Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Auto-categorize Outlook Phishing Email

Hello guys,I'm currently trying to create a Playbook that auto-categorize already analyzed phishing email, let me explain :Here is the current process :1. An analyst tags an email as Phishing using Outlook categories in the main Email box2. Thanks to a macro, the email is being put in a phishing email folder in outlook Now, I'd like Cortex XSOAR...

benzer by L0 Member
  • 3334 Views
  • 3 replies
  • 0 Likes

Stopping "Docker service is down" notifications

Hi, XSOAR is giving us warnings everyday at 1pm. We are receiving the email below```System Diagnostics found 1 issue(s) and 0 warning(s). Issues: Docker service is down Warnings: None Review warnings and issues in the System Diagnostics page. View it on https://URL```We are running podman instead of docker (installation default). I raised a supp...

Resolved! SLA best practices

Hi, I want to set sla times per severity type but it seems xsoar bind sla's to incident type, so i think i need to start each sla per severity in playbook by testing severity it is nearly clear for me. But i am confused what type of SLA should i create , xsoar gives you flexibility to create custom sla duration lets say; response time, detect t...

Resolved! Different response page server

Hi, In a multitenant deployment i want to place the response page somewhere else from the "Host-tenant" machine lets say customer environment. And configure "External Host Name" to this new server which is accessible from customer local area. Regards.

Playbook construction

I would like to ask the community if perhaps someone has created a playbook that takes in Snort/Suricata alert data. I am looking a creating a automated block process that will compare an IDS alert with a Threat notification from the PAN. If the src_ip, src_port, dst_ip, dst_port and timestamp match and the firewall took no action on the threat....

jpadro by L0 Member
  • 2092 Views
  • 1 replies
  • 0 Likes

Resolved! javascript return context key from variable

Hi! I have modified a simple Javascript automation, however i can't seem to put an input value as a context key. In the below sample i declare var Key = args.parent; and in the return statement i try to use this variable as context entry.In reality, I literally get the context set to "Key", regardless on what I specify in the input. It is like ...

Antanas by L2 Linker
  • 5023 Views
  • 5 replies
  • 0 Likes
  • 1302 Posts
  • 45 Subscriptions