Skip to main content

IBM Security Verify

IBM Security Verify is a comprehensive identity and access management (IAM) and identity governance platform that provides cloud-native identity as a service (IDaaS) capabilities for modern enterprises. This solution enables organizations to manage digital identities, control user access, enforce authentication policies, and secure applications across hybrid and multi-cloud environments.

CategorySecrets management
DirectionQuery source
Sign-inClient Secret
Query languagesSTIX
Websiteibm.com

Before you start​

Huntbase signs in to IBM Security Verify with Client Secret. Create the credential in IBM Security Verify first, then keep it to hand for the Connect step.

  1. In the IBM Security Verify admin console, go to Security › API access and select Add API client.
  2. Select the entitlement listed below, then save the client.
  3. On the client tile, open the action menu (three dots) and choose Connection details, then copy the client id and client secret.

Permissions:

  • readReports, which lets the client read SSO, authentication and management events. manageReports also works, but it grants more access.

For the vendor's own instructions, see IBM Security Verify API client documentation.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect IBM Security Verify​

  1. Go to Connections and click New connection, or click New connection on the IBM Security Verify product page.
  2. On Product, pick IBM Security Verify and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your IBM Security Verify lives:

FieldRequiredNotes
Server AddressYesThe hostname of your IBM Security Verify tenant, without https://.
PortYesSet the port number that is associated with the hostname or IP address. Defaults to 443.
Self-Signed Cert (PEM)NoProvide a self-signed or CA-signed certificate to securely communicate with the data source.

Credentials​

The only Method is Client Secret. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
Client IDYesClient ID of IBM Seurity Verify. Secret — not shown again after you save it.
Client SecretYesClient secret of Client ID of IBM Seurity Verify. Secret — not shown again after you save it.

Query it​

Once connected, IBM Security Verify can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​