Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

SAML connection error with PingID

Been fighting an integration issue for awhile now.  Was hoping someone had seen this error before.

 

Could not init SAML instance, IDPSSOURL: 'https://pid-dev.domain.com/site/SignOn.saml' is not available.

 

I was told by the tech who working on Ping

...

Resolved! XSOAR: MDE malware- Incident Enrichment

I am running error trying to pull the alert_id from a Defender incident under the sub playbook MDE Malware-Incident Enrichment -> Get full alert details using automation: 'microsoft-atp-get-alert-by-id'. 

 

Error: 

 Get full alert details: Missin
...

Disable/Enable Integration Instance via API

Can anyone provide an example of the API request they're utilizing to disable or enable an instance for an Integration via the CORE API?

 

Everything I've tried results in 400 error with this message:
"id": "errOptimisticLock",
"status": 400,
"title": "

...

mikeahrendt_0-1687536527716.png

automation script to take password

I'm attempting to write an automation that takes a user password. 

Then sends an api call containing that password, but when I enable the mandatory sensitive options on the automation script. The API call I wrote no longer runs. Are there any example

...

Sig_9 by L1 Bithead
  • 1685 Views
  • 2 replies
  • 1 Likes

Incident assignment in XSOAR

Hi,

 

Anyone please help me to understand automatic incident assignment by DBot to analyst. what are the steps have to perform?

how to define the shift in user roles?

 

Thanks.

DP696 by L2 Linker
  • 1240 Views
  • 2 replies
  • 0 Likes

E-mail preview image

Is there any way to use a task to preview an email (from an msg or eml) and not just see the filtered results?

I'm looking for a solution to display an email in xsoar as if I were to open it in outlook.

For analysis it would be important to see the e

...

  • 1053 Posts
  • 32 Subscriptions