Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Playbook construction

I would like to ask the community if perhaps someone has created a playbook that takes in Snort/Suricata alert data. I am looking a creating a automated block process that will compare an IDS alert with a Threat notification from the PAN. If the src_ip, src_port, dst_ip, dst_port and timestamp match and the firewall took no action on the threat....

jpadro by L0 Member
  • 2049 Views
  • 1 replies
  • 0 Likes

Resolved! javascript return context key from variable

Hi! I have modified a simple Javascript automation, however i can't seem to put an input value as a context key. In the below sample i declare var Key = args.parent; and in the return statement i try to use this variable as context entry.In reality, I literally get the context set to "Key", regardless on what I specify in the input. It is like ...

Antanas by L2 Linker
  • 4841 Views
  • 5 replies
  • 0 Likes

Question from Playbook Optimization webinar: Sub-Playbook quiet mode

Let's say we fix a sub playbook to run in quiet mode cos it's larger than 150KB. Will this affect the main playbook if it is dependent on the subplaybook output. Also will it fix all the older incidents that have already run ? ** Note: this is a question from our Customer Success Webinar: Playbook optimization in Cortex XSOAR Cortex XSOAR

rtsedaka by L6 Presenter
  • 2117 Views
  • 1 replies
  • 0 Likes

Question from Playbook Optimization webinar: Command modification

Is it possible to modify all instances of a command? For instance, if we wanted to change the "Run without a worker" setting on all usages of sleep - is that possible? Or would I need to do it 1-by-1? Or even possible per playbook maybe with multi-select? ** Note: this is a question from our Customer Success Webinar: Playbook optimization in C...

rtsedaka by L6 Presenter
  • 1974 Views
  • 1 replies
  • 0 Likes
  • 1298 Posts
  • 45 Subscriptions