ANY.RUN — Empowers SOC teams with a Cloud Sandbox for real-time malware analysis, Threat Intelligence Lookup, and high-quality feeds to enhance detection and threat coverage.
APIVoid — APIVoid wraps up a number of services such as ipvoid & urlvoid
ARIAPacketIntelligence — Manage Packet Intelligence rules in response to incidents. Instantly block conversations, redirect packets, generate alerts, or perform other actions.
AWS - EKS — The AWS EKS integration allows for the management and operation of Amazon Elastic Kubernetes Service (EKS) clusters.
AWS - GuardDuty — Amazon Web Services Guard Duty Service (gd)
AWS - IAM — Amazon Web Services Identity and Access Management (IAM)
AWS - IAM Identity Center — AWS IAM Identity Center
With AWS IAM Identity Center (successor to AWS Single Sign-On), you can manage sign-in security for your workforce identities, also known as workforce users. IAM Identity Center provides one place where you can create or connect workforce users and manage their access centrally across all their AWS accounts and applications. IAM Identity Center is the recommended approach for workforce authentication and authorization in AWS, for organizations of any size and type.
AWS - Lambda — Amazon Web Services Serverless Compute service (lambda)
AWS - Route53 — Amazon Web Services Managed Cloud DNS Service.
AWS - S3 — Amazon Web Services Simple Storage Service (S3)
AWS - SNS — This is the integration content pack which can create or delete topic/subscription on AWS Simple Notification System and send the message via SNS as well.
AWS - SQS — Amazon Web Services Simple Queuing Service (SQS)
AWS Elastic Load Balancing — Elastic Load Balancing (ELB) automatically distributes incoming application traffic across multiple targets and virtual appliances in one or more Availability Zones (AZs).
AWS Secrets Manager — AWS Secrets Manager helps you to securely encrypt, store, and retrieve credentials for your databases and other services.
AWS Systems Manager — AWS Systems Manager is the operations hub for your AWS applications and resources and a secure end-to-end management solution for hybrid cloud environments that enables safe and secure operations at scale.
AWS WAF — Amazon Web Services Web Application Firewall (WAF)
AWS-ILM — IAM Integration for AWS-ILM. This pack handles user account auto-provisioning
AWS-SNS-Listener — A long running AWS SNS Listener service that can subscribe to an SNS topic and create incidents from the messages received.
Abnormal Security — Abnormal Security detects and protects against the whole spectrum of email attacks
Absolute — Absolute is an adaptive endpoint security solution that delivers device security, data security and asset management of endpoints
Abuse.ch SSL Blacklist Feed — The SSL IP Blacklist contains all hosts (IP addresses) that SSLBL has seen in the past 30 days and
identified as being associated with a malicious SSL certificate.
AbuseIPDB — Central repository to report and identify IP addresses that have been associated with malicious activity online. Check the Detailed Information section for more information on how to configure the integration.
Access Investigation — This Content Pack automates response to unauthorised access incidents and contains customer access incident views and layouts to aid investigation.
Active Directory Query — Active Directory Query integration enables you to access and manage Active Directory objects (users, contacts, and computers).
ActiveMQ — Uses Durable Topic Subscribers to fetch messages and ingest them as incidents in Demisto.
Admin By Request — AdminByRequest is a Privileged Access Management (PAM) solution that enables secure, temporary elevation to local admin rights.
Agari Phishing Defense — Use the Agari Phishing Defense integration to retrieve Policy Events as Incidents, retrieve messages and remediate suspected messages.
AlphaSOC Wisdom — DNS and IP threat intelligence via the AlphaSOC platform
AlphaVantage — The Alpha Vantage content pack provides accessible APIs for financial market data such as stock prices. Utilize this pack to get open stock prices, high/low price, trade volume, and so on.
Altipeak — Integration with Safewalk identity management and report service
Amazon - Security Lake — Amazon Security Lake is a fully managed security data lake service.
Amazon DynamoDB — Amazon DynamoDB Amazon DynamoDB is a fully managed NoSQL database service that provides fast and predictable performance with seamless scalability. DynamoDB lets you offload the administrative burdens of operating and scaling a distributed database, so that you don't have to worry about hardware provisioning, setup and configuration, replication, software patching, or cluster scaling. With DynamoDB, you can create database tables that can store and retrieve any amount of data, and serve any level of request traffic. You can scale up or scale down your tables' throughput capacity without downtime or performance degradation, and use the AWS Management Console to monitor resource utilization and performance metrics. DynamoDB automatically spreads the data and traffic for your tables over a sufficient number of servers to handle your throughput and storage requirements, while maintaining consistent and fast performance. All of your data is stored on solid state disks (SSDs) and automatically replicated across multiple Availability Zones in an AWS region, providing built-in high availability and data durability.
Analyst1 — Enriches indicators with Analyst1 threat intelligence including actor, malware, and evidence data.
Anomali Enterprise — Use Anomali Match to query IOCs and conduct forensic searches.
Anomali Security Analytics — The Anomali Security Analytics pack allows users to manage security alerts by interacting directly with the Anomali Security Analytics platform. It supports creating search jobs, monitoring their status, retrieving results, and updating alert statuses or comments, streamlining integration with Palo Alto XSOAR.
Anomali ThreatStream Feed — Anomali ThreatStream Feed and Sample Management. This pack is designed to fetch, manage, and query threat intelligence feeds and associated samples from Anomali ThreatStream.
Ansible VMware — Manage and control VMware virtualisation hosts.
Anthropic Claude — Designed to assist security professionals with security investigations, threat hunting, and anomaly detection, leveraging Anthropic Claude's natural language conversational capabilities.
Anthropic Claude (Standard Connector) — Satellite pack of Anthropic Claude used for the Standard Connector deployment. Shares core logic with the Anthropic Claude pack via the AnthropicClaudeApiModule.
Anything LLM — This content pack contains an integration for Anything LLM that supports the use of Retrieval Augmented Generation (RAG) with an LLM and vector DB. The LLM and vector DB can be fully local for maximum data privacy or configured to use cloud-based services such as OpenAI. A large range of LLMs and vector DBs are supported.
Apache Tomcat — Modeling Rules for the Apache Tomcat logs collector
Apache Web Server — Modeling Rules for the Apache Web Server logs collector
AppNovi — Search your combined security data in appNovi via simplified search or search via the appNovi security graph.
AppSentinels.ai — Appsentinels.ai offers a platform for collecting, analyzing, and managing security events to provide comprehensive application protection.
AquatoneDiscover (Deprecated) — Deprecated. Use ***AquatoneDiscover*** script from ***Common Scripts** pack instead.
. aquatone-discover will find the targets nameservers and shuffle DNS lookups between them. Should a lookup fail on the target domains nameservers, aquatone-discover will fall back to using Google public DNS servers to maximize discovery.
ArcannaAI — Siscale Arcanna.Ai Cognitive automation platform that provides AI assistance to IT & Cybersecurity teams
ArcusTeam — ArcusTeam's DeviceTotal Platform helps to identify and manage vulnerabilities found on IoT devices
Arduino — Communicate with an Arduino over a network. Sample code for the Arduino is provided to get up and running. There are functions in the Arduino code to handle setting and getting pin values as well as arbitrary data.
Arista Switch — Modeling & Parsing Rules for Arista EOS Switch Events Logs.
Arkime — Arkime (formerly Moloch) is a large scale, open source, indexed packet capture and search tool.
Armis — Agentless and passive security platform that sees, identifies, and classifies every device, tracks behavior, identifies threats, and takes action automatically to protect critical information and systems
Armorblox — Armorblox is an API-based platform that stops targeted email attacks, protects sensitive data, and automates incident response.
Asana Connect — Use the Asana Connect integration to connect to projects related to your Asana account.
Asimily Insight — Integrate Asimily Insight to ingest security anomalies, CVEs, and leverage detailed asset data for streamlined incident investigation.
Asset — Base pack for any packs using asset fields.
Ataya — Integrate with Ataya Harmony for manage the 5G UE session
Atlassian Cloud MCP — Integrate with Atlassian Cloud via the Model Context Protocol (MCP) server to automate Atlassian operations.
Atlassian Confluence Cloud — Atlassian Confluence Cloud allows users to interact with confluence entities like content, space, users and groups. Users can also manage the space permissions.
AttackIQ Platform — An attack simulation platform that provides validations for security controls, responses, and remediation exercises.
Attivo Botsink — Network-based Threat Deception for Post-Compromise Threat Detection.
Auditd — Auditd Modeling Rules and Parsing Rules Pack.
Augur Security — Leverage Augur Security's preemptive threat intelligence to provide actionable IOC enrichment and orchestration. Augur's daily indicators returns a list of CIDRs that are unique to Augur Security's ML based predictions of malicious actor's network. The file, host and ip endpoints can be used by playbook to enrich IOCs.
AutoFocus by Palo Alto Networks — Use the Palo Alto Networks AutoFocus integration to distinguish the most
important threats from everyday commodity attacks.
Automox — This pack empowers you with comprehensive solutions to manage your Automox device fleet with ease!
Avaya Aura Communication Manager — The Avaya Aura Communication Manager is an extensible IP telephony platform that delivers rich voice, video, mobility, messaging and engagement capabilities on a resilient, distributed network that supports SIP/IP-based, digital and analog communication devices.
Azure App Service — Azure App Service is an HTTP-based service for hosting web applications, REST APIs, and mobile back ends. This pack contains normalization rules for ingesting and modeling Azure App Service Resource logs.
Azure Compute — Create and Manage Azure Virtual Machines
Azure Data Explorer — Use Azure Data Explorer integration to collect and analyze data inside clusters of Azure Data Explorer and manage search queries.
Azure Firewall — Azure Firewall is a cloud-native and intelligent network firewall security service that provides breed threat protection for cloud workloads running in Azure. It's a fully stateful firewall as a service, with built-in high availability and unrestricted cloud scalability. This pack contains an integration with a main goal to manage Azure Firewall security service, and normalization rules for ingesting and modeling Azure Firewall Resource logs.
Azure Key Vault — Use Key Vault to safeguard and manage cryptographic keys and secrets used by cloud applications and services.
Azure Kubernetes Services — Deploy and manage containerized applications with a fully managed Kubernetes service.
Azure Log Analytics — Log Analytics is a service that helps you collect and analyze data generated by resources in your cloud and on-premises environments.
Azure Logs — Normalizes various Azure logs to the Cortex Data Model (XDM) schema, including Azure Entra ID events ingested via the Office 365 data source and Azure logs ingested via the Azure Event Hub data source.
Azure Network Security Groups — Azure Network Security Groups are used to filter network traffic to and from Azure resources in an Azure virtual network
Azure Open AI Service — The primary purpose of this Cortex XSOAR integration is to bridge the gap between human-level security analysis and automated incident response by leveraging the power of Azure OpenAI. It effectively transforms a large language model, like GPT-4o, into a consistent, on-demand cybersecurity analyst that integrates directly into automated workflows.
Unlike a simple chatbot, this integration is built for reliability and automation. Its core function is to send unstructured security data (such as email headers, logs, or observables) to the AI and compel it to return its analysis in a strictly defined, structured JSON format. This is achieved through a combination of specific API parameters and a detailed system prompt that instructs the AI on its role, the analysis to perform, and the exact schema to use for its response.
Once the structured JSON is received, the integration performs two key actions:
Automated Incident Enrichment: It parses the JSON and uses the data to automatically populate custom fields within the XSOAR incident. This enriches the incident with an AI-generated verdict, a summary, a justification, and a confidence score, all without manual intervention.
Enhanced Playbook Automation: By providing predictable, machine-readable output, the integration allows playbooks to make intelligent, data-driven decisions. For example, a playbook can automatically escalate a high-confidence "Malicious" incident or close a "Benign" one, significantly accelerating the response lifecycle.
The integration also includes robust error handling to ensure it functions reliably in a production environment. In essence, it operationalizes artificial intelligence for security operations, turning expert knowledge into a scalable, automated resource that enhances both the speed and quality of incident response.
Azure Resource Graph — Azure Resource Graph is an Azure service designed to extend Azure Resource Management by providing efficient and performant resource exploration with the ability to query at scale across a given set of resources. This pack is primarily used to allow for executing Azure Resource Graph queries.
Azure Risky Users — Azure Risky Users provides access to all at-risk users and risk detections in Azure AD environment.
Azure SQL Management — Microsoft Azure SQL Database is a managed cloud database provided as part of Microsoft Azure
Azure WAF — Azure Web Application Firewall is used to detect web related attacks targeting your web servers hosted in azure and allow quick respond to threats
AzureDevOps — Create and manage Git repositories in Azure DevOps Services.
AzureFlowLogs — This pack contains data normalization to XDM fields and timestamp ingestion for logs.
BMC Discovery — BMC Discovery integration allows searching for endpoints information, triggering Discovery runs and running custom user queries.
BMC Helix ITSM — BMC Helix ITSM allows customers to manage service requests, incidents, change requests, tasks, problem investigations, known errors and work order tickets.
Binalyze AIR — Collect over 300 different types of evidence under 10 minutes.
Binalyze AIR Extended — Integrate with Binalyze AIR to orchestrate incident response and forensic operations directly from Cortex XSOAR.
BitDam — BitDam secure email gateway protects from advanced content-borne threats with the most accurate prevention of known and unknown threats, at their source.
Bitbucket — Bitbucket Cloud is a Git-based code and CI/CD tool optimized for teams using Jira
Bitsight — The BitSight integration provides visibility into BitSight findings, enabling remediation within your security program
Bitwarden Password Manager — Bitwarden Password Manager is a secure, open-source tool for storing and managing passwords and sensitive information across devices.
BloodHound Enterprise (Deprecated) — Deprecated. Use the SpecterOps BloodHound Enterprise pack instead. BloodHound Enterprise identifies and remediates Active Directory vulnerabilities to enhance security posture.
Bluecat Address Manager — Use the BlueCat Address Manager integration to enrich IP addresses and manage response policies.
Blueliv ThreatCompass — Blueliv ThreatCompass systematically looks for information about companies,products, people, brands, logos, assets, technology and other information, depending on your needs. Blueliv ThreatCompass allows you to monitor and track all this information to keep your data, your organization and its employees safe
Blueliv ThreatContext — The Threat Context module provides SOC, Incident Response and Threat Intelligence teams with continuously updated and intuitive information around threat actors, campaigns, malware indicators, attack patterns, tools, signatures and CVEs. Analysts can rapidly gather enriched, contextualized information to enhance cybersecurity processes before, during and after an attack.
Bmc Helix Remedyforce — Integration of BMC Helix Remedyforce with Cortex XSOAR. BMC Helix Remedyforce integration allows customers to create/update service requests and incidents. It also allows to update status, resolve service requests and incidents with customer notes. This integration exposes standard ticketing capabilities that can be utilized as part of automation & orchestration.
Bonusly — Bonus.ly is an employee recognition platform which enterprises use to for employee recognition. We're building tools to help people feel a sense of purpose and progress at work. The platform which also has an API enables employees to recognize each other by providing a point based bonus system. Bonus.ly helps your employees feel connected, engaged, and aligned is mission critical right now. Bonusly makes employee recognition easy and fun, fostering community and creating company-wide alignment. It also provides employees with positive feedback in the work that they are doing.
Brandefense — Branddefense is looking for data for each brand and collecting information and alarming the related brand about dark web finding (credentials, similar domain names etc.) related to the firm.With Brandefense integration it is possible to automate Brand related alarms and breach notifications, actions and much more.
Brandefense Digital Risk Protection Services — Brandefense Digital Risk Protection, External Attack Surface Management, and Actionable Threat Intelligence integration for Cortex XSOAR.
BreachRx — Automate your privacy Incident Response workflow through the BreachRx platform.
Brocade Switch — Modeling Rules for the Brocade Switch logs collector
Brute Force — This Content Pack helps you automate the repetitive tasks associated with Brute Force incidents. Custom incident views and layouts aid investigation.
C2sec irisk — Understand Your Cyber Exposure as Easy as a Google Search
CIRCL — The Computer Incident Response Center Luxembourg (CIRCL) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents.
This pack includes:
# CIRCL Passive DNS which is a database storing historical DNS records from various resources.
# CIRCL Passive SSL is a database storing historical X.509 certificates seen per IP address. The Passive SSL historical data is indexed per IP address.
# CIRCL CVE Search, interface to search publicly known information from security vulnerabilities in software and hardware along with their corresponding exposures.
CIRCL hashlookup (hashlookup.circl.lu) — CIRCL hash lookup is a public API to lookup hash values against known database of files. NSRL RDS database is included and many others are also included. The API is accessible via HTTP ReST API and the API is also described as an OpenAPI. The service is free and served as a best-effort basis.
CSCDomainManager — CSCDomainManager is the world's first multilingual domain management tool, available in English, French, and German. It uses rules-based technology, customizable reporting, granular user management, and more to enable you to manage your domain.
CVE-2021-40444 - MSHTML RCE — This pack handles Microsoft MSHTML RCE CVE-2021-40444. CVE-2021-4044 refers to the MSHTML engine, that has been found vulnerable to arbitrary code execution by a specially crafted Microsoft Office document or rich text format file.
CVE-2021-44228 - Log4j RCE — This pack handles Apache Log4j RCE CVE-2021-44228, a 0-day exploit in the popular Java logging library log4j2.
CVE-2022-26134 - Confluence RCE — This pack handles Confluence RCE CVE-2022-26134 vulnerability, a 0-day exploit via OGNL injection in Confluence Server & Data Center.
CVE-2022-30190 - MSDT RCE — This pack handles MSDT RCE CVE-2022-30190, aka Follina vulnerability, a 0-day exploit in Microsoft MSDT protocol handler
Carbon Black Common Fields — Carbon Black common fields concentrates all of the mutual content entities for the Carbon Black integrations.
Carbon Black Endpoint Standard — Next-generation antivirus + EDR in one cloud-delivered platform that stops commodity malware, advanced malware, non-malware attacks and ransomware.
Carbon Black Enterprise Live Response — Collect information and take action on remote endpoints in real time with Carbon Black Enterprise Live Response.
Carbon Black Enterprise Protection — Carbon Black Enterprise Protection is a next-generation endpoint threat prevention solution to deliver a portfolio of protection policies, real-time visibility across environments, and comprehensive compliance rule sets in a single platform.
CaseManagement-Generic — Case Management - Generic
Built by the Cortex Customer Success Team to provide quick deployment of Case Management with XSOAR
Celonis — The Celonis Platform offers you a suite of process mining and intelligence features, helping you to integrate your data and then use that data to analyze, improve, and monitor your business performance across key metrics.
Censys — The Censys integration adds the ability to enrich IPs, web properties, and certificates in Palo Alto XSOAR and XSIAM with Censys Platform data. It also adds actions to initiate a Censys rescan of a host or web property and retrieve event history for an IP address. Additionally, users can find related infrastructure to a host, certificate, or web property.
Centrify Vault — Centrify Vault integration to create/fetch/delete secrets/folders/sets.
CertStream — Gets a stream of newly created certificates from Certificate Transparency (https://certificate.transparency.dev/)
Change Management — If you use Pan-Os or Panorama as your enterprise firewall and Jira or ServiceNow as your enterprise ticketing system, this pack will assist you to perform a well coordinated and documented process.
Check Point Dome9 (CloudGuard) — Dome9 integration allows to easily manage the security and compliance of the public cloud.
Check Point Harmony Endpoint — Check Point Harmony Endpoint provides a complete endpoint security solution built to protect organizations and the remote workforce from today's complex threat landscape.
Check Point Infinity NDR — Collect network security events from Check Point Infinity NDR for your secured SaaS periodically
Check Point Threat Emulation (SandBlast) — Upload files using polling, the service supports Microsoft Office files, as well as PDF, SWF, archives and executables. Active content will be cleaned from any documents that you upload (Microsoft Office and PDF files only). Query on existing IOCs, file status, analysis, reports. Download files from the database. Supports both appliance and cloud. Supported Threat Emulation versions are any R80x.
Check Point XDR — Fetch and manage incidents from Check Point XDR.
CheckPhish — Check any URL to detect suspicious behavior.
Cherwell — Cloud-based IT service management solution
CimTrak - System Integrity Assurance — The CimTrak integration helps you detect unexpected system/device/config modifications and automatically respond/react to threats
CircleCI — CircleCI is a modern continuous integration and continuous delivery (CI/CD) platform. CircleCI automates the building, testing, and deployment of software.
Cisco ASA — Cisco Adaptive Security Appliance Software is the core operating system for the Cisco ASA Family. It delivers enterprise-class firewall capabilities for ASA devices.
Cisco ASR — Cisco Aggregation Services Router (ASR) is a service used on cisco routers for combine traffic link for better performance and scalability.
Cisco AppDynamics — AppDynamics enables you to automate incident management, gain real-time performance metrics, and optimize applications to meet business needs moment to moment.
Cisco Firepower — Use the CiscoFirepower integration for unified management of firewalls, application control
Cisco ISE — Next-generation secure network access.
Cisco ISR — Cisco Integrated Services Routers (ISRs) are high-performance routers designed to provide advanced security, multicloud access, and wireless capability in one device.
Cisco Meraki — Cloud controlled WiFi, routing, and security.
Cisco Nexus — Cisco Nexus is a series of switches that offer high-density, high-performance, and highly scalable networking solutions, designed to meet the demands of modern enterprise networks.
Cisco ThousandEyes — Enables automatic collection of network performance and health events from Cisco ThousandEyes, providing actionable insights into device health, network paths, and application performance.
Cisco UCM — Parsing and modeling rules for Cisco UCM logs forwarded via Syslog
Cisco Umbrella Reporting — Use Cisco Umbrella's Reporting to monitor your Umbrella integration and gain a better understanding of your Umbrella usage. Gain insights into request activity and blocked activity, determining which of your identities are generating blocked requests. Reports help build actionable intelligence in addressing security threats including changes in usage trends over time. The Umbrella Reporting v2 API provides visibility into your core network and security activities and Umbrella logs. This integration was integrated and tested with version 2 of Cisco-umbrella-reporting.
Cisco Umbrella cloud security — Basic integration with Cisco Umbrella that allows you to add domains to destination lists (e.g. global block / allow)
Cisco WSA — Cisco Secure Web Appliance protects your organization by automatically blocking risky sites and testing unknown sites before allowing users to click on them.
Cisco WebEx Feed — Whitelist feed for Cisco Webex using a screen scrape of the website.
Cisco Webex Teams — Send messages, create rooms and more, via the Cisco Webex Teams (Cisco Spark) API.
Cisco Wireless LAN Controller — Cisco Wireless LAN Controller (WLC) is used to manage and ensure seamless and secure wireless communication within organizations.
CiscoSMA — The Security Management Appliance (SMA) is used to centralize services from Email Security Appliances (ESAs) and Web Security Appliances (WSAs).
Citrix — Citrix is a unified platform that provides management, monitoring, and delivery services for Citrix products and resources across cloud and on-premise environments. It centralizes administration, enhances visibility, and simplifies operational workflows.
Citrix ADC — Citrix ADC is an application delivery controller (ADC) is a purpose-built networking appliance used to improve the performance, security, and resiliency of applications delivered over the web.
Clarizen IAM — IAM Integration for Clarizen. This pack handles user account auto-provisioning
Claroty — Use the Claroty CTD to manage assets and alerts.
Claroty xDome — Use xDome to manage assets and alerts.
Clearswift DLP — The Clearswift Endpoint Data Loss Prevention (DLP) solution offers visibility, control, monitoring and policies that help a company protect its assets.
Cloaken — Unshorten URLs onsite using the power of a Tor proxy server to prevent leaking IP addresses to adversaries.
Cloud Convert — Use this integration to convert files using CloudConvert API
Cloud Incident Response — This content Pack helps you automate collection, investigation, and remediation of incidents related to cloud infrastructure activities in AWS, Azure, and GCP.
Cloud Security Policy Management — This pack contains playbooks and scripts used for tasks in other cloud security content packs.
Cloud-IDS — Google Cloud IDS, a next-generation advanced intrusion detection service that provides threat detection for intrusions, malware, spyware and command-and-control attacks.
CloudShark — Use the CloudShark integration to upload, share, and collaborate on network packet capture files using your on-premises CS Enterprise system.
Cloudflare MCP — Integrate with Cloudflare via the Model Context Protocol (MCP) server to automate Cloudflare operations.
Cloudflare WAF — Use Cloudflare WAF to manage firewall rules, filters, and IP-lists.
Cloudflare Zero Trust — Cloudflare provides network and security products for consumers and businesses, utilizing reverse proxies for web traffic, edge computing, and a content distribution network to provide content across its network of servers.
Code42 — The Code42 INCYDR integration accelerates insider threat incident response and remediation procedures for potential data exfiltration across computers, email, cloud and SaaS apps.
Cofense Feed — Ingest human-verified phishing indicators from Cofense Intelligence. Cofense Intelligence is reliable, human-verified phishing intelligence for actionable defense and strategic planning. Cofense researchers track emerging trends in phishing, research active threats, and supplement highest-priority investigations.
Cofense Intelligence (Deprecated) — Deprecated. Use Cofense Intelligence v2 instead. Use the Cofense Intelligence integration to check the reputation of URLs, IP addresses, file hashes, and email addresses.
Cofense Intelligence v2 — Cofense Intelligence allows users to search for threat intelligence reports based on domains, IPs, email address, file hashes, URLs and extracted strings.
Cofense Triage — Cofense Triage allows users to fetch reports by using the fetch incidents capability. It also provides commands to get entities like reporters, rules, categories, and more.
Cofense Vision — Cofense Vision empowers security teams to hunt for email messages and quarantine threats in mailboxes. Analysts can setup jobs to remove emerging phishing campaigns based on trusted and credible IOCs through an automated workflow.
Cognni — Autonomous detection and investigation of information security incidents and other potential threats.
Cohesity Helios — This integration interacts with Cohesity Helios and performs actions based on alerts raised.
Common Types — This Content Pack will get you up and running in no-time and provide you with the most commonly used incident & indicator fields and types.
Commvault Backup Solutions — This pack contains Modeling and Parsing Rules for normalizing Commvault Backup API logs
Commvault Cloud — Commvault Cloud provides pre-built integrations, automation workflows, and playbooks to streamline operations, enhance threat intelligence integration, and gain actionable insights through advanced reporting and analytics.
Comprehensive Investigation by Palo Alto Networks — Are you a Palo Alto Networks customer? We have just the content pack to help you orchestrate incident response across Palo Alto Networks products.
ComputerVisionEngine — The ComputerVision Integration by using the Deep-learning library yolo-coco and OpenCV is able to recognize objects on photographs, i.e. planes, luggage, people, dogs, cats, etc.
The integration can be used in playbooks to extract objects on rasterized websites in phishing campaigns and making IOCs out of them.
Additionally, the integration is useful in CCTV systems significantly reducing the number of false - positives and creating custom workflows in XSOAR playbooks for on-prem physical security!
ConcentricAI — Plugin for Concentric.ai Concentric’s Semantic Intelligence™ solution discovers and protects business critical, unstructured data.
We use deep learning to identify risky sharing, inappropriate third party access, assets in the wrong location,
mis-classified documents, or lateral movement of data – all without rules or complex upfront configuration.
Confluera — This content pack uses the Confluera integration to fetch detections & progressions from confluera's Iq-Hub portal
Content Testing — Supports assessment of upgraded Marketplace content packs against custom content and enables content testing within XSOAR. Dynamically select and test automations, playbooks, and sub-playbooks as required prior to push to production. Create a "UnitTesting" incident type and review the "Help" tab in the layout for description of the tools available and the examples using the testing tools.
ContextReplica — Downloads an exact replica of the JSON context as it appears in the Cortex XSOAR incident or issue context UI, supporting XSOAR, XSIAM, and Agentix platforms.
Coralogix — Coralogix Integration can be used for searching incidents and other data from Coralogix as well as tagging interesting timestamps at Coralogix from Cortex XSOAR
Core Alert Fields — This Content Pack will provide you with the core alert fields.
Corelight Zeek — An open-source software network analysis framework.
Cortex 911 — Palo alto Networks Cortex is the industry’s most comprehensive product suite for security operations empowering enterprises with the best-in-class detection, investigation, automation and response capabilities. Cortex 911 program empowers selected partners to respond to breaches immediately with Palo Alto Networks products and services.
Cortex Response And Remediation — The Cortex Response & Remediation Pack delivers a powerful collection of automated playbooks designed to streamline incident response and remediation processes. Built to support an Autonomous SOC vision.
Cortex XDR by Palo Alto Networks — Automates Cortex XDR incident response, and includes custom Cortex XDR incident views and layouts to aid analyst investigations.
Cortex Xpanse — Content for working with Attack Surface Management (ASM).
CounterCraft Deception Director — CounterCraft Deception Solution detects advanced adversaries. Automate counterintelligence campaigns to discover targeted attacks with real-time active response.
CounterTack — CounterTack empowers endpoint security teams to assure endpoint protection for Identifying Cyber Threats. Integrating a predictive endpoint protection platform
Covalence For Security Providers — Triggers by any alert from endpoint, cloud, and network security monitoring, with mitigation steps where applicable. Query Covalence for more detail.
Covalence Managed Security — Triggers by triaged alerts from endpoint, cloud, and network security monitoring. Contains event details and easy-to-follow mitigation steps.
Cribl — Query and manage search jobs, datasets, and saved searches in your Cribl Cloud deployment.
CriminalIP — Criminal IP integration with Palo Alto Xsoar provides AI and OSINT-powered cyber threat intelligence for IP and domain analysis, along with comprehensive attack surface management capabilities.
Crisis Management — This Content Pack helps you automate data collection and crisis event communications such as monitoring remote employee health and safety well being.
CrowdSec — Enrich the data you have on your threats with the most advanced real-world CTI.
CrowdStrike Falcon — The CrowdStrike Falcon OAuth 2 API (formerly the Falcon Firehose API), enables fetching and resolving detections, searching devices, getting behaviors by ID, containing hosts, and lifting host containment.
CrowdStrike Falcon Intel — Threat intelligence service by CrowdStrike focused on delivering a technical feed to help organizations better defend themselves against adversary activity.
CrowdStrike Falcon Streaming — Use the CrowdStrike Falcon Stream v2 integration to stream detections and audit security events.
CrowdStrike Malquery — Use the MalQuery Pack to query the contents of over a half-billion binary files, both clean and malicious, that are part of Falcon MalQuery's corpus.
CrowdStrike OpenAPI — Use the CrowdStrike OpenAPI integration to interact with CrowdStrike APIs that do not have dedicated integrations in Cortex XSOAR, for example, CrowdStrike FalconX, etc.
Crowdstrike Falcon Intel Feed — Tracks the activities of threat actor groups and advanced persistent threats (APTs) to understand as much as possible about their known aliases, targets, methods, and more.
Cryptocurrency — This Content Pack enables you to add a reputation for cryptocurrency addresses.
Cryptosim — CRYPTOSIM meets the SIEM needs of corporations by its unique correlation engine works, capable of hierarchical correlation.
CyCognito — Fetches the issues associated with a particular asset from the CyCognito platform.
CyCognito Feed — Provides a feed integration to retrieve the discovered assets.
CybelAngel — CybelAngel Event Collector receives reports from the CybelAngel platform, which specializes in external attack surface protection and management.
Cyber Triage — Allows you to conduct a mini-forensic investigation on an endpoint. It pushes a collection tool to the remote endpoint, collects volatile and file system data, and analyzes the data.
CyberArk — Provides a Safe Haven, where all your administrative passwords can be securely archived, transferred and shared by authorized users.
CyberArk Endpoint Privilege Manager — Endpoint Privilege Manager helps remove local admin rights while improving user experience and optimizing IT operations.
CyberArk Identity — This integration collects events from the Idaptive Next-Gen Access (INGA) using REST APIs.
CyberArk PAM Self-Hosted — This pack contains modeling & parsing rules for CyberArk PAM Self-Hosted Vault audit event logs.
CyberArk Privileged Threat Analytics — CyberArk Privileged Threat Analytics (PTA) leverages the analytic capabilities of PTA and assigns a risk score to privileged sessions.
