<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Read Email Body in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/read-email-body/m-p/520946#M1380</link>
    <description>&lt;P&gt;I am trying to write a playbook that will read the email body and understand what the email is related to base on keywords or patterns. Is there a script or integration that could do that? My best idea is to use Machine Learning for it, but I am not sure it will work. Thank you&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Nov 2022 22:26:45 GMT</pubDate>
    <dc:creator>axespera</dc:creator>
    <dc:date>2022-11-10T22:26:45Z</dc:date>
    <item>
      <title>Read Email Body</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/read-email-body/m-p/520946#M1380</link>
      <description>&lt;P&gt;I am trying to write a playbook that will read the email body and understand what the email is related to base on keywords or patterns. Is there a script or integration that could do that? My best idea is to use Machine Learning for it, but I am not sure it will work. Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 22:26:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/read-email-body/m-p/520946#M1380</guid>
      <dc:creator>axespera</dc:creator>
      <dc:date>2022-11-10T22:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Read Email Body</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/read-email-body/m-p/520967#M1381</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257070"&gt;@axespera&lt;/a&gt;, the ML model for email body analysis works best if there is existing classified content for it to learn from. Refer -&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-9/cortex-xsoar-admin/machine-learing-models/phishing-classifier-demo/dbotpredictoutofthebox-examples#id605dcf55-5101-493b-810e-1cc3966ff82c," target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-9/cortex-xsoar-admin/machine-learing-models/phishing-classifier-demo/dbotpredictoutofthebox-examples#id605dcf55-5101-493b-810e-1cc3966ff82c,&lt;/A&gt;&amp;nbsp;to see how it works once configured correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to do this without ML. I have previously done this with the help of a tags fields and playbook. The playbook checked the emails body for a list of keyword matches. Ex. if it contained un-subscribe the playbook would add "newsletter" to the tags fields. We had conditional check for multiple keywords with tags added for promotional, offer, financial, credential and newsletter. We then had a secondary playbook that checked for combination of tags. We also had tags added from the other parts of the email like the header.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-11-11 at 12.55.30 pm.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45272iBC2580771701B379/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-11-11 at 12.55.30 pm.png" alt="Screen Shot 2022-11-11 at 12.55.30 pm.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Incident_Tagging_-_Email_Header_Fri_Nov_11_2022.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45273i4F10B848E5166BA6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Incident_Tagging_-_Email_Header_Fri_Nov_11_2022.png" alt="Incident_Tagging_-_Email_Header_Fri_Nov_11_2022.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 01:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/read-email-body/m-p/520967#M1381</guid>
      <dc:creator>jfernandes1</dc:creator>
      <dc:date>2022-11-11T01:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Read Email Body</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/read-email-body/m-p/521115#M1392</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208028"&gt;@jfernandes1&lt;/a&gt;&amp;nbsp;Thank you, my understanding is that with machine learning it would check for malicious words to make the decision, would you know if with the classifier I could make it just check if the words are business related or not instead of malicious or not? Also, I liked what you did with the tags.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 04:14:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/read-email-body/m-p/521115#M1392</guid>
      <dc:creator>axespera</dc:creator>
      <dc:date>2022-11-14T04:14:27Z</dc:date>
    </item>
  </channel>
</rss>

