Hi Martin, I don't know logrun.
I was able to make it work.
I had issues with the customs event properties which was not actived for it.
Thanks
------------------------------
Benjamin Yabre
------------------------------
Original Message:
Sent: Fri April 21, 2023 02:47 AM
From: Martin Schmitt
Subject: How to exploit Crowdstrike IOC ingested into Qradar
Hi Benjamin,
are you aware of logrun? For a first test it is useful. If you know how the logs should look like or if you can get them somewhere or find logs been similar and change them slightly like having the md5 for which the rule is designed it is quite helpful.
Have a great day!
Martin
------------------------------
Martin Schmitt
Original Message:
Sent: Thu April 20, 2023 10:44 AM
From: Benjamin Yabre
Subject: How to exploit Crowdstrike IOC ingested into Qradar
I have installed Corwdstrike app to ingest their IOC to Qradar.
I would like to know how to exploit these IOC with my rule.
can someone help me with the steps ?
Thanks
------------------------------
Benjamin Yabre
------------------------------