<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic playbook user investigation - generic in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/playbook-user-investigation-generic/m-p/580271#M3145</link>
    <description>&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;hello everyone,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;I was reviewing the user investigation - generic playbook for a bit, I would like to have your support by explaining to me what types of uses this playbook could be applied to and if anyone of you already has it implemented.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Thank you all&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Mar 2024 19:42:14 GMT</pubDate>
    <dc:creator>gerardo.rodriguez</dc:creator>
    <dc:date>2024-03-13T19:42:14Z</dc:date>
    <item>
      <title>playbook user investigation - generic</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/playbook-user-investigation-generic/m-p/580271#M3145</link>
      <description>&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;hello everyone,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;I was reviewing the user investigation - generic playbook for a bit, I would like to have your support by explaining to me what types of uses this playbook could be applied to and if anyone of you already has it implemented.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Thank you all&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 19:42:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/playbook-user-investigation-generic/m-p/580271#M3145</guid>
      <dc:creator>gerardo.rodriguez</dc:creator>
      <dc:date>2024-03-13T19:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: playbook user investigation - generic</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/playbook-user-investigation-generic/m-p/580751#M3152</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/812718387" target="_blank"&gt;@SOAR-ADMIN&lt;/A&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can find the details about the playbook on the below page.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/playbooks/user-investigation---generic" target="_blank" rel="nofollow noopener noreferrer"&gt;https://xsoar.pan.dev/docs/reference/playbooks/user-investigation---generic&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If you want to check which playbooks use it as a sub-playbook, there are some examples below:&lt;BR /&gt;&lt;BR /&gt;Cortex XDR - Large Upload&lt;BR /&gt;Possible External RDP Brute-Force&lt;BR /&gt;Cortex XDR - Port Scan&lt;BR /&gt;Cortex XDR - First SSO Access&lt;BR /&gt;Cortex XDR - Possible External RDP Brute-Force&lt;BR /&gt;DLP Incident Feedback Loop&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 08:52:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/playbook-user-investigation-generic/m-p/580751#M3152</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2024-03-18T08:52:40Z</dc:date>
    </item>
  </channel>
</rss>

