- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-24-2024 08:02 AM
Hi,
Does anyone have a #Cortex XSOAR sync with a MISP server (bidirectional sync)?
I have two objectives:
Does anyone know if this is possible?
Is a playbook necessary for updates and synchronization?
09-25-2024 10:20 AM
Hello,
Sadly I do not see we support mirroring for this integration so this will have to be through a job that runs every time the feed is updated or time based (#2) .
Then you could run the commands needed to update MISP with the information found on XSOAR. The MISP v3 integration has several commands that can add objects, events and attributes to MISP so that should assist in #1.
This would definitely have to be a custom playbook as we do not have any OOTB.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!