CyberChef — Integration with your CyberChef server or https://prod.apifor.io service for CyberChef.
CyberTotal — This pack is the integration of Demisto and CyberTotal. CyberTotal is a cloud-based threat intelligence service developed by CyCraft, which cohesively integrates multiple and varied CTI sources, open source intel, and proprietary threat intel to provide best-in-class threat intelligence. CyberTotal helps companies quickly identify and triage threats as well as verify security alerts through automated correlation analysis and knowledge base optimization.
CyberX - Central Manager — This is a small integration which is able to update alerts inside of Cyber X.
Cybereason — Endpoint detection and response to manage and query malops, connections and processes.
Cyberhaven — Fetches DLP incidents from the Cyberhaven data security platform and enables investigation of events and data lineage.
Cyberint — Cyberint provides intelligence-driven digital risk protection. This integration will help your enterprise effectively consume actionable cyber alerts to increase your security posture.
Cyberpion — Cyberpion's platform provides the breadth and depth of discovery and vulnerability assessment that security teams need to manage the threats from their far-reaching online ecosystems. Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets and their artifacts. You can use this pack to push Cyberpion Action Items directly into your XSOAR instance, and also get additional information relating to those Action Items, and much more
Cybersixgill Actionable Alerts — The integration allow retrieving Cybersixgill's actionable alerts based on organization assets
Cybersixgill-DVE — Powered by the broadest automated collection from the deep and dark web, Cybersixgill’s Dynamic Vulnerability Exploit (DVE) Score is a feed of common known vulnerabilities, scored by their probability of getting exploited. The DVE Score feed enables Cortex XSOAR users to track threats from vulnerabilities that others define as irrelevant, but have a higher probability of being exploited. It is the only solution that predicts the immediate risks of a vulnerability based on threat actors’ intent.
DVE Score is also the most comprehensive CVE enrichment solution on the market: Cortex XSOAR users gain unparalleled context and can accelerate threat response and decision making, effectively giving security teams a head start on vulnerability management.
Cyberwatch — Find, prioritize, and fix vulnerabilities. Use this integration to fetch Assets, CVE, and Security issues from Cyberwatch.
Cymptom — Cymptom is a Breach and Attack Simulation solution that revolutionizes
the existing approach by transforming attack simulation into a data analysis question.
Cymptom agentless scanning brings real-time always-on visibility into the entire
security posture.
Cymulate — You can now verify your security posture on-demand using the Cymulate integration, which allows you to launch simulations of cyberattacks, breach, and attacks against yourself
Cypho Threat Intelligence — The Cypho-XSOAR Content Pack automates incident management between Cypho and Cortex XSOAR. It includes 7 automations, 1 playbook, 23 incident types, and 72 incident fields, enabling users to assign incidents, add comments, update severity, approve or dismiss issues, download attachments, and fetch incidents from Cypho. This content pack ensures incidents in XSOAR accurately reflect the current state of Cypho tickets, streamlines workflows, reduces manual effort, and improves operational efficiency and compliance.
Cyren Inbox Security — Cyren Inbox Security protects Office 365 mailboxes from evasive phishing, business email compromise, and fraud.
Cyren Threat InDepth Threat Intelligence — Threat InDepth's actionable and contextualized intelligence helps enterprises improve their threat detection and response by providing unprecedented visibility into new email-borne security threats faster than other security vendors.
Cyware Intel Exchange — Cyware Intel Exchange enables security teams to ingest, enrich, analyze, and share threat intelligence in real time.
DB2 — This pack's purpose is to provide helpful commands to build a connectivity and run queries on IBM DB2 database.
DBot Truth Bombs — Nefarious attackers coming in at you from all fronts. Don't you wish you could just go Texas Ranger on them?
DFIRe — Automate DFIRe forensic case management and IOC indicator synchronization from Cortex XSIAM and Cortex XSOAR.
DHS Feed — Provides cyber threat indicators from the Cybersecurity and Infrastructure Security Agency’s (CISA’s) free Automated Indicator Sharing (AIS) by the Department of Homeland Security (DHS).
DNSOverHttps — Use this pack to make DNS queries over HTTPS to Cloudflare or Google DoH service.
DSPM — Remediate data security risks with Prisma Cloud DSPM, using automated playbooks and seamless risk distribution.
DUO Admin — DUO for admins.
Must have access to the admin api in order to use this
Darkmon — Stay ahead of cyber threats with Darkmon TIP - real-time threat intelligence from the Clear, Deep, and Dark Web tailored to your assets. The pack provides indicator enrichment, compromised-credentials monitoring, board-level VIP email protection, ransomware mention tracking, brand-targeting NRD detection, and critical CVE pipelines, plus provider-agnostic incident response playbooks ready to plug into any SOC stack.
Darktrace — Populates Darktrace Model Breaches and AI Analyst Events in Cortex XSOAR, allowing for cross-platform automated investigation and response.
DarktraceASM — Populates Darktrace ASM Risks in Cortex XSOAR, allowing for cross-platform automated investigation and response.
DataBee — Use DataBee pack to retrieve information from DataBee, including findings, users, and devices.
Datadog Cloud SIEM — Datadog Cloud SIEM is a scalable, cloud-native SIEM that analyzes telemetry from cloud and on-premises systems to surface actionable security signals, with out-of-the-box detection rules and dashboards to help teams investigate and respond faster.
Dataminr Pulse — Dataminr Pulse's AI-powered, real-time intelligence integrates into Cortex XSOAR workflows for faster detection and response.
DeepInstinct — At Deep Instinct, we prevent what others can't find.
DeepL — Uses DeepL (https://www.deepl.com/) to translate text or files
Default — Got a unique incident? This Content Pack helps you automate the core steps of enrichment and severity calculation for any kind of incident.
Delinea Account Lifecycle Manager — Formerly known as "Thycotic Account Lifecycle Manager", Delinea Account Lifecycle Manager automates and streamlines service account governance to control service account sprawl.
Delinea DevOps Secrets Vault — This integration pack helps you retrieve the data stored in the Delinea DevOps Storage Vault and use it in other integrations.
Delinea Secret Server — Secure privileges for service, application, root and administrator accounts across your enterprise.
Dell EMC Unity — Dell EMC Unity is a mid-range storage array product line that offers both hybrid and all-flash models, designed for affordable all-flash performance solutions or cost-effective hybrid solutions, supporting various protocols and use cases.
Device Security by Palo Alto Networks — Collects Palo Alto Networks Device Security alerts and vulnerabilities in Cortex XSOAR, applies RACI-based triage guidance, and supports ServiceNow ticket creation and status-based incident closure workflows.
Devo — Use the Devo integration to query Devo for alerts, lookup tables, and to write to lookup tables.
Dig (Deprecated) — Deprecated. Dig script moved to CommonScripts pack.
Digital Defense Frontline VM — Use the Digital Defense Frontline VM to identify and evaluate the security and business risks of network devices and applications deployed as premise, cloud, or hybrid network-based implementations.
Dnstwist — Use the DNSTwist integration to detect typosquatting, phishing, and corporate espionage.
Docusign — The Docusign pack for Cortex XSIAM allows you to collect and analyze security and audit events from your Docusign account. This provides visibility into user logins, document actions, and administrative changes to help you detect threats and ensure compliance.
DomainTools Iris Detect — Iris Detect protects against malicious domains impersonating your brands and supply chain.
DomainTools Iris Investigate — Facilitates automation of key infrastructure characterization and hunting portions of the incident response process. Organizations will have access to essential domain profile, web crawl, SSL, and infrastructure data from within Cortex XSOAR. Requires a DomainTools Iris Investigate API key.
Doppel — This Content pack for Doppel mirrors the alerts created by Doppel as XSOAR incidents. The pack also contains the commands to perform different operations on Doppel alerts.
Dragos Platform — The Dragos Platform offers customers visibility into their ICS/OT assets, vulnerabilities, threats, and response actions.
Dragos Worldview — The pack contains an integration that pulls from the Dragos Worldview API. The integration can be configured to fetch report as incidents. The integration has commands which can pull the indicators related to a report and any files associated with the report in the API.
Drift — Drift Pack containing integrations with the Drift API
Dropbox — Use the Dropbox integration to fetch events
Druva — Centrally orchestrate ransomware response and recovery via API integrations and automated playbooks. This content pack will empower you to get back to normal faster after security incidents such as insider threats and ransomware attacks.
DuoAuth — The Duo Auth API lets developers integrate with Duo Security's platform at a low level. Must have access to the auth api in order to use this
EDL Monitor — This content pack can monitor EDL contents a by emailing the content of an EDL as a zipped file to a specified user at an interval (simply configure a job to run the playbook included), and/or simply monitor the EDL for availability and email the user if the EDL is not available
ETD XSOAR Connector — Cisco Email Threat Defense (ETD) Connector fetches message events and creates incidents, allowing analysts to reclassify email verdicts and perform remediation actions.
EWS Mail Sender — Exchange Web Services and Office 365 Email Sender. Note: this Integration supports Office 365 basic authentication only. If you are using Office 365, we recommend using the EWS O365 Integration instead, which supports modern authentication (oauth2).
EasyVista — EasyVista Service Manager manages the entire process of designing, managing and delivering IT services.
EclecticIQ Platform — Threat Intelligence Platform that connects and interprets intelligence data from open sources, commercial suppliers and industry partnerships.
Edgescan — Cloud-based continuous vulnerability management and penetration testing solution.
Elasticsearch — Search for and analyze data in real time.
Supports version 6 and later.
Elasticsearch Monitoring — Elasticsearch and OpenSearch monitoring dashboard and widgets tracking statistics and cluster status.
Email Communication — Do you have to send multiple emails to end users? This content pack helps you streamline the process and automate updates, notifications and more.
Email Hippo — Use this tool to verify email sources as fake emails that were used as part of phishing attacks.
EmailRepIO — Provide email address reputation and reports from EmailRep.io.
Employee Offboarding — There’s a multitude of tasks to offboard an employee. So let us help you streamline the process and complete that checklist with this Content Pack.
Endace — This integration uses Endace APIs to search, archive and download PCAP file from either a single EndaceProbe or many via the InvestigationManager and enables integration of full historical packet capture into security automation workflows
Endgame — Endpoint protection built to stop advanced attacks before damage and loss occurs
Envoy — Envoy is offering an enterprise workplace visitor management software platform.
European Union Vulnerability Database — The European Union Vulnerability Database (EUVDB) is a vulnerability database that provides information about vulnerabilities in software and hardware products. It is maintained by the European Union Agency for Cybersecurity (ENISA) and is intended to help organizations identify and mitigate vulnerabilities in their systems.
Exabeam Advanced Analytics — The Exabeam Security Management Platform provides end-to-end detection, User Event Behavioral Analytics, and SOAR.
ExabeamDataLake — Exabeam Data Lake provides a highly scalable, cost-effective, and searchable log management system. Data Lake is used for log collection, storage, processing, and presentation.
Exceed LMS — A specialized LMS and Phishing Simulator created to manage security awareness content for small, medium and large enterprise organizations.
Exchange 2016 Compliance Search — Exchange Server 2016 Compliance Search enables you to search for and delete an email message from all mailboxes in your organization.
Exodus Intelligence EVE Platform — Built on original research from some of the best reverse engineers in the world as well as cutting edge machine learning technology, [Exodus Intelligence’s EVE](https://vpx.exodusintel.com) platform provides deep intelligence about the latest vulnerabilities. This integration allows Cortex XSOAR users to add context regarding the nature of vulnerabilities and their likelihood to be exploited in the wild, identify platforms on which given vulnerabilities exist and have been verified to be exploitable, update incidents with specific mitigation guidance, and much more.
Exterro/AccessData — Use the Exterro package to integrate with the Exterro FTK Suite, enabling the playbook automation of incident response workflows upon detection of a possible threat.
ExtraHop Reveal(x) — Network detection and response. Complete visibility of network communications at enterprise scale, real-time threat detections backed by machine learning, and guided investigation workflows that simplify response.
F5 APM — F5 BIG-IP Access Policy Manager (APM) is a secure, flexible, high-performance access management proxy solution managing global access to your network, the cloud, applications, and application programming interfaces (APIs).
F5 ASM — Modeling Rules for the F5 ASM logs collector
F5 BIG-IP Advanced WAF — Used for protecting applications with behavioral analytics, layer 7 DoS mitigation, application-layer encryption of sensetive data, threat intelligence services and API security.
F5 LTM — You can use this pack to automate traffic management use cases in integration with F5 Local Traffic Manager (LTM), the integration with F5 LTM included with the pack comes with several commands to get LTM information about nodes, pools and pool members, along with that some of those commands can be used to automate remediation actions such as disabling an active node.
F5 Silverline — An integration with F5 Silverline to retrieve alerts and read/update IP lists.
Fidelis Elevate Network — Automate Detection and Response to Network Threats and data leakage in your organization with Fidelis Elevate Network Integration.
FireEye Central Management — FireEye Central Management (CM Series) is the FireEye threat intelligence hub. It services the FireEye ecosystem, ensuring that FireEye products share the latest intelligence and correlate across attack vectors to detect and prevent cyber attacks
FireEye Common Fields — FireEye common fields concentrates all of the mutual content entities for the FireEye integrations.
FireEye Email Security (EX) — FireEye Email Security series protects against breaches caused by advanced email attacks.
FireEye Feed — FireEye indicators and reports feed for Cortex XSOAR TIM
FireEye HX — FireEye Endpoint Security is an integrated solution that detects and protects endpoints against known and unknown threats. The FireEye HX Cortex XSOAR integration provides access to information about endpoints, acquisitions, alerts, indicators, and containment. Customers can extract critical data and effectively operate the security operations automated playbooks.
FireEye Helix — FireEye Helix is a security operations platform. FireEye Helix integrates security tools and augments them with next-generation SIEM, orchestration and threat intelligence tools such as alert management, search, analysis, investigations and reporting.
FireEye Network Security (NX) — FireEye Network Security is an effective cyber threat protection solution that helps organizations minimize the risk of costly breaches by accurately detecting and immediately stopping advanced, targeted, and other evasive attacks hiding in Internet traffic.
Forcepoint Email Security — Provides protection and filtering capabilities of inbound and outbound traffic for email systems.
Forcepoint Secure Web Gateway — Forcepoint Secure Web Gateway is an advanced web security solution that protects organizations from online threats and enforces web usage policies. It offers web filtering, malware protection, data loss prevention, and secure web access.
Forcepoint Security Management Center — Forcepoint SMC provides unified, centralized management of all models of Forcepoint engines whether physical, virtual or cloud—across large, geographically distributed enterprise environments.
FortiSIEM — Search and update events of FortiSIEM and manage resource lists.
FortiSandbox — FortiSandbox is an advanced security tool that goes beyond standard sandboxing. It combines proactive mitigation, enhanced threat detection, and in-depth reporting, using Fortinet's dynamic antivirus technology, dual-level sandboxing, and FortiGuard cloud integration to counter advanced threats. It effectively detects viruses, Advanced Persistent Threats (APTs), and malicious URLs, integrating seamlessly with existing Fortinet devices like FortiGate and FortiMail for comprehensive network protection.
Fortimail — FortiMail is a comprehensive email security solution by Fortinet, offering advanced threat protection, data loss prevention, encryption, and email authentication to safeguard organizations against email-based cyber threats and protect sensitive information.
Fortinet Fortiweb — The Fortiweb integration manages WAF policies and blocks cookies, URLs, and hostnames.
Forward XSOAR Audit Logs to Splunk HEC — This automation script takes a timeframe as input fetches the audit logs for the defined period. Then it pushes them to Splunk HEC.
ForwardAuditLogsToSplunkHEC — This pack allows you to setup a job to forward audit logs from XSOAR to Splunk HEC. This requires a Core REST API instance and Splunk Py instance.
FraudWatch PhishPortal — FraudWatch International provides anti-phishing and online brand protection solutions.
Free Enrichers — This content Pack helps set up free enrichers (Plug & Enrich, Free with sign-up) available for TIM
Free Feeds — This content Pack helps set up free feeds (Plug & Fetch, Free with signup and Generic) available for TIM
Freshdesk — The Freshdesk integration allows you to create, update, and delete tickets; reply to and create notes for tickets as well as view Groups, Agents and Contacts.
Freshworks Freshservice — Freshservice is a service management solution that allows customers to manage service requests, incidents, change requests tasks, and problem investigation.
FullHunt — Integration with FullHunt, the attack surface database of the internet.
FullHunt enables companies to discover all of their attack surfaces, monitor them for exposure, and continuously scan them for the latest security vulnerabilities.
G Suite Admin — G Suite Admin integration with Cortex XSOAR. G Suite or Google Workspace Admin is an integration to perform an action on IT infrastructure, create users, update settings, and more administrative tasks.
G Suite Security Alert Center — Fetch alert types, delete or recover alerts, retrieve an alert's metadata, and create or view alert feedback.
GCP — Manage and secure your Google Cloud Platform (GCP) environment from Cortex. This pack lets you automate cloud operations across GCP services.
GCP IAM — Manage identity and access control for Google Cloud Platform resources.
GDPR — This Content Pack helps you facilitate the breach notification process according to the GDPR requirements, in response to a data breach incident.
GDPR Compliance — Ensure your organization is following GDPR guidelines with the relevant dashboard and report evidence.
GLIMPS Detect — This Content Pack is used to create an XSOAR integration for GDetect. Thanks to this integration, submit files to GLIMPS Malware and identify instantly malware and ransomware. Get detailed and contextualized threat information by switching to the GLIMPS Malware Expert interface easily
GZip — Use this pack to zip and unzip files with GZip.
Gamma — Streamline discovery, classification and remediation of data loss instances across Enterprise SaaS applications (Slack, Jira, Github, Gdrive, Gmail, O365, etc.). Playbook engages with users while simultaneously allowing the Security team to instantly investigate and/or automatically remediate.
Gatewatcher AionIQ — This pack provide integration with Gatewatcher NDR solution : AIonIQ
Gem — Integrate with Gem to use alerts as a trigger for Cortex XSOAR’s custom playbooks, and automate response to specific TTPs and scenarios.
Generic API Call — Content pack to enable execution of generic API calls to a variety of endpoints outside the scope of other integrations
Generic Export Indicators Service — Use this pack to generate a list based on your Threat Intel Library, and export it to any product in your network, such as firewalls, agents or SIEMs. This pack supports ongoing distribution of indicators from XSOAR to other products in the network, by creating an endpoint with a list of indicators that can be pulled by external vendors.
Generic MCP — This content pack provides a generic integration with Model Context Protocol (MCP) servers. By connecting to any external MCP server, the system automatically discovers the tools exposed by that server and generates corresponding agentic system actions, enabling Cortex agents to immediately use new capabilities without manual configuration.
Generic Webhook — Simplify data ingestion without an API. Connect to diverse services and create incidents from webhooks with a quick, flexible setup.
Generic Webhook (Form Data) — A version of the Generic Webhook integration that accepts a form data body. Note: raw_json field is required.
GenericAPIEventCollector — This pack provides a generic API event collector integration that can be used to collect events from various sources.
GenericSQL — Connect and execute sql queries in 5 Databases: MySQL, PostgreSQL, Microsoft SQL Server, Oracle and Teradata
Genesys Cloud — Genesys Cloud is a unified, all-in-one cloud collaboration and contact center platform that provides customer interaction and operational audit event data.
Getting Started with XSOAR — This wizard is designed to provide a step-by-step walkthough on getting started with XSOAR
Gigamon ThreatINSIGHT — Gigamon ThreatINSIGHT allows a fast detection and effective response to active threats.
Giphy — Display random GIF in the War Room (e.g. !giphy hello). Powered By Giphy.
GitGuardian — GitGuardian is a developer-first solution scanning GitHub activity in real-time for API secret tokens, database credentials, certificates.
GitHub — Manage GitHub issues and pull requests directly from Cortex XSOAR
GitHub Feed — A feed to ingest indicators of compromise (IOCs) from Github repositories. The feed supports general IOC extraction, STIX data ingestion, and out-of-the-box parsing of YARA rules.
GitHub MCP — Integrate with GitHub via the Model Context Protocol (MCP) server to automate GitHub operations.
Github Maltrail Feed — Maltrail is a malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails, along with static trails compiled from various AV reports and custom user defined lists, where trail can be anything from domain name (e.g. zvpprsensinaix.com for Banjori malware), URL (e.g. hXXp://109.162.38.120/harsh02.exe for known malicious executable), IP address (e.g. 185.130.5.231 for known attacker) or HTTP User-Agent header value (e.g. sqlmap for automatic SQL injection and database takeover tool). Also, it uses (optional) advanced heuristic mechanisms that can help in discovery of unknown threats (e.g. new malware).
https://github.com/stamparm/maltrail
Gmail — Gmail API and user management (This integration replaces the Gmail functionality in the GoogleApps API and G Suite integration).
Google Apigee Edge — Apigee is Google Cloud's native API management platform that can be used to build, manage, and secure APIs — for any use case, environment, or scale. Apigee offers high performance API proxies to create a consistent, reliable interface for your backend services. The proxy layer gives you granular control over security, rate limiting, quotas, analytics, and more for all of your services.
Apigee supports REST, gRPC, SOAP, and GraphQL, providing the flexibility to implement any API architectural style.
Google BigQuery — Integration for Google BigQuery, a data warehouse for querying and analyzing large databases. In all commands, for any argument not specified, the BigQuery default value for that argument will be applied.
Google Calendar — Google Calendar integration with Cortex XSOAR.
Google Chat via Webhook — Integration for sending notifications to a Google Chat Space via incoming webhook
Google Chrome — The official browser from Google. Chrome is a cross-platform web browser which brings you the best of Google.
Google Cloud Compute — Google Compute Engine delivers virtual machines running in Google's innovative data centers and worldwide fiber network. Compute Engine's tooling and workflow support enable scaling from single instances to global, load-balanced cloud computing.
Google Cloud Logging — Google Cloud Logging is a managed logging solution provided by Google Cloud Platform (GCP) that allows users to collect, store, search, analyze, and monitor logs generated by GCP services, third-party applications, and custom applications running on GCP.
Google Cloud Pub / Sub — Google Cloud Pub / Sub is a fully-managed real-time messaging service that allows you to send and receive messages between independent applications.
Google Cloud SCC — This pack leverages the features of Google Cloud Security to provide an organization-wide framework for detection and response.
Google Cloud Storage — Google Cloud Storage is a RESTful online file storage web service for storing and accessing data on Google Cloud Platform infrastructure.
Google Docs — Use the Google Docs integration to create and modify Google Docs documents.
Google Dorking — Automate the process of google dorking searches in order to detect leaked data.
Google Drive — Google Drive allows users to store files on their servers, synchronize files across devices, and share files. This integration helps you to create a new drive, query past activity and view change logs performed by the users, as well as list drives and files, and manage their permissions.
Google Drive (Standard Connector) — Satellite pack of Google Drive used for the Standard Connector deployment. Shares core logic with the Google Drive pack via the GoogleDriveApiModule.
Google Gemini — Leverage Google's advanced AI models for intelligent analysis, content generation, and conversational capabilities in your workflows.
Google IP Ranges Feed — Use the Google IP Ranges Feed integration to get GCP and Google global IP ranges.
Google Key Management Service — Use the Google Key Management Service API for CryptoKey management and encrypt/decrypt functionality.
Google SecOps — Retrieve Google SecOps detections, impacted assets, IOC matches, and 3P alerts to enrich your XSOAR workflows.
Google Sheets — The Google Sheets API is a RESTful interface that lets you read and modify a spreadsheet's data. The most common uses of this API include the following tasks- create spreadsheets, read and write spreadsheets cells, update spreadsheet formatting
Google Vault — Archiving and eDiscovery for G Suite.
Google Vertex AI — Fine-tuned to conduct natural conversation. Using Google Vertex Ai (PaLM API for Chat) The current integration of Google Vertex Ai is focusing only on the Generative AI model (PaLM) using the Chat prediction. Later, this plugin will be updated to include the following:
- Model Creation
- Model Fine Tuning
- PaLM for Text
GoogleThreatIntelligence — Analyzes suspicious hashes, URLs, domains, and IP addresses, and fetch incidents as DTM Alerts or ASM Issues from the Google Threat Intelligence platform.
Gophish — Gophish is a powerful, open-source phishing framework that makes it easy to test your organization's exposure to phishing.
Grafana — Grafana client to interact with Grafana server API.
GraphQL — Generic GraphQL client to interact with any GraphQL server API.
GravityZone — Retrieve security events and threats from GravityZone and manage the incident response
GreatHorn — The only cloud-native security platform that stops targeted social engineering and phishing attacks on cloud email platforms like Office 365 and G Suite.
GreyNoise — GreyNoise is a threat intelligence service that collects and analyzes Internet-wide scan and attack traffic. With this integration, users can contextualize existing alerts, filter false-positives, identify compromised devices, and track emerging threats. The full integration code can be found here: https://github.com/demisto/content/tree/master/Packs/GreyNoise
GreyNoise Indicator Feed — This content pack fetches IPv4 Internet Scanner indicators from GreyNoise.
Group-IB Digital Risk Protection — Group-IB Digital Risk Protection (DRP) is a cloud-based solution that continuously monitors online channels for brand abuse, scams, phishing, and other digital threats. It leverages machine learning and human analysis to detect the illegitimate use of logos, trademarks, and content across websites, social media, dark web, and more. The platform not only identifies incidents (called violations) in real-time, but also classifies and scores each violation to determine its severity, thereby prioritizing those that require urgent action. DRP implements a rigorous three-stage takedown process to maximize the elimination of confirmed threats like scam sites and phishing pages. This package includes several incident types, a classifier and mapper, a dedicated layout, and automation for updating received violations. A playbook is also provided to help you respond to violations more efficiently.
Group-IB Threat Intelligence — Group-IB Threat Intelligence is a system for analyzing and attributing cyberattacks, threat hunting, and protecting network infrastructure based on data relating to adversary tactics, tools, and activity. Use this pack to fast receive incidents related to you, attribute them to adversaries to do instant response, enrich your security with an enormous IOCs collection, and provide possibilities for manual investigation through Group-IB data via Cortex XSOAR interface.
GsuiteAuditor — G Suite Auditor integration with Cortex XSOAR. G Suite Auditor is an integration to recieve audit log data from G Suite services like drive,gmail and more. The integration uses Google Admin SDK
Guidance Encase Endpoint — Use the Enterprise Service Bus (ESB) to request scans of specified endpoints.
Gurucul Risk Analytics — Gurucul Risk Analytics (GRA) is a Unified Security and Risk Analytics platform.
HCL BigFix — HCL BigFix Patch provides an automated, simplified patching process that is administered from a single console.
HIPAA - Breach Notification — This Content Pack helps you streamline and automate the repetitive tasks associated with HIPAA breach notifications incidents.
HIPAA Compliance — Ensure your organization is following HIPAA guidelines with the relevant dashboard and report evidence.
HPE Aruba Central — Aruba Central helps manage and monitor your network infrastructure from a centralized platform.
HPE Aruba Clearpass — Aruba ClearPass Policy Manager provides role and device-based network access control for employees, contractors, and guests across any multivendor wired, wireless and VPN infrastructure.
HPE Switch — HPE (Hewlett Packard Enterprise) switches offer enterprise-grade networking solutions with flexibility, scalability, and robust security features. They provide essential enterprise features like VLAN support, QoS, and IPv4/IPv6 routing, ensuring efficient performance and management.
HYAS Insight — Use the HYAS Insight integration to interactively lookup PassiveDNS, DynamicDNS, WHOIS, Sample Malware Records, C2 Attribution, Passive Hash, SSL Certificate, Open Source Indicators, Device Geo, Sinkhole, Malware Sample Information Information either as playbook tasks or through API calls in the War Room.
HYAS Protect — Use the HYAS Protect integration to get the verdict information for FQDN, IP Address and NameServer.
HackerOne — HackerOne is a vulnerability coordination and bug bounty platform that connects businesses with penetration testers and cyber-security researchers.
Hackuity — From a war-room, query your Hackuity cockpit in order to seamlessly retrieve information related to your vulnerability stock.
Halcyon — Halcyon is a device management platform that helps organizations monitor, control, and secure their network of devices. It provides centralized tools for overseeing hardware and software inventory, deploying updates, enforcing security policies, and ensuring compliance across device environments.
HarfangLab EDR — This connector allows to fetch security events and/or threats from a HarfangLab EDR Manager and manage the incident response.
HashiCorp Terraform — Hashicorp Terraform provide infrastructure automation to provision and manage resources in any cloud or data center.
HashiCorp Vault — Manage Secrets and Protect Sensitive Data through HashiCorp Vault. Ingest and normalize Vault Audit logs.
Hoxhunt — Integration with Hoxhunt to manage Hoxhunt incidents
Huawei FW — The Huawei HiSecEngine USG6500E series provides enterprise-class, next-generation firewall protection for small and medium-sized enterprises, delivering high-performance, proactive defense against advanced network threats.
Huawei Network Devices — Modeling rule for Huawei Network Devices such as S Series Switches and AR Series Access Routers.
Hudsonrock — Indicator enrichment from Hudsonrock free APIs
Humio — Instantly search live log data at scale. Create dashboards to visualize and analyze complex systems in real time
Hunting — Extracts IOCs from the incident details and attached files using regular expressions, and then hunts for hashes on endpoints using available tools.
Hybrid Analysis (Deprecated) — Deprecated. Use the CrowdStrike Falcon Sandbox v2 integration instead. Fully automated malware analysis with unique Hybrid Analysis.
IAM SCIM — Classifiers for IAM integrations that use SCIM (System for Cross-domain Identity Management).
IBM AIX — IBM Advanced Interactive eXecution (AIX) is a series of UNIX operating systems that's usually used for corporate servers, NAS and workstations.
IBM Guardium — IBM Guardiam is a family of data security software that uncovers vulnerabilities and protects sensitive on-premises and cloud data.
IBM MaaS360 Security — The IBM MaaS360 Security pack allows you to monitor security events on your IBM MaaS360 Security environment.
IBM QRadar — Fetch offenses as incidents and search QRadar
IBM Security QRadar SOAR — Case management that enables visibility across your tools for continual IR improvement
IBM Security Verify — Centralize and streamline your identity and access management processes with IBM Security Verify. This content pack provides comprehensive tools and integrations to manage and protect user identities, enforce security policies, and ensure compliance across your organization. Leverage automated workflows and API integrations to enhance your security posture and simplify identity governance and administration.
IBM Storage Scale — The IBM Storage Scale pack provides high-performance collection of Command Line Interface (CLI) audit log records. Its concurrent fetching architecture is engineered for large-scale deployments, ensuring efficient data ingestion into Cortex XSIAM. It enables monitoring of critical configuration changes and user commands to enhance the security of the storage infrastructure.
IBM X-Force Exchange — IBM X-Force Exchange lets you receive threat intelligence about applications,
IP addresses, URls and hashes
IP-API — Integrate with the IP-API.com IP enrichment service.
IP2LocationIO — IP2Location.io API integration to query IP geolocation.
IPQualityScore (IPQS) Threat Risk Scoring — Provides IPQualityScore threat and reputation intelligence for risk scoring and enrichment of ip, phone, email, URL, and file indicators.
IRIS DFIR — IRIS is a collaborative platform aiming to help incident responders to share technical details during investigations.
ISO 27001 Compliance — Ensure your organization is following ISO 27001 guidelines with the relevant dashboard and report evidence.
Icebrg — Reduces risk by accelerating threat detection, triage, and response to rapidly-evolving breaches across global networks.
Identity — Base pack for any packs using identity fields.
Illumio Rapid Ransomware Containment — Provides integrations and playbooks to interact with Illumio Core APIs and automate network security tasks
Illusive Networks — Enrich SOC incident triage and investigation data with valuable Illusive information and forensics, and manage the way Illusive deploys deceptions across the network.
Imperva Skyfence — The Imperva Skyfence Cloud Gateway is a Cloud Access Security Broker (CASB) that provides visibility and control over sanctioned and unsanctioned cloud apps to enable their safe and productive use.
