malware analysis, IR, DFIR, threat hunting, threat intel, blue team, phishing kits, Author of @PhishKitTracker project
Oct 5, 2020 • 76 tweets • 57 min read
Hey for all you #infosec friends stuck with #ibm#qradar just like me, just remember it’s still better than having no #siem at all. Here is my contribution to the community, a mega thread of qradar tips to improve your life
equals is case sensitive
username equals 'neonprimetime'
will not find 'Neonprimetime'
(notice the capital N)
from the GUI use contains to be case insensitive!