Cortex XSOAR Discussions

Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

automation script to take password

I'm attempting to write an automation that takes a user password. 

Then sends an api call containing that password, but when I enable the mandatory sensitive options on the automation script. The API call I wrote no longer runs. Are there any example

...

Sig_9 by L1 Bithead
  • 2383 Views
  • 2 replies
  • 1 Likes

Incident assignment in XSOAR

Hi,

 

Anyone please help me to understand automatic incident assignment by DBot to analyst. what are the steps have to perform?

how to define the shift in user roles?

 

Thanks.

DP696 by L2 Linker
  • 1561 Views
  • 2 replies
  • 0 Likes

E-mail preview image

Is there any way to use a task to preview an email (from an msg or eml) and not just see the filtered results?

I'm looking for a solution to display an email in xsoar as if I were to open it in outlook.

For analysis it would be important to see the e

...

Multiple sync on the same incident

Dear LIVEcommunity users,

 

Since version 6.0, Cortex XSOAR implements incident mirroring. Do you know if it is possible to enable two (or more) different syncs on the same incident (e.g. 2 Jira integrations, or 1 Jira and 1 ServiceNow) ?

If yes :

  • Ho
...

how to re-pull QRadar case

Our client leverages QRadar as their SIEM.

will pull in all cases and then have a pre-processing rule that drops any case that does not have "MSSP" in the name.

This works 99% of the time, but there are certain times when MSSP cases get dropped and we

...

JoshBoyd by L2 Linker
  • 1417 Views
  • 2 replies
  • 0 Likes

Resolved! Block IP using Panorama Integration

Hi,

I have integrated Panorama with XSOAR, instance is successfully created.

Now I have to block IP using this integration. I want to block ips just using panorama xsoar integration by using Static Address Group
Can anyone please assist how to go forw

...

Himangi by L2 Linker
  • 1780 Views
  • 1 replies
  • 0 Likes

Resolved! Exclude character while using variable.

incident.labels.source_address_ids:["1.2.3.4']

 

for above json value when i am parsing/using variable in title field getting error ( i.e. expecting ',' )

 

is there any way while calling variable we can ignore/exclude characters ( [ and " )

 

tried

...

IAwadiya by L1 Bithead
  • 1475 Views
  • 2 replies
  • 0 Likes

Resolved! Setting a pre-processing rule

Hi all,

In a list field, I want to go through all indexes one by one and if there is *malware* in all indexes(malware execution, malware alert, malware), I want to drop it. However, I could not edit this in the "Conditions for Incoming Incident" fiel

...

Attaching a CSV File to the Mail Attachment

I want to attach the CSV file in the Playbook as an attachment to the e-mail and send it. I use Msgraph. If I send it without attachments, the mail is sent. But when I add an attachment, the mail is not sent. I'm using the following command. I tried

...

  • 1220 Posts
  • 43 Subscriptions
Top Liked Authors