ForeScout App for IBM QRadar

Similar documents
CounterACT NetFlow Plugin

ForeScout Extended Module for Qualys VM

ForeScout CounterACT. Windows Vulnerability DB. Configuration Guide. Updated February 2018

ForeScout App for Splunk

ForeScout Extended Module for Bromium Secure Platform

ForeScout Extended Module for ServiceNow

Use the Executive Dashboard

CounterACT Afaria MDM Plugin

CounterACT External Classifier Plugin

CounterACT Check Point Threat Prevention Module

CounterACT User Directory Plugin

CounterACT Aruba ClearPass Plugin

CounterACT Syslog Plugin

CounterACT Reports Plugin

CounterACT CEF Plugin

CounterACT Microsoft System Management Server (SMS) System Center Configuration Manager (SCCM) Plugin

CounterACT DNS Enforce Plugin

Control Network Vulnerabilities

Ensure Instant Messaging and Peer to Peer Compliance

Prevent Network Attacks

ForeScout Amazon Web Services (AWS) Plugin

Control Wireless Networks

Ensure Antivirus Compliance

Classify Assets. How-to Guide. CounterACT Version 7.0.0

CounterACT Advanced Tools Plugin

Classify Mobile Assets

Manage External Devices

ForeScout Extended Module for VMware AirWatch MDM

ForeScout CounterACT. Configuration Guide. Version 1.1

CounterACT Security Policy Templates

CounterACT Hardware Inventory Plugin

ForeScout Extended Module for MobileIron

ForeScout CounterACT. Assessment Engine. Configuration Guide. Version 1.0

ForeScout Extended Module for MaaS360

ForeScout Extended Module for IBM BigFix

Forescout. eyeextend for Palo Alto Networks Wildfire. Configuration Guide. Version 2.2

ForeScout CounterACT. Track Changes to Network Endpoints. How-to Guide. Version 8.0

ForeScout Extended Module for Advanced Compliance

Forescout. eyeextend for IBM BigFix. Configuration Guide. Version 1.2

ForeScout CounterACT. Ensure Instant Messaging and Peer to Peer Compliance. How-to Guide. Version 8.0

ForeScout Extended Module for Carbon Black

ForeScout CounterACT. Configuration Guide. Version 1.2

ForeScout Extended Module for IBM BigFix

Forescout. eyeextend for MobileIron. Configuration Guide. Version 1.9

ForeScout CounterACT. Configuration Guide. Version 5.0

Forescout. Configuration Guide. Version 3.5

ForeScout CounterACT. Plugin. Configuration Guide. Version 2.3

ForeScout Extended Module for HPE ArcSight

ForeScout CounterACT. Ensure Antivirus Compliance. How-to Guide. Version 8.0

Forescout. eyeextend for IBM MaaS360. Configuration Guide. Version 1.9

ForeScout Extended Module for ArcSight

ForeScout Extended Module for ServiceNow

Enterprise Manager/Appliance Communication

ForeScout Extended Module for Web API

Forescout. eyeextend for Carbon Black. Configuration Guide. Version 1.1

CounterACT Macintosh/Linux Property Scanner Plugin

Forescout. eyeextend for VMware AirWatch. Configuration Guide. Version 1.9

ForeScout CounterACT Linux Plugin

Forescout. Plugin. Configuration Guide. Version 2.2.4

ForeScout CounterACT. Controller Plugin. Configuration Guide. Version 1.0

ForeScout CounterACT. Plugin. Configuration Guide. Version 1.2

ForeScout CounterACT. Deploying SecureConnector as a Service as Part of a Machine Image. How-to Guide. Version 8.0

ForeScout CounterACT. Core Extensions Module: CEF Plugin. Configuration Guide. Version 2.7

Forescout. Control Network Vulnerabilities. How-to Guide. Forescout version 8.1

SecureConnector Advanced Features

Forescout. eyeextend for Splunk. Configuration Guide. Version 2.9

Easy-to-Use PCI Kit to Enable PCI Compliance Audits

Forescout. Configuration Guide. Version 1.3

ForeScout CounterACT. Configuration Guide. Version 1.2

ForeScout Extended Module for Splunk

ForeScout Extended Module for Splunk

ForeScout Extended Module for Palo Alto Networks Next Generation Firewall

Forescout. eyeextend for ServiceNow. Configuration Guide. Version 2.0

Integrate Palo Alto Traps. EventTracker v8.x and above

CounterACT Wireless Plugin

ForeScout Extended Module for Symantec Endpoint Protection

ForeScout CounterACT. Centralized Licensing. How-to Guide. Version 8.0

ForeScout CounterACT. Classify Devices. How-to Guide. Version 8.0

ForeScout Extended Module for Tenable Vulnerability Management

Centrify for QRadar Integration Guide

ForeScout CounterACT. (AWS) Plugin. Configuration Guide. Version 1.3

Forescout. Configuration Guide. Version 2.4

Integrate Sophos Enterprise Console. EventTracker v8.x and above

ForeScout CounterACT. Plugin. Configuration Guide. Version 2.3

ForeScout CounterACT. Single CounterACT Appliance. Quick Installation Guide. Version 8.0

