IBM Cloud Security Advisor
IBM Cloud Security Advisor is a centralized security management platform that helps organizations monitor, detect, and respond to security threats and compliance issues across their IBM Cloud infrastructure and workloads. This comprehensive security service provides unified visibility into security posture, vulnerabilities, configuration issues, and potential threats within IBM Cloud environments.
| Category | Vulnerability management |
| Direction | Query source |
| Sign-in | API Key |
| Query languages | STIX |
| Website | ibm.com |
Before you start
Huntbase signs in to IBM Cloud Security Advisor with API Key. Create the credential in IBM Cloud Security Advisor first, then keep it to hand for the Connect step.
See the IBM Cloud Security Advisor documentation for how to create this credential.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect IBM Cloud Security Advisor
- Go to Connections and click New connection, or click New connection on the IBM Cloud Security Advisor product page.
- On Product, pick IBM Cloud Security Advisor and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your IBM Cloud Security Advisor lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | Specify the IP address or hostname of the data source. |
Credentials
The only Method is API Key. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| Account ID | Yes | Account ID of IBM Cloud Security Advisor. Secret — not shown again after you save it. |
| API Key | Yes | API Key of IBM Cloud Security Advisor. Secret — not shown again after you save it. |
Query it
Once connected, IBM Cloud Security Advisor can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog