Lab Title |
Abstract |
Building UAX Federated Search Connectors in QRadar Suite |
Learn how to build a custom federated search connector for IBM Security QRadar Suite using STIX-shifter; an open source project under the Open Cybersecurity Alliance. STIX-shifter is a python library that connects and queries products that house data repositories by using STIX Patterning, and returns results as STIX Observations. This session will cover the structure and major classes of STIX-shifter, mapping fields between STIX and a target data source, translating STIX patterns into native queries, translating query results into STIX objects, how a connector communicates with the data source via APIs, and how to test a connector with STIX-shifter’s CLI commands. |
Understanding the Fundamentals of Playbook Building |
New to building Playbooks? Still using the old Workflows? This lab will help establish the similarities and differences of the old Workflows and the new Playbooks model. We will discuss how to make complex SOP style and simple automation style playbooks so that you will be ready to establish new or start the conversion of your playbooks. Quickly build new scripts, utilize functions, and add tasks for your analysts to complete and more as we work to build the fundamental knowledge of automations. |
"SOAR: Configuring The QRadar SOAR Plugin" |
Now that you have all of telemetry and visibility of your threat and its behavior, you ever stopped to ask yourself the question: "what do I do about it?" Well in this session we will help you configure the very connected tissue that brings our SIEM and SOAR together, allowing you to complete the life cycle of your incident response triage from end to end. |
Better Together: QRadar SIEM + SOAR + EDR End To End |
In this lab, you will learn how to bring our portfolio together in a very simple yet wholistic way, allowing you to unlock the endless posibilities for solving threats from end to end when we are better together. |
How to Fight Fraud |
Trustboard - How to fight fraud with offline investigation - How to fight fraud in real time (web, mobile) - SOAR integration - how to automate the response |
Mobile Threat Mgmt and Mobile Threat Defense (Qradar & Zscaler Integration) |
In this instructor-led lab you will learn best practices for Deploying iOS, Android and Windows devices, Distributing applications, Enforcing policy compliance, and Protecting devices from advanced mobile threats" |