Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Yara Rules error

Hi,

 

Trying to use yarascan automation from yara pack on marketplace, always receiving "HasMatch: false"

 

Here it goes the printscreen with the command and the contextdata showing the entryid

 

 

The content has that rule

 

 

Could you help?

 

Re

...

FabioFerreira_0-1679411632399.png
FabioFerreira_1-1679411743582.png

SetGridField

How can I map keys (query, network.cidr, network.country) to a table? I'm trying with below command, is not working for CIDR & Country.

!SetGridField context_path="Whois.IP" grid_id="whoisipinfo" overwrite="true" columns="IP Address,CIDR,Country" key

...

How to realign taskIds number

Hello,

While I'm creating a playbook, the taskids don't follow the proper order due to the changes made.

How can these tasks be realigned to follow an ascending order?

Thanks,

Josep

Josep by L4 Transporter
  • 781 Views
  • 1 replies
  • 0 Likes

Resolved! SAML Role Mapping in XSOAR

Hi,

 

We are using SAML integration for XSOAR user authentication and azure AD as an IDP. I'm bit confused in SAML role mapping in XSOAR. for eg. in Azure AD we have only one group and users are mapped to it. but in XSOAR we want to give analyst perm

...

DP696 by L2 Linker
  • 1514 Views
  • 2 replies
  • 0 Likes

Formatting an Array of Values

Hey Everyone,

 

In the context I have one key that holds multiple email values, I need to use them in my "SendEmailReply" automation. However when I call the key as a variable in To field, it comes as an array not single object. Is there any out of t

...

Resolved! Email Classification with Subject

I'm currently using EWSv2 to listen to emails and have a classifier as well for fixed subjects. Is there a approach that I can use to take a part of an email subject to classify emails?

 

As an example:

Email Subject 1: Incident#1213131 

Email Subjec

...

Resolved! Need a time limit for EmailAskUser task.

When automation EmailAskUser is used, a wait task is placed after it waiting if there's an answer. If there's no answer the automation will stay there forever, a time threshold is needed to continue the automation. How can be this time limit set?

Josep by L4 Transporter
  • 3519 Views
  • 8 replies
  • 0 Likes

Resolved! Add manual input to a query on a button?

Greetings all.
I have this situation I am trying to resolve, but can't find a solution.

I have a dynamic section in a layout, in which I want to add a button. When clicked, this button should run a query, but it should first ask for a user input, which

...

Integrating splunk with XSOAR.

Hi,

 

Can someone help me with the below queries?

We are in process of integrating splunk with XSOAR.
It’s a cloud service and can be accessed via SplunkCloud and SplunkEnterpriseSecuritySuite.

 

It should be integrated via SplunkCloud or SplunkEnterp

...

DP696 by L2 Linker
  • 3224 Views
  • 1 replies
  • 0 Likes

Obtain list content from api

Hi!
I want to get the content of a list from the API REST. The endpoint /lists returns all lists and their content. Is there a way to get only the content of a list?

In addition, the content of the list brings the line breaks and spaces corresponding

...

rdevega_0-1678707954535.png
rdevega_1-1678708140520.png
rdevega by L0 Member
  • 1073 Views
  • 1 replies
  • 0 Likes

Resolved! Need help on extract indicators from Email body

Hello Team,

 

I have developed a playbook which extract indicators like IP,URL,Domain and Hash from Email body.

but in some cases extract indicators and other automation which are available in xsoar cannot extract domains.

can anyone suggest me how to ex

...

Priyash7 by L0 Member
  • 3770 Views
  • 3 replies
  • 0 Likes

Extracting urls from html text

when I extract indicators from body of an email (the body of the email is in html format). I don't get the URLs, only the domains inside the URLs are extracted but the URLs itself not extracted.

 

what I understand in extracting domains, that it work

...

  • 1138 Posts
  • 36 Subscriptions
Top Solution Authors
Top Liked Authors