QRadar Use Case Manager
QRadar Use Case Manager includes a use case explorer that offers flexible reports that are related to your rules. QRadar Use Case Manager also exposes pre-defined mappings to system rules and helps you map your own custom rules to MITRE ATT&CK tactics and techniques.
Explore Rules Through Visualization and Generated Reports
Explore the rules through different filters to ensure that they work as intended.
Generate reports from predefined templates, such as searches based on rule response and actions, log source coverage, and many others.
Customize reports to see only the information that is critical to your analysis.
Tune Your Environment Based on Built-in Analysis
Gain tuning recommendations unique to your environment right within the app.
Identify top offense-generating or CRE-generating rules, and then follow the guide to tune them.
Reduce the number of false positives by reviewing the most common configuration steps. Easily update network hierarchy, building blocks, and server discovery based on recommendations.
Visualize Threat Coverage Across the MITRE ATT&CK Framework
Visually understand your ability to detect threats based on ATT&CK tactics and techniques.
View predefined QRadar tactic and technique mappings and add your own custom mappings to help ensure complete coverage.
Use new insights to prioritize the rollout of new use cases and apps to effectively strengthen your security posture.