do I need to run the malware and run the query aro...
# general
p
do I need to run the malware and run the query around the developed IOC
c
Just create an IOC around what the query is searching for, yes. no need to run actual malware