ForeScout CounterACT. Configuration Guide. Version 1.4

CounterACT HPS Applications Plugin

Forescout. Configuration Guide. Version 8.1

ForeScout CounterACT. Plugin. Configuration Guide. Version 2.2.4

ForeScout CounterACT. Cisco PIX/ASA Firewall Integration Module. Configuration Guide. Version 2.1

Integrate Sophos Appliance. EventTracker v8.x and above

KYOCERA Net Admin Installation Guide

Patch Manager INSTALLATION GUIDE. Version Last Updated: September 25, 2017

Integrate Microsoft ATP. EventTracker v8.x and above

ForeScout CounterACT. Work with IPv6 Addressable Endpoints. How-to Guide. Version 8.0

Forescout. Plugin. Configuration Guide. Version 1.2.2

Forescout. Engine. Configuration Guide. Version 1.3

ForeScout CounterACT. ARF Reports Module. Configuration Guide. Version 1.0.3

Integrate Malwarebytes EventTracker Enterprise

ForeScout CounterACT. Configuration Guide. Version 4.1

Transcription:

How-to Guide Version 2.0.0

Table of Contents About IBM QRadar Integration... 3 Use Cases... 3 Visualization of CounterACT Endpoint Compliance Status & Connectivity... 3 Agent Health and Compliance for Windows... 3 Generate IBM QRadar Offense to Drive CounterACT Action... 3 Right-click to Trigger CounterACT Action... 4 Connecting Appliance Option added to Configuration Setup... 4 Additional QRadar Documentation... 4 About This Module... 4 Requirements... 5 QRadar Requirements... 5 CounterACT Requirements... 5 Networking and Communication Protocol Requirements... 5 What to Do... 5 Install the Plugin... 5 Download App Files... 6 Install and Configure the ForeScout App for QRadar... 6 New Features... 7 QRadar Action on Offense by Credibility and Severity... 7 QRadar Action on Offense by Description... 8 QRadar Send SIEM Update... 9 QRadar WinCollect Agent Compliance... 10 Integrate the ForeScout Functionalities into IBM QRadar... 10 View Widget Details... 11 Customize the Display of the Dashboard... 12 Display Inventory Data... 12 Running Action Items... 13 Additional CounterACT Documentation... 15 Documentation Portal... 15 Customer Support Portal... 15 CounterACT Console Online Help Tools... 15 Version 2.0.0 2

About IBM QRadar Integration CounterACT integrates with IBM QRadar SIEM servers to provide complete visibility of network endpoints, including unmanaged endpoints. QRadar integration lets you send policy status and selected host information from CounterACT to QRadar SIEM servers and trigger CounterACT actions based on SIEM messages. Use Cases This section describes important use cases supported by this module. Visualization of CounterACT Endpoint Compliance Status & Connectivity Agent Health and Compliance for Windows Generate IBM QRadar Offense to Drive CounterACT Action Right-click to Trigger CounterACT Action Connecting Appliance Option added to Configuration Setup Visualization of CounterACT Endpoint Compliance Status & Connectivity An IBM QRadar security administrator can monitor the current security posture on the IBM QRadar dashboard as per the configurations of different security solutions deployed. The security administrator can add CounterACT widgets to the dashboard. These widgets cover the following visualization scenarios: Endpoint compliance status summaries Registered corporate users vs. guests Device types in the network Patterns of network access over time For more information, see Integrate the ForeScout Functionalities into IBM QRadar. Agent Health and Compliance for Windows An IBM QRadar security administrator can ensure that the IBM QRadar WinCollect agent is installed and functioning properly on Windows endpoints within the network. An IBM QRadar WinCollect agent is a Windows Log Collection Agent, a stand-alone Windows application that is installed on both the IBM QRadar machine and the Windows host to allow IBM QRadar to collect Windows-based events. FOr more information, see QRadar WinCollect Agent Compliance. Generate IBM QRadar Offense to Drive CounterACT Action An organization uses a network firewall to detect targeted Denial of Service (DOS) attacks on their web applications. The same organization also has IBM QRadar SIEM to collect and aggregate logs from CounterACT, firewall, and web applications. When IBM QRadar detects a targeted DOS attack via firewall log correlation, an Offense is Version 2.0.0 3

