Hello,
The Application Configuration Guide lists the applications that are defined by default -
https://www.ibm.com/docs/en/qsip/7.4?topic=guide-default-applications.Can you please tell me how Qradar detects such applications as Web.Malware(sql), Web.Malware(blacklist), Web.Malware(flux)? What algorithm is used?
What level of thread visibility do I need to provide for analysis? Would it be sufficient to parse the first 64 bytes payload? Or do I need to do full packet capture?
I would like to understand how it works in order to use it in my rules.
For example:
and when the flow matches Application is Web.Malware(sql)
or
and when the flow matches Application is any of [Web.Malware(blacklist) or Web.Malware(flux)]
Thanks!
------------------------------Aleksey Zhorov------------------------------------------------------------
Aleksey Zhorov
------------------------------