Cortex XSOAR Discussions

Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Mapping fields to XSOAR IOCs

I'd appreicate guidance on how to update IOC fields with information extracted from an excuted playbook task. 

 

My use case centers around updating File Hash IOCs to include file signature metadata information to enable easier cleaning up of IOCs as

...

jemeche by L0 Member
  • 1387 Views
  • 3 replies
  • 0 Likes

Resolved! [Multi-Tenant] System configuration levels

in a multi tenant environment, should I forward all the system configurations to tenants or are some of them meant only for hosts?

CSP cases in particular, can be pretty confusing. CSP tells me to put a sys config on the main account and in another c

...

Rasterized content on Incident Layout

Hello!
I have a question. How can I make it so that I would like to rasterize email/url. The image that appears in the war room (which is the result of running the command) i would like to display on one layout field.

I guess I should use dynamic secti

...

szodinn by L0 Member
  • 1200 Views
  • 1 replies
  • 0 Likes

Resolved! No output in action

In the "cybereason-get-sensor-id" task we manage to retrieve the sensor id for a given machine, but only in the result tab.

 

In fact, it looks like the integration doesn't return an output result, so we're not able to use the sensorId as an input fu

...

Aurelien19_0-1690534478128.png
Aurelien19_1-1690534544985.png

Custom Fetch Incidents

Hi, I want to use Exabeam integration in XSOAR but not to fetch incidents (incident responder) as it is currently set in fetch-incidents command, that is in fetch_incidents function.

The plan would be to fetch with get-notable-users command, which pr

...

MMagdic by L2 Linker
  • 1281 Views
  • 1 replies
  • 0 Likes

Resolved! Limit of Support Licence

Hello,

 

I am just wondering if we are losing XSOAR Support after installing several custom Docker images which are not in the following list, on our XSOAR* Environment :
==> https://hub.docker.com/r/demisto

 

* : OnPremise - BarMetal XSOAR

 

Thanks i

...

How to run and or use HelloWorld Integration?

Hello all,

 

Fresh install of XSOAR onto Ubuntu, all went well. I a trying to run the HelloWorld integration but I keep getting the error:

 

Failed to execute test-module command. Error: Verify that the server URL parameter is correct and that you ha

...

GWynn by L3 Networker
  • 1794 Views
  • 3 replies
  • 0 Likes

Resolved! Custom Data Storage

Hello,

 

Is there a way to store custom Data elsewhere than in incidents ? I suceeded in "Lists" but it appears than maximum list size is 209715 characters ==> https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.9/Cortex-XSOAR-Administrator-Gui

...

Resolved! Widget expected data Format

Hello,

 

I was not able to find in XSoar Documentation, the "formats" which are expected for all Widget Types :
- Data Table
- Graph
- Text Input
- Select
- List
- Map
- Date Picker
- File Picker

 

Do you know them ?

 

Thanks in advance for your reply and be

...

  • 1216 Posts
  • 42 Subscriptions
Top Solution Authors
Top Liked Authors