{
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"id": "XSOAR Summary",
"layout": [
{
"forceRange": false,
"h": 7,
"i": "2054da70-8d2d-11ed-aaea-5513d4d2e96d",
"id": "2054da70-8d2d-11ed-aaea-5513d4d2e96d",
"reflectDimensions": true,
"w": 6,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "",
"commitMessage": "",
"dataType": "scripts",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "",
"byTo": "",
"field": "",
"fromValue": null,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "",
"id": "382c00f1-33ac-44d6-8ffd-8bc8829c7767",
"isPredefined": false,
"itemVersion": "",
"modified": "2023-01-05T19:13:56.659718296Z",
"name": "Live Community",
"packID": "",
"packName": "",
"params": {
"limit": "10"
},
"prevName": "Live Community",
"propagationLabels": [
"all"
],
"query": "RSSWidget_LC",
"shouldCommit": false,
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 1,
"widgetType": "text"
},
"x": 0,
"y": 0
},
{
"forceRange": false,
"h": 3,
"i": "93729f70-8d31-11ed-aecc-5dccbe14e065",
"id": "93729f70-8d31-11ed-aecc-5dccbe14e065",
"reflectDimensions": true,
"w": 3,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "",
"commitMessage": "",
"dataType": "incidents",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "days",
"byTo": "",
"field": "",
"fromValue": 30,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "5.0.0",
"id": "",
"isPredefined": false,
"itemVersion": "1.2.11",
"modified": "2023-01-05T18:07:40.615732902Z",
"name": "Active Incidents - Line chart",
"packID": "CommonWidgets",
"packName": "Common Widgets",
"packPropagationLabels": [
"all"
],
"params": {
"groupBy": [
"type"
],
"valuesFormat": "abbreviated"
},
"prevName": "Active Incidents - Line chart",
"propagationLabels": [],
"query": "-category:job and -status:archived and -status:closed",
"shouldCommit": false,
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 0,
"widgetType": "pie"
},
"x": 6,
"y": 1
},
{
"forceRange": false,
"h": 1,
"i": "388d29d0-8d32-11ed-aecc-5dccbe14e065",
"id": "388d29d0-8d32-11ed-aecc-5dccbe14e065",
"reflectDimensions": true,
"w": 2,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "",
"commitMessage": "",
"dataType": "system",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "",
"byTo": "",
"field": "",
"fromValue": null,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "5.0.0",
"id": "disk-current-usage",
"isPredefined": true,
"itemVersion": "1.2.11",
"modified": "2023-01-05T18:07:40.616955063Z",
"name": "Disk Current Usage",
"packID": "CommonWidgets",
"packName": "Common Widgets",
"packPropagationLabels": [
"all"
],
"params": {
"colors": {
"isEnabled": true,
"items": {
"#00CD33": {
"value": -1
},
"#FAC100": {
"value": 60
},
"#FF1B15": {
"value": 80
}
},
"type": "above"
},
"currencySign": "%",
"signAlignment": "right"
},
"prevName": "Disk Current Usage",
"propagationLabels": [],
"query": "disk.usedPercent./",
"shouldCommit": false,
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 18,
"widgetType": "number"
},
"x": 6,
"y": 0
},
{
"forceRange": false,
"h": 1,
"i": "3d6c1c90-8d32-11ed-aecc-5dccbe14e065",
"id": "3d6c1c90-8d32-11ed-aecc-5dccbe14e065",
"reflectDimensions": true,
"w": 2,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "",
"commitMessage": "",
"dataType": "system",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "",
"byTo": "",
"field": "",
"fromValue": null,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "5.0.0",
"id": "cpu-current-usage",
"isPredefined": true,
"itemVersion": "1.2.11",
"modified": "2023-01-05T18:07:40.620831175Z",
"name": "CPU Current Usage",
"packID": "CommonWidgets",
"packName": "Common Widgets",
"packPropagationLabels": [
"all"
],
"params": {
"colors": {
