IBM QRadar SOAR

 View Only
  • 1.  Auto Trigger WHOIS Lookup for DNS Name Artifacts

    Posted Mon May 02, 2022 06:07 PM
    Hello,

    I'm wondering if there's a way to automatically trigger the WHOIS lookup that's available within DNS Name artifacts?

    I'd like to have the report auto pulled so it doesn't require manual action.

    Here's a screenshot of the WHOIS section of a DNS Name artifact:


    Thanks!

    ------------------------------
    Liam Mahoney
    ------------------------------


  • 2.  RE: Auto Trigger WHOIS Lookup for DNS Name Artifacts

    Posted Tue May 03, 2022 04:29 AM
    At this moment, there is no built-in way to automatically pull the Whois report on SOAR standalone.

    ------------------------------
    Gilbert Liao
    ------------------------------



  • 3.  RE: Auto Trigger WHOIS Lookup for DNS Name Artifacts

    Posted Mon September 09, 2024 12:31 PM

    Any update to this?  Can the software do this now?



    ------------------------------
    Joshua Cochran
    ------------------------------



  • 4.  RE: Auto Trigger WHOIS Lookup for DNS Name Artifacts

    Posted Tue September 10, 2024 03:44 AM

    The built-in Whois function (as shown in the original post above) cannot be automatically triggered, but there are apps you can use in rules or playbooks to automate the lookup.

    e.g. "RDAP/WHOIS function for SOAR" app https://exchange.xforce.ibmcloud.com/hub/extension/423ad33ee836d572276a8524f86bf11e

    It also includes a manual rule for your reference.



    ------------------------------
    Gilbert Liao
    ------------------------------