Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Move War Room Entries section

Hi all!
I want to move this section to a different tab in the layout. How do I do that?

I've tried using the War Room Entries section to the tab where I wanted it to be, but the filter 'URL Enrichment' is not listed. Any tips?

 

Thanks!

Screenshot 2023-08-11 at 12.43.01 PM.png

Cortex XSOAR Deployment

I want to ask for the Cortex XSOAR installation which is a free trial, can it only be installed on premise or can it be done on a cloud basis? because after I requested a free trial for cortex XSOAR they directed it to install on premise


Resolved! Playbook Args

Hi all, 

I want to get an argument from user when playbook running. Actually, the first method I can think of is as below. But can you give a more user-friendly example?

Ekran görüntüsü 2023-08-10 163821.png

Resolved! XSOAR Shift Management and Incident Assignment

I've read a little about the Shift Management function.

Does this allow for intelligence to auto-assign incidents?

Example:
5 people on shift, based on threshold of SLA, auto-assign incident round robin style to the analyst that are in the queue?

Is ther

...

JoshBoyd by L2 Linker
  • 1992 Views
  • 2 replies
  • 0 Likes

Resolved! AWS describe-vpc-endpoints

I am not seeing the AWS command describe-vpc-endpoints in any of the integrations...I just want to confirm I'm not missing it somewhere before I submit a feature request.  Thanks.

Incident Layout dynamic section as input

Hello!
I would like to ask you how to implement a way to define the input values on the Incident Layout.

For example, I would need it in a case where I have a sub playbook and I want to give a value to one of its mandatory arguments without having to

...

szodinn by L0 Member
  • 1315 Views
  • 2 replies
  • 0 Likes

Resolved! SlackAskV2 automation

Hi all,


I'm trying out SlackAskV2 and my message is being sent to the channel successfully. I used 'Yes' and 'No' as options.

When I click the 'Yes' or 'No' buttons from the slack channel, nothing is returned to the War Room.

Now, where do I find the

...

Mapping fields to XSOAR IOCs

I'd appreicate guidance on how to update IOC fields with information extracted from an excuted playbook task. 

 

My use case centers around updating File Hash IOCs to include file signature metadata information to enable easier cleaning up of IOCs as

...

jemeche by L0 Member
  • 1270 Views
  • 3 replies
  • 0 Likes
  • 1171 Posts
  • 39 Subscriptions
Top Solution Authors
Top Liked Authors