Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

XSOAR Mark war room entries as note

Hi everyone,

 

I have button in the incident layout and the script it triggers creates a new incident and posts all of the war room entries to the new incident. In the incident, we have some notes that should also be seen as notes in the new incident

...

Retrieve screenshots from Notes section

Hi!

 

We are trying to give more importance to XSOAR within our SOC processes. As part of the changes we are introducing, we want all alert documentation to be done from now on in the 'Notes' section of each XSOAR incident.

 

The issue we are facing

...

adocasar by L1 Bithead
  • 527 Views
  • 2 replies
  • 0 Likes

WHOIS Integration - Connection Refused Errors

Hi All,

I am using hois integration to use "domain" command. I sometimes have array of strings for domains and sometimes single string and in most of cases whois return results to me but i got sometimes "Connection Refused" Issue. I already adjusted

...

Syedhkt by L2 Linker
  • 587 Views
  • 1 replies
  • 0 Likes

DT Query, special characters in key:value pair

I'm trying to create a "dt" filter for use with the GenericPolling playbook. (https://xsoar.pan.dev/docs/playbooks/generic-polling)

The key I need to check for the existence of is

MsGraph.Alert.Evidence.[1].@odata\.type

(XSOAR automatically adds the "

...

cmcneil_0-1726072639505.png
cmcneil_1-1726073507105.png
cmcneil by L2 Linker
  • 1417 Views
  • 3 replies
  • 0 Likes

setPlaybook + Post-Processing

 

Hi everyone,

I have a Post-Processing script that uses the setPlaybook command to switch the incident to a playbook called test1.

 

The problem is that when I close the incident, the script doesn’t run just once - it keeps setting the same playbook

...

NivNet by L1 Bithead
  • 315 Views
  • 1 replies
  • 0 Likes

How do we join the Slack DFIR community?

Hi Everyone!

 

I’m hoping you can aim me in the right direction.

I’m trying to join the PAN DFIR slack community via this url:https://start.paloaltonetworks.com/join-our-slack-community

 

But the register button doesn’t seem to work for me, despite m

...

J.Pedlow by L1 Bithead
  • 1173 Views
  • 5 replies
  • 0 Likes

XSOAR EWS 2022 Integration

As you know, the current EWS integration is limited to Exchange 2019. Could you please confirm if there are any plans to extend support for Exchange 2022? Additionally, are there any recommended workaround solutions for implementing inbox monitoring

...

[Cortex XSOAR] Integration TIM to SIEM Elastic

Hello Team,

 

I have a case that must integrate indicator from TIM Cortex XSOAR to SIEM 3rd Party like Elastic. Is there any documentation about how to integrate indicator from TIM for Elastic? Because when I search in documentation from Cortex XSOAR

...

A.Faruq by L0 Member
  • 296 Views
  • 0 replies
  • 0 Likes
  • 1264 Posts
  • 43 Subscriptions
Top Liked Authors