IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  QRadar 7.3.1 as IPS

    Posted Wed February 12, 2020 02:47 PM
    Im having distributed deployment of QRadar 7.3.1.
    I have created a custom rule to detect IP Scanning on my network, and rule is working fine.
    Now using Custom Action, I want QRadar not only to generate an offence when someone connects to my network device but ALSO to disable the ethernet port  of router / firewall at which the attacking laptop is connected. By writing custom scripts, can i make my QRadar to log in to the firewall (Juniper) and execute JunOS commands to disable that specific port.
    Any help in this regard will be highly appreciated.
    Regards.

    ------------------------------
    Shahzad Ahmed
    ------------------------------


  • 2.  RE: QRadar 7.3.1 as IPS

    Posted Thu February 20, 2020 08:37 AM
    Hi @Shahzad Ahmed,

    I am not an expert in Juniper but I think it is doable. Just one challenge I am thinking about.
    1) I am not sure you will get what ethernet port the attacker is connected to, in the log from QRadar. (Excude me if I am wrong)

    QRadar can do the login to the firewall and disable the port (I would probably say block the IP/ MAC instead of port)​

    ------------------------------
    Chinmay Kulkarni
    ------------------------------