Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Indicator enrichment detail in layout

Hi,

 

In one of our playbook there are 2 enrichment type of integrations deployed for ip enrichment (virustotal and abusedb) all works well as expected and they feed indicator itself but shows only verdict in indicator layout although these enrichmen

...

MKececioglu_0-1661949108501.png
MKececioglu_1-1661949119395.png

Playbook task naming in subplaybooks

Hi!

 

I can't find much data on Subplaybook naming numbers - how are they being assign and when do they change?

I've run into the following issue: i had a standalone playbook with some subplaybooks inside. In the main playbook I've been referring to

...

Antanas by L2 Linker
  • 2791 Views
  • 7 replies
  • 0 Likes

Resolved! Get command arguments in Powershell scripts

Hi all

 

I'm trying to get Command-Arguments in a self-made script in Powershell.

 

On Python it is:
demisto.args().get('<command-argument>')

 

What is it in Powershell? Because I tried it with:
$demisto.Args()["<command-argument>"]

But this didn't worked on

...

Resolved! Upload IOC from file to firewall via XSOAR

Hi, 

 

I want to find a way of maximum automatization of the next process: IOC are extracted from CSV file to Cortex XSOAR and than only this indicators are uploaded to firewalls. 

 

I found automations for each step separately but maybe exist any pl

...

asernova by L0 Member
  • 1688 Views
  • 1 replies
  • 0 Likes

Fail to connect to Marketplace

Hello,

Having installed XSOAR v6.8 in RH7.6, also configured Docker too.

Proxy and internal DNS is required in our environment.

Configured the Proxy on both WebUI and Docker as well.  

We could login to GUI, but we cannot reach the marketplace.

Found

...

Resolved! CrowdStrike Falcon detection mirroring

Hi there, I hope to find some help here.
We are facing issues to make the CrowdStrike Falcon mirroring options work. @
We are following the instruction provided in the documentation https://xsoar.pan.dev/docs/reference/integrations/crowdstrike-falcon 

H

...

Isabelle by L0 Member
  • 3351 Views
  • 2 replies
  • 0 Likes

Credential management in XSOAR

Hi,

 

How are the credentials for the integrations handled within the product? I.e., are passwords and keys stored in the cloud?

And how are these managed securely?

 

Thanks,

 

DP696 by L2 Linker
  • 1641 Views
  • 1 replies
  • 0 Likes

Resolved! XSOAR Engine Backup/Restore

Background:
In our XSOAR platform setup, the XSOAR server is cloud hosted by Palo Alto and the XSOAR engines are deployed at 2 different data centers (on-prem).  Each of these datacenters will have a single Cortex XSOAR engine server installed, which

...

gnakhede by L1 Bithead
  • 2175 Views
  • 2 replies
  • 0 Likes

Are XSOAR incident type updated?

Hello,

When an incident comes to XSOAR the classifier set the incident type.

I would like to know if the incident is updated with new alerts (for ex. in Cortex XDR), will the incident type in XSOAR be updated if needed or is the type set and never ch

...

lulu42 by L0 Member
  • 1309 Views
  • 1 replies
  • 0 Likes

Resolved! RHEL Installer Type and Podman Installation Steps

1. What RHEL installer type (minimal or full fledge GUI) should be considered for XSOAR engine server?

 

2. Is there any documentation by Palo Alto on Podman proxy configuration for XSOAR Engine installation and any specific URLs required to be white

...

gnakhede by L1 Bithead
  • 2416 Views
  • 3 replies
  • 0 Likes
  • 1106 Posts
  • 34 Subscriptions