Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Get Incident List from Microsoft 365 Defender

Hi Team, I want to get the events between the dates I give from Microsoft 356 Defender. In the ‘microsoft-365-defender-incidents-list’ command, the limit is set to maximum 100. What should I do to make the limit unlimited? The command: test_data ={’$filter": “createdTime gt 2024-03-16T06:00:00.29Z and createdTime lt 2024-07-22T09:00:00.29Z”} ex...

XSOAR File Issue

Hi All, I tried to send an attachment using the attachment ID in Exchange Web Services (EWS) for Office 365, and I was also able to see the entry ID of the file in context object. However, the structure of the entry ID is different from the standard format. I created a ZIP file from a text file and uploaded it to the context, but I'm facing an i...

Syedhkt by L2 Linker
  • 1474 Views
  • 1 replies
  • 0 Likes

Resolved! cve-2024-41110 Docker vulnerability impact XSOAR?

Who is impacted?Users of Docker Engine v19.03.x and later versions who rely on authorization plugins to make access control decisions. Who is not impacted?Users of Docker Engine v19.03.x and later versions who do not rely on authorization plugins to make access control decisions and users of all versions of Mirantis Container Runtime are not vul...

Issue in loading and pulling podman images

We are getting below error in Redhat while loading the images. Error: payload does not match any of the supported image formats: * oci: open test21.tar/index.json: not a directory * oci-archive: loading index: open /var/tmp/container_images_oci3039334482/inde x.json: no such file or directory * docker-archive: writing blob: adding layer with blo...

Evidence XSOAR

Hi everyone,Does anyone know if it's possible to paste evidence (screenshots) into an Incident using CTRL+V? I've tested it and sometimes it works, but sometimes it doesn't...Does anyone know if it's possible to create a button that allows uploading files (pictures and documents) as evidence?Cortex XSOAR

tlmarques by L4 Transporter
  • 928 Views
  • 1 replies
  • 0 Likes

Issues with Report Creation in Cortex XSOAR 6.12 Free Edition

I'm currently using the free edition of Cortex XSOAR and have encountered a couple of issues related to reports: Missing "Add New Report" Button: According to the documentation and tutorials I've followed, there should be an "Add Report" button in the reports interface. However, in my instance, this button is missing. Is this a limitation of t...

chmalla9_0-1722191186602.png
chmalla9_1-1722191219379.png
chmalla9 by L0 Member
  • 1148 Views
  • 1 replies
  • 0 Likes

Troubleshooting an XSOAR 8 on-prem installation

Hi team, I wanted to see if there is any way to troubleshoot or view debug output/logs in XSOAR 8 on-prem? I have not had much luck getting the OVA version fo deploy successfully, let alone completing the install and accessing a functional UI. I am persistently stuck at an NGINX screen trying to access the FQDN, but have no way to look at logs t...

ZIP a file XSOAR

Hi Team, I'm trying to zip a file using ZipFile Automation as a task in the playbook and after it has been zipped use the ZIP file EntryID to be sent attached in an email, I'm getting this error: 'Unable to read file with id b4841215-d627-4c36-9cb6-243199452aaf', ValueError('failed to get artifact file path, invalid file (52)\n' ZipFile Ta...

Resolved! Crowdstrike API upgradation

I recently got news that crowdstrike is going to upgrade api version so what needs to do at xsoar side in terms of integration. According to my info we just need to update the pack or what else Cortex XSOAR

Syedhkt by L2 Linker
  • 1688 Views
  • 1 replies
  • 0 Likes

Migrating instances to a new server - Accessing API Keys

Hello Live Comm, I have created a new XSOAR Server with a different OS and have begun migrating the data. I need to migrate the instances and we don't have records of the original API keys. Is there a way to access and view the API keys configured on the platform? I need to migrate all of them is there a way to do this? Many thanks, M Sysec Co...

Polling XDR Integration for Alerts that are not Incident Based

Hello all, I am running a Use-Case that requires me to poll the XDR Tenant for all alerts. These include Alerts that are found in an XDR Incident and Independent Alerts that are not found in an incident. For example a Low Severity alert from a BIOC Analytics Source that has not opened or should I say referenced in an incident. These Independent ...

  • 1298 Posts
  • 45 Subscriptions