TheHive-Project / TheHive-Project/Cortex-Analyzers
IBM QRadar Analyzer
Open
Nobody has claimed this yet.
category:feature-request
help wanted
scope:analyzer
- Dominant language
- Python
- Stars
- 490
- Forks
- 405
- Avg merge
- 2d 43m
- Merged PRs (30d)
- 8
Description
Request Type
Feature
Description
Adding a new analyzer for Cortex : IBM QRadar (https://www.ibm.com/support/knowledgecenter/SS42VS_7.2.6/com.ibm.qradar.doc/c_rest_api_getting_started.html)
Would be great if we could:
- Submit a IOC and retrieve info of events related to it from QRadar
- Submit a number of offense and import the Observables related to it from QRadar to TheHive
- Etc.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names no target files or tests; start by locating the repository's existing analyzer implementations and reading the linked IBM QRadar REST API documentation. Define which IOC and offense queries are supported, then verify that related events and observables can be imported into TheHive.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100