{"id":20317925,"url":"https://github.com/crowdsecurity/crowdsec-qradar-app","last_synced_at":"2026-03-19T15:14:54.733Z","repository":{"id":172956581,"uuid":"626285241","full_name":"crowdsecurity/crowdsec-qradar-app","owner":"crowdsecurity","description":null,"archived":false,"fork":false,"pushed_at":"2023-07-27T06:40:50.000Z","size":2067,"stargazers_count":0,"open_issues_count":0,"forks_count":2,"subscribers_count":3,"default_branch":"main","last_synced_at":"2026-02-09T15:51:45.890Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"HTML","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/crowdsecurity.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-04-11T06:53:57.000Z","updated_at":"2023-04-12T09:31:13.000Z","dependencies_parsed_at":"2024-07-19T20:52:59.665Z","dependency_job_id":null,"html_url":"https://github.com/crowdsecurity/crowdsec-qradar-app","commit_stats":null,"previous_names":["crowdsecurity/crowdsec-qradar-app"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/crowdsecurity/crowdsec-qradar-app","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fcrowdsec-qradar-app","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fcrowdsec-qradar-app/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fcrowdsec-qradar-app/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fcrowdsec-qradar-app/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/crowdsecurity","download_url":"https://codeload.github.com/crowdsecurity/crowdsec-qradar-app/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fcrowdsec-qradar-app/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30710710,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-19T05:29:31.190Z","status":"ssl_error","status_checked_at":"2026-03-19T05:28:25.821Z","response_time":57,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-14T18:37:19.021Z","updated_at":"2026-03-19T15:14:54.682Z","avatar_url":"https://github.com/crowdsecurity.png","language":"HTML","funding_links":[],"categories":[],"sub_categories":[],"readme":"# CrowdSec QRadar App\n\nQRadar App which allows users to leverage CrowdSec's Smoke CTI to get information about IP as seen by CrowdSec's network. This is enabled via a right click on IP GUI action. The intelligence includes:\n\n1. Types of attacks the IP has been observed performing.\n2. Background Noise Score. This can be used to know whether the particular IP is only targeting your infrastructure or is targeting others too. \n3. Aggressivity which quantifies frequency of attacks.\n4. Other fields like Geolocation details, AS details, sighting details etc\n\n## Configuration\n\nWe need to provide the App, CrowdSec CTI API Key. You can find the instructions to obtain it [here](https://docs.crowdsec.net/docs/next/cti_api/getting_started)\n\nNow navigate to the CrowdSec App in QRadar's Admin page. Click on CrowdSec App Settings Icon.\n\n![CrowdSec App Settings](/images/qradar_crowdsec_cfg.png)\n\nA pop-up will appear. Enter the API Key and click on Submit.\n\n![CrowdSec App Settings Popup](/images/crowdsec_app_config_window.png)\n\nThe App is now configured !\n\n## Usage\n\nNavigate to Log Activity pane in QRadar. Right click on an IP either in Source IP or Destination IP column. Hover over \"More Options\". You will see a new option \"CrowdSec IP Lookup\". Click on it.\n\n![CrowdSec Right Click Option](/images/right_click_show_act.png)\n\nThis will open a popup with the information about the right clicked IP found in CrowdSec's Smoke Dataset.\n\n![CrowdSec App Popup](/images/lookup_results.png)\n\nYou can click on the \"Show\" button to see the RAW JSON response from the API.\n\n![JSON View](/images/qradar_json_view.png)\n\n## References\n\nYou can find our latest taxonomy about attack details, classifications, scores etc in [our official docs](https://docs.crowdsec.net/docs/next/cti_api/taxonomy)\n\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcrowdsecurity%2Fcrowdsec-qradar-app","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcrowdsecurity%2Fcrowdsec-qradar-app","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcrowdsecurity%2Fcrowdsec-qradar-app/lists"}