<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proofpoint Threat Response XSOAR integration Block URL, Block Domain, Block IP lists? in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/proofpoint-threat-response-xsoar-integration-block-url-block/m-p/557629#M2617</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/290284"&gt;@teegs7070&lt;/a&gt;, I think that is a limitation from ProofPoint's API. According to the documentation you need to get id's from the UI interface first. Below is an extract from the API documentation that was sent to our engineering team when the integration was created. I say this because, I was not able to find "List API" on the online documentation portal. It's either not available anymore or behind a customer portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;List management API &lt;/STRONG&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt; One of the fundamental blocks of Threat Response is the concept of Lists. Lists are used to add hosts/hashes/urls to them and then block those atomic indicators on the enforcement devices. Threat Response exposes lists management functionality though the API. To perform actions on a list, you must first obtain the identification number (list-id) for that list in Threat Response. The steps below describe how to locate the ID: &lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt;1. Log in to Threat Response. &lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt;2. Navigate to the Lists page (and to the sub-tab for the list you are looking for). &lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt;3. Click on the desired list to display the list details. &lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt;4. Review the URL in your browser’s address bar; the ID will be at the end of the URL.&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Sep 2023 01:24:01 GMT</pubDate>
    <dc:creator>jfernandes1</dc:creator>
    <dc:date>2023-09-13T01:24:01Z</dc:date>
    <item>
      <title>Proofpoint Threat Response XSOAR integration Block URL, Block Domain, Block IP lists?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/proofpoint-threat-response-xsoar-integration-block-url-block/m-p/557557#M2616</link>
      <description>&lt;P&gt;Hello, we successfully have integrated Proofpoint Threat Response Logs into our XSOAR instance. One of the problems we noticed right away is that it seems like its only a one way API flow, as in we cannot send any commands from XSOAR back to Proofpoint Threat Response. For example, with the integration we created a layout with certain button scripts to block URL or block domain. When going to do so, the script asks for Blacklist Domain List ID, or Blacklist URL List ID? I have some visibility into our Proofpoint Admin console and I have no clue where these lists are being stored, or how to view them. Anyone else have Proofpoint TRAP integrated and able to successfully block IOC's and close TRAP incidents directly from XSOAR?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 13:21:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/proofpoint-threat-response-xsoar-integration-block-url-block/m-p/557557#M2616</guid>
      <dc:creator>teegs7070</dc:creator>
      <dc:date>2023-09-12T13:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Proofpoint Threat Response XSOAR integration Block URL, Block Domain, Block IP lists?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/proofpoint-threat-response-xsoar-integration-block-url-block/m-p/557629#M2617</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/290284"&gt;@teegs7070&lt;/a&gt;, I think that is a limitation from ProofPoint's API. According to the documentation you need to get id's from the UI interface first. Below is an extract from the API documentation that was sent to our engineering team when the integration was created. I say this because, I was not able to find "List API" on the online documentation portal. It's either not available anymore or behind a customer portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;List management API &lt;/STRONG&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt; One of the fundamental blocks of Threat Response is the concept of Lists. Lists are used to add hosts/hashes/urls to them and then block those atomic indicators on the enforcement devices. Threat Response exposes lists management functionality though the API. To perform actions on a list, you must first obtain the identification number (list-id) for that list in Threat Response. The steps below describe how to locate the ID: &lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt;1. Log in to Threat Response. &lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt;2. Navigate to the Lists page (and to the sub-tab for the list you are looking for). &lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt;3. Click on the desired list to display the list details. &lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;EM&gt;&lt;FONT size="2"&gt;4. Review the URL in your browser’s address bar; the ID will be at the end of the URL.&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 01:24:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/proofpoint-threat-response-xsoar-integration-block-url-block/m-p/557629#M2617</guid>
      <dc:creator>jfernandes1</dc:creator>
      <dc:date>2023-09-13T01:24:01Z</dc:date>
    </item>
  </channel>
</rss>

