Searching

Updated 1 week ago by Elvis Hovor

You can use the Search bar at the top of the TruSTAR Web App to find Intel Reports and Indicators that contain a specified term.

You can use the Filter feature to apply Enclave, date, tags and Indicator filters when searching. 

Basic Searching

Search return all results that have a complete match with the term you specified. The count of results returned is displayed directly below the Search bar.

  • Click the IOCs count to display the Indicators that contain the search term.
  • Click the Reports count to display the Inte Reports that contain the search term.
Please note when searching that the default time frame is the last 90 days. Expand the Date Last Seen filter to view all results available.

Searching with Wildcards

You can use the wildcard character * at the start or end of the search term to find partial matches. For example, if you want to search for all variants on a domain name, you can add a * after the main part of the domain. For example, you can use the term "acme.*" to find all occurrences of Acme URLs, regardless of whether they end in .com or .biz or another domain.

Wildcard search is limited to two wildcard characters (*)

Advanced Searching

You can use operators like AND, OR, NOT and precedence as part of the match criteria.

To use operators and precedence, you must type /tsquery before the query string.

Enter /tsquery followed by the search string you want to use, then press the Enter key to start the search.

Supported Operators

Search For Reports that...

Search Type

Syntax

Contain a specific word in the Intel Report title

title-search

/tsquery title:<keyword1>

Have all specified terms (AND operator)

and-search

 /tsquery keyword1 + keyword2

Have at least one of the specified terms (OR operator)

or-search

/tsquery keyword1 | keyword2

Exclude the specified keyword

not-search

/tsquery keyword1 +- keyword2

Have multiple keywords, using multiple operands and apply precedence logic to the results

precedence-search

/tsquery keyword1 + ( keyword2 | keyword 3)

Contain a specific word in the report body

report-body

/tsquery body: <keyword1>

TruSTAR uses the Elasticsearch Search Query String format. Check this Elasticsearch support article for more information.


How Did We Do?