Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Is there a way to launch a playbook from a button in an incident

I have a couple different use cases where I have several steps in a playbook that I would like to complete again after the playbook is complete. I basically have several steps in a playbook that I would like to have launched by a button. I am trying to avoid the lengthy process of converting the steps to a standalone script. Plus, it is much eas...

Resolved! Playbooks repository

Does anyone know and can share if there are websites or communities like this where playbooks used in Cortex XSOAR are shared? I'm not talking about code, but flowcharts etc

tlmarques by L4 Transporter
  • 1983 Views
  • 1 replies
  • 0 Likes

Issue in health check playbook under system diagnostics and health check content pack

I have installed system diagnostics and health check content pack from marketplace(using xsoar version 6.12). I have followed the steps given in this article: https://xsoar.pan.dev/docs/reference/packs/system-diagnostics-and-health-check The pack has a playbook "Health Check", I am executing that playbook by creating a manual incident. I am gett...

Himangi by L2 Linker
  • 2585 Views
  • 2 replies
  • 0 Likes

Extracting Domains Not from URL

Hello Live Comm, I am working on a use-case that allows us to extract indicators from specific reports and then pushes them to monitoring systems. We have seen that using the built-in Extract Indicator command causes domains to be extracted from URLs. Is there a way to allow only domains that are not in a URL to be extracted? I can see that you...

Unable to retrieve work_notes from Servicenow.

We have the Servicenow V2 integratoin enabled and we are able to retrieve "comments' but "work_notes" are not visible. - No errors are observed (it's just empty)- We are able to "add" work_notes from XSOAR. - We verified the permissions of the accounts being used in ServiceNow and no restrictions. - The "Use Display Value" checkbox is selected. ...

Resolved! Unable to fetch incident taks with Servicenow V2 integration.

Our company will use Servicenow "Incidents taks" to send a task to another team.Currently it is only possible to fetch "sc_tasks" which are Service Catalog tasks, however these service catalog tasks are not being used in our company. Use-case is that for example helpdesk opened a Incident and they send an "Incident task" to the SOC to help , a...

Resolved! Unable to send Slack block messages

I've been trying to send a block message from the SlackBlockBuilder automation. However, when I try to test it out via the debugger panel, it would result in an error. Spoiler (Highlight to read) Command: !SlackBlockBuilder list_name="SLACKV3_BLOCK_ASK_URLALERT" channel_id="[redacted]" persistent="false" reply="Thank you for your res...

IDarma by L0 Member
  • 3601 Views
  • 3 replies
  • 0 Likes

Delete File from War Room

Hi everyone, I would like to ask is it possible to permanently delete the downloaded file in War Room? My team wants to make use of the Jobs function in XSOAR to handle files, and the file should be deleted in XSOAR after handling it.Thanks,Eliza

ElizaWan by L0 Member
  • 4014 Views
  • 3 replies
  • 0 Likes

Access to XSOAR Community edition

Hello everybody, after reading through some of the threads here, most people run into a similar issue as I did. Not receiving the URL to download - has anyone found a suitable solution? I used a company email, I waited a week for it to come after the approval - yet nothing came, does anyone have the link for me? Thanks in advance.

JanGrob by L1 Bithead
  • 2019 Views
  • 2 replies
  • 0 Likes

O365 mail Graph API Integration - Best Practices

Hey all, I was exploring O365 graph API and wondering what are some of the best practices for this integration. One thing we came up was to IP restriction (Palo alto IP) in Microsoft side. Are there any other condition access policies that can be added to make sure we follow best practices, other than securing the Palo alto tenant and Micr...

Using Microsoft Authenticator MFA

Hello LiveComm, I am working on using MFA for authentication to xsoar on a server that has Active Directory (On-Prem) SAML authentication already in use. The use case is to require the user to authenticate using the Microsoft Authenticator app. I have searched around and have not found any documentation regarding this except for DUO though this ...

  • 1298 Posts
  • 45 Subscriptions