Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Resolved! Assigning an array of Values to a key/variable

Hey guys, I'm working on separating internal and external IP(s) on a playbook and I want to use those values in a email body. So currently I'm using a temporary list to store IP(s) then call when needed in the same playbook with ${lists.templist}. But I have two limitations with this approach, Cannot add more than one IP, as setList fails. ...

Communication Task Authentication failed

Hi, I want users to authenticate in Cortex XSOAR before answering the form sent by mail like explained here https://docs.paloaltonetworks.com/cortex/cortex-xsoar/6-5/cortex-xsoar-admin/playbooks/playbook-tasks/communication-tasks/create-a-data-collection-task/create-communication-task-authentication The AD authentication instance seems to work...

lulu42 by L0 Member
  • 1899 Views
  • 1 replies
  • 0 Likes

Handling errors in a playbook

I'm looking to change the flow of my playbook not only if errors are encountered in my tasks, but dependant also on what those errors are. I found a tutorial on docs.paloaltonetworks.com that included this: Step 3: For new tasks, in the Task Name field, type a meaningful name for the task that corresponds to the data you are collecting. Step 4...

Dbot Score for Virustotal IP check is always 1

Hey Guys, I'm facing this issue that doesn't matter how malicious the IP is Dbotscore is being 1 for the VT IP automation, Things I tried, 1. Setting a threshold in VT integration for 1. 2 . Setting the reliability to A+ 2. Running the command !ip ip="54.37.136.187" long="false" threshold="1" sampleSize="10" wait="60" retries="0" fullResp...

Resolved! SetGridField Issue

I'm testing the inbuilt playbook "Integrations and Incidents Health Check" , however it throws an error on the block which contains SetGridField, which is the error shown below. I have few questions regarding the automation and troubleshooting,1) What is grid field mentioned in troubleshooting? is it the same as the grid_id?2) Is grid_Id is ju...

vidurasupun_0-1655096548235.png

Resolved! A question from the Phishing V3 webinar: Investigation

It does within an isolated container. We use XSOAR to investigate all kinds of malicious content and it is designed for it - Can we get more information on this? Is it the hardening of Docker ? or others? Note: This question was asked during our Customer Success Webinar: Phishing V3

rtsedaka by L6 Presenter
  • 2524 Views
  • 1 replies
  • 0 Likes

Error (July 1, 2022 2:50 PM) Script failed to run: "docker images demisto/python3:3.9.8.24399" with error "exec: "docker": executable file not found i

I am getting an error like this when i add instance while integration cortex x soarError(July 1, 2022 2:50 PM)Script failed to run: "docker images demist o/python3:3.9.8.24399" with error "exec: "docker": executable file not found in $PATH" and output "" (2617) (2603)

  • 1298 Posts
  • 45 Subscriptions