generated. The security administrator would then have the source of the attack automatically blocked by the firewall to prevent further disruption of service to the application(s) on the network. Right-click to Trigger CounterACT Action You can right-click on any IP address/mac field to send action type to CounterACT. CounterACT sets properties and triggers policies to take action. For more information, see Running Action Items. Connecting Appliance Option added to Configuration Setup When adding a QRadar SIEM server, the operator can select the CounterACT appliance to communicate between the IBM QRadar SIEM server and the assigned CounterACT devices. For more information, refer to the ForeScout Extended Module for IBM QRadar Configuration Guide. Additional QRadar Documentation Refer to online documentation for more information about the IBM QRadar solution: http://www.ibm.com/support/knowledgecenter/ss42vs_7.2.8/com.ibm.qradar.doc/q radar_ic_welcome.html About This Module CounterACT integrates with IBM QRadar SIEM servers to provide complete visibility of network endpoints, including unmanaged endpoints. QRadar integration lets you send policy status and selected host information from CounterACT to QRadar SIEM servers and trigger CounterACT actions based on SIEM messages. The QRadar Module works with the ForeScout App for QRadar to integrate CounterACT and QRadar so that you can: Use policies and actions provided by the QRadar Module to regularly push endpoint data to QRadar. See QRadar Send SIEM Update. View CounterACT data in a dedicated, customizable QRadar dashboard. See View Widget Details. Define CounterACT policies that respond to QRadar offenses. Configure QRadar to send offenses to CounterACT based on custom Offence. Offences can combine data from multiple sources. The ForeScout App for IBM QRadar and the ForeScout Extended Module for QRadar work together to support communications between CounterACT and QRadar. You must install and configure both components to work with the features described in this document. For example, CounterACT policies and actions provided by the QRadar Module are used to populate QRadar with CounterACT data. Read this document together with the ForeScout Extended Module for IBM QRadar Configuration Guide. Version 2.0.0 4

Requirements This section describes all the requirements for the QRadar 2.0.0 release. QRadar Requirements This release supports IBM QRadar version 7.2.8 and above. Uninstalling the previous version of this App is not required. CounterACT Requirements The ForeScout App for QRadar interacts with an Enterprise Manager running 7.0.0 and above. The following components must be installed: Service Pack 2.3.2 and above ForeScout Extended Module for QRadar version 2.0.0 Syslog Plugin 3.1.4 and above Networking and Communication Protocol Requirements Verify connectivity between CounterACT and targeted QRadar servers on the configured TCP or UDP port. The default port is 514. What to Do Perform the following to carry out the integration: Verify that requirements are met. See Requirements for details. Download and install the ForeScout Extended Module for IBM QRadar. See Install the Plugin for details. Define target IBM QRadar SIEM servers, and assign CounterACT devices to them. See the ForeScout Extended Module for IBM QRadar Configuration Guide. Install the Plugin This section describes the installation and configuration for the ForeScout App for QRadar. Perform the following steps to work with the dashboard. For steps performed in the CounterACT Console, refer to the ForeScout Extended Module for IBM QRadar Configuration Guide. Version 2.0.0 5

1. Review the ForeScout Extended Module for IBM QRadar Configuration Guide and this How-to Guide. 2. Download App Files 3. Install and Configure the ForeScout App for Download App Files The ForeScout App for QRadar consists of the following components: ForeScoutCounterACTAppforIBMQRadar_2.0.0.zip You will need to install these components onto your QRadar server. Download these components to a location that can be accessed during installation. Install and Configure the ForeScout App for QRadar If a Beta version of this release is installed in your environment, uninstall the Beta release before you install this release. To install and configure the module: 1. Log into IBM QRadar as an Admin user. 2. In the QRadar Dashboard, select the Admin tab. 3. Select Log Source Extensions. 4. Browse to the ForeScout files and select package.txt-contentexport-20161103122528.zip. Version 2.0.0 6

5. To complete installation, you are prompted to Deploy Changes. In the Admin tab, the ForeScout icon appears in the Plugins section. No further configuration is required. New Features Four new policy templates have been added to allow communication about Offenses between CounterACT and QRadar. These default policies are in place for you to use as a starting point for creating multiple policies that respond to QRadar Offenses. QRadar Action on Offense by Credibility and Severity Keeping track of the credibility and severity of an Offense is important. Any High or Medium levels indicate a possible failure of Compliance. A QRadar Action on Offense by Credibility and Severity policy is created in CounterACT so that, depending upon the severity and credibility level of the Offense, action is taken. To view the credibility and severity of an Offense: 1. In the QRadar Console, select the Offenses tab. 2. In the left pane, select All Offenses. The full list of offenses display. Version 2.0.0 7

