Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Adding user to Team members of an incident by python script

Hello, There is the section "Team Members" with two fields "Owner" and "Participants". I want to add some users to "Participants" but there isn't this field in the context data. I found in the documentation https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-9/cortex-xsoar-admin/incidents/incident-access-control-configuration that "Team m...

PachaOne_1-1666882573164.png
PachaOne by L1 Bithead
  • 1941 Views
  • 1 replies
  • 0 Likes

Resolved! How to change a .xlsx file in context data or upload new from python script

Hi all, Could you help me with the following problem? I have an incident with .xlsx file that I handle by pandas and openpyxl. After the file will be handled, I need to save it to the context data to upload it to IRP by IRP integration and process a ticket. but I have a problem: when I save the .xlxs file by the method .save from openpyxl t...

PachaOne by L1 Bithead
  • 2830 Views
  • 1 replies
  • 0 Likes

Command "setList" issue introducing variables from context

Hello, We're using command "demisto.executeCommand("setList",{"listName":listName,"listData":listContent})" in order to introduce data in a json list. Where the "listName" is a json list name and "listContent" is data extracted from the context. The issue: The values introduced in "listContent" are like this example, "IPs" is a context variabl...

Josep by L4 Transporter
  • 2944 Views
  • 4 replies
  • 0 Likes

Resolved! SAML role configuration in XSOAR

Hi, We are using SAML 2.0 integration for user authentication to XSOAR. Can someone help to understand what value need to update on "SAML Roles Mapping" in XSOAR under Settings->User and Roles-> Roles. Thanks, Deepa

DP696 by L2 Linker
  • 2069 Views
  • 1 replies
  • 0 Likes

Resolved! Looking for a way to identify links between our parent and subplaybooks.

This relates to lifecycle management and removing old unused playbooks/subplaybooks. We can use the XSOAR Metrics widget to see when a playbook last executed, however this isn't always a good indicator as we have playbooks for rare events which have never triggered but are still required. This isn't such an issue with our parent playbooks as ...

DHodd1 by L0 Member
  • 1951 Views
  • 1 replies
  • 0 Likes

Convert Multiple Files

Hello, I am trying to convert multiple files with different extensions using the 'ConvertFile' automation, so that it can be display on the layout. However, when there are different types of files in one incident, it keeps giving me an error. What would be the best way to list all files and convert them by EntryID? Here what I currently have con...

axespera_0-1670353410461.png
axespera by L1 Bithead
  • 2634 Views
  • 3 replies
  • 0 Likes

A question from the Malware Pack v2 webinar: Malware pack playbooks optimization

Kudos for all the work on developing these playbooks. Are they optimized so the incidents don't get flagged under System Diagnostics (exceptionally big incidents, exceptionally big context, etc)? Note: This question was asked as part of Cortex XSOAR Customer Success Webinar: Malware Investigation & Response V2

rtsedaka by L6 Presenter
  • 1997 Views
  • 1 replies
  • 0 Likes

A question from the Malware Pack v2 webinar: Misclassification rate

How do you address the extremely high misclassification rate of both file detonation (any semi-sophisticated malware won't divulge any information in a sandbox) as well as the high misclassification by Virustotal (both FP and TP)? Note: This question was asked as part of Cortex XSOAR Customer Success Webinar: Malware Investigation & Respon...

rtsedaka by L6 Presenter
  • 1842 Views
  • 1 replies
  • 0 Likes

Resolved! Make a section in layout a static list?

Hi all!I've been looking at trying to make a section in a layout a static list, but could not find any easy ways to do it.Essentially what I am looking for is:I have a layout, in which I have a section called X. Now what I want is that every time an incident is created, the section field X is populated with the contents of a list called Y. The c...

Resolved! XSOAR NSlookup and ThreatVault info

Hi everybody, is there a way how to get following information in XSOAR? - NSLOOKUP - I have an IP address and need to get name from internal DNS server - Threat Vault info - I have an information from the firewall (threat name and threat ID) and I need to get more info like CVE number, threat description etc. Thank you, Jan

Resolved! integration indicator pull limits?

Hi there, I've just started testing threat feed integration in XSOAR. For some reason, the integration instance was only downloading 100 indicators on each pull whereas the source has thousands. Is it because my AWS instance doesn't have a license? Is there a limit on how many indicators can be downloaded into XSoar? Thanks in advance!

boweic by L0 Member
  • 2078 Views
  • 1 replies
  • 0 Likes
  • 1298 Posts
  • 45 Subscriptions