Cross-case IOC pivot
Type any entity - a hash, IP, PID, registry key - and see every case it appears in. This is one indexed Aurora query across the entire corpus; the file-based engine cannot do it.
Showing entities that appear in more than one case.
| Entity | Kind | Cases | Facts | Seen in |
|---|---|---|---|---|
▣8128 | pid | 3 | 12 | |
▣8712 | pid | 3 | 12 | |
▣1096 | pid | 3 | 9 | |
▣8260 | pid | 3 | 7 | |
▷sysvol/windows/temp/ncpa-2.0.4.exe | appcompatcache | 3 | 6 | |
▣6036 | pid | 3 | 6 | |
▣7868 | pid | 3 | 6 | |
⊞pid:1096:irtimer:28 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:104 | handle | 3 | 3 | |
⊞pid:1096:tpworkerfactory:16 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:40 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:108 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:112 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:132 | handle | 3 | 3 | |
⊞pid:1096:directory:knowndlls32 | handle | 3 | 3 | |
⊞pid:1096:directory:knowndlls | handle | 3 | 3 | |
•pid:2216 | cmdline | 3 | 3 | |
⊞pid:1096:etwregistration:152 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:156 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:160 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:168 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:36 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:148 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:44 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:52 | handle | 3 | 3 | |
⊞pid:1096:event:120 | handle | 3 | 3 | |
⊞pid:1096:event:124 | handle | 3 | 3 | |
⊞pid:1096:event:4 | handle | 3 | 3 | |
⊞pid:1096:event:56 | handle | 3 | 3 | |
⊞pid:1096:event:60 | handle | 3 | 3 | |
⊞pid:1096:directory:basenamedobjects | handle | 3 | 3 | |
⊞pid:1096:iocompletion:12 | handle | 3 | 3 | |
⊞pid:1096:file:\device\harddiskvolume2\windows\syswow64 | handle | 3 | 3 | |
⊞pid:1096:etwregistration:144 | handle | 3 | 3 | |
⊞pid:1096:iocompletion:164 | handle | 3 | 3 | |
⊞pid:1096:iocompletion:80 | handle | 3 | 3 | |
⊞pid:1096:irtimer:180 | handle | 3 | 3 | |
⊞pid:1096:irtimer:188 | handle | 3 | 3 | |
⊞pid:1096:irtimer:20 | handle | 3 | 3 | |
⊞pid:1096:file:\device\harddiskvolume2\windows | handle | 3 | 3 |