Skip to content

semsaksoy/qradar_usom

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

16 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Qradar USOM Integration

"USOM" is a cyber intelligence sharing platform provided by Turkey's government. USOM publishes malicious sites when it detected so that this project ensures that the list is stored in the reference set and kept up to date in order to be used in QRadar rules.

Installation

The project doesn't need any dependencies, just run the following command on the QRadar CLI as root.

bash <(curl -s https://raw.githubusercontent.com/semsaksoy/qradar_usom/master/usom_install.sh)

Result

ss1 This installation script will download the usom update script and add it to the cron so that it runs on an hourly basis.

ss2 Reference data view

Example

ss3 Rule conditions

ss4 Rule response

ss5 Offense view

ss6 Events view

Scripts are not official IBM solutions. IBM highlights Modified (YUM) is not supported through all other installations of non-QRadar software modules, RPMs, or Yellowdog Updater. Use at your own risk.

About

USOM cyber intelligence integration with Qradar

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages