Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! McAfee Mvision Integration Missing Image

Hello,

I am attempting to use the integration provided by EDR-Integrations by Martin Ohl. 

When performing the test I receive the error "Error response from daemon: pull access denied for mohlcyber/dxl, repository does not exist or may require 'docke

...

Run a command on all tenants from master

hi everyone,

 

I need some help with microsoft graph integrations with multi tenancy

 

I configured an instance of Microsoft Graph Mail Single User integration in the master and want to sync to all the tenants. Simply syncing won't work because the i

...

Apply transformers directly on variables

Hello,

I'm creating Json lists introducing data in them. I'm using "addToList" automation. The data introduced example:

listData:

{"key1":{

"subkey1: ${dataInput1},

"subkey2: ${dataInput2},

"subkey3: ${dataInput3},

"subkey4: ${dataInput4}

}

 

Is ther

...

Josep by L4 Transporter
  • 853 Views
  • 1 replies
  • 0 Likes

Even though get-remote-data command executes successfully, the entries returned in the GetRemoteDataResponse object is not being added to the incident

When the get-remote-data is being called, I am getting below errors when returning entries to the GetRemoteDataResonse. The command is executes successfully, but I do not get entries in the XSOAR incident which I have passed to the GetRemoteDataRespo

...

HarshPanchal_0-1674821669351.png
HarshPanchal_2-1674821769217.png

Panoroma IP Blocking Issue

I wanted to block ips via using xsoar, on Pan-os panorama. We have integrated xsoar and panoroma but non of the automations provide us a blocking on panorama. In addition to that I tried to give inputs to Block IP Generic v3 playbook(which is provide

...

UmutAK by L1 Bithead
  • 719 Views
  • 1 replies
  • 0 Likes

Search IOCs on VirusTotal Faster

We are running a playbook to search a list of IOCs on VirusTotal, the list is received by an attachment on incident creation. The playbook then exports the VirusTotal scores into the war room as a csv file. All this is achieved by manual indicator cr

...

XSOAR Tenant RO access

Hi All,

In an environment where one has a multi tenant setup, what is required from a licensing perspective in order to setup an account (pref read only) to be able to view both the master and any child tenants within. requirement for this account is

...

Ants by L1 Bithead
  • 590 Views
  • 1 replies
  • 0 Likes

Microsoft Sentinel Integration

I am having the following error while trying to create an instance of  "Microsoft Sentinel Integration":

Error
(April 12, 2023 9:47 AM)

Script failed to run: Error: [Traceback (most recent call last): File "<string>", line 1, in <module> NameError:

...

MSSSOC by L0 Member
  • 921 Views
  • 1 replies
  • 0 Likes

Get MFA authentication methods

Hello community!

 

I was wondering if there's any integration that would allow me to get the defined authentication methods for a given user. The use case is to know if someone who has entered credentials in a phishing portal has MFA enabled or not a

...

adocasar by L1 Bithead
  • 846 Views
  • 1 replies
  • 0 Likes
  • 943 Posts
  • 30 Subscriptions
Top Solution Authors