IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

Β View Only
Expand all | Collapse all

QRadar CE Features: UBA, SOAR, MITRE, Threat Feeds – Included or External?

  • 1.  QRadar CE Features: UBA, SOAR, MITRE, Threat Feeds – Included or External?

    Posted 15 days ago

    Hello Everyone,

    I have a quick question regarding IBM QRadar Community Edition.

    I would like to know whether the following features are included by default in the Community Edition or need to be integrated externally:

    🧠 UBA (User Behavior Analytics)
    πŸ” Threat Intelligence Integration
    πŸ—ΊοΈ MITRE ATT&CK Mapping Tools
    πŸ›°οΈ STIX/TAXII-based IBM Threat Intelligence Feeds
    πŸ€– SOAR (Security Orchestration, Automation and Response) – via IBM Resilient or any built-in capabilities

    If anyone here is an experienced QRadar user, I'd really appreciate it if you could also share the pros and cons of using QRadar (especially the Community Edition) in a lab or small-scale setup.

    Thanks in advance for your help and insights!



    ------------------------------
    Ashwin Gedekar
    ------------------------------


  • 2.  RE: QRadar CE Features: UBA, SOAR, MITRE, Threat Feeds – Included or External?

    Posted 15 days ago

    Ashwin, I just answered your setup question, pls have a look as well. As outlined already the CE edition is a standard image designed as AIO running a special license. However there a very little restrictions besides the fact that it is designed as a single box with performance limited to whatever hardware you have got. The idea is to install it on top of VMware. Regarding your questions: UBA yes  , Threat Intelligence yes, MITRE Attack mappimg yes, STIX/TAXII feeds yes. For SOAR you should have a look at the new cloud services integration (license needed). Everything else is included. Some Apps need to be extra installed like UBA or need extra integration work as STIX based feed. 

    BR



    ------------------------------
    [Karl] [Jaeger] [#ibmchampion]
    [QRadar Specialist]
    ------------------------------