Best community based AIO Cyber Security Portal
Use Cases and Deployment Scope
We have integrated IBM-Xforce with our SIEM(IBM Qradar). The IBM X-force threat intel enables us to research security threats, aggregation of intelligence via SIEM rules, and collaborate with peers.
Pros
- Ready made security research on threats.
- Security Intel
- Integrate threat intel feeds with SIEMs.
Cons
- Pruning of IOC to reduce false positives.
- Add more flexibility to integration on SIEMs to allow users to compare UserAgents, Compromised users/domains like HIBP.
- Only watch vulnerabilities for selected vendors.
Most Important Features
- Threat Intel Feeds& Confidence ratings.
- Security Research
- IOC/Collection Timelines
Return on Investment
- Threat Intel - Low Confidence IOC - Overhead.
- Lack of integration with IBM Qradar+Vulnerability via X-Force.
Alternatives Considered
CrowdStrike Falcon Endpoint Protection
Other Software Used
Darktrace, Trend Micro Cloud One - Conformity, Fortinet FortiGate
