Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Mulesoft integration with XSOAR

Hi, I wanted to integrate Mulesoft with XSOAR, Since Mulesoft is not available in XSOAR marketplace, looking for Mulesoft' s REST API documentation or connector which will be helpful to develop custom integration in XSOAR. Can you help me to get those details if you have already developed custom integration for Mulesoft. Thanks in advance.

DP696 by • L2 Linker
  • 2212 Views
  • 1 replies
  • 0 Likes

update-remote-system command not getting triggered

Is it necessary to add a tag to the entry or comment in XSOAR to get it mirrored on remote incident?Suppose, I do not add a tag to a note/war room entry, then do I get that entry in the "UpdateRemoteSystemArgs"? Currently, I am not getting that entry in the "UpdateRemoteSystemArgs". Is it so that I have done something wrong in configura...

Resolved! Execute playbook using an instance

Hi, we have an integration with different instances, and we want to execute a builtin playbook, inside another playbook, but we need to indicate which instance we want to use. The playbook does not have an "Advanced->Using" Field. Is there any way to set the instance? Or maybe do i need to clone the playbook, create an argument for the instan...

MTubia by • L1 Bithead
  • 2387 Views
  • 1 replies
  • 0 Likes

URLscan.io's SOAR spot: Chatty security tools leaking private data!

Community, have you noticed that we may be accidentally exposing confidential information of the users we protect by submitting URLs for analysis to URLscan.io? Credits to: FABIAN BRAUNLEIN Sensitive URLs to shared documents, password reset pages, team invites, payment invoices and more are publicly listed and searchable on urlscan.io, a se...

urlscan.PNG
XSOAR CONFIG - Prevent.png

Resolved! XSOAR Multi-Tenancy Architecture and System Requirements

Hi, I am planning to deploy 1 main machine and 4 host machines. I'll keep all the tenants in the host machines so the main machine won't have any tenants (I read somewhere that this is the recommended deployment). I want to save resources if possible so what is the minimum system requirements for the main machine with no tenants? The multi tenan...

Timeout in task not working

Hello, Timeout configuration does not function in "ScheduleCommand" task using an automation. The timeout is set inside the task in Advanced Tab->"Execution timeout(seconds)" and inside the automation in Settings->Advanced->Timeout(seconds), but is not working. Am I missing something?

Josep by • L4 Transporter
  • 1458 Views
  • 1 replies
  • 0 Likes

Filter out incidents having email communications associated with it

From all the incidents I have, I want to filter out the incidents having email communications associated with them.There are several fields in the context and in the incident of the context that identifies an incident as email communications associated.Can anybody help me with this ? maybe using any specific field from context or incident.

Help ML models

Hello, I need some help to understand how ML models work in XSOAR. In the documentation, I can only see models related to emails. I'd like to create a model just with the close reason, False Positive or True Positive. I already trained the model, however, I don't know exactly which are the inputs of the training or the inputs to use the model.

Josep by • L4 Transporter
  • 1705 Views
  • 1 replies
  • 0 Likes

Question Regarding Mirroring Integration In Cortex XSOAR

I've a couple of questions regarding mirroring in Cortex XSOAR which are listed below. 1. Is it possible to change the status of the XSOAR incident from Pending to Active in the get-remote-data command? I have checked couple of mirroring integration (e.g. ServiceNow v2, XSOAR Mirroring) and they are only closing the XSOAR incident once the remot...

Multiple Question realted to assign owner from playbook

Guys, I Have Phishing Playbook consists of two big parts: a- L1 Phishing playbook. b- L2 Phishing playbook. The flow starts from L1 doing the needed automation and tasks like (Extracting IOCs, Headers, Doing Enrichment, making Splunk searches, .... etc.) Then it will stop at the stopping point which ask the Analyst to categorize which type ...

Demisto.db Read only Error

Dears, I am facing an issue in one of the tenants as below once I am trying to press anything and as I check the directory I found that demisto is the owner and the permissions are drwxr. Appreciate any Support. "Write /var/lib/demisto/tenents/(tenant Name)/data/demisto.db: read-only file system "

mkhalil5 by • L0 Member
  • 1544 Views
  • 1 replies
  • 0 Likes

How to run playbook on scheduled interval for all XSOAR Incidents?

Hello team, I've use-case where I need to fetch related events for a particular incident periodically. For that, I've prepared a playbook which will pull the events related to each XSOAR incident and link that data in Contex of a particular XSOAR incident. As this needs to be applied to all incidents of selected custom incident type and I want m...

SHadfa by • L0 Member
  • 5531 Views
  • 4 replies
  • 0 Likes
  • 1310 Posts
  • 46 Subscriptions
Top Solution Authors