<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSOAR File Issue in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-file-issue/m-p/595062#M3528</link>
    <description>&lt;P data-unlink="true"&gt;We do something similar with our phishing playbook when an email is legitimate or known good.&lt;BR /&gt;The attachment we send back is the one which was received in the original incident. We use the incident EntryID which looks like "4@ 12345"&amp;nbsp;as shown in this screenshot.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Attachment IDs 2.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61555i9A6741664D2988F9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Attachment IDs 2.png" alt="Attachment IDs 2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then, in our send-mail command, using EWSO365, we reference the EntryID as the attachID. See screenshot below for details. Redacted items are not relevant to the issue at hand.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Attachment IDs 1.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61556iC6EABDBA988BDE4D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Attachment IDs 1.png" alt="Attachment IDs 1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As noted in the reference docs for the EWS O365 integration, the attachID in the send-mail command must reference a war room entry, not the Exchange attachment-ids. (&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/ewso365#19-send-an-email" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/integrations/ewso365#19-send-an-email&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;To first get the attachment, if it's not already part of your incident, you would need to run the "ews-get-attachment" command with attachment-ids you referenced in your post, then use the EntryID from that command as an input in your send-mail command. (&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/ewso365#1-get-the-attachments-of-an-item" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/integrations/ewso365#1-get-the-attachments-of-an-item&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
    <pubDate>Thu, 15 Aug 2024 22:44:28 GMT</pubDate>
    <dc:creator>cmcneil</dc:creator>
    <dc:date>2024-08-15T22:44:28Z</dc:date>
    <item>
      <title>XSOAR File Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-file-issue/m-p/592853#M3494</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi All,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I tried to send an attachment using the attachment ID in Exchange Web Services (EWS) for Office 365, and I was also able to see the entry ID of the file in context object. However, the structure of the entry ID is different from the standard format. I created a ZIP file from a text file and uploaded it to the context, but I'm facing an issue. Do you have any suggestions or solutions to help me with this? Please check attached pictures&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 04:50:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-file-issue/m-p/592853#M3494</guid>
      <dc:creator>Syedhkt</dc:creator>
      <dc:date>2024-07-24T04:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR File Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-file-issue/m-p/595062#M3528</link>
      <description>&lt;P data-unlink="true"&gt;We do something similar with our phishing playbook when an email is legitimate or known good.&lt;BR /&gt;The attachment we send back is the one which was received in the original incident. We use the incident EntryID which looks like "4@ 12345"&amp;nbsp;as shown in this screenshot.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Attachment IDs 2.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61555i9A6741664D2988F9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Attachment IDs 2.png" alt="Attachment IDs 2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then, in our send-mail command, using EWSO365, we reference the EntryID as the attachID. See screenshot below for details. Redacted items are not relevant to the issue at hand.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Attachment IDs 1.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61556iC6EABDBA988BDE4D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Attachment IDs 1.png" alt="Attachment IDs 1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As noted in the reference docs for the EWS O365 integration, the attachID in the send-mail command must reference a war room entry, not the Exchange attachment-ids. (&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/ewso365#19-send-an-email" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/integrations/ewso365#19-send-an-email&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;To first get the attachment, if it's not already part of your incident, you would need to run the "ews-get-attachment" command with attachment-ids you referenced in your post, then use the EntryID from that command as an input in your send-mail command. (&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/ewso365#1-get-the-attachments-of-an-item" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/integrations/ewso365#1-get-the-attachments-of-an-item&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 22:44:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-file-issue/m-p/595062#M3528</guid>
      <dc:creator>cmcneil</dc:creator>
      <dc:date>2024-08-15T22:44:28Z</dc:date>
    </item>
  </channel>
</rss>

