Obtain payloads bounded by time and IoCs of Cisco Firepower from XSOAR
Hello,
We'd like to use Cisco Firepower integration to obtain extra info for our playbooks. However, we can't find the proper command to get the payloads of an event.
Hello,
We'd like to use Cisco Firepower integration to obtain extra info for our playbooks. However, we can't find the proper command to get the payloads of an event.
Once a XSOAR incident is created, how can we find when a user actually clicked & opened incident for the first time?
Hi,
Can someone help me to get XSOAR engine self-signed public certificate.
Thanks,
Change the Section Header color in order to create visual alerts in the playbook.
Hello,
There is the section "Team Members" with two fields "Owner" and "Participants".
I want to add some users to "Participants" but there isn't this field in the context data.
I found in the documentation https://docs.paloaltonetworks.com/cortex
Hello,
When does a post-script execute? When the incident is completely closed?
Hi all,
Could you help me with the following problem?
I have an incident with .xlsx file that I handle by pandas and openpyxl. After the file will be handled, I need to save it to the context data to upload it to IRP by IRP integration and process
...
Hi,
The URL I wanted to web scrap requires authentication, can someone help me to pass username and password to the WebScraper OOTB automation in XOSAR.
Thanks.
Hello,
We're using command "demisto.executeCommand("setList",{"listName":listName,"listData":listContent})" in order to introduce data in a json list. Where the "listName" is a json list name and "listContent" is data extracted from the context.
Th
...
Hi,
We are using SAML 2.0 integration for user authentication to XSOAR.
Can someone help to understand what value need to update on "SAML Roles Mapping" in XSOAR under Settings->User and Roles-> Roles.
Thanks,
Deepa
This relates to lifecycle management and removing old unused playbooks/subplaybooks.
We can use the XSOAR Metrics widget to see when a playbook last executed, however this isn't always a good indicator as we have playbooks for rare events which ha
...
Hello, I am trying to convert multiple files with different extensions using the 'ConvertFile' automation, so that it can be display on the layout. However, when there are different types of files in one incident, it keeps giving me an error. What wo
...
Kudos for all the work on developing these playbooks. Are they optimized so the incidents don't get flagged under System Diagnostics (exceptionally big incidents, exceptionally big context, etc)?
Note: This question was asked as part of Cortex XSOA
...
How would you handle an EDR alert that involves more than one file? How does this playbook present this to the user?
Note: This question was asked as part of Cortex XSOAR Customer Success Webinar: Malware Investigation & Response V2
How do you address the extremely high misclassification rate of both file detonation (any semi-sophisticated malware won't divulge any information in a sandbox) as well as the high misclassification by Virustotal (both FP and TP)?
Note: This questi
...Subject | Likes |
---|---|
1 Like | |
1 Like | |
1 Like | |
1 Like | |
1 Like |
User | Likes Count |
---|---|
2 | |
1 | |
1 | |
1 | |
1 |