"isEnabled": true,
"items": {
"#00CD33": {
"value": -1
},
"#FAC100": {
"value": 50
},
"#FF1B15": {
"value": 80
}
},
"type": "above"
},
"currencySign": "%",
"signAlignment": "right"
},
"prevName": "CPU Current Usage",
"propagationLabels": [],
"query": "cpu.usedPercent",
"shouldCommit": false,
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 18,
"widgetType": "number"
},
"x": 8,
"y": 0
},
{
"forceRange": false,
"h": 1,
"i": "4459cb10-8d32-11ed-aecc-5dccbe14e065",
"id": "4459cb10-8d32-11ed-aecc-5dccbe14e065",
"reflectDimensions": true,
"w": 2,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "",
"commitMessage": "",
"dataType": "system",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "",
"byTo": "",
"field": "",
"fromValue": null,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "5.0.0",
"id": "memory-current-usage",
"isPredefined": true,
"itemVersion": "1.2.11",
"modified": "2023-01-05T18:07:40.620365002Z",
"name": "Memory Current Usage",
"packID": "CommonWidgets",
"packName": "Common Widgets",
"packPropagationLabels": [
"all"
],
"params": {
"colors": {
"isEnabled": true,
"items": {
"#00CD33": {
"value": -1
},
"#FAC100": {
"value": 70
},
"#FF1B15": {
"value": 90
}
},
"type": "above"
},
"currencySign": "%",
"signAlignment": "right"
},
"prevName": "Memory Current Usage",
"propagationLabels": [],
"query": "memory.usedPercent",
"shouldCommit": false,
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 18,
"widgetType": "number"
},
"x": 10,
"y": 0
},
{
"forceRange": false,
"h": 3,
"i": "5a678b90-8d32-11ed-aecc-5dccbe14e065",
"id": "5a678b90-8d32-11ed-aecc-5dccbe14e065",
"reflectDimensions": true,
"w": 2,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "",
"commitMessage": "",
"dataType": "indicators",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "days",
"byTo": "",
"field": "",
"fromValue": 30,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "6.2.0",
"id": "",
"isPredefined": false,
"itemVersion": "1.2.11",
"modified": "2023-01-05T18:07:40.615827377Z",
"name": "Malicious/Suspicious Indicators in Incidents",
"packID": "CommonWidgets",
"packName": "Common Widgets",
"packPropagationLabels": [
"all"
],
"params": {
"colors": {
"isEnabled": false,
"items": {},
"type": "above"
},
"valuesFormat": "regular"
},
"prevName": "Malicious/Suspicious Indicators in Incidents",
"propagationLabels": [],
"query": "(verdict:Malicious) and incident.id:*",
"shouldCommit": false,
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 0,
"widgetType": "number"
},
"x": 10,
"y": 4
},
{
"forceRange": false,
"h": 3,
"i": "be52c4d0-8d32-11ed-aecc-5dccbe14e065",
"id": "be52c4d0-8d32-11ed-aecc-5dccbe14e065",
"reflectDimensions": true,
"w": 3,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "",
"commitMessage": "",
"dataType": "incidents",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "days",
"byTo": "",
"field": "",
"fromValue": 7,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "5.0.0",
"id": "incident-severity-by-types",
"isPredefined": true,
"itemVersion": "1.2.11",
"modified": "2023-01-05T18:07:40.616224647Z",
"name": "Incident Severity by Type",
"packID": "CommonWidgets",
"packName": "Common Widgets",
"packPropagationLabels": [
"all"
],
"params": {
"groupBy": [
"severity",
"rawType"
]
},
"prevName": "Incident Severity by Type",
"propagationLabels": [],
"query": "-category:job and -status:archived and -status:closed",
"shouldCommit": false,
"sort": [
{
"asc": true,
"field": "severity",
"fieldType": ""
}
],
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 18,
"widgetType": "bar"
},
"x": 9,
"y": 1
},
{
"forceRange": false,
"h": 3,
"i": "8f45d3c0-8d33-11ed-aecc-5dccbe14e065",
"id": "8f45d3c0-8d33-11ed-aecc-5dccbe14e065",
