<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSOAR to analyze PDF and Office files in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-to-analyze-pdf-and-office-files/m-p/597380#M3605</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;We have a playbook to perform the same.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/playbooks/microsoft-office-file-enrichment---oletools" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/playbooks/microsoft-office-file-enrichment---oletools&lt;/A&gt;&lt;BR /&gt;Download the content pack from the marketplace -&amp;nbsp;&lt;A href="https://cortex.marketplace.pan.dev/marketplace/details/Oletools/" target="_blank"&gt;https://cortex.marketplace.pan.dev/marketplace/details/Oletools/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope it helps!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Sep 2024 05:35:36 GMT</pubDate>
    <dc:creator>SPatil15</dc:creator>
    <dc:date>2024-09-10T05:35:36Z</dc:date>
    <item>
      <title>XSOAR to analyze PDF and Office files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-to-analyze-pdf-and-office-files/m-p/596656#M3596</link>
      <description>&lt;P&gt;Hi everyone,&lt;BR /&gt;Does anyone use XSOAR to analyze PDF and Office files?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;My idea is for users to send emails to a specific account. &lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;would then receive these emails, extract the files, and analyze them using tools like OLETools. If any suspicious activity is detected, it would notify the IT team. If no suspicious activity is found, it would send an email back to the user saying, "File is okay.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Does it make sense?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I’m new to DFIR and XSOAR, so I’d appreciate any feedback or suggestions on this approach.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 21:47:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-to-analyze-pdf-and-office-files/m-p/596656#M3596</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-09-03T21:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR to analyze PDF and Office files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-to-analyze-pdf-and-office-files/m-p/597380#M3605</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;We have a playbook to perform the same.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/playbooks/microsoft-office-file-enrichment---oletools" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/playbooks/microsoft-office-file-enrichment---oletools&lt;/A&gt;&lt;BR /&gt;Download the content pack from the marketplace -&amp;nbsp;&lt;A href="https://cortex.marketplace.pan.dev/marketplace/details/Oletools/" target="_blank"&gt;https://cortex.marketplace.pan.dev/marketplace/details/Oletools/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope it helps!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 05:35:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-to-analyze-pdf-and-office-files/m-p/597380#M3605</guid>
      <dc:creator>SPatil15</dc:creator>
      <dc:date>2024-09-10T05:35:36Z</dc:date>
    </item>
  </channel>
</rss>

