Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Responder QRadarAutoClose #441

Closed
cyberpescadito opened this issue Mar 19, 2019 · 1 comment
Closed

Responder QRadarAutoClose #441

cyberpescadito opened this issue Mar 19, 2019 · 1 comment
Assignees
Labels
category:feature-request Issue is related to a feature request scope:responder Issues/PRs pertaining to responders
Milestone

Comments

@cyberpescadito
Copy link
Contributor

Hi,

I want to share with you a responder that i wrote in python. He is working on my hive platform so I believe it's ready to use.

The main purpose of this responder is to close in one clic a QRadar offense from a TheHive case.

How it works:

Installation and configuration:
-Intall it in your Cortex Analyzers folder, in the responder section
-On Cortex WebUI, configure your QRadar console URL, an API key (service token), and a certificate if needed.

Use It:
-On TheHive, provide to your case the related QRadar offense ID in a customfield "externalReferences" (this have to be the customfield Internal Reference). I recommend to automatically fulfill via script this customfield when importing offenses as alert
-Clic the responder, and it will automagically close the offense in QRadar. That's all :-)

Happy threat hunting ;-)

@cyberpescadito cyberpescadito added the category:feature-request Issue is related to a feature request label Mar 19, 2019
@jeromeleonard jeromeleonard added this to the 2.2.0 milestone Oct 1, 2019
@jeromeleonard jeromeleonard self-assigned this Oct 1, 2019
@jeromeleonard jeromeleonard added the scope:responder Issues/PRs pertaining to responders label Oct 1, 2019
@jeromeleonard
Copy link
Contributor

thank you for your contribution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:feature-request Issue is related to a feature request scope:responder Issues/PRs pertaining to responders
Projects
None yet
Development

No branches or pull requests

2 participants