Cortex XDR - False Positive Incident Handling
This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response. This playbook handles false-positive incident closures for Cortex XDR - Malware investigation.
- Pack
- CortexXDR
- Tasks
- 14
Inputs
- Comment — Add comment to close this incident.
- Reason — Choose From - "Unknown" / "TruePositive" / "FalsePositive"
- AllowTag — The approving tag name for found indicators.
- AutoUnisolation — Whether automatic unisolation is allowed.
- HostID — The ID of the host for running an un-isolation process.
- FileSha256 — The File SHA256 you want to block.
Commands used
- closeInvestigation
- setIndicators
- xdr-allowlist-files