<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSOAR blacklisting O365 senders in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364206#M38</link>
    <description>&lt;P&gt;oops, someone just highlighted a typo in my suggestions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To install module from script:&lt;/P&gt;&lt;P class="p1"&gt;Install-Module -Name ExchangeOnlineManagement&lt;/P&gt;</description>
    <pubDate>Thu, 19 Nov 2020 17:59:22 GMT</pubDate>
    <dc:creator>jgomes</dc:creator>
    <dc:date>2020-11-19T17:59:22Z</dc:date>
    <item>
      <title>XSOAR blacklisting O365 senders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/361293#M30</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When analyzing a phishing case, I would like to block a sender for all the company. I've read in the Microsoft doc and they say you can do it by creating a blacklist. I've not been able to find it in XSOAR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way of doing that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 13:02:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/361293#M30</guid>
      <dc:creator>Sergio_Gonzalez</dc:creator>
      <dc:date>2020-11-06T13:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR blacklisting O365 senders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/363706#M34</link>
      <description>&lt;P&gt;Hello Sergio&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you are referring to the EWS O365 integration?&lt;/P&gt;&lt;P&gt;Does the doc you are referring to provide the API call in order to create the blacklist?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 06:50:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/363706#M34</guid>
      <dc:creator>dbaumstein</dc:creator>
      <dc:date>2020-11-18T06:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR blacklisting O365 senders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364024#M35</link>
      <description>&lt;P&gt;Hello thanks for the response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I've seen the 0365 doc (&lt;A href="https://docs.microsoft.com/en-US/microsoft-365/security/office-365-security/create-block-sender-lists-in-office-365?view=o365-worldwide" target="_blank"&gt;https://docs.microsoft.com/en-US/microsoft-365/security/office-365-security/create-block-sender-lists-in-office-365?view=o365-worldwide&lt;/A&gt;) and I've seen that is possible to do, but I don't know if there is something already coded in XSOAR or should I duplicate the integration and figure out how to do this part, seems kind of tricky.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 10:51:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364024#M35</guid>
      <dc:creator>Sergio_Gonzalez</dc:creator>
      <dc:date>2020-11-19T10:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR blacklisting O365 senders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364199#M36</link>
      <description>&lt;P&gt;Looking on the EWS v2 integration, I do not see the option to create or modify a blacklist.&lt;/P&gt;&lt;P&gt;You can file in a feature request at&amp;nbsp;&lt;A href="https://xsoar.ideas.aha.io/" target="_blank"&gt;https://xsoar.ideas.aha.io/&lt;/A&gt;&amp;nbsp; so our engineering team can see if this can be added.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gilad&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 16:45:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364199#M36</guid>
      <dc:creator>GShriki</dc:creator>
      <dc:date>2020-11-19T16:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR blacklisting O365 senders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364205#M37</link>
      <description>&lt;P&gt;Hi Sergio,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My understanding (unless changed recently) is the Microsoft Web based API still does not support updating the global O365 email sender block lists - as seen in the Admin Centre UI.&amp;nbsp; This can be done via Mail transport rules API, but is only available via Power Shell module e.g.&amp;nbsp; ExchangeOnlineManagement&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;XSOAR supports Powershell Core on Linux. The is a few Power shell docker images in Demisto/XSOAR Docker Hub (e.g.&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;demisto/powershell-ubuntu:7.0.3.12001). However non of these have the ExchangeOnlineManagement pre-installed. So a custom Docker image required.&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Microsoft has a docket container registry and powershell image e.g.&amp;nbsp;mcr.microsoft.com/powershell - however this also does not have the module installed (I just checked). So needs some docker customizations - or see workaround below.&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;So I think your options are:&lt;/P&gt;&lt;P class="p1"&gt;1/ Manual task to have analyst login Exchange Online Admin centre and add the email/s manully.&lt;/P&gt;&lt;P class="p1"&gt;2/ Run Custom Linux Docker for Powershell with the right modules loaded, and run a pre-tested script&lt;/P&gt;&lt;P class="p1"&gt;3/ Run Windows Engine (with modules installed) and with custom automation to run your own powershell .ps scripts on engine.