Add Pre-Process Rule - Tutorials - 6.x - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR 6.x Tutorials

Product
Cortex XSOAR
Version
6.x
Creation date
2022-10-13
Last date published
2023-06-05
Category
Tutorials

Pre-process rules enable you to perform certain actions on events as soon as they are ingested into Cortex XSOAR. We can use pre-process rules to drop incidents, close duplicate incidents, link incidents together, run a script, etc. In this example, our organization has been running a phishing awareness campaign to check if internal users properly report phishing emails. We don't want to investigate these incidents, as we know they are not truly malicious emails.

  1. Select SettingsIntegrationsPre-Process RulesNew Rule.

    From Cortex XSOAR v6.11 and later, go to SettingsOBJECTS SETUPIncidentsPre-Process RulesNew Rule.

  2. In the Rule Name field, type, Phishing Awareness Campaign.

  3. In the Conditions for Incoming incident section, add the following filter:

    best-employee-award.PNG
  4. In the Action field, select Drop.

  5. Click Save.

    All future incidents that include this subject are dropped. If the awareness campaign concludes or a new email subject is used, you may want to remove or edit this pre-process rule.