<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Phishing  PlayBook Issue in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/phishing-playbook-issue/m-p/599721#M3681</link>
    <description>&lt;P&gt;Yeah. As of now, XSOAR OOTB phishing playbook provides fetching only through attachment files.&lt;BR /&gt;If you wish to extract indicators from the Email Body, you would have create a separate task for that using 'enrichindicators' command.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Oct 2024 17:05:45 GMT</pubDate>
    <dc:creator>pagnihotri</dc:creator>
    <dc:date>2024-10-07T17:05:45Z</dc:date>
    <item>
      <title>Phishing  PlayBook Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/phishing-playbook-issue/m-p/599640#M3672</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;I'm currently developing a phishing playbook that is already available in XSOAR. I'm curious why the IOCs are not being extracted from the email body, while it seems that IOC extraction only occurs from attachments in the .eml or .msg files.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Syedhkt_0-1728275077529.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62597i515C275CED61FDAA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Syedhkt_0-1728275077529.png" alt="Syedhkt_0-1728275077529.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; #phishing&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 04:25:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/phishing-playbook-issue/m-p/599640#M3672</guid>
      <dc:creator>Syedhkt</dc:creator>
      <dc:date>2024-10-07T04:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Phishing  PlayBook Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/phishing-playbook-issue/m-p/599721#M3681</link>
      <description>&lt;P&gt;Yeah. As of now, XSOAR OOTB phishing playbook provides fetching only through attachment files.&lt;BR /&gt;If you wish to extract indicators from the Email Body, you would have create a separate task for that using 'enrichindicators' command.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 17:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/phishing-playbook-issue/m-p/599721#M3681</guid>
      <dc:creator>pagnihotri</dc:creator>
      <dc:date>2024-10-07T17:05:45Z</dc:date>
    </item>
  </channel>
</rss>

