IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

June 2019 submissions to App Exchange

  • 1.  June 2019 submissions to App Exchange

    Posted Wed July 03, 2019 02:45 PM

    We've made a number of new publications to the IBM App Exchange for Resilient which I'm happy to announcement. Below are the submissions and a brief description of the functionality.

    * IBM Supported Apps

    Ansible - These functions allow for the running of Ansible Playbooks and Modules as part of your incident investigation and remediation actions. Playbooks provide an extensible capability to control, monitor and effect change in an Enterprise's computer infrastructure.

    Data Feeder - These capability allows one to create an duplication of the Resilient objects (incident, notes, artifacts, attachments, etc.) for the purpose of data analysis. A variety of data-stores are supported including SQL databases, Splunk, ElasticSearch and flat fire json data representation. Any number of Business Intelligence (BI) tools can be used for reporting and analysis.

    * Community Apps

    netMiko - This integration supports a variety of firewalls which can be interrogated and configured using SSH. We will develop and publish direct integrations for a number of firewalls which will compliment this general solution.

    Google Cloud DLP - This integration brings capabilities to Resilient to identify and redact personally identifiable information (PII) in a body of text. PII information includes credit card numbers, names, social security numbers, US and selected international identifier numbers, phone numbers, GCP credentials, etc.

    Task Helper Functions - A number of integrations have been written to manage your incident tasks within a workflow. This package includes
    * Task creation
    * Task updates
    * Task completion
    * Task note creation

    SpamHaus - This integration allows a Resilient user to submit an IP Address or Domain Name artifact to SpamHaus to check if it's found in its blocklist.

    PhishTank - Lookup a URL against PhishTank's database to verify if the URL is a known Phishing site.

    If there are integrations you're interested in, please let us know. Some may already be on our roadmap and your interest can help us prioritize their rollout. There may also be other companies with capabilities already written which they can share on the App Exchange for the entire community.



    ------------------------------
    Mark Scherfling
    ------------------------------