Imperva WAF — Use the Imperva WAF integration to manage IP groups and Web security policies in Imperva WAF.
Impossible Traveler — Catch the impossible traveler. This Content Pack helps you quickly determine the legitimacy of remote access attempts and contain malicious activity.
Indeni — Indeni is a turn-key automated monitoring providing visibility for security infrastructure. Indeni's production-ready Knowledge is curated from vetted, community-sourced experience, to deliver automation of tedious tasks with integration with your existing processes.
display: Indeni
Infinipoint — Use the Infinipoint integration to retrieve security and policy incompliance events, vulnerabilities or incidents. Investigate and respond to events in real-time
InfoArmor VigilanteATI — VigilanteATI redefines Advanced Threat Intelligence. InfoArmor's VigilanteATI platform and cyber threat services act as an extension of your IT security team.
Infoblox NIOS — Infoblox NIOS is a comprehensive solution that consolidates DNS, DHCP, and IP address management into a single platform. It is designed to simplify network management by automating these critical functions and providing a centralized console for managing them.
Infoblox Threat Defense with DDI — Utilize the Infoblox Threat Defense with DDI integration to manage SOC Insight incident response, indicator enrichment, and block cyber threats.
Infocyte — Infocyte detection and response platform integration for conducting agentless (non-persistent) or agented detection, hunting, triage and forensic analysis of endpoints
Integrations & Incidents Health Check — Do you know which of your integrations or open incidents failed? With this content, you can view your failed integrations and open incidents
Intel471 Feed — This content pack fetches actor and malware related indicators from Intel 471. It also fetches watcher alerts.
Intezer — Malware detection and analysis based on code reuse
Inventa — Handling DSAR reporting within Inventa Instance, including PII categories found, storages with data related to the PII etc.
IoT 3rd Party Integrations by Palo Alto Networks (Deprecated) — Deprecated. Palo Alto Networks IoT 3rd Party Integrations. Here is the document on how to get the latest Palo Alto Networks IoT 3rd Party Integrations Content Pack https://docs.paloaltonetworks.com/iot/iot-security-integration/get-started-with-iot-security-integrations/third-party-integrations-using-a-full-featured-xsoar-server
Ipinfo — Use the ipinfo.io API to get data about an IP address
Ipstack — One of the leading IP to geolocation APIs and global IP database services.
IronNet — The IronDefense Integration allows users to interact with IronDefense alerts within Demisto. The Integration provides the ability to rate alerts, update alert statuses, add comments to alerts, and to report observed bad activity.
Ironscales — IRONSCALES is a self-learning email security platform, automatically responding to malicious emails.
Ironscales Event Collector — IRONSCALES is a self-learning email security platform, automatically responding to malicious emails.
Ivanti Critical Vulnerabilities — This pack handles CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, and CVE-2024-21893 - Ivanti critical vulnerabilities
Ivanti Heat — Use Ivanti Heat integration to manage issues and create Demisto incidents from ivanti.
Ivanti Pulse Secure VTM — The Pulse Secure Virtual Traffic Manager (VTM) provides application-centric traffic management and load balancing solutions in a range of software, appliance-ready, virtual appliance, and cloud-compute product variants.
JARM — This pack introduces the JARM indicator type and commands for generating new JARM fingerprints of servers using TLS.
Keeper Secrets Manager — Use Secrets Manager to manage secrets and protect sensitive data through Keeper Vault.
Keeper Security — Use Keeper Security to manage and extract data regarding your Keeper Security products.
Kenna — Use the Kenna v2 integration to search and update vulnerabilities, schedule a run connector, and manage tags and attributes.
Keyfactor — Basic Keyfactor Integration that Posts CSR and Retrieves the certificates.
Kibana — This integration enables using Elastic Security for SIEM for security operations management and searching Elastic logs. This pack is to be used in combination with the Elasticsearch v2 integration.
Kiteworks — The Kiteworks platform unifies, tracks, controls, and secures sensitive content communications.
Koodous — Check Android app samples (APK) against Koodous API
Kubernetes — An open-source container orchestration platform that automates deploying, managing and scaling containerized applications.
LINENotify — LINE API Integration is used for sending a message to LINE Group.
LOLBAS Feed — "Living off the land binaries" is a term used to describe malware or hacking techniques that take advantage of legitimate tools.
LSASS Credential Dumping — Credential Dumping is an attack technique where attackers extract user authentication credentials such as usernames and passwords. When users log on to a system, the credentials get stored in the memory process Local Security Authority Subsystem Service (LSASS). Both administrative users and SYSTEM can harvest these credentials. This attack is only possible because operating systems store credentials in memory to save users from having to enter credentials whenever they want to use a service.
Lacework — Lacework provides end-to-end cloud security automation for AWS, Azure, and GCP with a comprehensive view of risks across cloud workloads and containers.
Lansweeper — Lansweeper content pack allows users to search specific assets, providing detailed information about each asset such as it’s type, operating system, serial number and much more contextual information.
LastInfoSec — This integration allows to interact with the LastInfoSec API
Lastline — Use the Lastline v2 integration to provide threat analysts and incident response teams with the advanced malware isolation and inspection environment needed to safely execute advanced malware samples, and understand their behavior.
LenelS2 NetBox — browser-based access control and event monitoring system
Linkshadow — Fetch Network Anomalies data from LinkShadow and execute the remediation Actions.
Linux Events Collection — Linux is an operating system for servers, desktops, cloud, and IoTs
Lockpath Keylight — Use the LockPath KeyLight integration to manage GRC tickets in the Keylight platform.
LogPoint SIEM Integration — Use this Content Pack to fetch incident logs from LogPoint, analyze them for underlying threats, and respond to these threats in real-time.
Logsign SIEM — Logsign SIEM provides to collect and store unlimited data, investigate and detect threats, and respond automatically.
Logz.io — Logz.io Package to fetch alerts from logz.io and threat hunting
Looker — Use the Looker integration to query an explore, save queries as looks, run looks, and fetch look results as incidents.
Lookout Mobile Endpoint Security (MES) — Lookout Mobile Endpoint Security (MES) provides visibility and protection against mobile threats with AI-driven mobile security dataset.
Lost / Stolen Device — Looking to reduce the multiple triage, response and mitigation steps involved in handling lost/stolen devices? We’ve got just the Content Pack for you!
Luminar IOCs & leaked credentials — This connector allows integration of intelligence-based IOC data and customer-related leaked records identified by Luminar
Luminate (Deprecated) — Deprecated. No available replacement. Enrich your report and Respond to incidents with Luminate
Lumu — SecOps operation, reflect and manage the Lumu Incidents either from XSOAR Cortex or viceversa using the mirroring integration flow
MAC Vendors — Query MAC Vendor's list of registered MAC and vendor names via their API
MISP — Malware information and threat sharing platform.
MISP Threat Actors — This pack downloads and parses the MISP threat actor galaxy into XSOAR TIM.
MITRE ATT&CK — Fetches indicators from MITRE ATT&CK.
MITRE ATT&CK - Courses of Action — Looking for actionable intelligence? This intelligence-driven Pack provides manual or automated remediation of MITRE ATT&CK techniques.
MITRE Caldera — Interact with MITRE Caldera via the v2 API.
MS-ISAC — This content pack's purpose is to integrate with the MS-ISAC private API to fetch MS-ISAC events and alert details.
MacOS — The operating system the powers every Mac device. A Unix operating system developed and marketed by Apple.
Machine Learning — Help to manage machine learning models in Cortex XSOAR
Magnet Forensics — Magnet Automate is a workflow orchestration platform by Magnet Forensics that automates digital forensic investigations. This pack enables Cortex XSOAR to integrate with Magnet Automate to manage cases, start and monitor workflow runs against evidence sources, manage processing nodes, and control forensic workflows — all through the Magnet Automate REST API.
Mail Listener — Listen to a mailbox, enable incident triggering via e-mail
Mail Sender (New) — Send emails implemented in Python with embedded image support
MailListener - POP3 — Listen to a mailbox, enable incident triggering via e-mail
Majestic Million Feed — Use the Majestic Million pack to ingest the top known websites as 'good' indicators.
Maltiverse — Maltiverse helps you to analyze suspicious hashes, URLs, domains, and IP addresses.
Malware Core — Supporting pack for the Malware Investigation & Response pack.
Malware Investigation and Response — Accelerate the investigation of your endpoint malware alerts and incidents and trigger containment activities quickly.
MalwareBazaar — MalwareBazaar offers an API to download malware samples, comment malware samples, and obtain intel based on file hash, tag, signature, file type, etc.
MalwareBazaar Feed — MalwareBazaar is a project from abuse.ch with the goal of sharing malware samples with the infosec community, AV vendors and threat intelligence providers.
ManageEngine — ManageEngine Endpoint Central is a Unified Endpoint Management solution that helps in managing thousands of servers, desktops, laptops and mobile devices from a single console.
ManageEngine ADAudit Plus — ADAudit Plus helps keep your Windows Server ecosystem secure and compliant by providing full visibility into all activities.
ManageEngine ADManager Plus — An Active Directory (AD) management and reporting solution that allows IT administrators and technicians to manage AD objects easily and generate instant reports at the click of a button.
ManageEngine ADSelfService Plus — ManageEngine ADSelfService Plus is an identity security solution with adaptive MFA, SSO, and password management capabilities.
ManageEngine_PAM360 — PAM360 integrates with Cortex XSOAR that fetches passwords directly from the PAM360 vault to use in their tasks.
McAfee Database Security — McAfee Database Security is a software solution that monitors the Database Management System (DBMS) and protects it from internal and external threats and intra database exploits.
McAfee ESM — Run queries and receive alarms from Intel Security ESM.
Menlo Security — The cloud-based Menlo Security Isolation Platform (MSIP) eliminates the possibility of malware reaching user devices via compromised or malicious Web sites, Email or documents.
MicroFocus SMAX — You can use this pack to fetch SMAX incidents/requests and automate different sort of actions
Microsoft 365 Defender — Microsoft Defender XDR (formerly Microsoft 365 Defender) is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks.
Microsoft Azure AD Connect Health Feed — Indicator feed from Microsoft Azure AD Connect Health endpoints, fetching URLs and DomainGlobs used by Azure AD, with which you can create a list (allowlist, EDL, etc.) for your SIEM or firewall service to ingest and apply to its policy rules.
Microsoft DHCP — Dynamic Host Configuration Protocol (DHCP) is a client/server protocol that automatically provides an Internet Protocol (IP) host with its IP address and other related configuration information such as the subnet mask and default gateway.
Microsoft DNS — The Microsoft Domain Name Server (DNS) produces audit logs that identify resources from your company that are connected to the internet or your private network, and translate domain names to IP addresses.
Microsoft Defender for Cloud — Unified security management and advanced threat protection across hybrid cloud workloads.
Microsoft Defender for Cloud Apps — Microsoft Cloud App Security Integration, a Cloud Access Security Broker that supports various deployment modes
Microsoft Defender for Endpoint — Microsoft Defender for Endpoint (previously Microsoft Defender Advanced Threat Protection (ATP)) is a unified platform for preventative protection, post-breach detection, automated investigation, and response.
Microsoft Defender for Identity — A cloud-based security solution that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.
Microsoft Endpoint Configuration Manager — The configuration manager provides the overall Configuration Management (CM) infrastructure and environment to the product development team (formerly known as SCCM).
Microsoft Graph API — Use the Microsoft Graph API integration to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSOAR, for example, Mail Single-User, etc.
Microsoft Graph Files — Use the O365 File Management (Onedrive/Sharepoint/Teams) integration to enable your app get authorized access to files in OneDrive, SharePoint, and MS Teams across your entire organization. This integration requires admin consent.
Microsoft Graph Files (Standard Connector) — Satellite pack of Microsoft Graph Files used for the Standard Connector deployment. Shares core logic with the Microsoft Graph Files pack via the MicrosoftGraphFilesApiModule.
Microsoft Graph Groups — Microsoft Graph Groups enables you to create and manage different types of groups and group functionality according to your requirements.
Microsoft Graph Mail — Microsoft Graph enables authorized access to a user’s Outlook mail data in personal or organizational accounts.
Microsoft Graph Mail Single User — Microsoft Graph grants Demisto authorized access to a user's Microsoft Outlook mail data in a personal account or organization account.
Microsoft Graph Search — Use the Microsoft Search API in Microsoft Graph to search content stored in OneDrive or SharePoint: files, folders, lists, list items, or sites.
Microsoft Graph Security — Unified gateway to security insights - all from a unified Microsoft Graph
Security API.
Microsoft Graph Teams (Standard Connector) — Satellite pack of Microsoft Graph Teams used for the Standard Connector deployment. Shares core logic with the Microsoft Graph Teams pack via the MicrosoftGraphTeamsApiModule.
Microsoft Graph User — Use the Microsoft Graph integration to connect to and interact with user objects on Microsoft Platforms.
Microsoft IIS Web Server — The Microsoft IIS Web Server pack parses IIS logs and normalizes them to the Cortex Data Model (XDM) schema.
Microsoft Intune — Microsoft Intune is a family of endpoint management solutions that enable you to protect and administer all your endpoints from a single place.
Microsoft Sentinel — Microsoft Sentinel is a cloud-native security information and event manager (SIEM) platform that uses built-in AI to help analyze large volumes of data across an enterprise.
Microsoft Sysmon — System Monitor (Sysmon) is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event log.
Microsoft Teams — Send messages and notifications to your team members.
Microsoft Windows AMSI — The Windows Antimalware Scan Interface (AMSI) is a security feature in Windows OSs that allows services to scan for files, memory and other data for threats.
Microsoft Windows Event Logs — The Windows event log is a detailed record of system, security and application notifications stored by the Windows operating system.
MicrosoftGraphTeams — O365 Teams (Using Graph API) gives you authorized access to a user’s Teams enabling you to facilitate communication through teams as that user, or read conversations and/or messages of that user.
MicrosoftWSUS — Modeling Rules for the Microsoft WSUS logs collector
Mimecast — Mimecast unified email management offers cloud email services for email security, continuity and archiving emails.
Minerva Labs Anti-Evasion Platform — Minerva eliminates the endpoint security gap while empowering companies to embrace technology fearlessly.
MobileIron-UEM — This MobileIron UEM Content Pack enables fetching device data and incidents from both MobileIron Core and Cloud. The integration, apart from providing custom commands helpful when doing data enrichment, includes sample playbooks and an incident layout to help analyst investigations
Monday — Integrates with Monday.com to collect activity logs and audit logs.
MongoDB — Use the MongoDB integration to search and query entries in your MongoDB.
MongoDB Atlas — Cloud-based database service for deploying, managing, and scaling MongoDB clusters.
Multi-Tenant Performance — Provides monitoring information for Multi-Tenant hosts and HA groups. It includes information like CPU, disk, and memory usage, as well as the number of Docker containers being used.
MxToolBox — All of your MX record, DNS, blacklist and SMTP diagnostics in one integrated tool
MySQL Enterprise — The modeling rules for MySQL Enterprise event collectors.
NCSC Cyber Asssessment Framework — This pack contains an incident type and relevant fields to initiate a self-assessment against the National Cyber Security Centre's Cyber Assessment Framework.
All assessment questions are sent via e-mail and the responses also sent via e-mail. The assessments can also be answered within the Cortex XSOAR platform.
NGFW TS Agent Deployment — Deploy Palo Alto Networks NGFW Terminal Service Agents to Windows Hosts
NGINX Web Server — Modeling Rules for the NGINX Web Server logs collector
NIST — This Content Pack helps you follow the phases in handling an incident according to the NIST computer security incident handling guidelines.
NIST 800-171 Compliance — Ensure your organization is following NIST 800-171 guidelines with the relevant dashboard and report evidence.
NIST 800-53 Compliance — Ensure your organization is following NIST 800-53 guidelines with the relevant dashboard and report evidence.
NIST CSF Compliance — Ensure your organization is following NIST CSF guidelines with the relevant dashboard and report evidence.
Ncurion — Ncurion is a container-based, standardized detection engine that protects the nature of intrusion detection.
Neosec — Utilize Neosec behavioral analytics to protect your API estate from OWSP top 10 vulnerabilities and suspicious user behavior.
