Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Block IP using Panorama Integration

Hi,

I have integrated Panorama with XSOAR, instance is successfully created.

Now I have to block IP using this integration. I want to block ips just using panorama xsoar integration by using Static Address Group
Can anyone please assist how to go forw

...

Himangi by L2 Linker
  • 1401 Views
  • 1 replies
  • 0 Likes

Resolved! Exclude character while using variable.

incident.labels.source_address_ids:["1.2.3.4']

 

for above json value when i am parsing/using variable in title field getting error ( i.e. expecting ',' )

 

is there any way while calling variable we can ignore/exclude characters ( [ and " )

 

tried

...

IAwadiya by L1 Bithead
  • 1198 Views
  • 2 replies
  • 0 Likes

Resolved! Setting a pre-processing rule

Hi all,

In a list field, I want to go through all indexes one by one and if there is *malware* in all indexes(malware execution, malware alert, malware), I want to drop it. However, I could not edit this in the "Conditions for Incoming Incident" fiel

...

Attaching a CSV File to the Mail Attachment

I want to attach the CSV file in the Playbook as an attachment to the e-mail and send it. I use Msgraph. If I send it without attachments, the mail is sent. But when I add an attachment, the mail is not sent. I'm using the following command. I tried

...

Resolved! delay in a playbook

Hello everyone, 

 

What is the best option to add a delay in a playbook, for example I have 2 automated tasks and want task 2 to start after task 1 finishes by 1 hour.

 

I thought of creating a one-line automation that has time.sleep(amount) and addi

...

How to know if a zip file is encrypted in XSOAR

Hello,

We'd like to know if a zip file is encrypted inside a playbook or a automation. The way in which XSOAR works with these files does not allow the use of python libraries. Is there a way through the File context value to know if the file is encr

...

Josep by L4 Transporter
  • 2259 Views
  • 7 replies
  • 0 Likes
  • 1109 Posts
  • 34 Subscriptions