<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I get the scores of the indicators I extract with commands? in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578276#M3100</link>
    <description>&lt;P&gt;Greetings to everyone,&lt;/P&gt;
&lt;P&gt;With the help of an automation, I extract indicators from incoming incidents. I do this by running commands that createNewIndicator and then enrichIndicator. But these are not written to the context. I need to write them to the context, find out if it is Malicious or Suspicious and send it as an email. When I search with the searchIndicator command, most of the time, it searches without the indicator and the result is misleading.&lt;/P&gt;
&lt;P&gt;How can I do this in the simplest way?&lt;/P&gt;
&lt;P&gt;In short, how can I find out whether the indicators I extract are Malicious or not in the simplest way? (I do all of this in automation. But I will create a separate task in the playbook for the "Send mail if malicious" part).&lt;/P&gt;</description>
    <pubDate>Sun, 25 Feb 2024 22:22:18 GMT</pubDate>
    <dc:creator>YilmazDincer</dc:creator>
    <dc:date>2024-02-25T22:22:18Z</dc:date>
    <item>
      <title>How can I get the scores of the indicators I extract with commands?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578276#M3100</link>
      <description>&lt;P&gt;Greetings to everyone,&lt;/P&gt;
&lt;P&gt;With the help of an automation, I extract indicators from incoming incidents. I do this by running commands that createNewIndicator and then enrichIndicator. But these are not written to the context. I need to write them to the context, find out if it is Malicious or Suspicious and send it as an email. When I search with the searchIndicator command, most of the time, it searches without the indicator and the result is misleading.&lt;/P&gt;
&lt;P&gt;How can I do this in the simplest way?&lt;/P&gt;
&lt;P&gt;In short, how can I find out whether the indicators I extract are Malicious or not in the simplest way? (I do all of this in automation. But I will create a separate task in the playbook for the "Send mail if malicious" part).&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 22:22:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578276#M3100</guid>
      <dc:creator>YilmazDincer</dc:creator>
      <dc:date>2024-02-25T22:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: How can I get the scores of the indicators I extract with commands?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578279#M3101</link>
      <description>&lt;P&gt;What I really want is to write the DBotScore key in the content. But I don't know how to write it.&lt;/P&gt;
&lt;P&gt;If I can write it to the context, I can send the scores one by one from there. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dbotcontext.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57847i40B803AFFD96984A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dbotcontext.png" alt="dbotcontext.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 22:50:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578279#M3101</guid>
      <dc:creator>YilmazDincer</dc:creator>
      <dc:date>2024-02-25T22:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: How can I get the scores of the indicators I extract with commands?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578387#M3106</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you run &lt;STRONG&gt;!createNewIndicator&lt;/STRONG&gt;, the indicator will be written to context along with the score under the context key &lt;STRONG&gt;CreatedIndicator&lt;/STRONG&gt; in your context data. Are you not seeing that behavior?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jqamruddin_0-1708977353828.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57861iC39A358402F5CC7D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jqamruddin_0-1708977353828.png" alt="jqamruddin_0-1708977353828.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 19:56:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578387#M3106</guid>
      <dc:creator>jqamruddin</dc:creator>
      <dc:date>2024-02-26T19:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: How can I get the scores of the indicators I extract with commands?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578435#M3108</link>
      <description>&lt;P&gt;Yes, it doesn't show results. I do this in a custom automation with the command "demisto.executeCommand('createNewIndicator', pseudo, pseudo)".&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 08:48:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578435#M3108</guid>
      <dc:creator>YilmazDincer</dc:creator>
      <dc:date>2024-02-27T08:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can I get the scores of the indicators I extract with commands?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578513#M3109</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will need to use &lt;STRONG&gt;CommandResults&lt;/STRONG&gt; class to return the outputs to context in a custom automation. &lt;BR /&gt;Here is some documentation on that:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://xsoar.pan.dev/docs/integrations/code-conventions#commandresults" target="_blank"&gt;https://xsoar.pan.dev/docs/integrations/code-conventions#commandresults&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 16:20:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-can-i-get-the-scores-of-the-indicators-i-extract-with/m-p/578513#M3109</guid>
      <dc:creator>jqamruddin</dc:creator>
      <dc:date>2024-02-27T16:20:05Z</dc:date>
    </item>
  </channel>
</rss>