"reflectDimensions": true,
"w": 4,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "",
"commitMessage": "",
"dataType": "incidents",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "days",
"byTo": "",
"field": "",
"fromValue": 7,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "5.0.0",
"id": "top-active-playbooks",
"isPredefined": true,
"itemVersion": "1.2.11",
"modified": "2023-01-05T18:07:40.618465028Z",
"name": "Top Active Playbooks",
"packID": "CommonWidgets",
"packName": "Common Widgets",
"packPropagationLabels": [
"all"
],
"params": {
"groupBy": [
"playbookId"
]
},
"prevName": "Top Active Playbooks",
"propagationLabels": [],
"query": "status:active -category:job",
"shouldCommit": false,
"size": 5,
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 18,
"widgetType": "column"
},
"x": 6,
"y": 4
},
{
"forceRange": false,
"h": 3,
"i": "733666e0-8d3d-11ed-ab8d-db82a841bdea",
"id": "733666e0-8d3d-11ed-ab8d-db82a841bdea",
"reflectDimensions": true,
"w": 4,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "utilities",
"commitMessage": "",
"dataType": "incidents",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "days",
"byTo": "",
"field": "",
"fromValue": null,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "5.0.0",
"id": "",
"isPredefined": false,
"itemVersion": "1.2.11",
"modified": "2023-01-05T18:07:40.62003365Z",
"name": "Text Widget",
"packID": "CommonWidgets",
"packName": "Common Widgets",
"packPropagationLabels": [
"all"
],
"params": {
"text": "# Analyst Links\n| Link | Description |\n| --- | --- |\n| [Palo Alto Networks URL Filtering](https://urlfiltering.paloaltonetworks.com/) | Check a URL Category via Palo Altos Test a Site utility |\n| [Cortex XSOAR Admin Guide](https://docs-cortex.paloaltonetworks.com/p/XSOAR) | Cortex XSOAR Admin Guide |\n| [Cortex XSOAR Developer Guide](https://xsoar.pan.dev/) | The XSOAR Developer Guide |\n| [Cortex XSOAR Integration Reference](https://xsoar.pan.dev/docs/reference/index) | Reference documentation for Cortex XSOAR Integrations |\n| [Palo Alto Networks Live Community](https://live.paloaltonetworks.com/) | Palo Alto Networks Live Community, which includes training and how-to blog posts! |\n| [Palo Alto Networks Support Portal](https://support.paloaltonetworks.com/) | Palo Alto Networks Support Portal |"
},
"prevName": "Text Widget",
"propagationLabels": [],
"query": "",
"shouldCommit": false,
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 0,
"widgetType": "text"
},
"x": 0,
"y": 7
},
{
"forceRange": false,
"h": 3,
"i": "b82027f0-8d3d-11ed-ab8d-db82a841bdea",
"id": "b82027f0-8d3d-11ed-ab8d-db82a841bdea",
"reflectDimensions": true,
"w": 4,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "utilities",
"commitMessage": "",
"dataType": "incidents",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "days",
"byTo": "",
"field": "",
"fromValue": null,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "5.0.0",
"id": "",
"isPredefined": false,
"itemVersion": "1.2.11",
"modified": "2023-01-05T18:07:40.62003365Z",
"name": "Working Incidents",
"packID": "CommonWidgets",
"packName": "Common Widgets",
"packPropagationLabels": [
"all"
],
"params": {