&lt;/P&gt;&lt;P class="p1"&gt;3/ Use 'remote' SSH shell command use case to any windows to run dynamic BAT/Powershell scripts. Messing, but the benefit is service Authentication can be done in a way that Domain connected device is trusted and doesn't need to stor credentials to disk.&lt;/P&gt;&lt;P class="p1"&gt;e script credentials.&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;My suggestion to try is:&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;1/ Create new docker based on powershell e.g.&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; /docker_image_create base=demisto/powershell-ubuntu:7.0.3.12001 name=new_powershell&lt;/P&gt;&lt;P class="p1"&gt;demisto/powershell-ubuntu:7.0.3.12001&lt;/P&gt;&lt;P class="p1"&gt;2/ In you Automation script - add 'Import-Module ExchangeOnlineManagement' at top of script. This will import module before running the rest of script. Also is invoked every time new docker in spawned (added only a couple seconds delay)&lt;/P&gt;&lt;P class="p1"&gt;3/ The of the script is tricky. You should to build your power shell credentials object from a password variable from XSOAR Vault. You will also need to write script, or have an account, that does not use MFA. Microsoft has articles on this.&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;e.g.&lt;/P&gt;&lt;P class="p1"&gt;Import-Module ExchangeOnlineManagement&lt;/P&gt;&lt;P class="p1"&gt;$User = "Domain01\ServiceAccount01" or "srvacc01@home.com"&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;$password = &amp;lt;from XSOAR key vault&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;$PWord = ConvertTo-SecureString -String "P@sSwOrd" -AsPlainText -Force&lt;BR /&gt;$Credential = New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList $User, $PWord&lt;/P&gt;&lt;P class="p1"&gt;Connect-ExchangeOnline -UserPrincipalName &amp;lt;name&amp;gt; -ShowProgress $false .... etc...&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;When selecting 'new' Automation and selecting Powershell (instead of default Python) - this will give you example on how to handle powershell object rendering to war room etc. Powershell $demisto namespace is the same as python I think e.g. like 'set' context etc.&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Good luck!..&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 17:45:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364205#M37</guid>
      <dc:creator>jgomes</dc:creator>
      <dc:date>2020-11-19T17:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR blacklisting O365 senders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364206#M38</link>
      <description>&lt;P&gt;oops, someone just highlighted a typo in my suggestions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To install module from script:&lt;/P&gt;&lt;P class="p1"&gt;Install-Module -Name ExchangeOnlineManagement&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 17:59:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364206#M38</guid>
      <dc:creator>jgomes</dc:creator>
      <dc:date>2020-11-19T17:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR blacklisting O365 senders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364387#M39</link>
      <description>&lt;P&gt;We have it on our roadmap to release new integration in PowerShell that will allow to block senders globally.&lt;BR /&gt;It should be release by the end of this quarter.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 21:46:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364387#M39</guid>
      <dc:creator>aazadaliyev</dc:creator>
      <dc:date>2020-11-19T21:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR blacklisting O365 senders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364484#M40</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In relation with that I suppose that this new integration will work in a way of when I block a sender, it affects to all the company right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 08:59:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364484#M40</guid>
      <dc:creator>Sergio_Gonzalez</dc:creator>
      <dc:date>2020-11-20T08:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR blacklisting O365 senders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364485#M41</link>
      <description>&lt;P&gt;Thank you very much for the response. I will try to test it and see if it works!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 09:00:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364485#M41</guid>
      <dc:creator>Sergio_Gonzalez</dc:creator>
      <dc:date>2020-11-20T09:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR blacklisting O365 senders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364661#M42</link>
      <description>&lt;P&gt;correct&lt;/P&gt;</description>
      <pubDate>Sat, 21 Nov 2020 08:25:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-blacklisting-o365-senders/m-p/364661#M42</guid>
      <dc:creator>aazadaliyev</dc:creator>
      <dc:date>2020-11-21T08:25:23Z</dc:date>
    </item>
  </channel>
</rss>

