<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Missing context in indicator preview. I executed an NVD reputation command on CVE via a custom script. in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/missing-context-in-indicator-preview-i-executed-an-nvd/m-p/615798#M3739</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/258347"&gt;@assubramania&lt;/a&gt;,&amp;nbsp;this happens because the NVD command&amp;nbsp;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;!nvd-search-cve&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;is not a reputation command but rather a CVE lookup command. One way to map the &lt;STRONG&gt;metrics&lt;/STRONG&gt; output from the command &lt;EM&gt;&lt;STRONG&gt;!nvd-search-cve&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;to your CVE type indicator is to create an indicator field of type Grid, containing all the&amp;nbsp;columns that are part of the &lt;STRONG&gt;metrics&lt;/STRONG&gt; result (see screenshot), associate it to the CVE indicator type, and then set the grid with the values from that output in a different task in your playbook. To populate the grid you can use the automation attached (&lt;EM&gt;SetGridField4Indicator&lt;/EM&gt;). Lastly, in order to display the new field in your CVE indicator layout, you need to edit the layout to include it (see screenshots "&lt;EM&gt;CVE Indicator layout.png&lt;/EM&gt;" and "&lt;EM&gt;CVE Indicator View.png&lt;/EM&gt;")&lt;BR /&gt;&lt;BR /&gt;This is the syntax to use the command attached:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="python"&gt;!SetGridField4Indicator grid_id=cvemetrics columns="CVSS Vector String,CVSS Integrity Impact,CVSS Scope,CVSS Attack Complexity,CVSS User Interaction,CVSS Confidentiality Impact,CVSS Attack Vector,CVSS Privileges Required,CVSS Base Score,Exploitability Score,Impact Score,CVSS Availability Impact,CVSS Base Severity" context_path=NistNVD.CVESearch.metrics indicator=CVE-2024-10154&lt;/LI-CODE&gt;
&lt;DIV id="2996@273bb15d-faa2-4580-8af0-8a48016614d3" class="chat-box war-room-entry"&gt;
&lt;DIV class="entry-body "&gt;
&lt;DIV class="ui grid"&gt;
&lt;DIV class="row entry-body-content"&gt;
&lt;DIV class="wide column"&gt;
&lt;DIV class="entry-wrapper"&gt;
&lt;DIV class="entry-view vertical-strech"&gt;
&lt;DIV class="vertical-strech"&gt;
&lt;DIV class="entry-note-view" data-test-id="entry-note-text"&gt;
&lt;DIV class="entry-text-view"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="2997@273bb15d-faa2-4580-8af0-8a48016614d3" class="artifact war-room-entry"&gt;
&lt;DIV class="entry-user-image-container"&gt;Let me know if you have any questions.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2024 15:43:31 GMT</pubDate>
    <dc:creator>AbelSantamarina</dc:creator>
    <dc:date>2024-10-30T15:43:31Z</dc:date>
    <item>
      <title>Missing context in indicator preview. I executed an NVD reputation command on CVE via a custom script.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/missing-context-in-indicator-preview-i-executed-an-nvd/m-p/614625#M3727</link>
      <description>&lt;DIV class="p-rich_text_section"&gt;Hi Team, The standard customer, where there is missing context in indicator preview. I executed an NVD reputation command on CVE via a custom script (CV Reputation).The results are in the attached playground data, but they're not reflected in the indicator sample. Please refer the screenshot.&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;STRONG data-stringify-type="bold"&gt;What has been done:&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;Non- working:&lt;BR /&gt;Integration: Nist NVD (Community Contribution)&lt;BR /&gt;Command: ! nvd-search-cve cve="CVE-2024-10198"In the war room we see the desired metric in context data but no context data metric populated in indicator sample.&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;Working:&lt;BR /&gt;Integration: Recorded Future v2 (Partner Contribution)&lt;BR /&gt;Command:!cve cve="CVE-2024-10198"Were we could see the metric in war room and the indicator sample.&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;Any suggestion urgently.&lt;/DIV&gt;</description>
      <pubDate>Fri, 25 Oct 2024 03:19:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/missing-context-in-indicator-preview-i-executed-an-nvd/m-p/614625#M3727</guid>
      <dc:creator>assubramania</dc:creator>
      <dc:date>2024-10-25T03:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Missing context in indicator preview. I executed an NVD reputation command on CVE via a custom script.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/missing-context-in-indicator-preview-i-executed-an-nvd/m-p/615798#M3739</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/258347"&gt;@assubramania&lt;/a&gt;,&amp;nbsp;this happens because the NVD command&amp;nbsp;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;!nvd-search-cve&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;is not a reputation command but rather a CVE lookup command. One way to map the &lt;STRONG&gt;metrics&lt;/STRONG&gt; output from the command &lt;EM&gt;&lt;STRONG&gt;!nvd-search-cve&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;to your CVE type indicator is to create an indicator field of type Grid, containing all the&amp;nbsp;columns that are part of the &lt;STRONG&gt;metrics&lt;/STRONG&gt; result (see screenshot), associate it to the CVE indicator type, and then set the grid with the values from that output in a different task in your playbook. To populate the grid you can use the automation attached (&lt;EM&gt;SetGridField4Indicator&lt;/EM&gt;). Lastly, in order to display the new field in your CVE indicator layout, you need to edit the layout to include it (see screenshots "&lt;EM&gt;CVE Indicator layout.png&lt;/EM&gt;" and "&lt;EM&gt;CVE Indicator View.png&lt;/EM&gt;")&lt;BR /&gt;&lt;BR /&gt;This is the syntax to use the command attached:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="python"&gt;!SetGridField4Indicator grid_id=cvemetrics columns="CVSS Vector String,CVSS Integrity Impact,CVSS Scope,CVSS Attack Complexity,CVSS User Interaction,CVSS Confidentiality Impact,CVSS Attack Vector,CVSS Privileges Required,CVSS Base Score,Exploitability Score,Impact Score,CVSS Availability Impact,CVSS Base Severity" context_path=NistNVD.CVESearch.metrics indicator=CVE-2024-10154&lt;/LI-CODE&gt;
&lt;DIV id="2996@273bb15d-faa2-4580-8af0-8a48016614d3" class="chat-box war-room-entry"&gt;
&lt;DIV class="entry-body "&gt;
&lt;DIV class="ui grid"&gt;
&lt;DIV class="row entry-body-content"&gt;
&lt;DIV class="wide column"&gt;
&lt;DIV class="entry-wrapper"&gt;
&lt;DIV class="entry-view vertical-strech"&gt;
&lt;DIV class="vertical-strech"&gt;
&lt;DIV class="entry-note-view" data-test-id="entry-note-text"&gt;
&lt;DIV class="entry-text-view"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="2997@273bb15d-faa2-4580-8af0-8a48016614d3" class="artifact war-room-entry"&gt;
&lt;DIV class="entry-user-image-container"&gt;Let me know if you have any questions.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 15:43:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/missing-context-in-indicator-preview-i-executed-an-nvd/m-p/615798#M3739</guid>
      <dc:creator>AbelSantamarina</dc:creator>
      <dc:date>2024-10-30T15:43:31Z</dc:date>
    </item>
  </channel>
</rss>

