How to push Bulk IOC list in file format to Cortex XDR (IP address,Malicious URLS,Malicious Hashes ) via from XSOAR

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to push Bulk IOC list in file format to Cortex XDR (IP address,Malicious URLS,Malicious Hashes ) via from XSOAR

L2 Linker

Hi Team,

 

I have integrated the Instance Cortex XDR - IOC content pack: Cortex XDR by Palo Alto Networks

 

kindly help me, below which command to push bulk update IOC indicators to Cortex XDR if am wrong kindly guide me.

 

Instance = Cortex XDR - IOC

 

Cortex XDR-IOC  
xdr-iocs-create-sync-file Creates the sync file for the manual process. Run this command when instructed by the XDR support team.
xdr-iocs-disable Disables IOCs in the XDR server.
xdr-iocs-enable Enables IOCs in the XDR server.
xdr-iocs-push Push modified IOCs to Cortex XDR.
xdr-iocs-set-sync-time (Deprecated) Set sync time manually. (Do not use this command unless you understand the consequences.)
xdr-iocs-sync Sync your IOC with Cortex XDR and delete the old.
xdr-iocs-to-keep-file Create a file with all the IOCs that are going to sync to Cortex XDR.

 

 

 

 

chiranjeevi
2 REPLIES 2

L2 Linker

The following IOCs were not pushed due to following errors: 1.179.247.182: Expiration time 1716529790609 is invalid; expiration date cannot be in the past. 45.141.148.220: Expiration time 1716529790609 is invalid; expiration date cannot be in the past.

chiranjeevi

L2 Linker

Hi Team,

 

For bulk of IOC Lists i.e 100 no's IP's, Hashes, Domain names. how to push from XSOAR to XDR as a file or any form? does anyone worked this usecase scenario, kindly share!

 

 

For Single or Limit of 10 no's (IP , hashes, Domains Name ) the below command was working.

!xdr-iocs-enable indicator="172.15.1.50" 

!xdr-iocs-push indicator="172.15.1.50" 

 

!xdr-iocs-push indicator="fea456b3a78e87c2c99c5997b7255f553495a06a29bd7d4096cf72bfcbe1ed9b"

 

!xdr-iocs-enable indicator="vmtoolsd.exe"

 

Regards,

Chiranjeevi

chiranjeevi
  • 138 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!