Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

setPlaybook + Post-Processing

 

Hi everyone,

I have a Post-Processing script that uses the setPlaybook command to switch the incident to a playbook called test1.

 

The problem is that when I close the incident, the script doesn’t run just once - it keeps setting the same playbook

...

NivNet by L1 Bithead
  • 523 Views
  • 1 replies
  • 0 Likes

How do we join the Slack DFIR community?

Hi Everyone!

 

I’m hoping you can aim me in the right direction.

I’m trying to join the PAN DFIR slack community via this url:https://start.paloaltonetworks.com/join-our-slack-community

 

But the register button doesn’t seem to work for me, despite m

...

J.Pedlow by L1 Bithead
  • 1501 Views
  • 5 replies
  • 0 Likes

XSOAR EWS 2022 Integration

As you know, the current EWS integration is limited to Exchange 2019. Could you please confirm if there are any plans to extend support for Exchange 2022? Additionally, are there any recommended workaround solutions for implementing inbox monitoring

...

[Cortex XSOAR] Integration TIM to SIEM Elastic

Hello Team,

 

I have a case that must integrate indicator from TIM Cortex XSOAR to SIEM 3rd Party like Elastic. Is there any documentation about how to integrate indicator from TIM for Elastic? Because when I search in documentation from Cortex XSOAR

...

A.Faruq by L0 Member
  • 440 Views
  • 0 replies
  • 0 Likes

Update XSOAR Incident via API - version issues

I am trying to update XSOAR Incidents via API, but am having issues with the Optimistic lock and incident versions etc.

I can create incidents via API call and can also get the information from incidents via API. 

When I create a new incident in our

...

kbratt by L1 Bithead
  • 421 Views
  • 0 replies
  • 0 Likes

Export Playbook and Import

Hi,

Iam trying to figure out how to perform the following:

Export a playbook, overwrite some of its tasks (send-mail Exchange) and upload the playbook back to XSOAR.

I found in Docu an API for playbook import as yaml but no export API.

 

If Anyone co

...

  • 1285 Posts
  • 44 Subscriptions
Top Solution Authors
Top Liked Authors