UBA : User Accessing Risky IP Spam
The QRadar® User Behavior Analytics (UBA) app supports use cases based on rules for certain behavioral anomalies.
UBA : User Accessing Risky IP, Spam (previously called X-Force® Risky IP Spam)
Enabled by default
False
Description
This rule detects when a local user or host is connecting to a spam-sending host.
Support rules
- X-Force Risky IP, Spam
- BB:UBA : Common Event Filters
Required configuration
- Set "Enable X-Force Threat Intelligence Feed" to Yes in .
- Enable the following rule: X-Force Risky IP Spam.
Log source types
All supported log sources.