Hello
In many environments, the QRadar Assets tab is used as a supporting investigation feature.
Some common use cases:
-- Identifying systems involved in an offense
-- Viewing hostname, IP, MAC address, OS, and service details
-- Understanding internal asset context during investigations
-- Asset-based rule tuning and correlation
-- Prioritizing offenses related to critical assets
-- Supporting threat hunting activities
Advantages:
-- Automatically builds asset profiles from logs and flow data
-- Provides additional context during offense investigation
-- Helps analysts quickly identify affected systems
-- Reduces the need to switch between multiple tools during analysis
Limitations observed:
-- Asset accuracy depends on proper log source integration
-- Incomplete or inconsistent logs can lead to outdated asset data
-- Requires proper asset reconciliation tuning for better results
The feature becomes more useful when:
-- Network flows are enabled
-- Log sources are properly configured
-- Vulnerability data is integrated
-- Asset reconciliation is tuned correctly
------------------------------
Anushka Gulave
------------------------------