<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Upload IOC from file to firewall via XSOAR in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/upload-ioc-from-file-to-firewall-via-xsoar/m-p/512364#M1120</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to find a way of maximum automatization of the next process: IOC are extracted from CSV file to Cortex XSOAR and than only this indicators are uploaded to firewalls.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found automations for each step separately but maybe exist any playbook or integration with such functionality?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And another less important question is how to compare IOC what XSOAR had before enrichment from file with this new? I know that it's possible to give additional attribute field during extracting from file but don't understand how to compare with all another's.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Aug 2022 12:00:36 GMT</pubDate>
    <dc:creator>asernova</dc:creator>
    <dc:date>2022-08-19T12:00:36Z</dc:date>
    <item>
      <title>Upload IOC from file to firewall via XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/upload-ioc-from-file-to-firewall-via-xsoar/m-p/512364#M1120</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to find a way of maximum automatization of the next process: IOC are extracted from CSV file to Cortex XSOAR and than only this indicators are uploaded to firewalls.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found automations for each step separately but maybe exist any playbook or integration with such functionality?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And another less important question is how to compare IOC what XSOAR had before enrichment from file with this new? I know that it's possible to give additional attribute field during extracting from file but don't understand how to compare with all another's.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 12:00:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/upload-ioc-from-file-to-firewall-via-xsoar/m-p/512364#M1120</guid>
      <dc:creator>asernova</dc:creator>
      <dc:date>2022-08-19T12:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Upload IOC from file to firewall via XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/upload-ioc-from-file-to-firewall-via-xsoar/m-p/512472#M1127</link>
      <description>&lt;P&gt;The simplest way to do this wouldn't require a playbook at all - import the indicators with the CSV feed integration then export them out to the firewalls with an integration compatible with your firewalls such as Generic Export Indicator Service or TAXII.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A playbook is really only required if you want to do something specific with/to the indicators other than, as well as, or before exporting them. One common example is tagging indicators if/when they meet specific conditions, and then using that tag as part of the indicator query when doing the export. This playbook provides a good example of tagging indicators for that purpose:&amp;nbsp;&lt;A href="https://xsoar.pan.dev/docs/reference/playbooks/tag-massive-and-internal-io-cs-to-avoid-edl-listing" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/playbooks/tag-massive-and-internal-io-cs-to-avoid-edl-listing&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The timeline section on the indicator summary page will show you a list of changes since the creation of the indicator, which includes changes made due to enrichment.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 01:07:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/upload-ioc-from-file-to-firewall-via-xsoar/m-p/512472#M1127</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2022-08-22T01:07:49Z</dc:date>
    </item>
  </channel>
</rss>

