Skip to content

crmade/OpenCanary-QRadarCE

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 

Repository files navigation

OpenCanary-QRadarCE

This is a project for integrating OpenCanary (Honeypot) with QRadar. This extension allows for the detection of cyber intrusions using opensource and free to use software. Combining the use of honeypots and monitoring software (SIEM), detecting and alerting abnormal internal activity is possible and easy to accomplish.

Installation:

  1. Download the zip file.
  2. Import the package from the extension management option in QRadar.
  3. Install the extension.
  4. Hunt for the bad guys!

Notes: 1/11/2022 When importing through the extension manager, the auto detection needs to be enabled manually. For this go to the admin tab, DSM Editor, search for OpenCanry, click on select button, select the tab Configuration and enable the first option: Enable Log Source Autodetection. Save it and close the window.

About

OpenCanay integration with QRadar

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published