XSOAR - Error in XDR Automation
Hi, When i am trying to execute the automation xdr-get-incident-extra-data (Cortex XDR - IR) in playbook, i am getting an error as shown in the screenshot below. What could be the reason? Kindly help, Thanks, Nithin
Hi, When i am trying to execute the automation xdr-get-incident-extra-data (Cortex XDR - IR) in playbook, i am getting an error as shown in the screenshot below. What could be the reason? Kindly help, Thanks, Nithin
We are using the EWS O365 integration to monitor an Exchange Online inbox. Any emails that hit the inbox get an incident created, and a Playbook handles things from there. This is working just fine but the problem I'm having is that it is ignoring calendar invite emails. Some phishing attempts we've seen come in as calendar invites, so I'd like ...
Hi all,I have two tenants. One of them is called A and one is called B. I have Mail integration on tenant B. How can I run "!send-mail to= example[@]example[.]com subject=Hello body=Hello body" from tenant A to tenant B? Is it done with demisto.internalHTTPRequest()?
Hello everyone, I have a script that need to get incidents from server. incidents = execute_command( "xdr-get-incidents", { "lte_creation_time": last_creation_time.split("+")[0], "gte_creation_time": first_creation_time.split("+")[0], "page": page, "limit...
Hi , Is there a way to automate the process of mapping every incident to its MITRE Technique ,or it should be manual for every incident ?
Hi, I have been using Panorama integration to block the IP. Is there any way where I can unblock the IP or remove the IP from address group of Panorama.
does anyone have a xql query that will return endpoint_names with and associated CVE count?
Hi everyone. I am new to this industry and I am looking for guidance on how to extract IOC from threat intel email body in Xsoar Playbook. Hoping if someone can help out. Thank you.
XSOAR server based community edition is always asking me my admin cred. It happens every 10 seconds. How can I remediate this issue ? Thanks in advance.
Hey, I need your help. We are receiving alerts "XDR Incident 945 - 'Large upload (generic)' generated by #XDR Analytics detected... Basically, this appears when the user makes a call, shares documents, or shares their screen (using Microsoft Teams). In the #XSOAR event I can see that the processname is ms-teams.exe and the destination ip is ...
Hi Team, Can you please suggest a few case studies where CrowdStrike XDR is integrated with Cortex SOAR and what were the areas and use cases that were implemented and helped the customer? We wanted to present this to a management that already has crowdstrike XDR and we want to showcase how cortex SOAR can help.
Hello community, I have some playbooks that are responsible for closing incidents in the various sources (XDR, QRadar, XSOAR, JIRA, ...) once I enter a reason or reason for them to be closed. I have done this using a "Set" automation that waits for input from the user and gives an error as it is a "Set" where the value "value" that is i...
Hi, I am trying to take a sum of incidents over a given time, and divide this sum per month, using Beve Syntax. I there any syntax that would give me a per-month break down? So I can take incidents per month, and display them in a widget using a bar graph. Thanks
Hi, I am trying to setup remote repositories, in a first step only the dev environment. In About -> Troubleshooting I have set "ui.version.control.show.remote" to "true" (copy-pasting it from the documentation [1] and checking multiple times for typos and additional spaces). However, in the "Advanced" view it does not show the "Content Re...
Hi , in my Qradar integration I don't have this parameter , I have enabled the "Long Running Instance" and still it takes too long for the incidents to be fetched. Is there a way to manually configure the Incident Fetch Interval. I'm using IBM QRadar v3

