Generic Export Indicators Service (v3.4.1)
Use this pack to generate a list based on your Threat Intel Library, and export it to any product in your network, such as firewalls, agents or SIEMs. This pack supports ongoing distribution of indicators from XSOAR to other products in the network, by creating an endpoint with a list of indicators that can be pulled by external vendors.
- Author
- Cortex XSOAR
- Support
- xsoar
- URL
- https://www.paloaltonetworks.com/cortex
- Categories
- Data Enrichment & Threat Intelligence
Incident fields (4)
- Generic Export Indicators Service Action
- Generic Export Indicators Service Indicators List
- Generic Export Indicators Service Tag
- Generic Export Indicators Service Type
Integrations (1)
- Generic Export Indicators Service
Layouts (1)
- EDL Change Layout
Playbooks (2)
- Block Domain - External Dynamic List
- PAN-OS EDL Service Configuration
README
Simple, manual process to modify external dynamic lists (EDLs) in Cortex <~XSOAR>XSOAR</~XSOAR><~XSIAM>XSIAM</~XSIAM>. This pack may help replace an existing manual process for updating firewall allowlists and blocklists, so analysts may make these changes directly in Cortex <~XSOAR>XSOAR</~XSOAR><~XSIAM>XSIAM</~XSIAM>. You just need to simply paste in a list of indicators to add or remove them from the EDL.
Note: This pack does not perform indicator type validation at this time. Indicators will be added to the EDL exactly as entered.