3. Double-click on an offense. The Offense detail page opens. The Relevance, Severity and Credibility values are listed in the right corner. Sub-rules include default action to be taken on: High Credibility and (High) Severity events By default the last offense credibility is set to 8, 9, and 10. Medium Credibility and (Medium) Severity events - By default the last offense credibility is set to 4, 5, 6, and 7. Low Credibility and (Low) Severity events - By default the last offense credibility is set to 1, 2, and 3. QRadar Action on Offense by Description When CounterACT receives an Offense from QRadar, sub-rules of the QRadar Action on Offense by Description policy will apply specific action. To view the offense type based on the description field: 1. In the QRadar Console, select the Offenses tab. 2. In the left pane, select All Offenses. The full list of offenses display. 3. Using a default Offense as an example, double-click on an offense that contains the words Honeypot or Tarpit in the Description field. The Offense detail page opens. Version 2.0.0 8

ForeScout App for QRadar supports the following Offense rules: Access to Honeypot or Tarpit Defined Address Attack followed by Attack Response Device Stopped Sending Events Excessive Firewall Denies Local Flood (TCP) SSH Server Scanner New Host Discovered Refer to the IBM QRadar User Guide for more information: http://www.ibm.com/support/knowledgecenter/ss42vs_7.2.8/com.ibm.qradar.doc/q radar_ic_welcome.html QRadar Send SIEM Update When QRadar sends an hourly update to CounterACT, the widgets automatically update to display the information in the Dashboard. Version 2.0.0 9

QRadar WinCollect Agent Compliance A CounterACT policy detects Windows endpoints on both the IBM QRadar machine and the Windows host to allow IBM QRadar to collect Windows-based events. For example, if the policy detects that an endpoint is not in compliance, it will direct the user of the endpoint to a URL to install the QRadar WinCollect Agent. It is recommended that the URL be available from outside the corporate network to ensure that the user can access the QRadar agent installer. Integrate the ForeScout Functionalities into IBM QRadar Now that you have established communication between the ForeScout Extended Module for IBM QRadar and the IBM QRadar SIEM server, you can work with ForeScout functionalities in the IBM QRadar Dashboard. To import widgets into the QRadar Dashboard: 1. Follow steps in the ForeScout Extended Module for IBM QRadar Configuration Guide to deploy the app to the QRadar console. 2. Open the QRadar console in a browser (recommend using Google Chrome ) and go to the QRadar Web Console. See QRadar support for additional URL information. 3. In the QRadar console, select the Dashboard tab. 4. Select Add Item. 5. Select ForeScout and then select Compliance Status Summary. Compliance Status Summary The number of endpoints that have or have not fulfilled organizational requirements for compliance policies. For example, the number of endpoints that have or have not installed prohibited applications such as instant messaging or peer-to-peer applications. Version 2.0.0 10

Device Classification Host Connection Status Corporate/Guest Status CounterACT Dashboard Indicates the percentage of all the different types of devices that are connected to the network. Example: Windows, Mac, Android, Unknown. The number of endpoints that are currently connected to your network. The number of endpoints in your organization not considered part of the corporate network, for example, personal laptops used by outside contractors. CounterACT may have detected these endpoints when they did not properly authenticate with the network. You can have multiple CounterACT Dashboards. 1. Select the IP address in the ForeScout CounterACT field and then select Open. The CounterACT login opens. 2. Log in. The CounterACT Dashboard opens. The widget displays on the Dashboard as a pie chart. 6. The widget is added to your dashboard. 7. Repeat steps 1-6 to add additional widgets to the QRadar Dashboard. View Widget Details Each widget watches IP addresses related to their subject matter. You can drill-down into each widget to get detailed information: 1. Within a widget, select the View Detail link. The Details page opens. 2. In the Time Range field, select the time slot for which you want to view more details then select Update. The information displays as a pie chart. Version 2.0.0 11

