IBM QRadar

Overview

IBM® QRadar® is a SIEM platform that provides situational awareness and compliance support. QRadar uses a combination of flow-based network knowledge, security event correlation, and asset-based vulnerability assessment.

 

Integration Benefits

This integrations will allow to automatically crosscheck all the log sources already onboarded into QRadar against Maltiverse Threat Intelligence feeds for IP, Hostnames, URL’s and file Hashes related fields. That will automatically trigger new alerts pointing out to possible Security Incidents

It enables you to rapidly research the latest global security threats, aggregate actionable intelligence, consult with experts and collaborate with peers.


Reference Set Mapping


In order to configure Maltiverse Feeds into QRadar Threat Intelligence APP it is needed to map each maltiverse feed with a reference set and then create a Rule to generate offenses whenever there is a match. The following table relates the most relevant Collections with a recommendation of a reference set to map with and an explanation of the rule logic:

Collection (Maltiverse Feed)Observable TypeReference SetRule Logic
Command and ControlsIPv4 AddressBotnet C&C IPswhen any of Destination IP are contained in any of Botnet C&C IPs
Command and ControlsDomain NameMalware Hostnameswhen any of Domain are contained in any of Malware Hostnames
Malware DistributionIPv4 AddressMalware IPswhen any of Destination IP are contained in any of Malware IPs
Malware DistributionDomain NameMalware Hostnameswhen any of Domain are contained in any of Malware Hostnames
Malware DistributionURLMalware URLswhen any of Request URL are contained in any of Malware URLs
MalwareFile HashMalware Hashes SHAwhen any of File Hash are contained in any of Malware Hashes SHA
PhishingURLPhishing URLswhen any of Request URL are contained in any of Phishing URLs
Malicious URLsURLMalicious URLswhen any of Request URL are contained in any of Malicious URLs
Trial