IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  YARA & Sigma Rule Manager, Permissions for Adding/Enabling Rules

    Posted Mon November 25, 2024 10:06 AM
    Edited by SIEM-2020 Wed November 27, 2024 12:58 AM


    The Yara & Sigma Rule Manager seems to be a valuable app for Threat Hunting an we would like to use.  However the permissions cause some headache in our environment where we have 4 User with Admin role and 20 users with Analyst role.  Maybe we are just missing the rights knobs or settings  and someone can point us to a solution. 

    Installation requires an API Key with Admin Userrole.  When we try a less privilged role, the app configuration of the API key fails. However, we do not want to give Permission to all of our SIEM users to add and enable rules on the fly.   The normal role modell, does not allow this either.

    Is there a way to allow AQL based hunting with this App,  but inhibit creation of rules ?    Often the rules are payload based searches and can have a performance impact. Or can we at least make sure, that new rules are added in "Disabled" state ? 



    ------------------------------
    SIEM-2020
    ------------------------------



  • 2.  RE: YARA & Sigma Rule Manager, Permissions for Adding/Enabling Rules

    Posted Wed December 11, 2024 06:03 AM

    Hello, 

    After install have you completed the following steps:
    https://www.ibm.com/docs/en/qradar-common?topic=checklist-assigning-user-capabilities-manager-yara-sigma-rules



    ------------------------------
    Comghall Morgan
    QRadar Support Architect
    IBM
    ------------------------------



  • 3.  RE: YARA & Sigma Rule Manager, Permissions for Adding/Enabling Rules

    Posted Wed December 11, 2024 07:30 AM

    Hello Morgan, 

    yes, we completed that step.  This is  mandatory to make the App visible to users in  non Admin userroles. 

    However the API-Key assigned to the App requires admin permission and admin userrole. 

    This results in a situation where any user with access to the App can install rules, regardles of the permissions of his own user role. 



    ------------------------------
    SIEM-2020
    ------------------------------