IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Is there a "blacklist" of application hashes

    Posted Thu March 25, 2021 09:01 AM

    Hi, is there a blacklist of hashes of (bad / malicious / suspected) mobile applications (as you can find those in google play store / apple store) that can be used in qradar to check the app hashes i reive in certain events against when people install app on their device ?



    #QRadar
    #Support
    #SupportMigration


  • 2.  RE: Is there a "blacklist" of application hashes

    Posted Thu March 25, 2021 08:06 PM

    Hi, no-One ? is my question not clear maybe ?

    Just let me know

    If we do not keep[ track of thios on x-force maybe some ideas on other locations where to find such lists ?

    thanks



    #QRadar
    #Support
    #SupportMigration


  • 3.  RE: Is there a "blacklist" of application hashes

    Posted Fri March 26, 2021 07:17 AM

    Hi.

    I guess you can use a reference list for this. And correct me if I'm wrong, but don't we get such intel right into the box from x-force?



    #QRadar
    #Support
    #SupportMigration


  • 4.  RE: Is there a "blacklist" of application hashes

    Posted Fri March 26, 2021 07:44 AM

    Hi yes thanks, surely a reference list can be used to implement it but the question here is if such a list is already maintained so that we dont have to build / maintain it ourselves ??? Maybe in x-force ? Maybe elsewhere ... it would need both iOS and Android apps ...

    thanks koen



    #QRadar
    #Support
    #SupportMigration


  • 5.  RE: Is there a "blacklist" of application hashes

    Posted Wed March 31, 2021 08:43 PM

    Hi, no updates ? I could imagine that there is a list of malicious mobile device apps ?



    #QRadar
    #Support
    #SupportMigration


  • 6.  RE: Is there a "blacklist" of application hashes

    Posted Thu May 06, 2021 08:59 AM

    Hello koenkleingeld,

    it is correct that IBM QRadar uses X-Force malware data. This database is extensiv but focuses more on regular malicious files instead of iOS and Android apps.

    Regards

    Manuel Hauptmann



    #QRadar
    #Support
    #SupportMigration