XSOAR - Manual Review Indicators

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

XSOAR - Manual Review Indicators

L2 Linker

Hi, 
I have created a playbook that extracts IOC from a csv in a mail.
I want to ask the analyst if they want to manually review or auto block the IOCs.
If the analyst marks Manual review I want it to loop over every IOC and the analyst should mark to block or not.

Anybody has an idea of how to loop over every IOC.
I saved it to context under ${IOC} and the amount is obviously changing for every incident.

Another idea that will work even better but probably impossible to implement 

Bar_Magnezi_0-1721193781083.png

 

In the picture instead of marking and running over every ioc, Just list all of the IOC as an options to answer as multi select.
The IOCs that will be marked will be marked for block.




1 REPLY 1

L4 Transporter

Hi @Bar_Magnezi ,

 

For the first question, you can use subplaybook to loop through each input. 

Documentation: https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.5/Cortex-XSOAR-Administrator-Guide/Sub-Pla...

Video: https://www.youtube.com/watch?v=-Db98zkG7qc

For the second question, you can provide your IOC list as an answer and every item in the list will be provided to be multi-selected, then you can perform blocking action by taking the answer as an input.

gyldz_0-1721721366582.png

 

  • 102 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!