visual studio cortex app blocking
while running a project from visual studio, the cortex app blocking the executable saying it is malicious activity. I have attached a screenshot of the issue. Please solve the issue ASAP.
while running a project from visual studio, the cortex app blocking the executable saying it is malicious activity. I have attached a screenshot of the issue. Please solve the issue ASAP.
I have deployed a number of other roles using SAML successfully. Now when it comes to assigning the Read-only role this has become a challenge. Unlike the other previously configured roles that also included not only the SAML mapping but also the Shift assignments, which work. The Read-Only role does not, this issue is specific to the role and i...
HelloI'll try to get a API request from our Panoramas.The curl request looks like;curl -X GET "https://<panorama>/api/?key=<api-key>&type=op&<show><devices><all></all></devices></show>"So, I tried with the Integration "Palo Alto Networks PAN-OS"There is a command "panorama", where I mitgh e...
I am attempting to close a single incident via the XSOAR API and the Batch Close Incidents endpoint (POST /incident/batchClose). The information about my request and the response are posted below. The status of the incident was new before I sent the close request and does not appear to have changed after sending the request even though the respo...
Hello Everyone, If any integration(RSA Netwitness or Syslog) in XSOAR is failed and got some error then can I send mail to any team member as integration got some error. I have already configured System diagnostic but it cannot work.I need any alternative way or solution for this.
Hello When I request a Wildfire request then I do not get a lot of Information in the "Output" to work with other tasks.To get more infos, I do in the Demisto CLI this: !wildfire-report format=xml hash=<sha256-Hash> verbose=true raw-response="true" extend-context=contextKey=JsonOutputPath But then all infos are in the "Resuls"-"Tab" instea...
The integration created does pull the tickets .However i couldn't see rawjson field getting updated though using the below line.I couldn't do field mapping as i can't see the data on choosing instance under classification and mapping rawJSON : JSON.stringify(case.records[i])
Looking for some help on create an API integration for creating incidents and mapping those fields to normalized fields. I can create an incident just fine, I can assign the incident type, the issue I'm running into is the field normalization. IE lets take the following field called Souce IP in XSoar. The script that I'm using calls it OriginIp....
Hi ! My xSoar System Diagnostic shows an alert for 3 incidents with exceptionally big context (>1 000 KB). That being said, when I press the "View in incidents" button, the query returns no results ... How can I find the 3 incidents to remediate the situation ? Thanks.
I am having difficulty connecting my integration to microsoft defender with the grant type as client credentials. if anyone is familiar with making calls to api's and receiving tokens, I would definitely need your assistance.
I have the integration enabled and configured using the requirements stated in the Marketplace, but when I try to load the dashboard it says I don't have the SSH integration enabled. But I do, and I have a local user and have tested it manually, so I don't think this is credential related. It just looks like the integration is not able to access...
Hi, I need help about How get via API an incident update. I don't see this option (sorry), I can set a new incident but I don't update an incident. This way must be API, I use this route "/incident". Can you help me, plase? Regards
Hi, I need help about How get via API update an incident. I don't see this option (sorry), I can set a new incident but I don't update an incident. This way must be API, I use this route "/incident". URL API: https://cortexip/incident Can you help me, plase? Regards Cortex XSOAR
Helloa customer I work for is trying to perform a partial import of data from a XSOAR to another instance of the same with same version.They want a partial import beacause they have not so much resources on the second instance and they just need it to test some things. But the question is, is it supported?Should Palo Alto discourage this type of...
Hello all, We're trying to develop a playbook that first look at similar incident (FindSimilarIncidents) before proceeding but it isn't able to find any similar incident (even when we have duplicate of the current incident). For a bit of context this playbook is executed from the result of a Tenable scan when vulnerabilities are identified. For ...

