<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help on extract indicators from Email body in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/need-help-on-extract-indicators-from-email-body/m-p/534667#M1897</link>
    <description>&lt;P&gt;Better open your own discussion than using answered discussion.Till then you can see this nice clip about indicators by palo alto &lt;A href="https://www.youtube.com/watch?v=DVGWeYJMDQQ&amp;amp;t=375s" target="_blank"&gt;https://www.youtube.com/watch?v=DVGWeYJMDQQ&amp;amp;t=375s&lt;/A&gt; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Mar 2023 08:41:03 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2023-03-16T08:41:03Z</dc:date>
    <item>
      <title>Need help on extract indicators from Email body</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/need-help-on-extract-indicators-from-email-body/m-p/431148#M343</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have developed a playbook which extract indicators like IP,URL,Domain and Hash from Email body.&lt;/P&gt;&lt;P&gt;but in some cases extract indicators and other automation which are available in xsoar cannot extract domains.&lt;/P&gt;&lt;P&gt;can anyone suggest me how to extract domains from Email body.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 17:45:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/need-help-on-extract-indicators-from-email-body/m-p/431148#M343</guid>
      <dc:creator>Priyash7</dc:creator>
      <dc:date>2021-09-02T17:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on extract indicators from Email body</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/need-help-on-extract-indicators-from-email-body/m-p/431169#M344</link>
      <description>&lt;P&gt;Extracting domains is a difficult task.&amp;nbsp; If you consider that a domain can almost be anything separated by a "." it gets very difficult to design a regular expression that can extract that without getting a lot of false positives.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Typically the way things are handled by XSOAR out of the box is that we first identify either email addresses (&lt;A href="mailto:email@domain" target="_blank"&gt;email@domain&lt;/A&gt;) or a URL (&lt;A href="http://domain/otherstuff" target="_blank"&gt;http://domain/otherstuff&lt;/A&gt;) and pull the domains out of those.&amp;nbsp; If you are able to identify a regular expression that could effectively grab a domain out of a normal email without catching other stuff as well you can create a custom regex in the domain indicator type.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure there's a great solution here I just wanted to help identify why it's a tricky problem!&lt;/P&gt;&lt;P&gt;I hope that helps!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 18:41:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/need-help-on-extract-indicators-from-email-body/m-p/431169#M344</guid>
      <dc:creator>DougCouch</dc:creator>
      <dc:date>2021-09-02T18:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on extract indicators from Email body</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/need-help-on-extract-indicators-from-email-body/m-p/534414#M1891</link>
      <description>&lt;P&gt;Hi DougCouch,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have face similar issues, I want to extract the indicator from PDF file. is it the same method that i can use to create the regex expression to extract domain that have - and also [.] ? is there any document or tutorial on that ?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 02:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/need-help-on-extract-indicators-from-email-body/m-p/534414#M1891</guid>
      <dc:creator>slabu</dc:creator>
      <dc:date>2023-03-15T02:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on extract indicators from Email body</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/need-help-on-extract-indicators-from-email-body/m-p/534667#M1897</link>
      <description>&lt;P&gt;Better open your own discussion than using answered discussion.Till then you can see this nice clip about indicators by palo alto &lt;A href="https://www.youtube.com/watch?v=DVGWeYJMDQQ&amp;amp;t=375s" target="_blank"&gt;https://www.youtube.com/watch?v=DVGWeYJMDQQ&amp;amp;t=375s&lt;/A&gt; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 08:41:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/need-help-on-extract-indicators-from-email-body/m-p/534667#M1897</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-03-16T08:41:03Z</dc:date>
    </item>
  </channel>
</rss>