Customize the Display of the Dashboard You can re-order the widgets on the Dashboard using the drag-and-drop method. Simply drag the grey bar of the widget frame to the desired location. Display Inventory Data Use the CounterACT Inventory to view a real-time display of threats detected by IBM QRadar. The inventory lets you: Broaden your view of the organizational network from device-specific to activity-specific. View endpoint information reported by the IBM QRadar Offences and Disposition Triggers. View endpoints that have been detected with specific Offences. Easily track IBM QRadar Offence detection activity. Incorporate inventory detections into policies. To access the inventory: 1. In the CounterACT Console, select the Inventory icon from the Console toolbar. 2. Navigate to the IBM QRadar folder. The list of QRadar offenses display. Version 2.0.0 12

Running Action Items To Trigger a CounterACT action item: 1. In QRadar, go to Log Activity tab. 2. Right-click on an IP address that is managed by CounterACT and select Request CounterACT Alert Disposition from the menu. 3. The ForeScout Policy Disposition pane displays. Version 2.0.0 13

4. The CounterACT Enterprise Manager address is populated into the ForeScout CounterACT field. Select an Action from the drop-down menu. For the action selected, CounterACT send an alert to QRadar saying this IP address needs to have a Null/Notify/Remediate/ Quarantine / Other action done to it. 5. Select Submit. 6. In the CounterACT Policy Manager, select Apply. 7. In the Action column of the Policy Manager, hovering over the HTTP Notification icon displays a list of all the parameters for that sub-rule. An optional Send Updates to QRadar SIEM Server action is enabled for each sub-rule. For more information, see QRadar Send SIEM Update. Version 2.0.0 14

Additional CounterACT Documentation For more detailed information about the CounterACT features described here or additional CounterACT features and modules, refer to the following resources: Documentation Portal Customer Support Portal CounterACT Console Online Help Tools Documentation Portal The ForeScout Documentation Portal is a Web-based library containing information about CounterACT tools, features and functionality and integrations. To access the Documentation Portal: 1. Go to www.forescout.com/kb. 2. Use your customer support credentials to log in. 3. Select the CounterACT version you want to discover. Customer Support Portal The Customer Support Portal provides links to CounterACT version releases, service packs, plugins and modules as well as related documentation. The portal also provides a variety of How-to Guides, Installation Guides and more. To access the Customer Support Portal: 1. Go to https://updates.forescout.com/support/index.php?url=counteract. 2. Select the CounterACT version you want to discover. CounterACT Console Online Help Tools Access information directly from the CounterACT Console. Console Help Buttons Version 2.0.0 15

Use context sensitive Help buttons to quickly access information about the tasks and topics you are working with. Console User Manual Select CounterACT Help from the Help menu. Plugin Help files 1. After the plugin is installed, select Options from the Tools menu and then select Plugins. 2. Select the plugin and then select Help. Documentation Portal Select Documentation Portal from the Help menu. Version 2.0.0 16

Legal Notice Copyright ForeScout Technologies, Inc. 2000-2017. All rights reserved. The copyright and proprietary rights in this document belong to ForeScout Technologies, Inc. ("ForeScout"). It is strictly forbidden to copy, duplicate, sell, lend or otherwise use this document in any way, shape or form without the prior written consent of ForeScout. All other trademarks used in this document are the property of their respective owners. These products are based on software developed by ForeScout. The products described in this document may be protected by one or more of the following U.S. patents: #6,363,489, #8,254,286, #8,590,004, #8,639,800 and #9,027,079 and may be protected by other U.S. patents and foreign patents. Redistribution and use in source and binary forms are permitted, provided that the above copyright notice and this paragraph are duplicated in all such forms and that any documentation, advertising materials and other materials related to such distribution and use acknowledge that the software was developed by ForeScout. Unless there is a valid written agreement signed by you and ForeScout that governs the below ForeScout products and services: If you have purchased any ForeScout products, your use of such products is subject to your acceptance of the terms set forth at http://www.forescout.com/eula/; If you have purchased any ForeScout support service ( ActiveCare ), your use of ActiveCare is subject to your acceptance of the terms set forth at http://www.forescout.com/activecare-maintenance-and-support-policy/; If you have purchased any ForeScout Professional Services, the provision of such services is subject to your acceptance of the terms set forth at http://www.forescout.com/professional-services-agreement/; If you are evaluating ForeScout s products, your evaluation is subject to your acceptance of the applicable terms set forth below: - If you have requested a General Availability Product, the terms applicable to your use of such product are set forth at: http://www.forescout.com/evaluationlicense/. - If you have requested a Beta Product, the terms applicable to your use of such product are set forth at: http://www.forescout.com/beta-test-agreement/. - If you have purchased any ForeScout Not For Resale licenses, such license is subject to your acceptance of the terms set forth at http://www.forescout.com/nfr-license/. Send comments and questions about this document to: documentation@forescout.com 2017-03-15 14:27 Version 2.0.0 17