IBM QRadar EDR
IBM QRadar EDR (Endpoint Detection and Response) is an advanced cybersecurity platform designed for threat detection, investigation, and response across enterprise endpoints. This solution provides comprehensive visibility into endpoint activities, enabling security teams to identify, analyze, and remediate security incidents, malware infections, ransomware attacks, and advanced persistent threats (APTs) targeting workstations, servers, laptops, and other computing devices.
| Category | EDR |
| Direction | Query source |
| Sign-in | None |
| Query languages | STIX |
Before you start
The setup page can't take credentials for IBM QRadar EDR yet. Create the connection, then contact Huntbase support to finish signing it in.
For the vendor's own instructions, see QRadar EDR API application documentation.
Connect IBM QRadar EDR
- Go to Connections and click New connection, or click New connection on the IBM QRadar EDR product page.
- On Product, pick IBM QRadar EDR and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your IBM QRadar EDR lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The hostname of your QRadar EDR Hive server. |
| Port | Yes | Set the port number that is associated with the hostname or IP address. Defaults to 443. |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Query it
Once connected, IBM QRadar EDR can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog