Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

IronPort integration with XSOAR, receiving to mails

Hi, I wondered if it's possible to check URLs from mails via integration with XSOAR and then send a response with verdict to those address which was recipient for this mail under investigation? Maybe you can advice some features for realization or something with analogous functional? Will be tanksful for any answer!

asernova by L0 Member
  • 2081 Views
  • 1 replies
  • 0 Likes

Test sample in the playbook

Hi, Is it possible to influence the sample data that is shown in playbook edit mode, when using Test to validate the data in any task? I find that in some playbooks it can give me to select the latest incident of that type, but on others - it only allows the incident data that was created e.g. 6 months ago at best for that incident type. Even ...

Antanas by L2 Linker
  • 1683 Views
  • 1 replies
  • 0 Likes

Appending Incident field from a script

Dears, I am blocking urls on a security control then save the value of URL in incident field name (blocked urls) using setIncident command, But every time I block new url the incident field is not appending the new url to the old url. It replace the old value with the new value. Kindly need your suggestion for how to append the value in i...

Resolved! HTTPS with a Signed Certificate

Hi, As per the below link, XSOAR on-perm services by default use self-signed certificates for secure HTTP connections. It would be great if you confirmed this would be applicable for the hosted service as well. https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-5/cortex-xsoar-admin/high-availability/use-a-signed-certificate#:~:text=By%20...

DP696 by L2 Linker
  • 2847 Views
  • 2 replies
  • 0 Likes

Resolved! Installing Python Libraries for Custom Automations

I have a need to use a library called "Beautiful Soup" for scraping and HTML Parsing on a Custom Automation I am writing for use in a playbook. How do I install the dependencies so that I can use any library that I need ? Traditional on VSCode I would use pip install etc on the server I see that it isn't so simple. Thanks in advance Cortex XSOAR

Free Cortex XSOAR training!

Hello to all on the youtube channel for the live community there is a 6 hour free training. You can also test the free community edition for the Cortex XSOAR and schedule a workshop if want to play with the tool a little more: https://www.youtube.com/playlist?list=PLD6FJ8WNiIqUVEA2e5LZhmqNnwFcFhDTZ About registering to a Palo Alto free Wor...

Resolved! Returning output from scripts that run on indicators to the war room

Hi, I am playing around with buttons on indicator layouts. The output from the script comes as a notification on the bottom of the screen. The output gets truncated if long. To overcome the problem I used the following lines of code. ``` command_result = CommandResults(readable_output=text)result = command_result.to_context() return_results...

How to remove Integration "cache" completely

Hi, We are facing an issue where the integration ran into an error trying to pull an investigation from Secureworks, where an asset was not found, and the integration kept giving the same error continuously and would not pull the next investigation or further investigations after that. Below is the error the integration gives Error: Script...

Resolved! SLA Total Duration field in incident table

I can query successfully tickets that have an SLA > than X seconds. What I'm having trouble with is displaying a field in the incident table. For example: If i pull back tickets that have an SLA.TotalDuration > 2 days, I want to see the tickets and sort by the longest running SLA and see how much we went over by, but I can't do that bec...

JoshBoyd_0-1672172248049.png
JoshBoyd_1-1672172316199.png
JoshBoyd by L2 Linker
  • 2651 Views
  • 1 replies
  • 0 Likes

Resolved! Replying to an Email using a Playbook

Hi All, I need to automate customer follow ups using XSOAR. My requirements are as below. Listen to emails and create incidents for each sent email - EWS V2 is being used for this Once the initial mail is sent XSOAR will follow up with the customer sending replies to the initial email If customer replies, XSOAR will notify the analyst. I'm...

Resolved! Using Incident Variables Within Data Collection Web Form

Hello, I am attempting to use variables such as ${incident.name} within the Web Form in the section called "Short Description". After conducting tests I can see that It wont render any variables. They just appear as above. Now I can see that it supports Markdown, is there a way to display incident information in this section? The Use Case at han...

Podman - Docker - new Integration

Why does every time I install a new Integration like (Splunk) I get a warning ( unavailable docker image 'demisto/python3XXXXXX' ) Used by Integration (name of the integration)?although I have opened the access and if I go to the console i can pull this docker image and it will install without this warning.It should be done automatically right? ...

Cortex XDR Incident

Hello everyone, we started dealing with Cortex XDR and after getting the furst Incident, I am kinda lost. I am not even sure whats the issue, there is a lot of "information" on the management console. For example, the Incident, under "Key Assets & Artifacts" shows conhost.exe and powershell.exe with WF verdict, benign in this case, however, ...

klerini by L0 Member
  • 1714 Views
  • 1 replies
  • 0 Likes
  • 1307 Posts
  • 46 Subscriptions