IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  X-Force Risky IP, Spam

    Posted Thu January 12, 2023 09:19 AM

    Hello,
    I am a bit confuse with X-Force Risky IP, Spam dection rule
     I would like to know if all those detected IP should be blocked or just to pay attention with ?

    thanks 



    ------------------------------
    Benjamin Yabre
    ------------------------------


  • 2.  RE: X-Force Risky IP, Spam

    Posted Mon January 16, 2023 09:48 AM
    Hello Benjamin,

    these free x-force rules serve as an offer to identify local connections to a remote destination that are classified as spam hosts according to x-force. This can ultimately help to question your own risk assessment in relation to the local address that establishes this connection...

    Regards,
    Ralph

    ------------------------------
    Ralph Belfiore
    SIEM Expert
    pro4bizz GmbH
    Karlsruhe
    +4972190981727
    ------------------------------



  • 3.  RE: X-Force Risky IP, Spam

    Posted Mon January 16, 2023 09:57 AM
    Hello Ralph,
    thanks ,
    I would like to know if I should trust the IP declared as SPAM by x-force rules is always 100% true ?
    thanks

    ------------------------------
    Benjamin Yabre
    ------------------------------



  • 4.  RE: X-Force Risky IP, Spam

    Posted Mon January 16, 2023 11:27 AM
    Hello Benjamin,

    if you review the rule for example with use case manager you'll see the confidence value greater than 85 is set as default..
    Those values managed by x-force are dynamic. You can review those ips by right click on the destination ip -> more options -> plugin options -> x-force exchange lookup.. There you'll find context about the x-force rating to adjust your individual decison how to deal with. It's useful context..

    Regards,
    Ralph

    ------------------------------
    Ralph Belfiore
    SIEM Expert
    pro4bizz GmbH
    Karlsruhe
    +4972190981727
    ------------------------------



  • 5.  RE: X-Force Risky IP, Spam

    Posted Mon January 16, 2023 11:40 AM
    Hello Ralph,
    thank you very much I appreciate.
    Best regards

    ------------------------------
    Benjamin Yabre
    ------------------------------