Nessus — Vulnerability scanner for auditors and security analysts by Tenable Network Security
NetBox — This is the NetBox event collector integration for XSIAM
NetQuest OMX — NetQuest’s products are high-capacity service nodes that help security teams access and analyze network traffic. Powerful packet & flow processing features assist security tools in detecting and mitigating security threats as cost effectively as possible.
NetWitness — NetWitness Platform provides systems Logs, Network, and endpoint visibility for real-time collection, detection, and automated response with the Demisto Enterprise platform. Providing full session analysis, customers can extract critical data and effectively operate security operations automated playbook.
Netcraft — Netcraft takedown, submission and screenshot management.
Netcraft (Deprecated) — Deprecated. Use Netcraft_V2 (Display name: Netcraft) instead.
Netmiko — The Netmiko pack uses the Netmiko/Paramiko libraries to execute commands via SSH on platforms supported by these python modules.
Netmotion VPN — Parsing and modeling rules for Netmotion VPN logs via syslog
Netscout Arbor Edge Defense - AED — Use the Netscout Arbor Edge Defense integration to detect and stop both inbound threats and outbound malicious communication from compromised internal devices.
Netscout Arbor Sightline — Identify Potential Network Outages & Gain Business Insights to Solve Your Problems
Netskope — Cloud access security broker that enables to find, understand, and secure cloud apps.
Netskope v2 — Block URLs, domains and file hashes.
Nexthink — Nexthink helps IT teams deliver on the promise of the modern digital workplace.
Nist NVD — This integration can be used for daily routine vulnerability checks.(and used with several playbook)
The National Vulnerability Database (NVD), https://nvd.nist.gov, allows government agencies, software
vendors, and researchers to search and view information about vulnerabilities and vulnerable products. In
the Fall of 2019, NVD began offering web services to allow computer applications to better access the
NVD data
Non Supported (Deprecated) — Deprecated. No available replacement. Non supported in marketplace pack that includes old format content items. This pack has content items with to version < 6.0.0. Non Supported is not uploaded to GCS and considered ignored pack.
Nozomi Networks — An Integration Pack of Nozomi Networks OT Security Tools
Nutanix Hypervisor — Nutanix Hypervisor abstracts and isolates the VMs and their programs from the underlying server hardware, enabling a more efficient use of physical resources, simpler maintenance and operations, and reduced costs.
Office 365 — The product family of productivity and collaboration cloud based softwares owned by Microsoft.
Office 365 Feed — The Office 365 IP Address and URL web service is a read-only API provided by Microsoft to expose the URLs and IPs used by Office 365. The Office 365 Feed integration fetches indicators from the service, with which you can create a list (allowlist, blocklist, EDL, etc.) for your SIEM or firewall service to ingest and apply to its policy rules.
Okta Access Gateway — Okta Access Gateway is a reverse proxy based virtual application, designed to secure web applications that don't natively support SAML or OIDC.
Okta Auth0 — Identity platform to manage access to your applications.
Oletools — Oletools pack allows performing some basic oletools commands from Cortex XSOAR. oletools is a tool to analyze Microsoft OLE2 files
Ollama — Get up and running with large language models locally.
OnboardingIntegration — Creates mock email incidents using one of two randomly selected HTML templates. Textual content is randomly generated and defined to include some text (100 random words) and the following data (at least 5 of each data type): IP addresses, URLs, SHA-1 hashes, SHA-256 hashes, MD5 hashes, email addresses, domain names.
OneLogin — Simple customer authentication and streamlined workforce identity operations with APIs.
OnePassword — 1Password is a password manager used for storing and managing your account credentials, financial information, documents, and other sensitive data. It provides secure password generation, quick form filling, and cross-device synchronization. It also offers features like secure password sharing and monitoring for compromised accounts.
OpenAI — The OpenAI API can be applied to virtually any task that involves understanding or generating natural language or code.
OpenPhish — OpenPhish uses proprietary Artificial Intelligence algorithms to automatically identify zero-day phishing sites and provide comprehensive, actionable, real-time threat intelligence.
OpenSourceVulnerabilities — OSV (Open Source Vulnerability) is a vulnerability database for open source projects. For each vulnerability, it perform bisects to figure out the exact commit that introduces the bug, as well the exact commit that fixes it. This is cross referenced against upstream repositories to figure out the affected tags and commit ranges
OpsGenie — Get current on-call assignments, schedules, and users info
Oracle Cloud Infrastructure Feed — This feed provides information about public IP address ranges for services that are deployed in Oracle Cloud Infrastructure.
See additional information in this link:
https://docs.oracle.com/en-us/iaas/Content/General/Concepts/addressranges.htm
Oracle Database — A database management system designed for high performance, scalability, and secure data storage across cloud and on-premises environments.
Oracle IAM — A suite of solutions that enables secure user authentication, authorization, identity governance, and access control across enterprise applications and services.
Orca — Integrate with Orca security for bidirectional incident management and fetching of asset information.
OrionMalware — Analyze suspicious hashes or files using static and dynamic analysis
PAN-OS Policy Optimizer (beta) — This integration introduces Policy Optimizer and DAG features that are not available through the regular PAN API
PAN-OS by Palo Alto Networks — Manage Palo Alto Networks Firewall and Panorama. Use this pack to manage Prisma Access through Panorama. For more information see Panorama documentation.
PAN-OS to Strata Logging Service Monitoring — Monitor the PAN-OS FW log upload to the Strata Logging Service in a reoccurring job. The key pre-requisite is the configuration of the Strata Logging Service integration.
PAT Helpdesk Advanced — Manage helpdesk requests and tickets with PAT Helpdesk Advanced
PCAP Analysis — Don't miss out on critical forensic data! This Content Pack automates PCAP file analysis such as parsing, searching, extracting indicators, and more.
PCI DSS Compliance — Ensure your organization is following PCI DSS guidelines with the relevant dashboard and report evidence.
PHash (Deprecated) — Deprecated. please use Community Common Scripts instead.
Panorays — The Panorays pack enables organizations to monitor their own security posture by ingesting internal findings and security events from the Panorays platform, allowing for automated internal risk management and reporting.
PassiveTotal — Analyze and understand threat infrastructure from a variety of sources–passive DNS, active DNS, WHOIS, SSL certificates and more–without devoting resources to time-intensive manual threat research and analysis
Password Reset via Chatbot — Automates the process of resetting user passwords through a Slack or Teams message request to a chatbot.
PenfieldAI — Penfield.AI Incident Assignment for XSOAR
Pentera — Automate remediation actions based on Pentera, the Automated Security Validation Platform, proactively exposing high-risk vulnerabilities.
Perception Point — Loads incidents from Perception Point and releases falsely quarantined emails.
Perch — Perch is a co-managed threat detection and response platform.
PerimeterX — PerimeterX integration with Cortex XSOAR
Perplexity AI — Supports Perplexity AI's search, reasoning, and deep research LLM models. Integration provides support for the chat completion API and several search options in the API.
Phish.AI (Deprecated) — Deprecated. Vendor has declared end of life for this integration. No available replacement.
PhishTank — PhishTank is a free community site where anyone can submit, verify, track and share phishing data
PhishUp — PhishUp prevents phishing attacks, protects your staff and your brand with AI
Phishing — Phishing emails still hooking your end users? This Content Pack can drastically reduce the time your security team spends on phishing alerts.
Phishing Campaign — This pack can help you find related phishing, spam or other types of email incidents and characterize campaigns.
Phishing URL — Phishing URL is a project with the goal of detecting phishing URLs using machine learning
PhishingAlerts — This pack will help you handle your email security gateway alerts
PicusNGAutomation — Run commands on Picus NG and automate security validation with playbooks.
PingCastle — Active directory is quickly becoming a critical failure point in any big sized company, as it is both complex and costly to secure. PingCastle is a Windows-based utility to audit the risk level of your AD infrastructure and check for vulnerable practices. The Integrations and Playbooks in this allows you to listen for PingCastle reports, create an incident based on that report, upload the XML Report to the War Room as a file, and so on
PingIdentity — Integration with PingIdentity's PingOne identity platform
Pipl — Get contact, social, and professional information about people
Plain Text Feed — Fetches indicators from a plain text feed.
Polar Security — Polar Security, an IBM company, is an innovator in technology that helps companies discover, continuously monitor and secure cloud and software-as-a-service (SaaS) application data – and addresses the growing shadow data problem.
***
To use Polar Security on Cortex XSOAR, retrieve your user account's API credentials and enter them in the integration's configuration.
#### Configure an API account with Polar Security
- [Login](https://dashboard.polar-security.com) / [Register](https://www.polar.security/sign-up)
---
PolySwarm — Real-time threat intelligence from a crowdsourced network of security experts and antivirus companies.
Polygon — Analyze your files and URLs with Polygon playbooks and extract deep IOCs that appear when malicious code is triggered and executed.
Popular Cybersecurity News — Pack contains an Integration to fetch recent news from Popular security news sites like The Hacker News, Krebs on Security and Threatpost. Contains Playbook (to be run as a Job), News incident type and Layout including a grid for viewing the news articles along with redirects.
Port Scan — Port scans are a hacker favorite. This Content Pack automates IP and hostname enrichment, blocks malicious domains, blocks affected ports, and more.
Prisma Cloud by Palo Alto Networks — Automate and unify security incident response across your cloud environments, while still giving a degree of control to dedicated cloud teams.
Proactive Threat Hunting — The XSOAR Threat Hunting Pack enhances analyst capabilities by leveraging threat intelligence to uncover previously undetected threats, empowering proactive identification and mitigation of potential security risks.
Proofpoint CASB — Parsing and modeling rules for Proofpoint CASB logs
Proofpoint Cloud Threat Response — Proofpoint Cloud Threat Response (CTR) is the cloud-based alternative to TRAP (Threat Response Auto-Pull). known for its effective post-delivery remediation capabilities. Not only is this solution easy to use, but it also automates post-detection incident response and remediation tasks that slow down security teams.
Proofpoint Email Security — Proofpoint Email Security pack provides visibility into email security threats and protects your organization from phishing, malware, and compliance risks.
Proofpoint Feed — Detailed feed of domains and ips classified in different categories. You need a valid authorization code from Proofpoint ET to access this feed
Proofpoint Isolation — The Proofpoint Isolation pack enables automatic fetching and modeling rules for security events, such as Browser and Email Isolation logs.
Proofpoint ObserveIT — Proofpoint ObserveIT protects against data loss, malicious acts, and brand damage involving insiders acting maliciously, negligently, or unknowingly.
Proofpoint TAP — Use the Proofpoint Targeted Attack Protection (TAP) integration to protect against and provide additional visibility into phishing and other malicious email attacks.
Proofpoint Threat Protection — Threat Protection APIs are REST APIs that allow our Proofpoint On Demand customers to retrieve, add, update or delete certain PoD configurations.
Proofpoint Threat Response — Use the Proofpoint Threat Response integration to orchestrate and automate incident response.
Public DNS Feed — The Public DNS Feed fetches known IPs associated with public DNS servers from https://public-dns.info/
Publish List — The Publish List integration is used to publish XSOAR lists for external consumption.
Pulsedive — Leverage Pulsedive threat intelligence in Cortex XSOAR to enrich any domain, URL, or IP. Retrieve risk scores and factors, investigate contextual data, pivot on any data point, and investigate potential threats.
Pwned — Uses the Have I Been Pwned? service to check whether email addresses, domains, or usernames were compromised in previous breaches.
QR Code Reader — Pack contains an integration with api.qrserver.com to read QR codes from uploaded image files.
Qintel — Supports the Qintel suite of products including Patch Management Intelligence (PMI), QSentry and QWatch.
Qualys — Qualys Vulnerability Management let's you create, run, fetch and manage reports, launch and manage vulnerability and compliance scans, and manage the host assets you want to scan for vulnerabilities and compliance
QualysFIM — Cloud solution for detecting and identifying critical changes, incidents, and risks resulting from normal and malicious events
Quantum Security Systems — Use SOC Case Management Platform (SCMP) solution to manage and automated SOC activities in an efficient way
QueryAI — Query.AI is a decentralized data access and analysis technology that simplifies security investigations across disparate platforms without data duplication.
Quest Kace — Use the Comprehensive Quest KACE solution to Provision, manage, secure, and service all network-connected devices.
Quttera Website Malware Scanner — Detect suspicious/malicious/blocklisted content on domains/URLs. Run real-time normal/heuristic scan and database queries.
RDAP — This pack provides integration and automation for RDAP (Registration Data Access Protocol), allowing users to query and retrieve registration data for Internet resources such as domain names, IP addresses, and autonomous system numbers.
RSA Archer — The RSA Archer GRC Platform provides a common foundation for managing policies, controls, risks, assessments and deficiencies across lines of business.
RSA NetWitness Endpoint — RSA NetWitness Endpoint provides deep visibility beyond basic endpoint security solutions by monitoring and collecting activity across all of your endpoints on and off your network. The RSA Demisto integration provides access to information about endpoints, modules and indicators.
RSA NetWitness Packets and Logs — RSA NetWitness Logs and Packets decoders are responsible for the real-time collection of network data. The decode captures data in real time and can normalize and reconstruct data for full session analysis. In addition, the decoder can collect flow and endpoint data.
RSA NetWitness Security Analytics — RSA Security Analytics, compatible with prior to v11. A distributed and modular system that enables highly flexible deployment architectures that scale with the needs of the organization. Security Analytics allows administrators to collect two types of data from the network infrastructure, packet data and log data.
RSA SecurID — RSA SecurID is an MFA technology designed to increase security for network resources and help organizations maintain compliance.
RSS Feed — RSS Feed reader, imports new articles as Report indicator. All rss fields (e.g. author, published, tags) are available.
RST Threat Feed — High-fidelity threat intelligence database available via API to check domains, URLs, IP addresses and Hashes
RTIR — Request Tracker for Incident Response is a ticketing system which provides pre-configured queues and workflows designed for incident response teams.
Radware Cloud DDoS Protection Services — Radware Cloud DDoS Protection Service offers multi-layered defense using advanced behavioral algorithms to detect and mitigate Distributed Denial of Service (DDoS) attacks, from infrastructure-level floods to application-layer assaults. The service leverages a global network of scrubbing centers and supports flexible deployment options, including always-on, on-demand, and hybrid models, backed by an industry-leading mitigation SLA.
Radware Cloud WAF Services — Radware’s Cloud Security Services provides a range of fully managed, enterprise-grade cloud WAF and DDoS solutions to create a robust security network
Rapid7 InsightIDR — Rapid7 InsightIDR is a Cloud-Based SIEM that detect and respond to security incidents.
Rapid7 InsightVM — Vulnerability management solution to help reduce threat exposure.
Rapid7 InsightVM Cloud — Insight VM is a Vulnerability Management Tool which Scan your Network, Eliminate Vulnerabilities, Track and Communicate progress.
Rasterize — Converts URLs, PDF files, and emails to an image file or PDF file.
Reblaze WAF — Reblaze WAF is a fully managed, cloud-native security solution that protects web applications and APIs from modern cyber threats, bots, and DDoS attacks.
Reco — Reco is the leader in Dynamic SaaS Security — the only approach that eliminates the SaaS Security Gap (the growing gap between what you can protect and what’s outpacing your security).
Recorded Future — New Recorded Future content. Currently contains only alert functionality - for enrichment etc, refer to the 'Recorded Future Intelligence' pack.
Recorded Future Attack Surface Intelligence — Helps you take risk prioritization to the next level by helping you identify the biggest weaknesses within your attack surface.
Recorded Future Feed — Ingests indicators from Recorded Future feeds into Demisto.
Red Canary — Red Canary collects endpoint data using Carbon Black Response and CrowdStrike Falcon. The collected data is standardized into a common schema which allows teams to detect, analyze and respond to security incidents.
ReliaQuest Digital Risk Protection — GreyMatter Digital Risk Protection minimize digital risk by identifying unwanted exposure and protecting against external threats. The award-winning solution provides ongoing monitoring of a customer's unique assets and exposure across the open, deep, and dark web. This enables clients to detect data loss, brand impersonation, infrastructure risks, cyber threats, and much more.
