IBM Security QRadar SOAR

 View Only
  • 1.  Menu Item Rules for Multiple Artifacts instead of one by one

    Posted Wed April 28, 2021 07:57 AM

    We using Resilient V40.1, We have more than 1500 artifacts which belongs to Different IP-Address, Range, Segment etc


    When we execute the action / workflow like blocking ip-address on a firewall , we need to do for each every ip-address one by one using menu-item rules.


    We do not want to create automatic rules, our team need to validate the ip-address/IoC based on threat intelligence lookups.


    Is there anyway to select multiple ip-address and execute the menu item rules at a time for selected 100 ip-address, so it will work in loop ? or any other way to achieve this.



    ------------------------------
    Sunil I B
    ------------------------------


  • 2.  RE: Menu Item Rules for Multiple Artifacts instead of one by one

    IBM Champion
    Posted Wed April 28, 2021 09:22 AM
    Hi Sunil,

    There's an RFE open about this idea here: https://2e4ccba981d63ef83a875dad7396c9a0.ideas.aha.io/ideas/R-I-455

    This is definitely a feature our team would love to see implemented too.

    One idea that I have is that you could create some kind of flag field ~'Do the IP addresses in this incident need to be blocked by the Firewall?' and include it within a task in the incident. Then you could make an automatic rule that would have the condition 'when the field above is set to True' run a workflow that blocks the IP addresses in the firewall. The analysts would need to be trained on that the question should only be answered after the IOCs have been validated. Not going to be helpful with any of the IP addresses / IOCs you have stacked up, but it could help in the future!

    ------------------------------
    Liam Mahoney
    ------------------------------



  • 3.  RE: Menu Item Rules for Multiple Artifacts instead of one by one

    Posted Thu April 29, 2021 09:56 PM
    Hi Liam Mahoney, 

    Thanks for the response, meantime any other alternative or workaround approach available ?




    ------------------------------
    Sunil I B
    ------------------------------



  • 4.  RE: Menu Item Rules for Multiple Artifacts instead of one by one

    Posted Mon December 13, 2021 10:36 PM
    Any updates on this on feature enhancement for multiple menu item rules.

    ------------------------------
    Sunil I B
    ------------------------------



  • 5.  RE: Menu Item Rules for Multiple Artifacts instead of one by one

    Posted Fri April 08, 2022 03:45 AM

    Multi-select artifacts or attachments featured implemented in Resilient Latest Version ? 



    ------------------------------
    Sunil I B
    ------------------------------