IBM QRadar SOAR

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  Community App Round-Up

    Posted 12/18/18 08:50 PM
    This week saw a number of newly released Community-Provided Apps on the IBM Security App Exchange, with helpful functions to enhance the capabilities of your Resilient incident response workflows. With more Community Apps on their way, this thread is intended to provide an update of the newest releases.

    We appreciate any feedback on the current community apps and also if there are specific use cases you think we should cover. Use this thread to connect with our team or contribute feedback to your community.

    Google Cloud Functions to Sandbox:
    Serverless platforms have many applications: for incident response teams, this app shows use of Google Cloud Functions to perform URL investigations in the cloud without exposing your internal IPs. The cloud function used by this example workflow leverages a headless chrome instance to consume a URL and screenshot the result.

    IPinfo IP Address Enrichment:
    When investigating IP addresses, the IPinfo.io service provides information such as the geographic location, ASN, and hostname of the IP address. This integration provides a workflow function to query IPinfo for artifacts or other Resilient incident data.

    MxToolbox:
    The MxToolBox service provides a range of investigative tools for email routing (MX) and other DNS information, DNSBL blacklists, and general-purpose networking utilities (ping, traceroute). This package allows you to integrate these MxToolbox queries into your Resilient workflows and capture the results for further analysis.

    Pastebin:
    If you need to share information via Pastebin, this function will write pastes and store the shareable link in Resilient artifacts or notes. If you'd like to see another example of how Pastebin can work with Resilient check out this video on the IBM Security YouTube channel that shows an orchestrated response to email security alerts using a combination of functions.

    Pipl:
    This package contains a function that enriches user information (name, email address or social media username) from Pipl and retrieves personal, professional, demographic, and contact information. The response is structured data that can be displayed in a table or integrated into your other response activities.

    Search Twitter:
    A Resilient Circuits Function that allows a user to search tweets with one or more tags. Results are saved as a Rich Text note, or can be integrated into custom workflows.

    URL to DNS:
    This simple function takes a URL artifact and extracts the DNS name. This allows the correlation of artifacts between cases where the base DNS Name is the same, but the URL is different. It also allows threat intelligence lookups against the DNS Name instead of the target's unique URL, providing wider coverage.

    Wiki Lookup:
    The Resilient Wiki is the resource library within the Resilient platform. It holds documents that contain shared reference information such as breach notification requirements and incident response guides. This function can perform a lookup of these Wiki pages from a workflow. The lookup can be performed manually or automatically, and is helpful for referencing static data such as watchlists.

    ------------------------------
    Hugh Pyle
    ------------------------------