"text": "# Working Incidents\n| Item | Notes | \n| --- | --- |\n| Assign an Owner | Select Owner via the **Owner field**, or use the **+Assign to Me button+** to assign to yourself |\n| Closing an Incident | Select **+Actions -\u003e Close Incident+**, and complete close notes and reason | \n| Editing an Incident | Select **+Actions -\u003e Edit+**, or edit the field on the layout |\n| Linking Incidents | Use the **+Link Incidents button+** or run !linkIncidents in the CLI |\n| Closing as Duplicate | Use the **+Close as Duplicate button+** or run **!CloseInvestigationAsDuplicate** in the CLI | \n| Inviting a Team Member | You can tag team members with **@username**, or select the 3-dots, and select Team. You can also select ALT \\+ E (Win) or Option (Mac) \\+ E to navigate to this quickly |\n| Restrict Incident | Restricts the Incident to only invited Team Members. Select **+Actions -\u003e Restrict Incident+** | \n| Fast Navigation | Command \\+ K (Mac) or Ctrl \\+ K (Win) |\n| Focus on the CLI | Command \\+ ; (Mac) or Ctrl \\+ ; (Win) | \n\n### Notes\n- Mark entries as a Note by selecting **+Actions -\u003e Mark as Note+** on the war room entry. \n- Notes are important information that you want to make it easy for others to find and read.\n- Screenshots and images can be uploaded in line to Notes via the Command Line Interface (CLI)\n- Notes can be tagged, and war room filters applied to view Notes with specific tags.\n\n### Evidence\n- Mark entries as Evidence by selecting **+Actions -\u003e Mark as Evidence+** on the war room entry. \n- Evidence can be reviewed on the Evidence Board.\n"
},
"prevName": "Text Widget",
"propagationLabels": [],
"query": "",
"shouldCommit": false,
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 0,
"widgetType": "text"
},
"x": 4,
"y": 7
},
{
"forceRange": false,
"h": 3,
"i": "23045a50-8d3e-11ed-ab8d-db82a841bdea",
"id": "23045a50-8d3e-11ed-ab8d-db82a841bdea",
"reflectDimensions": true,
"w": 4,
"widget": {
"Cache": null,
"cacheVersn": 0,
"category": "utilities",
"commitMessage": "",
"dataType": "incidents",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"fromDateLicense": "0001-01-01T00:00:00Z",
"period": {
"by": "",
"byFrom": "days",
"byTo": "",
"field": "",
"fromValue": null,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z"
},
"definitionId": "",
"fromServerVersion": "5.0.0",
"id": "",
"isPredefined": false,
"itemVersion": "1.2.11",
"modified": "2023-01-05T18:07:40.62003365Z",
"name": "Useful commands",
"packID": "CommonWidgets",
"packName": "Common Widgets",
"packPropagationLabels": [
"all"
],
"params": {
"text": "# Useful Commands\n### Investigation / Enrichment\n| Command | Functionality |\n| --- | --- |\n| !DomainReputation | Checks Domain reputation |\n| !FileReputation | Checks reputation of a File hash |\n| !IPReputation | Checks IP address reputation |\n| !URLReputation | Checks URL reputation. |\n| !ExtractIndicatorsFromTextFile | Extracts IOCs from text file |\n| !ExtractIndicatorsFromWordFile | Extracts IOCs from Word file |\n| !ReadPDFFileV2 | Extracts IOCs from PDF file |\n\n### Data Manipulation\n| Command | Functionality |\n| --- | --- |\n| !Base64Decode | Decodes base64-encoded input |\n| !Base64EncodeV2 | Encodes input into base64 |\n| !UnEscapeIPs| Removes escape characters [ ] from IP(s) |\n| !UnEscapeURLs | Removes escape characters from URLs |\n| !UnzipFile | Unzips a file (supports password protection) |\n| !ZipFile | Zips a file with optional password |\n\n### Related Incidents \u0026 Canvas\n- Use the Related Incidents tab to find similar Incidents based on common fields and Indicators.\n- Use the Canvas to construct a map of the Incidents and Indicators visually. "
},
"prevName": "Text Widget",
"propagationLabels": [],
"query": "",
"shouldCommit": false,
"toServerVersion": "",
"vcShouldIgnore": false,
"vcShouldKeepItemLegacyProdMachine": false,
"version": 0,
"widgetType": "text"
},
"x": 8,
"y": 7
}
],
"name": "XSOAR Summary",
"period": {
"by": "",
"byFrom": "days",
"byTo": "",
"field": "",
"fromValue": 7,
"toValue": null
},
"toDate": "0001-01-01T00:00:00Z",
"version": -1,
"fromVersion": "6.0.0",
"description": "",
"isPredefined": true
}