Cortex XSOAR Discussions

Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Email Classification with Subject

I'm currently using EWSv2 to listen to emails and have a classifier as well for fixed subjects. Is there a approach that I can use to take a part of an email subject to classify emails?

 

As an example:

Email Subject 1: Incident#1213131 

Email Subjec

...

Resolved! Need a time limit for EmailAskUser task.

When automation EmailAskUser is used, a wait task is placed after it waiting if there's an answer. If there's no answer the automation will stay there forever, a time threshold is needed to continue the automation. How can be this time limit set?

Josep by L4 Transporter
  • 3667 Views
  • 8 replies
  • 0 Likes

Resolved! Add manual input to a query on a button?

Greetings all.
I have this situation I am trying to resolve, but can't find a solution.

I have a dynamic section in a layout, in which I want to add a button. When clicked, this button should run a query, but it should first ask for a user input, which

...

Integrating splunk with XSOAR.

Hi,

 

Can someone help me with the below queries?

We are in process of integrating splunk with XSOAR.
It’s a cloud service and can be accessed via SplunkCloud and SplunkEnterpriseSecuritySuite.

 

It should be integrated via SplunkCloud or SplunkEnterp

...

DP696 by L2 Linker
  • 3516 Views
  • 1 replies
  • 0 Likes

Obtain list content from api

Hi!
I want to get the content of a list from the API REST. The endpoint /lists returns all lists and their content. Is there a way to get only the content of a list?

In addition, the content of the list brings the line breaks and spaces corresponding

...

rdevega_0-1678707954535.png
rdevega_1-1678708140520.png
rdevega by L0 Member
  • 1179 Views
  • 1 replies
  • 0 Likes

Resolved! Need help on extract indicators from Email body

Hello Team,

 

I have developed a playbook which extract indicators like IP,URL,Domain and Hash from Email body.

but in some cases extract indicators and other automation which are available in xsoar cannot extract domains.

can anyone suggest me how to ex

...

Priyash7 by L0 Member
  • 3940 Views
  • 3 replies
  • 0 Likes

Extracting urls from html text

when I extract indicators from body of an email (the body of the email is in html format). I don't get the URLs, only the domains inside the URLs are extracted but the URLs itself not extracted.

 

what I understand in extracting domains, that it work

...

No download Link

Hello

 

I have received my license over email but the email does not contain any download link. Where can I get the files?

 

Thanks.

JDiaz15 by L1 Bithead
  • 1840 Views
  • 5 replies
  • 0 Likes

Resolved! Access a list from an integration

To access a list from an automation I use something like:

json = json.loads(demisto.executeCommand("getList", {"listName": "blabla"})

However, from an integration I cannot use the executeCommand method. Is there any way to access a list from an inte

...

rdevega by L0 Member
  • 2827 Views
  • 3 replies
  • 0 Likes

XSOAR Ideal Development Environment

Hi everyone, we are a small team of 3 and trying to understand if we request more resources than necessary from our admins. We all have our own xsoar instances for development because we don't want to write to the same automation someone else is work

...

  • 1177 Posts
  • 39 Subscriptions
Top Liked Authors