Remedy AR — BMC Remedy AR System is a professional development environment that leverages the recommendations of the IT Infrastructure Library (ITIL) and provides a foundation for Business Service Management (BSM) solutions. For incident management (i.e. create, fetch, update), please refer to Remedy On-Demand integration.
Remedy SR (Beta) — The BMC Service Request Management application enables an IT department and other business departments to easily define available services, publish those services in a service catalog, and automate fulfillment of those services for the user community, enabling users to help themselves.
This integration uses SOAP API and supports SRM 9.0 version.
Remote Access — Transfer files and execute commands via SSH on remote machines.
Retarus Secure Email Gateway — The Retarus Secure Email Platform provides comprehensive security and advanced email routing. It offers features such as Advanced Threat Protection and Email Archiving.
ReversingLabs TitaniumCloud — ReversingLabs TitaniumCloud provides file reputation services, threat classification and rich context on over 10 billion files.
ReversingLabs TitaniumScale — Extract internal threat indicators with static malware analysis engine. Classify files and determine threat level.
RiskIQ Digital Footprint — RiskIQ Digital Footprint integration enables your security team to manage assets outside your firewall and provides you with the ability to add or update assets and analyze your digital footprint from the view of the global adversary.
RiskSense — RiskSense is a cloud-based platform that provides vulnerability management and prioritization to measure and control cybersecurity risk.
Riverbed Flow Gateways — Riverbed Flow Gateways provide comprehensive network visibility by collecting and analyzing all NetFlow data. These gateways gather flow data from various sources, including routers, switches, and other Riverbed devices, ensuring end-to-end network insights for accurate and complete understanding of your network's behavior.
Roksit DNS Security — This integration provides adding selected domains to the Roksit Secure DNS's Blacklisted Domain List through API .
Rubrik Security Cloud — Rubrik Security Cloud revolutionizes the data management market, specifically backup/recovery, archival, and DR, by providing a global policy framework, workflow orchestration, and deep data intelligence as cloud-delivered applications. The content pack fetches Rubrik Anomaly Event and provides playbooks to analyze, discover and recover -- to mention a few -- organizational data. The content pack is rich with commands to perform on-demand scans, backups, recoveries and many more features exposed by the RSC API.
RunZero — RunZero a network discovery and asset inventory solution.
Rundeck — Rundeck is runbook automation for incident management, business continuity, and self-service operations
SANS — This SANS Content Pack helps you streamline incident response according to SANS guidelines as outlined in the SANS Incident Handler’s Handbook.
SAP BTP (Business Technology Platform) — SAP Business Technology Platform is a cloud-based platform that enables organizations to build, integrate, and extend applications using data, analytics, AI, and automation tools. It combines database, development, and integration services into a unified environment optimized for enterprise business processes.
SAP Cloud For Customer C4C — SAP Cloud for Customer (C4C) is a cloud-based Customer Relationship Management (CRM) solution from SAP that helps businesses manage customer interactions, sales, and marketing processes. This pack fetches, filters, and paginates audit events from your SAP C4C instance for security monitoring and analysis.
SAP-IAM — IAM Integration for SAP. This handles user account auto-provisioning
SOC Framework Pack Manager — Installs and configures SOC Framework content packs directly from the XSIAM Playground. Manages the foundation layer, NIST IR orchestration, and vendor enhancement packs through a single bootloader script.
SOCRadar — Streamline remediation of alerts and incidents with enhanced multi-tenant capabilities. Easily manage and automate security operations across multiple tenants, including for enrichment threat intelligence, reputation checking, and IoC feeds
SOCRadar ThreatFeed — Obtain indicators provided by SOCRadar to gain knowledge about the malicious activities.
SOCRadarTakedown — Submit and manage takedown requests for phishing domains, social media impersonation, source code leaks, and rogue mobile apps through the SOCRadar platform. This pack helps security teams automate the process of reporting and tracking malicious content for removal.
SOX Compliance — Ensure your organization is following SOX guidelines with the relevant dashboard and report evidence.
SSL Labs — This pack integrates with Qualys SSL Labs. A free online service performs a deep analysis of the configuration of any SSL web server on the public Internet
SaaS Security by Palo Alto Networks — SaaS Security connects directly to your sanctioned SaaS applications to provide data classification, sharing and permission visibility, and threat detection.
SailPoint IdentityIQ — SailPoint IdentityIQ context pack enables XSOAR customers to utilize the deep, enriched contextual data in the SailPoint predictive identity platform to better drive identity-aware security practices.
SailPoint IdentityNow — SailPoint IdentityNow content pack enables XSOAR customers to utilize the deep, enriched contextual data in the SailPoint IdentityNow platform to better drive identity-aware security practices.
Saviynt Enterprise Identity Cloud — Saviynt Enterprise Identity Cloud (EIC) is a cloud-based platform that converges identity governance, administration, and privileged access management into a single, intelligent solution to help organizations secure and manage user identities.
Schedule Task and Poll — This playbook will schedule a specified command and monitor for completion by looking for output in context. Make the playbook context shared globally if you have a command that returns to Context automatically and you have a specific key to monitor. The key monitored must be a single field value and not an array.
Screenshot Machine — This is an integration for Screenshot Machine.
Capture any online web page with website screenshot API.
SecBI — A threat, intelligence, and investigation platform, enabled by automation of detection and investigation, including remediation and prevention policy enforcements on all integrated appliances.
Secneurx Threat Feeds — This pack contains integration to fetch indicators from SecneurX Threat Intelligence Feeds
SecureAuth Identity Platform — The SecureAuth® Identity Platform is a flexible and adaptable identity and access management solution that helps organizations prevent the misuse of credentials and eliminate identity-related breaches.
Secureworks — Provides access to the Secureworks CTP and Taegis XDR systems
Security Intelligence Services Feed — A PassiveTotal with Security Intelligence Services Feed can provide you newly observed Domain, Malware, Phishing, Content and Scam Blacklist.
SecurityScorecard — Provides security scorecards and alerts for domains.
SecurityTrails — Integration for the SecurityTrails platform.
Securonix — Use the Securonix integration to manage incidents, threats, lookup tables, whitelists and watchlists.
SekoiaXDR — Request Sekoia Defend (XDR) from Cortex XSOAR
Semperis DSP — Semperis Directory Services Protector (DSP) provides security for Active Directory (AD) and Azure AD monitoring services.
SendGrid — SendGrid provides a cloud-based service that assists businesses with email delivery. It allows companies to track email opens, unsubscribes, bounces, and spam reports. Our SendGrid pack utilize these SendGrid use cases to help you send and manage your emails.
ServerLogs (Deprecated) — Deprecated. ServerLogs and ServerLogs_docker scripts moved to CommonScripts pack.
ServiceNow — Use The ServiceNow IT Service Management (ITSM) solution to modernize the way you manage and deliver services to your users.
ServiceNow Generic Feed — This pack contains an integration that can be used to pull indicators from ServiceNow CMDB and put them inside the TIM with the option to provide tagging.
ServiceNow MCP — Integrate with ServiceNow via the Model Context Protocol (MCP) server to automate ServiceNow operations.
Shadow IT — This Content Pack provides a new incident type for Shadow IT incidents, and a playbook to handle such scenarios.
Shift Management — This pack's purpose is to provide a single interface for all those essential elements of Shift management and handover in one place.
ShiftLeft CORE — See high risk vulnerabilities in your application before they go into production with ShiftLeft CORE
Shodan — A search engine used for searching Internet-connected devices
Siemens SiPass — Siemens SiPass is an access control system that enables you to manage physical access such as doors, gates, barriers, and elevators at multiple sites.
Sigma — This pack contains all needed objects to import and manage Sigma rules within Cortex TIM
Signum — To list all the users in a domain on Signum
Silent Push — The Silent Push platform focuses on proactive threat intelligence and threat hunting.
Silverfort — Silverfort protects organizations from data breaches by delivering strong authentication across entire corporate networks and cloud environments, without requiring any modifications to endpoints or servers. Using patent-pending technology, Silverfort's agentless approach enables multi-factor authentication and AI-driven adaptive authentication even for systems that don’t support it today, including proprietary systems, critical infrastructure, shared folders, IoT devices, and more. Use Silverfort integration to get & update Silverfort risk severity. This integration was integrated and tested with Silverfort version 2.12.
Simple API Proxy — This pack provides a simple API proxy to restrict privileges or minimize the amount of credentials issued at the API.
Simple Debugger — This content pack provides a simple debugger for debugging custom python automations in XSOAR. You can visually trace code execution, set breakpoints, step through the code, display local variables, and profile execution times of python functions.
Simple SFTP — Simple SFTP Integration to copy files from SFTP Server using paramiko.
Single Connect — Single Connect enables enterprises to remove static passwords stored in applications by instead keeping passwords in a secure password vault. It secures access to passwords through token-based authentication
Sixgill Darkfeed - Annual Subscription — This edition of Sixgill Darkfeed is intended for customers who have a direct annual subscription to Sixgill Darkfeed.
Get contextual and actionable insights to proactively block underground threats in real-time with the most comprehensive, automated stream of IOCs
For organizations who are currently Darkfeed customers.
Skyformation (Deprecated) — Deprecated. Vendor has declared end of life for this product. No available replacement.
Skyhigh Security SSE — Skyhigh Security is a cloud-based, multi-tenant service that enables Cloud Discovery and Risk Monitoring, Cloud Usage Analytics, Cloud Access and Control.
Slack — Interact with Slack API - collect logs, send messages and notifications to your Slack team.
Smokescreen IllusionBLACK — Smokescreen IllusionBLACK is a deception-based threat defense platform designed to accurately and efficiently detect targeted threats including reconnaissance, lateral movement, malware-less attacks, social engineering, Man-in-the-Middle attacks, and ransomware in real-time.
SolarWinds — SolarWinds allows users to fetch alerts and events by using the fetch incidents capability and commands.
SonicWall NSv — The SonicWall NSv Series virtual firewall offers all the security advantages of a physical firewall with the operational and economic benefits of virtualization, including system scalability and agility, speed of system provisioning, simple management and cost reduction.
Sophos Central — The unified console for managing Sophos products
Sophos XG Firewall — Use the Sophos XG Firewall to manage your firewall, detect and respond to threats on your network.
Spamcop — SpamCop is an email spam reporting service, integration allow checking the reputation of an IP address
Spamhaus Feed — The Spamhaus DROP (Don't Route Or Peer) lists are advisory "drop all traffic" lists, consisting of netblocks that are "hijacked" or leased by professional spam or cyber-crime operations (used for dissemination of malware, trojan downloaders, botnet controllers). The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
SpecterOps BloodHound Enterprise — This content pack integrates with BloodHound Enterprise to automatically ingest and analyze attack path findings from Active Directory and Azure environments, helping security teams identify and remediate privilege escalation risks.
SpecterOpsBHE (Deprecated) — Deprecated. Use the SpecterOps BloodHound Enterprise pack instead. This content pack integrates with BloodHound Enterprise to automatically ingest and analyze attack path findings from Active Directory and Azure environments, helping security teams identify and remediate privilege escalation risks.
Splunk — Fetch events as incidents and search Splunk
Spur Context API — Enrich IP addresses with data from the Spur Context API
SpyCloud — Integration for retrieving data from the SpyCloud ATO API
SpyCloud Enterprise Protection — Create breach, malware and access incidents in Cortex® XSOAR™ using the SpyCloud Enterprise Protection API. Provide enrichment for domains, IPs, emails, usernames, and passwords.
Squid — Squid is a caching proxy for the Web which reduces bandwidth and improves response times by caching and reusing frequently-requested web pages.
Stairwell — Inception is a security intelligence engine that automates the continuous capture, storage, and analysis of executable files.
Starter Pack — Starter Pack for learning how to build new content in Cortex XSOAR
Stellar Cyber — Integration to retrieve and update cases from the Stellar Cyber platform.
Strata Logging Service by Palo Alto Networks — Palo Alto Networks Strata Logging Service XSOAR Connector provides cloud-based, centralized log storage and aggregation for your on-premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR
StringSifter — StringSifter is a machine learning tool that automatically ranks strings based on their relevance for malware analysis.
Sumo Logic — Cloud-based service for logs & metrics management
Sumo Logic Cloud SIEM — Sumo Logic Cloud SIEM provides threat detection and incident response for modern IT environments. This content pack will allow you to apply automation to perform actual SOC analyst workflows. Using this content pack you will be able to fetch Incidents via Insights, update status of an Insight, add items to match list, add Threat Intel Indicators to Threat Intel Sources, and so on.
Superna Zero Trust — Automate ransomware response: critical path snapshots and user NAS lockout/unlock via secure API integration.
Suspicious Domain Hunting — This pack provides all the necessary tools for the Suspicious Domain Hunting use case. It uses the CertStream integration to ingest new SSL certificates and alert for type-squatting domains with SSL certificate, these alerts are then analyzed and mitigated.
Symantec Cloud Secure Web Gateway — Symantec Cloud Secure Web Gateway (SWG) is a cutting-edge cybersecurity solution designed to provide robust protection and control over internet traffic within organizations. Leveraging advanced threat intelligence, real-time content analysis, and secure web access policies, Symantec Cloud SWG ensures a secure and compliant online environment for users.
Symantec Data Loss Prevention — Symantec Data Loss Prevention enables you to discover, monitor and protect your sensitive corporate information.
Symantec Endpoint Detection and Response — Symantec EDR On-prem helps to detect threats on your network by filtering endpoints data to find Indicators of Compromise (IoCs) and take actions to remediate the threat(s) contain suspicious events, isolate potentially compromised devices, and delete malicious files and associated artifacts.
Symantec Endpoint Security — Use Cloud Platform Connections, a cloud-based security feature in Symantec Endpoint Security to discover and protect instances of public cloud platforms, and their workloads.
Symantec Managed Security Services — Leverage the power of Symantec Managed Security Services for continual threat monitoring and customized guidance 24x7
Symantec Management Center — Symantec Management Center provides a unified management environment for the Symantec Security Platform portfolio of products.
Symantec Messaging Gateway — Symantec Messaging Gateway protects against spam, malware, and targeted attacks and provides advanced content filtering, data loss prevention, and email encryption.
SymantecCloudSOC — This is the Symantec CloudSOC event collector integration for XSIAM
SymantecEmailSecurity — Symantec Email Security.cloud is a hosted service that filters email messages and helps protect organizations from malware (including targeted attacks and phishing), spam, and unwanted bulk email. The service offers encryption and data protection options to help control sensitive information sent by email and supports multiple mailbox types from various vendors.
SymantecICDM — Query the Symantec Endpoint Security Cloud using the official REST API.
Synopsys Coverity — Parsing and modeling rules for Synopsys Coverity logs
SysAid — SysAid is a robust IT management system that was designed to meet all of your needs as an IT department.
Sysdig Response Actions — This is an integration that will use Sysdig agent to respond to malicious activity by triggering different actions at the host or container level like killing a container, quarantine a file or perform a system capture
Syslog — Use the Syslog pack to send messages and mirror incident War Room entries to Syslog, or listen to incoming Syslog messages.
TAXII Feed — Ingest indicator feeds from TAXII 1 and TAXII 2 servers.
TAXII Server — This pack provides TAXII Services for system indicators (Outbound feed).
TCPIPUtils (Deprecated) — Deprecated. Use the TCPIPUtils.com API to get data about an IP address instead.
TIM - Indicator Auto-Processing — Too many threat feeds? This Content Pack automates the processing of indicators at scale, significantly reducing busywork for your analysts.
TIM - SIEM Integration — Update your SIEM with minimal fuss! This Content Pack automates the delivery of indicators to your SIEM for correlation, with minimal configuration.
TIM Campaign Tracking — This pack allows you to upload threat intelligence briefs to track IOCs related to specified threat actor campaigns. Using this pack you will be able to check what the adversary is trying to accomplish, why are they trying to accomplish this, and so on
TOPdesk — TOPdesk Enterprise Service Management software (ESM) lets your service teams join forces and process requests from a single platform
TXOne StellarOne — TXOne StellarOne is an OT (Operational Technology) security solution that centrally manages endpoint and OT asset protection. It provides logs in Syslog CEF format covering threat detections and login events to the StellarOne management console.
