In the Kaspersky CyberTrace web user interface, you can select the Retroscan page. To access this page, you need to switch to the System management mode. This mode is accessible only to users with the Administrator role.
Before using retrospective scan, you must enable and configure it. Later, you can also change the retrospective scan settings.
Retrospective scan allows you to rescan incoming events with objects (IP address, domain, URL, or hash) that were not considered malicious. The reason for checking these results could be that at the time of receiving such objects, Kaspersky CyberTrace did not contain information about related threats. However, because threat data feeds are regularly updated, it can be useful to save events that do not contain detected indicators, and then use updated indicators lists to rescan these events manually or according to a schedule.
Retroscan detections are included in the statistics and displayed on the Detections page, as well as on the graph, like all common detections. The results of retrospective scan are sent to the SIEM system. As well as for usual detections, the filters for sending retroscan detections to SIEM are also applied.
When a retrospective scan is in progress, all non-context values obtained from the events by applying the regular expressions specified in the retrospective scan settings on the Regular expressions tab are matched with the new indicators of the feeds enabled on the Feeds tab.
You can edit or add new regular expressions by selecting the Settings → Event sources page. If saved, the regular expressions will be available in the retrospective scan settings section on the Regular expressions tab.
In case of detection, the events that appeared in Kaspersky CyberTrace after adding an indicator to a feed will be displayed on the Detections page and will not be subject to retrospective scan.
If an indicator was added to a feed after its IP/Hash/URL had been obtained by means of a regular expression used in a retrospective scan, and if there were no detections related to this indicator, then the next retrospective scan run will display information about this indicator in the Detected indicators column, while the Date and time column will display the date and time of the indicator detection by the retrospective scan.
Each event related to this indicator will have its own record in the retrospective scan report.
The Retroscan page allows you to launch the retrospective scan manually and view the results when the scan process is finished.
On this page, you can perform the following actions:
This page also displays the following:
The size of events is displayed with a delay of up to one hour. The actual current size of saved events may exceed the displayed value.
The table contains the following columns:
The result contains detected indicators.
The result does not contain detected indicators.
The retrospective scan process was canceled.
The retrospective scan process failed.

Retroscan results
Launching a retrospective scan
To launch a retrospective scan,
Click the Start now button.
If needed, you can cancel the scan process.
Launching the retrospective scan can be unavailable for several reasons:
Configuring display of retrospective scan results that contain detection alerts
To display only the results that contain detection alerts,
Select Show only retroscan results with detection above the Results table.
Specifying the results period
You can specify the time period for displaying results by selecting one of the options above the Results table. You can select one of the following periods:

Specifying the time period for retroscan results
Viewing results of a single retrospective scan
To view detailed information about a single retrospective scan task:
On the page that opens, you can find detailed information about the first 50 detection events. To see all events, download the full report in CSV format (see below).
On the page, the following information is displayed:
Date and time shown on the scan results page may differ from the date and time indicated in a report in CSV format. This occurs due to UTC settings: UTC+0 is always used in a report in CSV format, while the time on the scan results page depends on the custom settings.
You can view detailed information about each indicator by expanding the bar with the indicator that you want. This information is contained in the following fields:
Downloading a report with the results of the retrospective scan
To download a report,
Click the Download full report button.
The generated CSV file contains the following data:
Date and time shown on the scan results page may differ from the date and time indicated in a report in CSV format. This occurs due to UTC settings: UTC+0 is always used in a report in CSV format, while the time on the scan results page depends on the custom settings.