<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Alerts - Slack Integration in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts-slack-integration/m-p/349062#M298</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/154986"&gt;@CChampagne1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I reached out to one of our Cortex XDR Product Managers on this to verify.&amp;nbsp; If the ability to include the hostname is a not available via configuration, I will submit a feature request.&amp;nbsp; I will keep you posted.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Sep 2020 13:14:19 GMT</pubDate>
    <dc:creator>dfalcon</dc:creator>
    <dc:date>2020-09-14T13:14:19Z</dc:date>
    <item>
      <title>Cortex XDR Alerts - Slack Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts-slack-integration/m-p/348002#M282</link>
      <description>&lt;P&gt;Is there any way to include the&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;hostname&lt;/EM&gt;&lt;/FONT&gt; for alerts received in Slack? They are very valuable to receive on the phone late at night, but would be even better if we had a bit more information:&amp;nbsp;&lt;EM&gt;hostname, domain, something that indicates this is a test box... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Any takers? Is there something we need to tweak, or is this a feature request?&lt;BR /&gt;&lt;BR /&gt;Examples:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;&lt;DIV class="p-section_block p-section_block--no_top_margin"&gt;&lt;DIV class="p-section_block_text_content"&gt;&lt;DIV class="p-section_block__text"&gt;&lt;DIV class="p-mrkdwn_element"&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Alert Name:&lt;/STRONG&gt;&amp;nbsp;Local Analysis Malware&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="p-block_kit_renderer__block_wrapper"&gt;&lt;DIV class="p-section_block"&gt;&lt;DIV class="p-section_block_text_content"&gt;&lt;DIV class="p-section_block__text"&gt;&lt;DIV class="p-mrkdwn_element"&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;FONT size="2"&gt;&lt;I&gt;&lt;STRONG&gt;Severity:&lt;/STRONG&gt;&amp;nbsp;Medium&lt;/I&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;I&gt;&lt;STRONG&gt;Source:&lt;/STRONG&gt;&amp;nbsp;XDR Agent&lt;/I&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;I&gt;&lt;STRONG&gt;Category:&lt;/STRONG&gt;&amp;nbsp;Malware&lt;/I&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;I&gt;&lt;STRONG&gt;Action:&lt;/STRONG&gt;&amp;nbsp;Detected (Reported)&lt;/I&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;I&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&amp;nbsp;Suspicious executable detected&lt;/FONT&gt;&lt;BR /&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;&lt;DIV class="p-section_block p-section_block--no_top_margin"&gt;&lt;DIV class="p-section_block_text_content"&gt;&lt;DIV class="p-section_block__text"&gt;&lt;DIV class="p-mrkdwn_element"&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Alert Name:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT size="2"&gt;&amp;nbsp;Binary file being created to disk with a double extension&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="p-block_kit_renderer__block_wrapper"&gt;&lt;DIV class="p-section_block"&gt;&lt;DIV class="p-section_block_text_content"&gt;&lt;DIV class="p-section_block__text"&gt;&lt;DIV class="p-mrkdwn_element"&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;I&gt;&lt;STRONG&gt;Severity:&lt;/STRONG&gt;&amp;nbsp;Medium&lt;/I&gt;&lt;BR /&gt;&lt;I&gt;&lt;STRONG&gt;Source:&lt;/STRONG&gt;&amp;nbsp;XDR BIOC&lt;/I&gt;&lt;BR /&gt;&lt;I&gt;&lt;STRONG&gt;Category:&lt;/STRONG&gt;&amp;nbsp;File Type Obfuscation&lt;/I&gt;&lt;BR /&gt;&lt;I&gt;&lt;STRONG&gt;Action:&lt;/STRONG&gt;&amp;nbsp;Detected&lt;/I&gt;&lt;BR /&gt;&lt;I&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&amp;nbsp;File file name =&amp;nbsp;&lt;STRONG&gt;.docx.exe,&amp;nbsp;&lt;/STRONG&gt;.xlsx.exe,&amp;nbsp;&lt;STRONG&gt;.pptx.exe,&amp;nbsp;&lt;/STRONG&gt;.pdf.exe,&amp;nbsp;&lt;STRONG&gt;.wav.exe,&amp;nbsp;&lt;/STRONG&gt;.mp3.exe,&amp;nbsp;&lt;STRONG&gt;.mkv.exe,&amp;nbsp;&lt;/STRONG&gt;.avi.exe,&amp;nbsp;&lt;STRONG&gt;.mp4.exe,&amp;nbsp;&lt;/STRONG&gt;.gif.exe,&amp;nbsp;&lt;STRONG&gt;.bmp.exe,&amp;nbsp;&lt;/STRONG&gt;.png.exe,&amp;nbsp;&lt;STRONG&gt;.jpg.exe,&amp;nbsp;&lt;/STRONG&gt;.jpeg.exe,&amp;nbsp;&lt;STRONG&gt;.m4a.exe,&amp;nbsp;&lt;/STRONG&gt;.html.exe,&amp;nbsp;&lt;STRONG&gt;.htm.exe,&amp;nbsp;&lt;/STRONG&gt;.mht.exe,&amp;nbsp;&lt;STRONG&gt;.d…&lt;/STRONG&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class="p-mrkdwn_element"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p-mrkdwn_element"&gt;&lt;SPAN&gt;&lt;FONT face="arial,helvetica,sans-serif" size="4"&gt;I ask because the &lt;STRONG&gt;Email&lt;/STRONG&gt; Alerts have this info:&lt;/FONT&gt;&lt;I&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Source:XDR Agent&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Category:Malware&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Action:Detected (Reported)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2" color="#FF0000"&gt;Host:MSEDGEWIN10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Starred:No&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Excluded:No&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Alert:39439&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Incident:13&lt;/FONT&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 09 Sep 2020 23:42:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts-slack-integration/m-p/348002#M282</guid>
      <dc:creator>CChampagne1</dc:creator>
      <dc:date>2020-09-09T23:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Alerts - Slack Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts-slack-integration/m-p/349062#M298</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/154986"&gt;@CChampagne1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I reached out to one of our Cortex XDR Product Managers on this to verify.&amp;nbsp; If the ability to include the hostname is a not available via configuration, I will submit a feature request.&amp;nbsp; I will keep you posted.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 13:14:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-alerts-slack-integration/m-p/349062#M298</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-09-14T13:14:19Z</dc:date>
    </item>
  </channel>
</rss>

