Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Using Microsoft Authenticator MFA

Hello LiveComm,

I am working on using MFA for authentication to xsoar on a server that has Active Directory (On-Prem) SAML authentication already in use. The use case is to require the user to authenticate using the Microsoft Authenticator app. I hav

...

Access to XSOAR Community edition

Hello everybody,

 

after reading through some of the threads here, most people run into a similar issue as I did. 

Not receiving the URL to download - has anyone found a suitable solution? 

 

I used a company email, I waited a week for it to come aft

...

JanGrob by L1 Bithead
  • 91 Views
  • 0 replies
  • 0 Likes

Community Edition

Hello, I have signed up for the community edition, however I have never received the download URL. Also, I signed up for the DFIR, but cannot access the slack, as the link is expired when sent.

loyglenn by L0 Member
  • 371 Views
  • 2 replies
  • 0 Likes

how can I get cortex Community Edition

Hi,

I filled out the form for the community edition at https://start.paloaltonetworks.com/sign-up-for-community-edition.html. I have received a confirmation email and an email for more information I have replied.

 

unfortunately I get no response to use

...

ten4you by L0 Member
  • 3578 Views
  • 4 replies
  • 0 Likes

Creating a Queue on Slack Integration

Hello all, 

I am working with Slack from the playbook level where a message summarizing an incident is sent followed by Slackask automation to ask users on a channel to confirm the information with two interactive buttons. Take note that the flow has

...

XSOAR Incident Re Run

soemtimes for testing purpose we need to create similar incident again but I am stuck at this phase. I have exisiting incident and i want to re run it(either manually create, duplicate and re run it or just simply re run exisitng incident, or importi

...

Syedhkt by L1 Bithead
  • 275 Views
  • 2 replies
  • 0 Likes

XSOAR Upgradtion Issue

Cortex XSOAR 8 will have a new FQDN and IP Address in the new platform. May I know is there any existing playbook have pulled the XSOAR data, and export to third-party platform automatically? If yes, it may require to re-configure the IP Address.

 

C

...

Syedhkt by L1 Bithead
  • 278 Views
  • 2 replies
  • 0 Likes

XSOAR - GET-GPO DisplayName

 

Hi,

I've created a playbook to analyze some alerts related to SOC and GPO, but the alerts come with ObjectGUID and I need to convert the GUID to DisplayName.

In PowerShell, the command is simple: (Get-GPO -Guid "$GUID").DisplayName.

I tried running

...

  • 947 Posts
  • 30 Subscriptions
Top Solution Authors
Top Liked Authors