IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Auto Trigger WHOIS Lookup for DNS Name Artifacts

    Posted Mon May 02, 2022 06:07 PM
    Hello,

    I'm wondering if there's a way to automatically trigger the WHOIS lookup that's available within DNS Name artifacts?

    I'd like to have the report auto pulled so it doesn't require manual action.

    Here's a screenshot of the WHOIS section of a DNS Name artifact:


    Thanks!

    ------------------------------
    Liam Mahoney
    ------------------------------


  • 2.  RE: Auto Trigger WHOIS Lookup for DNS Name Artifacts

    Posted Tue May 03, 2022 04:29 AM
    At this moment, there is no built-in way to automatically pull the Whois report on SOAR standalone.

    ------------------------------
    Gilbert Liao
    ------------------------------



  • 3.  RE: Auto Trigger WHOIS Lookup for DNS Name Artifacts

    Posted Mon September 09, 2024 12:31 PM

    Any update to this?  Can the software do this now?



    ------------------------------
    Joshua Cochran
    ------------------------------



  • 4.  RE: Auto Trigger WHOIS Lookup for DNS Name Artifacts

    Posted Tue September 10, 2024 03:44 AM

    The built-in Whois function (as shown in the original post above) cannot be automatically triggered, but there are apps you can use in rules or playbooks to automate the lookup.

    e.g. "RDAP/WHOIS function for SOAR" app https://exchange.xforce.ibmcloud.com/hub/extension/423ad33ee836d572276a8524f86bf11e

    It also includes a manual rule for your reference.



    ------------------------------
    Gilbert Liao
    ------------------------------