Cortex XSOAR Discussions

Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

XSOAR + Threat Intelligence

Hi, All!

 

I am working on integrating more threat intelligence into our XSOAR platform. Our latest efforts have been integrating other free sources of IOCs (AlienVault, Abuse.ch, etc...) and then we are going to work that into playbooks to create lo

...

User Restriction and permission

Hi,

using XSOAR I came across some issues related to user permissions and audit logs to have an account of the various activities performed on the platform:

- Is it possible to restrict user permission to execute scripts/commands only via field chang

...

XSOAR - Error in XDR Automation

Hi,

 

When i am trying to execute the automation xdr-get-incident-extra-data (Cortex XDR - IR) in playbook, i am getting an error as shown in the screenshot below. What could be the reason? Kindly help,

 

 

Thanks,

Nithin

nithink_0-1703677129627.png
nithin.k by L1 Bithead
  • 1003 Views
  • 3 replies
  • 0 Likes

xdr-get-incident command date time dispute

Hello everyone,

 

I have a script that need to get incidents from server. 

incidents = execute_command(
            "xdr-get-incidents",
            {
                "lte_creation_time": last_creation_time.split("+")[0],
                "gte_creati
...

Resolved! Unblock IP

Hi,

I have been using Panorama integration to block the IP. Is there any way where I can unblock the IP or remove the IP from address group of Panorama.

Himangi by L2 Linker
  • 1579 Views
  • 3 replies
  • 0 Likes

False Positives Microsoft Teams Large Upload

Hey,


I need your help.

We are receiving alerts "XDR Incident 945 - 'Large upload (generic)' generated by #XDR Analytics detected...

 

Basically, this appears when the user makes a call, shares documents, or shares their screen (using Microsoft Teams)

...

tlmarques by L4 Transporter
  • 1322 Views
  • 2 replies
  • 0 Likes

Resolved! Playbook waiting for a manual Set task

Hello community,

 

I have some playbooks that are responsible for closing incidents in the various sources (XDR, QRadar, XSOAR, JIRA, ...) once I enter a reason or reason for them to be closed.

 

 

I have done this using a "Set" automation that wa

...

rafaelusano_0-1703592508555.png
rafaelusano_1-1703592616387.png

Per Month Query using Beve Query Syntax

Hi,

 

I am trying to take a sum of incidents over a given time, and divide this sum per month, using Beve Syntax.

I there any syntax that would give me a per-month break down?  So I can take incidents per month, and display them in a widget using a b

...

  • 1177 Posts
  • 39 Subscriptions
Top Liked Authors