Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Adding user to Team members of an incident by python script

Hello, There is the section "Team Members" with two fields "Owner" and "Participants". I want to add some users to "Participants" but there isn't this field in the context data. I found in the documentation https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-9/cortex-xsoar-admin/incidents/incident-access-control-configuration that "Team m...

PachaOne_1-1666882573164.png
PachaOne by L1 Bithead
  • 1964 Views
  • 1 replies
  • 0 Likes

Resolved! How to change a .xlsx file in context data or upload new from python script

Hi all, Could you help me with the following problem? I have an incident with .xlsx file that I handle by pandas and openpyxl. After the file will be handled, I need to save it to the context data to upload it to IRP by IRP integration and process a ticket. but I have a problem: when I save the .xlxs file by the method .save from openpyxl t...

PachaOne by L1 Bithead
  • 2877 Views
  • 1 replies
  • 0 Likes

Command "setList" issue introducing variables from context

Hello, We're using command "demisto.executeCommand("setList",{"listName":listName,"listData":listContent})" in order to introduce data in a json list. Where the "listName" is a json list name and "listContent" is data extracted from the context. The issue: The values introduced in "listContent" are like this example, "IPs" is a context variabl...

Josep by L4 Transporter
  • 3015 Views
  • 4 replies
  • 0 Likes

Resolved! SAML role configuration in XSOAR

Hi, We are using SAML 2.0 integration for user authentication to XSOAR. Can someone help to understand what value need to update on "SAML Roles Mapping" in XSOAR under Settings->User and Roles-> Roles. Thanks, Deepa

DP696 by L2 Linker
  • 2112 Views
  • 1 replies
  • 0 Likes

Resolved! Looking for a way to identify links between our parent and subplaybooks.

This relates to lifecycle management and removing old unused playbooks/subplaybooks. We can use the XSOAR Metrics widget to see when a playbook last executed, however this isn't always a good indicator as we have playbooks for rare events which have never triggered but are still required. This isn't such an issue with our parent playbooks as ...

DHodd1 by L0 Member
  • 1985 Views
  • 1 replies
  • 0 Likes

Convert Multiple Files

Hello, I am trying to convert multiple files with different extensions using the 'ConvertFile' automation, so that it can be display on the layout. However, when there are different types of files in one incident, it keeps giving me an error. What would be the best way to list all files and convert them by EntryID? Here what I currently have con...

axespera_0-1670353410461.png
axespera by L1 Bithead
  • 2669 Views
  • 3 replies
  • 0 Likes

A question from the Malware Pack v2 webinar: Malware pack playbooks optimization

Kudos for all the work on developing these playbooks. Are they optimized so the incidents don't get flagged under System Diagnostics (exceptionally big incidents, exceptionally big context, etc)? Note: This question was asked as part of Cortex XSOAR Customer Success Webinar: Malware Investigation & Response V2

rtsedaka by L6 Presenter
  • 2036 Views
  • 1 replies
  • 0 Likes

A question from the Malware Pack v2 webinar: Misclassification rate

How do you address the extremely high misclassification rate of both file detonation (any semi-sophisticated malware won't divulge any information in a sandbox) as well as the high misclassification by Virustotal (both FP and TP)? Note: This question was asked as part of Cortex XSOAR Customer Success Webinar: Malware Investigation & Respon...

rtsedaka by L6 Presenter
  • 1875 Views
  • 1 replies
  • 0 Likes

Resolved! Make a section in layout a static list?

Hi all!I've been looking at trying to make a section in a layout a static list, but could not find any easy ways to do it.Essentially what I am looking for is:I have a layout, in which I have a section called X. Now what I want is that every time an incident is created, the section field X is populated with the contents of a list called Y. The c...

  • 1300 Posts
  • 45 Subscriptions
Top Liked Authors