QRadar Indicator Hunting V2
The Playbook queries QRadar SIEM for indicators such as file hashes, IP addresses, domains, or urls.
- Pack
- QRadar
- Tasks
- 57
Inputs
- MD5 — MD5 hash file or an array of hashes to search.
- QradarMD5Field — MD5 field to search in QRadar. If none are specified, the search will use a payload contains filter.
- SHA1 — SHA1 hash file or an array of hashes to search.
- QradarSHA1Field — SHA1 field to search in QRadar. If none are specified, the search will use a payload contains filter.
- SHA256 — SHA256 hash file or an array of hashes to search.
- QradarSHA256Field — SHA256 field to search in QRadar. If none are specified, the search will use a payload contains filter.
- IPAddress — Source or destination IP to search. Can be a single address or an array of addresses.
- QradarIPfield — IP field to search in QRadar. If none are specified, the search will use sourceip or destinationip (combined).
- URLDomain — Domain or Url can be single or an array of domain/urls to search. By default the LIKE clause is used.
- QradarURLDomainField — URL/Domain field to search in QRadar. If none are specified, the search will use a payload contains filter.
- TimeFrame — Time frame as used in AQL Examples can be LAST 7 DAYS START '2019-09-25 15:51' STOP '2019-09-25 17:51' For more examples review IBM's AQL documentation.
- InternalRange — A list of internal IP ranges to check IP addresses against. The comma-separated list should be provided in CIDR notation. For example, a list of ranges would be: "172.16.0.0/12,10.0.0.0/8,192.168.0.0/16" (without quotes).
- InvestigationIPFields — The values of these QRadar fields will be used for the playbook IP addresses outputs.
- InvestigationUserFields — The values of these QRadar fields will be used for the playbook user name outputs.
Outputs
- QRadar.DetectedUsers — Users detected based on the username field in your search.
- QRadar.DetectedInternalIPs — Internal IP addresses detected based on fields and inputs in your search.
- QRadar.DetectedExternalIPs — External IP addresses detected based on fields and inputs in your search.
- QRadar.DetectedInternalHosts — Internal host names detected based on hosts in your assets table. Note that the data accuracy depends on how the Asset mapping is configured in QRadar.
- QRadar.DetectedExternalHosts — External host names detected based on hosts in your assets table. Note that the data accuracy depends on how the Asset mapping is configured in QRadar.
Commands used
- qradar-assets-list
- qradar-search-retrieve-events