Skip to main content

Cyware Threat Intelligence eXchange

QRadar

Connector Category: Security Information and Event Management (SIEM)

About Integration

IBM QRadar is a Security Information and Event Management (SIEM) application that provides real-time visibility into your IT infrastructure and helps you accelerate threat detection and prioritization. This integration enables CTIX to update the Reference Sets in the QRadar application with CTIX data (as an internal application).

The QRadar internal application in Intel Exchange supports the following actions:

Action Name

Description

Update Reference Set

This action updates the reference sets of the IBM QRadar application with the data retrieved from Intel Exchange.

To configure QRadar as an internal application, do the following:

Configure QRadar as Internal Application

Before you Start 

  • You must have the URL, username and password, or authentication token of your QRadar account to configure the QRadar app in CTIX.

  • You must have the view and update tool integration permissions.

Steps 

  1. Sign in to the CTIX application.

  2. From Administration, open Integration Management, and select Internal Applications under Tool Integrations.

  3. Select Security Information and Event Management System.

  4. Look for QRadar and click on the app.

  5. Click Add Instance.

  6. Enter the instance name and base URL.

  7. Choose from the following authentication types:

    • Choose Username/Password and enter the User Name, and Password.

    • Choose Authentication Token and enter the token value to connect to the Qradar instance.

  8. To secure the connection between CTIX and QRadar server, select Verify SSL.

  9. Click Save.

Enable Update Reference set

After configuring the Qradar application on CTIX, enable the actions to update Qradar reference sets.

  1. From Administration, open Integration Management, and select Internal Applications under Tool Integrations.

  2. Select Security Information and Event Management System.

  3. Select QRadar and click the vertical ellipsis on the top right corner of the screen, and click Manage.

  4. Click Manage Action(s).

  5. Select the action to enable.

  6. Enable the toggle to update the reference sets.

  7. Click Save.

Create a Rule in CTIX to Update Reference Set in Qradar

From the Main Menu, select Rules under Actions.

Click New Rule.

Enter a rule name and a description.

Add any tags to easily identify and categorize components in the CTIX application.

Click Submit.

Set the following optional global conditions for a rule from Basic Details:

  1. Allow All Conditions: Applies all available conditions on the selected threat data object. When selected, the system notifies that the previously selected conditions will be removed, and the Conditions under Components on the left side of the screen are removed.

  2. Run Rule after Enrichment: Runs the rule only after data enrichment and confidence score evaluation are completed.

  3. Triggers on Manual Update: Triggers the rule to run for any manual update made to the existing threat data object by an analyst. It will not execute the rule for any new threat data objects coming into the application. This option removes the previously selected sources and collections and prompts you to confirm to allow all sources and collections for the trigger to update the threat data object.

  4. Exclude False Positive: Excludes the identified false positives to filter the data. By default, this option is selected and no false positives are included. This option ignores any conditions configured in the rule to remove false positive threat data objects.

  5. Exclude Indicators Allowed: Excludes the identified allowed indicators to filter the data. By default, this option is selected and no allowed indicators are included. This option ignores any conditions configured in the rule to remove the allowed threat data objects.

Define the Sources and collections, Conditions, and Actions for this rule.

In Actions, choose the following:

  1. Actions - Update Reference Set

  2. Application - QRadar

  3. Account - Choose the QRadar account.

  4. Choose the reference data set from QRadar. You can only see 10,000 reference sets at any given moment.

  5. Select Add or Remove as the Operation to retain or remove the IOC from the reference set.

Click Save.