QRadar Offense: How to Read and Investigate an Offense

An Offense in QRadar is a prioritized incident created when the Custom Rules Engine links Events or Flows according to a rule. A professional investigation does not begin and end with Magnitude: one must understand the rule that fired, open the contributing events and flows, check Source, Destination, assets, time, and business context, and then document the decision and Closing Reason.
IBM QRadar receives Events from log sources and Flows from traffic sources, passes them through the Custom Rules Engine — CRE — and can generate an Offense when rule conditions are met. An Offense centralizes the information needed for prioritization and investigation, but it is not proof that a compromise has occurred. It is a Case that says: “The detection system observed a pattern that warrants examination.”
The common mistake is to look at Magnitude, open a few recent Events, and close. Magnitude indeed helps with prioritization, but QRadar calculates it from a combination of Relevance, Severity, and Credibility and also considers factors such as the number of Events and Flows, number of sources, age of the Offense, asset weight, and vulnerability context. Therefore, the case must be broken down into its components.