Tableau — Tableau is a visual analytics platform transforming the way we use data to solve problems empowering people and organizations.
Tanium — Tanium endpoint security and systems management
Tanium Threat Response — Use the Tanium Threat Response integration to manage endpoints processes, evidence, alerts, files, snapshots, and connections.
Tavily — Tavily is a web service that provides real-time web search and retrieval capabilities through an API, enabling developers to fetch and extract relevant information from the internet in structured formats like JSON.
Team Cymru — Team Cymru's Scout integration provides comprehensive insights on IP addresses and domains for threat investigations.
Team Management — This pack contains playbooks and automation scripts to help with the management of team members within an incident. It's current features include:
- Ability to add team members to an incident based on username or role
TeamViewer — This is the TeamViewer event collector integration for XSIAM
Tenable Vulnerability Management (formerly Tenable.io) — A comprehensive asset centric solution to accurately track resources while accommodating dynamic assets such as cloud, mobile devices, containers and web applications.
Tenable.sc — With Tenable.sc (formerly SecurityCenter) you get a real-time, continuous assessment of your security posture so you can find and fix vulnerabilities faster.
Tessian — Tessian's complete cloud email security platform defends customers against advanced phishing threats, and protects their sensitive data on email.
Thales CipherTrust Manager — Manage Secrets and Protect Sensitive Data through Thales CipherTrust security platform
Thales SafeNet Trusted Access — SafeNet Trusted Access by Thales is an access management solution that allows organizations to centrally manage and secure access to business applications.
TheHive Project — Provides an integration, incident type and layout for use with TheHive Project.
Thinkst Canary — By presenting itself as an apparently benign and legitimate service(s), the Canary draws the attention of unwanted activity. When someone trips one of the Canary's triggers, an alert is sent to notify the responsible parties so that action can be taken before valuable systems in your network are compromised.
ThousandEyes — This pack is used to to fetch-incidents, get alerts details and to get agent list
Threat Vault by Palo Alto Networks — Use the Palo Alto Networks Threat Vault to research the latest threats (vulnerabilities/exploits, viruses, and spyware) that Palo Alto Networks next-generation firewalls can detect and prevent.
ThreatConnect Feed — ThreatConnect indicators feed for Cortex XSOAR TIM.
ThreatDown — ThreatDown (powered by Malwarebytes) Integration & Playbooks
ThreatExchange — Receive threat intelligence about applications, IP addresses, URLs and hashes, a service by Facebook
ThreatFox Feed — ThreatFox is a free platform from abuse.ch with the goal of sharing indicators of compromise (IOCs) associated with malware with the infosec community, AV vendors and threat intelligence providers. The ThreatFox Feed allows users to fetch indicators from ThreatFox.
ThreatMon — This integration pulls data from the ThreatMon API and updates XSOAR incidents. You can also update the status of your incidents, submit takedown requests, and request data removal for Black Market Monitoring findings directly from the XSOAR interface.
ThreatMon Threat Feed — Fetches Indicators of Compromise (IOCs) such as IPs, domains, URLs and file hashes from the ThreatMon IOC platform and ingests them into Cortex as indicators.
ThreatQ — Platform for collecting and interpreting intelligence data from open sources, and for managing indicator scores, types, and attributes.
ThreatVault Feed — Ingests threat intelligence data from ThreatVault
ThreatX — The ThreatX integration allows automated enforcement and intel gathering actions.
Tigera Calico — Calico Open Source is a networking and security solution for containers, virtual machines, and native host-based workloads.
Tor Exit Addresses Feed — Tor is free software and an open network that helps you defend against
traffic analysis, a form of network surveillance that threatens personal freedom
and privacy, confidential business activities and relationships, and state security.
Traceable — Traceable AI API Security Platform Integration
Trellix Email Security - Cloud — Trellix Email Security - Cloud (Formerly FireEye ETP) is a cloud-based platform that protects against advanced email attacks.
Trellix_ePO — Parsing and modeling rules for Trelix ePO logs via syslog in XML format
Trello — Trello is a card-based activity tracker. Use this content pack to organize and prioritize your personal and work life using boards, lists, cards and so on.
Trend Micro Email Security — Trend Micro Email Security is an enterprise grade solution to stop phishing, ransomware, BEC, other advanced email threats, and spam
Trend Micro InterScan Web Security — Trend Micro InterScan Web Security as a Service dynamically protects against cyber threats in the cloud, before they reach your users or network.
Trend Micro TippingPoint — Trend Micro TippingPoint protect against known, unknown and undisclosed vulnerabilities in your network
TrendAI Vision One™ — Purpose-built threat defense platform with XDR capabilities that correlate data across email, endpoints, servers, cloud, and networks.
TrendAI™ Apex One — TrendAI™ Apex One central automation to manage agents and User-Defined Suspicious Objects
TrendAI™ Deep Discovery™ Analyzer — Deep Discovery Analyzer is a turnkey appliance that uses virtual images of endpoint configurations to analyze and detect targeted attacks.
TrendAI™ Deep Security™ — TrendAI™ Deep Security™ provides runtime security for workloads (physical, virtual, cloud, and containers).
Tripwire — Tripwire is a file integrity managment(FIM),used to track files and folders on different systems and monitors their changes.
Troubleshoot — Use this pack to troubleshoot your environment.
TruSTAR (Deprecated) — Deprecated. Not supported since TrueSTAR was acquired by Splunk, No available replacement.
Trustwave Fusion — Trustwave Fusion is Trustwave's cloud-native platform that provides visibility and context in detection and response workflows.
TrustwaveSEG — Trustwave SEG is a secure messaging solution that protects businesses and users from email-borne threats, including phishing, blended threats, and spam. Trustwave Secure Email Gateway also delivers improved policy enforcement and data leakage prevention.
Tufin — Gather network intelligence from SecureTrack and SecureApp, perform topology queries in SecureTrack, and submit change tickets from SecureChange.
Twilio SendGrid — Twilio SendGrid is a cloud-based email platform designed to help businesses send and manage both transactional and marketing emails reliably and at scale.
Twinwave — TwinWave's threat analysis platform analyzes both URLs and files to detect credential phishing and malware threats. Our platform automatically navigates complex attack chains that attackers put in front of threats in order to evade analysis. In addition to detecting threats, the TwinWave platform generates actionable intelligence for threat hunting and other activities.
Twitter — A simple integration that uses Twitter's API to perform searches on twitter for tweets and users.
TwitterIOCHunter - Full Daily Feed — Implements the Twitter IOC project daily full feed as indicator feed into XSOAR. http://tweettioc.com/feed/api
US - Breach Notification — This Content pack helps you understand if a breach has occurred and automates repetitive tasks associated with US Breach notification procedures.
USTA — USTA is developed and operated by PRODAFT. Continuously growing since 2012, USTA is one of the first cyber intelligence platforms ever developed. Featuring a unique synergy of threat intelligence, fraud intelligence and brand protection modules; USTA responds directly and effectively to today's complex cyber threats.
Today, USTA is one of the most widely used threat-intel solutions of critical infrastructures.
USTAv4 Cyber Threat Intelligence Platform — Since 2012, we have been pioneering one of the first cyberthreat intelligence platforms ever developed. Our CTI platformU.S.T.A. (Unified Security Threat Alliance) entails a unique synergy of five main modules: Deep Sight, Brand Protection, Fraud Intelligence, Security Intelligence, and Attack Surface Management.
Ubiquiti Unifi — Ubiquiti UniFi is an integrated network management and security platform that provides centralized control of Wi-Fi access points, switches, gateways, and other devices. It offers unified monitoring, configuration, and security features through an intuitive cloud-based interface for businesses and organizations.
UltraMSG — UltraMSG Integration.
Send Whatsapp to Single Person Or Groups.
UnifiVideo NVR — This integration connects to UnifiVideo by Ubiquity Networks, which fetches motion events as incidents, allowing you to take video recordings and snapshots
Unisys Stealth — This integration is intended to aid companies in integrating with the Stealth EcoAPI service. Using the included commands, security teams can trigger dynamically isolation of users or endpoints from the rest of the Stealth network.
Unit 42 Intel (Deprecated) — Deprecated. Use the Unit 42 Threat Intelligence by Palo Alto Networks instead.
Unit 42 Threat Intelligence by Palo Alto Networks — Use the Unit 42 Threat Intelligence by Palo Alto Networks integrations to enrich indicators with threat intelligence data and fetch threat intelligence feeds.
Use Case Builder — To streamline the Use Case Design process and provide tools to help you get into production faster!
VMRay Analyzer — Analyze files and URLs using the VMRay Platform for accurate threat intelligence and high-quality IOCs.
VMWare NSX — VMware NSX is a comprehensive virtual networking and security platform that transforms how organizations manage and secure their digital infrastructure.
VMware — VMware vCenter Server is a centralized management platform for managing virtual machines and ESXi hosts.
VMware ESXi — Modeling Rules for the VMware ESXi logs collector
VMware Workspace ONE UEM — VMware workspace ONE UEM allows users to search enrolled corporate or employee-owned devices, provides detailed information about each device such as its serial number, installed OS's, pending OS updates, network details, and much more leveraging Workspace ONE UEM's (formerly AirWatch MDM) API.
VMware vCenter — Modeling Rules for the VMware vCenter logs collector
Varonis Data Security Platform — Streamline alerts, events and related forensic information from Varonis Data Security Platform
Varonis SaaS — Streamline alerts, events and related forensic information from Varonis SaaS
Vectra AI — This content pack allows to create incidents based on Vectra Accounts/Hosts/Detections objects.
Vectra RUX — Vectra RUX pack empowers the SOC to create incidents based on events detection using Vectra AI's Attack Signal Intelligence.
Vectra XDR — Vectra XDR pack empowers the SOC to create incidents using Vectra AI's Attack Signal Intelligence.
Veeam App — The Veeam Apps allow Veeam Data Platform Advanced and Premium customers to combine the automation and orchestration features of the Cortex product suite with a simple and powerful Veeam Data Platform that goes beyond backup providing businesses with reliable data protection, seamless recovery, and streamlined data management.
Vega — The Vega integration allows you to ingest alerts and incidents from the Vega platform into Cortex XSOAR.
VersaDirector — Versa Director is a virtualization and service creation platform that simplifies the design, automation, and delivery of SASE services. Versa Director provides the essential management, monitoring and orchestration capabilities needed to deliver all of the networking and security capabilities within Versa SASE.
Viper — Viper is a binary analysis and management framework. The integration provides the capabilities to search in the framework und to download samples.
VirusTotal — Analyze suspicious hashes, URLs, domains and IP addresses
WhisperGate and HermeticWiper & CVE-2021-32648 — On January 14th, 2022, reports began on a malware operation dubbed "WhisperGate" targeting multiple organizations in Ukraine.
On February 23, 2022, a new wiper malware known as "HermeticWiper" was disclosed by several cybersecurity researchers. The new wiper "HermeticWiper" was also being used against organizations in Ukraine.
Whois — This Content Pack helps you run Whois commands as playbook tasks or real-time actions within Cortex XSOAR to obtain valuable domain metadata.
Wiz — Integrate with Wiz for bidirectional Issue management, Detections investigation, and fetching of resource information.
Wolken ITSM — Use The Wolken IT Service Management (ITSM) solution to modernize the way you manage and deliver services to your users.This is case management. Cortex XSOAR interfaces with Wolken ITSM to help streamline security-related service management and IT operations.
Wordpress — The WordPress REST API provides an interface for applications to interact with your WordPress site.
Workday — Workday offers enterprise-level software solutions for financial management, human resources, and planning.
X509Certificate — The X509 Certificate Content Packs provides additional capabilities for handling, parsing and validating X509 Certificates in Cortex XSOAR.
XDR Best Practice Assessment — This content pack includes an incident type, custom fields, layout, and playbook to facilitate an XDR Best Practice Assessment for an existing deployment of Palo Alto Networks Cortex XDR Product. The assessment contains survey questions covering the following domains: Configurations, Agent Management, Policy and Profiles, Profile Extensions, Incident Management, and Incident Response. Answers to survey questions will be output to the incident layout along with best practice recommendations.
XM Cyber — XSOAR is a comprehensive SOAR platform that integrates different security tools to centralize incident management, driving better detection, investigation, and response to suspicious activity across your organization.The integration uses attack graph context and prioritization data that XSOAR receives from XM CEM, and also allows XSOAR to feed relevant entities back to CEM to be defined as breach points in CEM scenarios.
XQLDSHelper — Run an XQL query and creates an entry for the General Purpose Dynamic Section to display a graph or table widget based on the results. The query is executed by the 'xdr-xql-generic-query' command.
XSOAR - Simple Dev to Prod — This pack simplifies exporting custom content items between your XSOAR environments.
XSOAR CI/CD — This pack enables you to orchestrate your XSOAR system configuration.
XSOAR Content Update Notifications — This pack will check for any available content updates for existing packs and send an e-mail or Slack message to users to inform them of the updates.
XSOAR EDL Checker — Checks EDLs hosted by the XSOAR server to ensure they are functioning.
XSOAR Engineer Training — XSOAR Engineer Training (XET) Pack, this pack contains content utilized to train you on how to be an XSOAR Engineer.
XSOAR File Management — This pack let user manipulate file inside XSOAR more easily than with the builtin functions.
XSOAR Mirroring — Allows mirroring of XSOAR incidents between different instances.
XSOAR Storage — XSOAR Storage provides a server-wide Key/Value store that allows values to be stored and retrieved; it supports namespaces to assist with key collisions.
XSOAR Summary Dashboard — Dashboard that shows overall platform performance as well as support links and cheat sheets for reference. The dashboard also pulls the most recent XSOAR live community blog posts.
Xsoar-web-server — Contains a minimal webserver and an automation that can be used to generate predictable URLs that can be inserted into emails and the responses can be tracked. Also contains a test playbook meant to be a POC.
Xsoar_Utils — This is a wrapper on top of XSOAR API. Can be used to implement commands that call the XSOAR API in the background.
Yara — The pattern matching swiss knife for malware researchers.
Zero Day Live TI FUSION Feed — Blackwired defines a new approach to Threat Intelligence. The flagship Zero Day Live platform is designed to proactively prevent cyber-attacks before they happen. It is the first and only platform making military-grade cyber-warfare capability accessible to enterprise.
Zero Networks Segment — Integrates with Zero Networks Segment API to fetch and process audit and network events.
ZeroFox — Cloud-based SaaS to detect risks found on social media and digital channels.
Zerohack XDR — ZeroHack XDR is a Comprehensive Network and Host Threat Detection and Remediation software suite designed on the SaaS model for Clouds and On-Premises Environments. It provides advanced threat detection functionalities using Deep Packet Inspection, Passive Fingerprinting and AI Engine to monitor and learn the Network and individual behavior for early prediction of attacks.
Zimperium — Streamline investigation and remediation of mobile alerts, generated alerts based on anomalous or unauthorized activities using the Zimperium pack.
Zoom — Use the Zoom integration manage your Zoom users and meetings
Zoom Feed — Use the Zoom Feed to automatically ingest valid indicators such as CIDRs and DomainGlobs from Zoom. The indicators can then be added to firewall allow lists.
Zoom Mail — Use the Zoom Mail integration manage your ZMail
Zscaler Internet Access — Zscaler is a cloud security solution built for performance and flexible scalability.
ZscalerZPA — The Zscaler Private Access (ZPA) service enables organizations to provide access to internal applications and services while ensuring the security of their networks.
iLert — iLert is an IT alerting, on-call management and uptime monitoring platform that helps DevOps teams respond to incidents faster. Use this iLert content pack to alert and notify users more efficiently.
iManage Threat Manager — iManage Threat Manager uses modern techniques including machine learning and user Behavior Analytics to protect privileged information against internal and external threat actors.
iZOOlogic — Fetches threat incidents from iZOOlogic for automated ingestion into Cortex.
iboss — Manage block lists, manage allow lists, and perform domain, IP, and/or URL reputation and categorization lookups.
mnemonic MDR — Rapidly detect, analyse and respond to security threats with mnemonic's leading Managed Detection and Response (MDR) service.
xMatters — Use the xMatters pack to trigger events to on-call groups or users and wait for their response. Use their response to branch and take action in XSOAR.