<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Playbook to update IOCs on Microsoft Advanced Threat Protection (APT) in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/playbook-to-update-iocs-on-microsoft-advanced-threat-protection/m-p/552106#M2441</link>
    <description>&lt;P&gt;Hello Vhebri,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found this content pack from called 'Microsoft Defender for Endpoint' that includes this in the description:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Enriches IOCs from XSOAR to Microsoft Defender for Endpoint and vice versa,&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;and it allows the&amp;nbsp;Microsoft Defender for Endpoint integration to import events as XSOAR incidents.&lt;/P&gt;
&lt;P&gt;This should accomplish the items you are looking for. Hope this helps!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Link here:&amp;nbsp;&lt;A href="https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftDefenderAdvancedThreatProtection/" target="_blank"&gt;https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftDefenderAdvancedThreatProtection/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Aug 2023 17:54:00 GMT</pubDate>
    <dc:creator>Ivetto</dc:creator>
    <dc:date>2023-08-01T17:54:00Z</dc:date>
    <item>
      <title>Playbook to update IOCs on Microsoft Advanced Threat Protection (APT)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/playbook-to-update-iocs-on-microsoft-advanced-threat-protection/m-p/551336#M2413</link>
      <description>&lt;P&gt;I want to achieve below steps. is there any exiting playbook or have to customized playbook?&lt;/P&gt;
&lt;H2&gt;Step 1: Checking Existing IOCs in Microsoft APT&lt;/H2&gt;
&lt;P&gt;In this first step, we will fetch the list of existing IOCs from Microsoft APT and compare them with the IOCs you wish to add.&lt;/P&gt;
&lt;H2&gt;Step 2: Handling Existing IOCs&lt;/H2&gt;
&lt;P&gt;Upon comparing the fetched list with your desired IOCs, we will identify the existing items. Those already present in Microsoft APT will be ignored, and a notification email will be sent to your team, providing details about these items.&lt;/P&gt;
&lt;H2&gt;Step 3: Adding New IOCs to Microsoft APT&lt;/H2&gt;
&lt;P&gt;For the IOCs that are not already in Microsoft APT, we will proceed to add them using the XSOAR integration with Microsoft APT.&lt;/P&gt;
&lt;H2&gt;Step 4: Cross-Checking Addition of IOCs&lt;/H2&gt;
&lt;P&gt;After successfully adding the new IOCs, we will perform a cross-check by fetching the IOCs from Microsoft APT again. This verification step ensures the accuracy of the additions.&lt;/P&gt;
&lt;H2&gt;Step 5: Notifying the Team&lt;/H2&gt;
&lt;P&gt;Once the cross-check confirms that the new IOCs are added to Microsoft APT, we will use the "Send Email" integration in XSOAR to notify your team about the successful addition.&lt;BR /&gt;&lt;BR /&gt;if required custom playbook, kindly help me which automation I should use.?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 12:45:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/playbook-to-update-iocs-on-microsoft-advanced-threat-protection/m-p/551336#M2413</guid>
      <dc:creator>vhebri</dc:creator>
      <dc:date>2023-07-27T12:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Playbook to update IOCs on Microsoft Advanced Threat Protection (APT)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/playbook-to-update-iocs-on-microsoft-advanced-threat-protection/m-p/552106#M2441</link>
      <description>&lt;P&gt;Hello Vhebri,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found this content pack from called 'Microsoft Defender for Endpoint' that includes this in the description:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Enriches IOCs from XSOAR to Microsoft Defender for Endpoint and vice versa,&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;and it allows the&amp;nbsp;Microsoft Defender for Endpoint integration to import events as XSOAR incidents.&lt;/P&gt;
&lt;P&gt;This should accomplish the items you are looking for. Hope this helps!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Link here:&amp;nbsp;&lt;A href="https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftDefenderAdvancedThreatProtection/" target="_blank"&gt;https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftDefenderAdvancedThreatProtection/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 17:54:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/playbook-to-update-iocs-on-microsoft-advanced-threat-protection/m-p/552106#M2441</guid>
      <dc:creator>Ivetto</dc:creator>
      <dc:date>2023-08-01T17:54:00Z</dc:date>
    </item>
  </channel>
</rss>

