<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to know if a zip file is encrypted in XSOAR in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544907#M2212</link>
    <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;
&lt;P&gt;We are using Graph to get the files in sharepoint. This forces us that when we download the file it can only be placed in the context with the name "File". If we try to use this format within an automation, the output is not valid for processing. This is why you cannot download and use a downloaded file in the same automation, it must first be placed in the context in the XSOAR format and then used in the automation.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jun 2023 11:35:26 GMT</pubDate>
    <dc:creator>Josep</dc:creator>
    <dc:date>2023-06-06T11:35:26Z</dc:date>
    <item>
      <title>How to know if a zip file is encrypted in XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/543926#M2189</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We'd like to know if a zip file is encrypted inside a playbook or a automation. The way in which XSOAR works with these files does not allow the use of python libraries. Is there a way through the File context value to know if the file is encrypted?&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 09:13:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/543926#M2189</guid>
      <dc:creator>Josep</dc:creator>
      <dc:date>2023-05-30T09:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to know if a zip file is encrypted in XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/543956#M2193</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/226640"&gt;@Josep&lt;/a&gt;&amp;nbsp;, if you use zipfile instead of 7z while unzipping, the error will be provided if the zip file is protected. You can handle the error in the playbook to catch if the zip is password protected.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV id="47@21232f297a57a5a743894a0e4a801fc3$&amp;amp;$70fa4e0b-bcbd-44c7-813b-80792a4da928" class="artifact war-room-entry"&gt;
&lt;DIV class="entry-body "&gt;
&lt;DIV class="ui grid"&gt;
&lt;DIV class="row entry-body-content"&gt;
&lt;DIV class="wide column"&gt;
&lt;DIV class="entry-wrapper"&gt;
&lt;DIV class="entry-view vertical-strech"&gt;
&lt;DIV class="vertical-strech demisto-data"&gt;
&lt;DIV&gt;
&lt;DIV class="entry-note-view" data-test-id="entry-note-text"&gt;
&lt;DIV&gt;
&lt;DIV class="entry-text-view"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;!UnzipFile entryID=${File.EntryID} zipTool="zipfile"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV id="48@21232f297a57a5a743894a0e4a801fc3$&amp;amp;$70fa4e0b-bcbd-44c7-813b-80792a4da928" class="artifact error war-room-entry"&gt;
&lt;DIV class="entry-body "&gt;
&lt;DIV class="ui grid"&gt;
&lt;DIV class="row entry-body-content"&gt;
&lt;DIV class="wide column"&gt;
&lt;DIV class="entry-wrapper parent-entry-included"&gt;
&lt;DIV class="entry-view vertical-strech entry-error"&gt;
&lt;DIV class="vertical-strech demisto-data"&gt;
&lt;DIV&gt;&lt;SPAN class="entry-task-reason"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Reason&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;
&lt;DIV class="entry-note-view" data-test-id="entry-note-text"&gt;
&lt;DIV&gt;
&lt;DIV class="entry-text-view"&gt;&lt;SPAN class=""&gt;zipfile couldn't extract this file - try using zipTool=7z If you already tried both zipfile and 7z check that the zip file is valid. File &amp;lt;ZipInfo filename=filename compress_type=deflate filemode='-rw-r--r--' file_size=1118 compress_size=624&amp;gt; is encrypted, password required for extraction&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="49@21232f297a57a5a743894a0e4a801fc3$&amp;amp;$70fa4e0b-bcbd-44c7-813b-80792a4da928" class="procedural war-room-entry"&gt;
&lt;DIV class="entry-user-image-container"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="48@21232f297a57a5a743894a0e4a801fc3$&amp;amp;$70fa4e0b-bcbd-44c7-813b-80792a4da928" class="artifact error war-room-entry"&gt;
&lt;DIV class="entry-user-image-container"&gt;
&lt;DIV class="ellipsis entry-user-image error"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 30 May 2023 12:21:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/543956#M2193</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-05-30T12:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to know if a zip file is encrypted in XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544065#M2197</link>
      <description>&lt;P&gt;I'm confused by this statement: "The way in which XSOAR works with these files does not allow the use of python libraries." If you use a custom automation with a custom docker image you can import and use basically any library you want, I don't understand what the the restriction would be here.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 00:09:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544065#M2197</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2023-05-31T00:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to know if a zip file is encrypted in XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544116#M2198</link>
      <description>&lt;P&gt;Yes building your automation for this purpose is another solution. You&amp;nbsp;can use the built-in command "/docker_image_create" and specify other parameters. The only potential issue is you won't be able to delete dockers from the UI. You will need to go into the server to delete them.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;/docker_image_create name=&amp;lt;name_here&amp;gt; base=&amp;lt;base_image&amp;gt; dependencies=&amp;lt;comma_seperated_deps&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I hope this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 07:27:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544116#M2198</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-05-31T07:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to know if a zip file is encrypted in XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544351#M2201</link>
      <description>&lt;P&gt;This may help, in the wrar section of the script there is reference to passing the password if encrypted.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/scripts/unzip-file" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/scripts/unzip-file&lt;/A&gt;&amp;nbsp; , line 125 in the editor.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 15:31:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544351#M2201</guid>
      <dc:creator>shcrews</dc:creator>
      <dc:date>2023-06-01T15:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to know if a zip file is encrypted in XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544907#M2212</link>
      <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;
&lt;P&gt;We are using Graph to get the files in sharepoint. This forces us that when we download the file it can only be placed in the context with the name "File". If we try to use this format within an automation, the output is not valid for processing. This is why you cannot download and use a downloaded file in the same automation, it must first be placed in the context in the XSOAR format and then used in the automation.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 11:35:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544907#M2212</guid>
      <dc:creator>Josep</dc:creator>
      <dc:date>2023-06-06T11:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to know if a zip file is encrypted in XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544908#M2213</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;We want to check that the file can carry malware, for this we use a sandbox that only works if the file does not contain a password. This is why we don't want to open the file, just check if it has a password. &lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 11:38:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/544908#M2213</guid>
      <dc:creator>Josep</dc:creator>
      <dc:date>2023-06-06T11:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to know if a zip file is encrypted in XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/545027#M2216</link>
      <description>&lt;P&gt;It sounds like you could implement your playbook with logic something like this to meet your requirements:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Fetch file from Graph (file entry ID is written to context) -&amp;gt; Conditional task which calls a custom automation, where the custom integration uses the python zipfile (or similar) library to determine if the zip is encrypted, then returns the result&lt;/P&gt;
&lt;P&gt;-&amp;gt; (If unencrypted) sends to sandbox / (else) do other custom processing for encrypted zips.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 04:20:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-know-if-a-zip-file-is-encrypted-in-xsoar/m-p/545027#M2216</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2023-06-07T04:20:55Z</dc:date>
    </item>
  </channel>
</rss>

