About QAPPS

QLEAN suite QRadar extensions boost functionality, enhance user experience, and often replace costly commercial alternatives. These additions significantly improve system efficiency and user workflow.

QRadar Incident Notifier

Customizable notifications via:

  • Email, SMS, Telegram, Slack, MS Teams, and Jira
  • Automatic offense assignment to analysts
  • Configurable notification content and routing
  • Version: Loading...
    Uploaded: Loading...

    WinCollect Assisted Deployment

    Automates WinCollect agent (v7.3.1-22) deployment and configuration:

  • Flexible deployment profiles
  • Auto-detection for Windows Security, Application, System, IIS, DHCP, DNS, Exchange, SQL, custom
  • XPath filtering
  • Includes Sysmon
  • Remote monitoring/upgrades
  • Version: Loading...
    Uploaded: Loading...

    LDAP Data Enrichment

    Syncs QRadar reference data with Active Directory and LDAP stores.

  • Scheduled syncs
  • Supports complex LDAP queries
  • Detailed config
  • Version: Loading...
    Uploaded: Loading...

    VirusTotal Integration

    Integrates VirusTotal's API with IBM QRadar SIEM to analyze process hashes, detect malicious software, and generate offenses.

    QVTI requires Sysmon log data collected by WinCollect agents.

    Version: Loading...
    Uploaded: Loading...

    Network Hierarchy Management

    Extends QRadar to manage network hierarchy backups and restoration.

  • Scheduled/on-demand backups
  • User-created NH in CSV format
  • Validation
  • Version: Loading...
    Uploaded: Loading...

    QArtifact

    Provides comprehensive context by attaching various artifacts, including files, images, and links, directly to offenses.

    Version: Loading...
    Uploaded: Loading...

    TOR Nodes Monitoring

    Monitors Tor network connections, fetching Tor relay and exit node data from onionoo.torproject.org

    Includes the app and detection rules.

    Version: Loading...
    Uploaded: Loading...

    Missing Logs Alert

    Improves log source monitoring by allowing user-defined timeout values for different log source groups.

    Version: Loading...
    Uploaded: Loading...

    MS Exchange Audit

    Enables MS Exchange Admin and Mailbox Audit logs collection via Syslog.

    Version: Loading...
    Uploaded: Loading...

    Dynamic License Allocator

    Automatically re-allocates licenses across Managed hosts to handle EPS and FPM spikes.

    Version: Loading...
    Uploaded: Loading...

    Slow Search Alert

    Proactively notifies administrators via email about stalled searches.

    Version: Loading...
    Uploaded: Loading...

    Log Source EPS Details

    Fetches EPS statistics per log source, based on user-defined thresholds. Visualizes EPS trends in a dedicated QRadar tab, enabling users to analyze and drill down into EPS spikes.

    Version: Loading...
    Uploaded: Loading...

    MITRE ATT&CK for Windows

    Leverages Sysmon logs such as process creation, network connections, and file access, to provide correlation rules aligned with the MITRE ATT&CK framework.

    Version: Loading...
    Uploaded: Loading...

    MITRE ATT&CK for Linux

    Uses auditd logs to cover MITRE ATT&CK tactics and techniques.

    Auditd configuration guide included.

    Version: Loading...
    Uploaded: Loading...

    DGA Analyzer

    Identifies potentially malicious domains created by Domain Generation Algorithms (DGAs) by analyzing DNS query logs.

    Version: Loading...
    Uploaded: Loading...

    Session Manager

    Streamlines user session tracking and investigation, even when usernames are missing in logs (e.g., firewall, IDS/IPS, web server, OS, database). Allows searching by username or IP (right-click integration in the Log Activity tab) and specify a timeframe to retrieve session data.

    Version: Loading...
    Uploaded: Loading...

    Log Source Inventory

    Generates automated, scheduled Excel reports to track log source activity, using a default 12-hour timeout and a custom 72-hour timeout to distinguish between short-term and long-term inactivity.

    Version: Loading...
    Uploaded: Loading...

    Offense Reporter

    Generates configurable, domain-separated Excel reports covering all offenses (active, inactive, closed), including key details such as closing date and reason, notes, and closed-by user.

    Version: Loading...
    Uploaded: Loading...

    Find Similar Offenses

    Speeds up offense investigations and rule tuning with a button to quickly find similar offenses (triggered by the same rule).

    Version: Loading...
    Uploaded: Loading...

    Exclude From Correlation

    Adds a button to temporarily whitelist offense source values (e.g., IP, username) directly from the offense page, reducing repeated notifications during investigation or recovery.

    Version: Loading...
    Uploaded: Loading...