IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Learning Resilient Rules, Workflows and Playbooks.

    Posted Mon February 20, 2023 09:31 AM

    Hi guys,

    I have a query. I have been working on the Resilient administration side for a few months learning things. I have recently started working on rules, workflows and playbooks to get an understanding and learn them properly. 

    Could anyone provide guidance as to where I can learn them from scratch to a good level of understanding where I can create them easily?

    Support would be appreciated.



    ------------------------------
    Hamza
    ------------------------------


  • 2.  RE: Learning Resilient Rules, Workflows and Playbooks.

    Posted Wed February 22, 2023 10:25 AM

    Hi,

    For basic stuff, you could go to IBM Security Learning Academy: https://www.securitylearningacademy.com

    Just search for SOAR.

    For examples of scripts and how to handle  different SOAR operations, see the "resilient-script" section at https://github.com/ibmresilient

    Also, you might find interesting videos on youtube at the IR Gurus channel:  https://www.youtube.com/channel/UCDzfgxNNVskLfeUuZoTwoaA?app=desktop

    HTH



    ------------------------------
    Pierre Dufresne
    ------------------------------



  • 3.  RE: Learning Resilient Rules, Workflows and Playbooks.

    Posted Thu February 23, 2023 04:29 PM

    Have you attended any of the QRadar SOAR training? 
    https://community.ibm.com/community/user/security/events/event-description?CalendarEventKey=cb379bb1-bb4c-4d08-aae4-0186315c6366&CommunityKey=d2f71e8c-108e-4652-b59c-29d61af7163e



    ------------------------------
    Elizabeth Hecht
    ------------------------------



  • 4.  RE: Learning Resilient Rules, Workflows and Playbooks.

    Posted Fri February 24, 2023 06:47 AM

    Hi,

    Not sure if you check that, there's some SOAR Workshops also, eg. here for Europe, there's also another one for US time  https://community.ibm.com/community/user/security/events/event-description?CalendarEventKey=6b429fdb-23fd-4cad-ac15-0186316206b7&CommunityKey=d2f71e8c-108e-4652-b59c-29d61af7163e&Home=%2fcommunity%2fuser%2fsecurity%2fcommunities%2fcommunity-home%2frecent-community-events 



    ------------------------------
    David Dyen
    ------------------------------