Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

XSOAR cant connect to marketplace

Hi
installed a new instance of XSOAR community edition - but cant seem to connect to the marketplace - 
when i try curl to storage.googleapis.com
curl: (56) Recv failure: Connection reset by peer
curl to: https://xsoar.pan.dev works 

the firewall is not d

...

spandor by L0 Member
  • 2445 Views
  • 2 replies
  • 0 Likes

Integration classifier by workflow

Hi,

I have been thinking about this a few times by now. I have a mail listener that fetches incoming mails as incidents. To classify them I would like to send them through a playbook, as a classification key doesn't provide enough context to choose th

...

Docker issues with xSOAR

Hello,

 

A beginner here. It seems that after initial installation when trying to install new integrations and addons from Marketplace, I keep getting warnings about missing Docker images. If I list all the images with /docker_images I see the ones tha

...

antjar by L0 Member
  • 4589 Views
  • 3 replies
  • 0 Likes

Domain checker playbook

Has anyone written a playbook that would check the age of a domain, say via it's Whois creation date, and then do a task?*

*Originally contributed to dfircommunity.slack.com #playbooks channel by SteveC on Friday, May 15th, 2020 at 3:11 pm

 

ELaufer by L2 Linker
  • 7382 Views
  • 3 replies
  • 1 Likes

Resolved! XSOAR blacklisting O365 senders

Hello guys,

 

When analyzing a phishing case, I would like to block a sender for all the company. I've read in the Microsoft doc and they say you can do it by creating a blacklist. I've not been able to find it in XSOAR.

 

Is there a way of doing that?

 

K

...

how can I get cortex Community Edition

Hi,

I filled out the form for the community edition at https://start.paloaltonetworks.com/sign-up-for-community-edition.html. I have received a confirmation email and an email for more information I have replied.

 

unfortunately I get no response to use

...

ten4you by L0 Member
  • 3496 Views
  • 3 replies
  • 0 Likes

Demisto-Qradar Integration

Hi, How to filter out the incidents ingestion in to demisto from Qradar based on time.

Eg:

I have been integrated Demisto with Qradar on today and i want to start recieveing offences only generated from today.

We have done some filtering to recieve only

...

  • 942 Posts
  • 30 Subscriptions