Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Automate Reported Phishing Email Attachments to CrowdStrike Falcon Sandbox w/ XSOAR

I was wondering how to create a playbook so when a user reports an email as phishing, to somehow have it automatically upload to the CrowdStrike Falcon Sandbox for further analysis - Basically anytime a phishing email with an attachment is submitted to our company report phishing email inbox, to pull it from Abnormal Email Security, then send it...

passat2k by • L0 Member
  • 4613 Views
  • 3 replies
  • 0 Likes

Connecting Cortex XSOAR to Internal Cloud Hosted Panorama for Prisma Access Integration

I'm seeking assistance on securely establishing an SSH connection from Cortex XSOAR to Panorama as part of the integration Prisma Access with XSOAR. This integration aims to execute CLI commands on Panorama, which is hosted within Azure (internally). To ensure security and avoid exposing Panorama to the internet, I'm looking for best practices o...

Wassif by • L1 Bithead
  • 1812 Views
  • 1 replies
  • 1 Likes

Resolved! Looping A Sub-Playbook

Require some suggestions. I am trying to loop a sub-playbook. If the exit condition is met, everything is okay. However, if max number of iterations are reached the playbook throws and error that waiting for manual input and fails. Anyone has any idea if I am missing something #loopaplaybook

Resolved! Cortex XSOAR SSH Outbound Connection IP issue

Hello, I'm working on configuring SSH connections from Cortex XSOAR to our internal Azure-based system. To ensure secure and uninterrupted connectivity, I need to whitelist the IP address used by Cortex XSOAR for these outbound connections in our firewalls. Could you provide the IP ranges or specific IP addresses used by Cortex XSOAR for outboun...

Wassif by • L1 Bithead
  • 2086 Views
  • 1 replies
  • 0 Likes

Reopen XSOAR Incidents Bulk in XSOAR

Hello all, I need to reopen a large amount of incidents on Xsoar. Can anyone suggest how I can do this? I have tried to run both the built-in command and the automation to reopen from the run command button with the bulk incidents selected but to no avail. Many thanks, MR Cortex XSOAR

Get Specific List from /lists Endpoint (XSOAR API)

Hello, When Im sending GET request to https://myxsoar/lists. Im getting list of all XSOAR lists, there is anyway to get Specific list? I tried: https://myxsoar/lists/test_list but it doesn't work. I didn't find on the documentations anything about this endpoint. Any idea how or if I can do it? (Can run over the response list and search for spe...

BHalifa by • L1 Bithead
  • 1253 Views
  • 1 replies
  • 0 Likes

Resolved! XSOAR - EmailAskUserResponse

Hi I am new to XSOAR. I am trying to configure sending email to user and capturing their response via email. I used the script named ‘EmailAskUser’ to send email and then I am trying to capture the response using ‘EmailAskUserResponse’. However, it says item not found. The ‘responsentryid’ is mentioned of Task EmailAskUser. Share suggestions ...

Resolved! Help with feeds

Hello, I need your help. I need feeds for domain classification and another feed for phishing, to determine whether domains have been compromised or not. What do you recommend for Cortex XSOAR #

tlmarques by • L4 Transporter
  • 1950 Views
  • 1 replies
  • 0 Likes

We are having an error in the ForwardAuditLogsToSplunkHEC: Reason: Failed to execute BaseScript. Error: string indices must be integers

We are having an error in the ForwardAuditLogsToSplunkHEC: Reason: Failed to execute BaseScript. Error: string indices must be integers. We have a job sending the logs from XSOAR to Splunk, and suddenly has stopped working. As the script is part of the XSOAR default one. Please help resolve this.

Resolved! How to send via HTTP to the XSOAR data to be injected in a playbook?

I have a playbook that needs feedback from outside. To set some context, let's say that the playbook generates a UUID a5de4f06-2941-4e26-975e-5e6cb316916d and informs a user that they need to go to https://example.com/a5de4f06-2941-4e26-975e-5e6cb316916d. Over there they have some things to set and the backend of https://example.com is ready to ...

Hiding Incident Types from Specific Role

Hello all, I have recently come across a use case that requires me to hide incidents from the Tier 1 Team during escalation in order that it can be free to be assigned to a Tier 2 analyst. Is there a way to hide an incident based on an incident field being true, through a script or some kind of built - in function? I don't want to hide tabs or ...

Cortex XSOAR integration with Logrhythm SIEM

We were recently having use case for a SIEM integration with cortex XSOAR. We have an on-premise LogRhythm SIEM server which we need to integrate with our Cortex XSOAR. I have gone through the official XSOAR documentation for the integration but it wasn't of much help. Has anyone done the integration and made any playbooks? Kindly share the ...

  • 1310 Posts
  • 46 Subscriptions
Top Solution Authors