Creating a Playbook to Upload Indicators to Various XDR Tenants

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Creating a Playbook to Upload Indicators to Various XDR Tenants

L3 Networker

Hello all, 

I am currently building a playbook that can pull indicators from an external MISP system and then publish them to various tenants of Cortex XDR. I have seen that there was a similar post in the past yet the solution suggested in 2022 does not appear to work as expected. In regards to available automation scripts I am using the task called XDR Push Indicators and I receive the following error. 

michaelsysec242_0-1692889022972.png

Take note that I want to configure and push the indicators that I receive in a job and not from the threat intel indicators that are based on the XSOAR platform. For almost every XDR/EDR system there is a way to publish indicators. I don't see any task that allows me to push and indicator and choose what Severity or comment should be. What am I missing here ? 

Thanks in advance.

Cortex XSOAR 

Cortex XDR 

 

PCSAE
4 REPLIES 4

L4 Transporter

Hi @michaelsysec242 ,

 

I see that there are two commands run and one of them was successful. What is the difference between those two commands or do you have two different integration instances enabled which caused the command to run two times?

L3 Networker

Hello @gyldz ,

I am working with a few different Integrations including XDR IR, IOC and XQL. In the image I have sent I am only running it on a specific instance under the IOC integration. I cannot see any result of success from this method. Can you suggest a solution for this ?

If not ill head over to the support to escalate this. 

Thanks 

PCSAE

Hi @michaelsysec242 ,

 

Unfortunately, I could not reproduce this in my environment. Could you please proceed with the support ticket?

L2 Linker

Hello,

 

TRY on below order !

 

The following indicators were not found : 20.125.137.168 

 

1. We need to enable the indicator

!xdr-iocs-enable indicator="20.125.137.168"

 

2. search the indicator whether its was listed

!SearchIndicator query="20.125.137.168"

 

3.Push the indicator

!xdr-iocs-push inidcator="20.125.137.168"

 

 

Regards,

Chiranjeevi

chiranjeevi
  • 1739 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!