Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Community Edition

Hello, I have signed up for the community edition, however I have never received the download URL. Also, I signed up for the DFIR, but cannot access the slack, as the link is expired when sent.

loyglenn by L0 Member
  • 287 Views
  • 1 replies
  • 0 Likes

Creating a Queue on Slack Integration

Hello all, 

I am working with Slack from the playbook level where a message summarizing an incident is sent followed by Slackask automation to ask users on a channel to confirm the information with two interactive buttons. Take note that the flow has

...

XSOAR Incident Re Run

soemtimes for testing purpose we need to create similar incident again but I am stuck at this phase. I have exisiting incident and i want to re run it(either manually create, duplicate and re run it or just simply re run exisitng incident, or importi

...

Syedhkt by L1 Bithead
  • 239 Views
  • 2 replies
  • 0 Likes

XSOAR Upgradtion Issue

Cortex XSOAR 8 will have a new FQDN and IP Address in the new platform. May I know is there any existing playbook have pulled the XSOAR data, and export to third-party platform automatically? If yes, it may require to re-configure the IP Address.

 

C

...

Syedhkt by L1 Bithead
  • 245 Views
  • 2 replies
  • 0 Likes

XSOAR - GET-GPO DisplayName

 

Hi,

I've created a playbook to analyze some alerts related to SOC and GPO, but the alerts come with ObjectGUID and I need to convert the GUID to DisplayName.

In PowerShell, the command is simple: (Get-GPO -Guid "$GUID").DisplayName.

I tried running

...

Phisphing feeds and enrichment

Hello, I need your help. I need feeds for domain classification and another feed for phishing, to determine whether domains, emails have been compromised or not. What do you recommend for Cortex XSOAR  

 

What feed and integration people use??

I need

...

Resolved! XSAOR with HA using Open search Upgrade

Hi Team,

The customer uses the XSOAR in High Availability using OpenSearch. and the number of app servers is 2.

So is it possible to upgrade the XSOAR not stopping the server?

 

For ex) Stop the App server 1 and upgrade the App server 1 first, an s

...

XSOAR Multi-Engine Deployment on CentOS7

I just had our instance migrated to 8.5.  during testing we figure out that we could not update our engine using the shell program and need to do a zip deployment.  The basic instructions for ZIP does not support multple engines on the same host.  He

...

kreeves by L1 Bithead
  • 231 Views
  • 1 replies
  • 0 Likes

Unable to send Slack block messages

I've been trying to send a block message from the SlackBlockBuilder automation. However, when I try to test it out via the debugger panel, it would result in an error.

 
Spoiler
Command: 
!SlackBlockBuilder list_name="SLACKV3_BLOCK_ASK_URLAL
...

IDarma by L0 Member
  • 489 Views
  • 2 replies
  • 0 Likes
  • 943 Posts
  • 30 Subscriptions
Top Solution Authors
Top Liked Authors