Creating and Debugging Custom Rule Par 3 Payload Contains

preview_player
Показать описание
Link to a Box folder with a file with an index of the most recent videos, go to the second page and look for a file named Security Intelligence Tutorial, Demos & Uses Cases Version XXX.pdf
Рекомендации по теме
Комментарии
Автор

Nice work Jose. Please while writing a rule that will aggregate many IP addresses or usernames, how do i see the fileds when the rule fire.
Eg, a network port scan rule (same source IP, different destination IPs) How will i see the destinattion IPs when the rule fire?

dromdominic
Автор

You are the best Jose. I want to know one thing can I download IBM Qradar to my lab for free ? And how i improve my rule writing skills ? is having any resourse for both of I asked questions ?

bairammamedov