Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

XSOAR 6.11 Content Bundle Update via API

Hello 

We have build a CICD Pipeline to manage Lists in a external Git-Repository. The reason for that is we want to have the option to let our analyst create message templates and config files in a versioned way. Also we don't want that our analyst h

...

JBoehm_0-1719908025087.png
JBoehm by L1 Bithead
  • 1116 Views
  • 2 replies
  • 0 Likes

Fetch Indicator Integration

Hello 

 

i plan to implement a custom integration which fetches IP Indicators. So far so good i was able to create the indicators with no issue. However i would like to update some fields eg. Hostname and also some custom fields like a Gridfield of V

...

JBoehm by L1 Bithead
  • 1194 Views
  • 2 replies
  • 0 Likes

XSOAR Qradar Offense Ingestion Doubt

Hello all,

 

 

We've a situation that we would like to clarify if it's a misconfiguration or if it is an expected behaviour.

#Qradar integration is only fetching ofenses that includes specific rule ids but qradar how it works associates new events and

...

DSilva8 by L0 Member
  • 986 Views
  • 1 replies
  • 0 Likes

Resolved! Remove file types from the context data

We have been building a playbook to decrypt all encrypted attachments and detonate in a wildfire and Mimecast sanbox using their integrations. I am struggling currently to remove jpegs and pngs from the context data so they are not being sent to the

...

GoQR.me QR Code Reader misbehaving

I have an XSOAR 8.5 instance with a playbook which makes use of the GoQR.me QR Code Reader integration.

It had been working nicely in the playbook for months, but has begun to misbehave.

 

In the playbook, images are extracted from a phishing email a

...

mattem by L1 Bithead
  • 2559 Views
  • 4 replies
  • 0 Likes

Append Multiple Ips to input

Hello Live Comm,

We are working on a WebEx playbook where IPs need to be added to proxy profiles. However, we are encountering an issue where, if a user mentions multiple IPs, the playbook task fails to add those IPs. Could you please suggest changes

...

  • 1266 Posts
  • 43 Subscriptions
Top Liked Authors