QRadar SOAR: Integration with Microsoft Active Directory (BQ440G)

Overview

Gain hands-on experience with the IBM Security® QRadar® SOAR platform. Learn how to integrate with Active Directory by using the LDAP and Active Directory Function for SOAR app integration. Explore the actions which can be performed from the SOAR platform to respond to cases which users are involved.

This course is designed and built on a QRadar SOAR stand-alone virtual machine (v50.1.54) with a complementary SOAR App Host (v1.14.1). However, the concepts that the course covers apply to all on-premises or SaaS versions of QRadar SOAR.

Audience

Security Operations Center (SOC) Analyst

Security Analyst 

Incident Responder 

Managed Service Security Provider (MSSP)

Prerequisites

null

Objective

What you will learn:

  • Gain hands-on experience with the SOAR console
  • Integrate the LDAP and Active Directory Function for SOAR solution
  • The actions that you can take on Active Directory from the SOAR platform

 

Skills you will gain:

  • SOAR Software
  • Playbooks
  • Threat response
Details anzeigen

Course Outline

Section 1: Video of LDAP and Active Directory integration with QRadar SOAR

Section 2: Lab