<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to push Bulk IOC list in file format to Cortex XDR (IP address,Malicious URLS,Malicious Hashes ) via from XSOAR in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-push-bulk-ioc-list-in-file-format-to-cortex-xdr-ip/m-p/590921#M3420</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have integrated the Instance&amp;nbsp;&lt;SPAN&gt;Cortex XDR - IOC content pack:&amp;nbsp;Cortex XDR by Palo Alto Networks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;kindly help me, below which command to push bulk update IOC indicators to Cortex XDR if am wrong kindly guide me.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Instance = &lt;STRONG&gt;Cortex XDR - IOC &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="939"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="297"&gt;Cortex XDR-IOC&lt;/TD&gt;
&lt;TD width="642"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-create-sync-file&lt;/TD&gt;
&lt;TD width="642"&gt;Creates the sync file for the manual process. Run this command when instructed by the XDR support team.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-disable&lt;/TD&gt;
&lt;TD width="642"&gt;Disables IOCs in the XDR server.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-enable&lt;/TD&gt;
&lt;TD width="642"&gt;Enables IOCs in the XDR server.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-push&lt;/TD&gt;
&lt;TD width="642"&gt;Push modified IOCs to Cortex XDR.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-set-sync-time (Deprecated)&lt;/TD&gt;
&lt;TD width="642"&gt;Set sync time manually. (Do not use this command unless you understand the consequences.)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-sync&lt;/TD&gt;
&lt;TD width="642"&gt;Sync your IOC with Cortex XDR and delete the old.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-to-keep-file&lt;/TD&gt;
&lt;TD width="642"&gt;Create a file with all the IOCs that are going to sync to Cortex XDR.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2024 12:14:23 GMT</pubDate>
    <dc:creator>cV V</dc:creator>
    <dc:date>2024-07-02T12:14:23Z</dc:date>
    <item>
      <title>How to push Bulk IOC list in file format to Cortex XDR (IP address,Malicious URLS,Malicious Hashes ) via from XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-push-bulk-ioc-list-in-file-format-to-cortex-xdr-ip/m-p/590921#M3420</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have integrated the Instance&amp;nbsp;&lt;SPAN&gt;Cortex XDR - IOC content pack:&amp;nbsp;Cortex XDR by Palo Alto Networks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;kindly help me, below which command to push bulk update IOC indicators to Cortex XDR if am wrong kindly guide me.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Instance = &lt;STRONG&gt;Cortex XDR - IOC &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="939"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="297"&gt;Cortex XDR-IOC&lt;/TD&gt;
&lt;TD width="642"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-create-sync-file&lt;/TD&gt;
&lt;TD width="642"&gt;Creates the sync file for the manual process. Run this command when instructed by the XDR support team.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-disable&lt;/TD&gt;
&lt;TD width="642"&gt;Disables IOCs in the XDR server.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-enable&lt;/TD&gt;
&lt;TD width="642"&gt;Enables IOCs in the XDR server.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-push&lt;/TD&gt;
&lt;TD width="642"&gt;Push modified IOCs to Cortex XDR.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-set-sync-time (Deprecated)&lt;/TD&gt;
&lt;TD width="642"&gt;Set sync time manually. (Do not use this command unless you understand the consequences.)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-sync&lt;/TD&gt;
&lt;TD width="642"&gt;Sync your IOC with Cortex XDR and delete the old.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;xdr-iocs-to-keep-file&lt;/TD&gt;
&lt;TD width="642"&gt;Create a file with all the IOCs that are going to sync to Cortex XDR.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 12:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-push-bulk-ioc-list-in-file-format-to-cortex-xdr-ip/m-p/590921#M3420</guid>
      <dc:creator>cV V</dc:creator>
      <dc:date>2024-07-02T12:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to push Bulk IOC list in file format to Cortex XDR (IP address,Malicious URLS,Malicious Hashes ) via from XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-push-bulk-ioc-list-in-file-format-to-cortex-xdr-ip/m-p/590929#M3421</link>
      <description>&lt;DIV class="row entry-parent"&gt;
&lt;DIV class="floated left aligned sixteen wide mobile six wide tablet sixteen wide computer column"&gt;
&lt;DIV class="entry-metadata"&gt;
&lt;P class="entry-task-command"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;I run the below command for IOC push to XDR but show an error expiration time invalid and date cannot be in the past.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="entry-task-command"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="entry-task-command"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Kindly help me to resolve this error and need to push ioc's to XDR, error screenshot attached for your reference please help me.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="entry-task-command"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="entry-task-command"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Command:&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV class="display-parent-entry"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;STRONG&gt;&lt;SPAN class="parent-entry-label ellipsis show-as-link" title="!xdr-iocs-push indicator=&amp;quot;1.179.247.182,45.141.148.220&amp;quot; using=&amp;quot;Cortex XDR - IOC_instance_1&amp;quot; (Cortex XDR - IOC[Cortex XDR - IOC_instance_1])"&gt;!xdr-iocs-push indicator="1.179.247.182,45.141.148.220" using="Cortex XDR - IOC_instance_1"&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV class="display-parent-entry"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="entry-view vertical-strech"&gt;
&lt;DIV class="vertical-strech demisto-data"&gt;
&lt;DIV&gt;
&lt;DIV class="entry-note-view" data-test-id="entry-note-text"&gt;
&lt;DIV&gt;
&lt;P class="entry-text-view"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN class=""&gt;The following IOCs were not pushed due to following errors: 1.179.247.182: Expiration time 1716529790609 is invalid; expiration date cannot be in the past. 45.141.148.220: Expiration time 1716529790609 is invalid; expiration date cannot be in the past.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 04 Jul 2024 11:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-push-bulk-ioc-list-in-file-format-to-cortex-xdr-ip/m-p/590929#M3421</guid>
      <dc:creator>cV V</dc:creator>
      <dc:date>2024-07-04T11:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to push Bulk IOC list in file format to Cortex XDR (IP address,Malicious URLS,Malicious Hashes ) via from XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-push-bulk-ioc-list-in-file-format-to-cortex-xdr-ip/m-p/591192#M3435</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For bulk of IOC Lists i.e 100 no's IP's, Hashes, Domain names. how to push from XSOAR to XDR as a file or any form? does anyone worked this usecase scenario, kindly share!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Single or Limit of 10 no's (IP , hashes, Domains Name ) the below command was working.&lt;/P&gt;
&lt;P&gt;!xdr-iocs-enable indicator="172.15.1.50"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!xdr-iocs-push indicator="172.15.1.50"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!xdr-iocs-push indicator="fea456b3a78e87c2c99c5997b7255f553495a06a29bd7d4096cf72bfcbe1ed9b"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!xdr-iocs-enable indicator="vmtoolsd.exe"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Chiranjeevi&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 09:31:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-push-bulk-ioc-list-in-file-format-to-cortex-xdr-ip/m-p/591192#M3435</guid>
      <dc:creator>cV V</dc:creator>
      <dc:date>2024-07-04T09:31:29Z</dc:date>
    </item>
  </channel>
</rss>

