QRadar Creating a rule that fires with internal communication to C&C or bad site

  Рет қаралды 25,043

Jose Bravo

Jose Bravo

Күн бұрын

Пікірлер
@jbravovideos
@jbravovideos 6 жыл бұрын
Threat Intelligence App allows feeds of IOCs via STIX/TAXII to be placed on Reference sets for rules to use. RFSI are mostly a set of smart rules.
@tedahd5004
@tedahd5004 6 жыл бұрын
what are the relations between Threat Intelligence app and Reference Set and the Package (RFISI) ?
@collinp72
@collinp72 5 жыл бұрын
Jose - where is the best place to get the logs to replay as you have shown. Do you have any that can be used or is there a repository somewhere you van point us to?
@rktumuluri
@rktumuluri 7 жыл бұрын
Mr Jose Bravo, Your videos are quite usefull. Can u share related "data-sets" etc to allow us to complete the tutorial.
@djangoWarri0r
@djangoWarri0r 2 жыл бұрын
Heyy, i am looking for a way to cater spaces in my command, For example, i am testing a rule WMIC to execute local process. The command to do this is. Cmd>wmic process call create notepad.exe Now, it can be any process in my rule i say, command contains any of wmic process call create but it do not works due to spaces b/w args. How would you cater cases like these in which an offense should be generated based on the part of command available in event. Thanks
@jagadishyellulla8057
@jagadishyellulla8057 7 жыл бұрын
Hi Jose Bravo, Thanks for the video. I'm unable create Authorized Service Token, saying application error. Could u please help me out.
What Makes QRadar So Special 2017
19:26
Jose Bravo
Рет қаралды 13 М.
黑天使被操控了#short #angel #clown
00:40
Super Beauty team
Рет қаралды 61 МЛН
The evil clown plays a prank on the angel
00:39
超人夫妇
Рет қаралды 53 МЛН
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
Rule to write to a Reference Set
7:13
Jose Bravo
Рет қаралды 1,5 М.
QRadar: Rules, Offenses and Searches - Best Practices
33:41
Big Blue Helps
Рет қаралды 1,2 М.
QRadar  Logs, Network Flows, QFlows and VFlows working for you
15:42
QRadar Detecting Phishing emails
13:28
Jose Bravo
Рет қаралды 24 М.
Proxy vs Reverse Proxy vs Load Balancer | Simply Explained
13:19
TechWorld with Nana
Рет қаралды 286 М.
QRadar: All about QRadar Rules - Part 1
22:50
Big Blue Helps
Рет қаралды 10 М.
How DeepSeek AI Helped Me Create Maps Effortlessly
9:49
GeoDelta Labs
Рет қаралды 788 М.
QRadar: Creating your first search
8:59
Big Blue Helps
Рет қаралды 1,3 М.
黑天使被操控了#short #angel #clown
00:40
Super Beauty team
Рет қаралды 61 МЛН