Code Monkey home page Code Monkey logo

crowdsec-qradar-app's Introduction

CrowdSec QRadar App

QRadar App which allows users to leverage CrowdSec's Smoke CTI to get information about IP as seen by CrowdSec's network. This is enabled via a right click on IP GUI action. The intelligence includes:

  1. Types of attacks the IP has been observed performing.
  2. Background Noise Score. This can be used to know whether the particular IP is only targeting your infrastructure or is targeting others too.
  3. Aggressivity which quantifies frequency of attacks.
  4. Other fields like Geolocation details, AS details, sighting details etc

Configuration

We need to provide the App, CrowdSec CTI API Key. You can find the instructions to obtain it here

Now navigate to the CrowdSec App in QRadar's Admin page. Click on CrowdSec App Settings Icon.

CrowdSec App Settings

A pop-up will appear. Enter the API Key and click on Submit.

CrowdSec App Settings Popup

The App is now configured !

Usage

Navigate to Log Activity pane in QRadar. Right click on an IP either in Source IP or Destination IP column. Hover over "More Options". You will see a new option "CrowdSec IP Lookup". Click on it.

CrowdSec Right Click Option

This will open a popup with the information about the right clicked IP found in CrowdSec's Smoke Dataset.

CrowdSec App Popup

You can click on the "Show" button to see the RAW JSON response from the API.

JSON View

References

You can find our latest taxonomy about attack details, classifications, scores etc in our official docs

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.