$sha_list$$', ' ', ''), ',', '","') || '"]')
)
SELECT DISTINCT
CAST(split.sha AS TEXT) AS sha256,
process_journal.pathname AS path,
process_journal.sophosPID AS sophos_pid
FROM split
LEFT JOIN sophos_process_journal AS process_journal ON
LOWER(split.sha) = process_journal.sha256
AND process_journal.time > STRFTIME('%s', 'now', '-30 days')
AND process_journal.eventType = 0
WHERE
split.sha != ''
AND process_journal.sophosPID != ''
Top Comments