Configure the VirusTotal (API v3), Palo Alto Networks Wildfire, and Active Directory Query Instances - Tutorials - 6.x - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR 6.x Tutorials

Product
Cortex XSOAR
Version
6.x
Creation date
2022-10-13
Last date published
2023-06-05
Category
Tutorials
  • VirusTotal investigates suspicious files, domains, URLs, IP addresses, etc.

  • Palo Alto Networks WildFire v2 submits files, returns the report, and looks up the file reputation.

  • Active Directory Query 2 accesses and manages Active Directory objects (users, contacts, and computers) and runs AD queries.

VirusTotal (API v3)
  1. Go to SettingsINTEGRATIONSInstances and search for VirusTotal (API v3) (Partner Contribution).

  2. Click Add instance.

  3. Add the VirusTotal API key.

    For testing purposes, if you do not have a VirusTotal subscription, you can use the VirusTotal public API, which is limited to 500 requests per day, at a rate of 4 requests per minute, and cannot be used in commercial products or services. The VirusTotal premium API does not have these limitations.

  4. Click Test and then Save & Exit.

Palo Alto Networks WildFire v2
  1. Go to SettingsINTEGRATIONSInstances and search for Palo Alto Networks WildFire v2.

  2. Click Add instance.

  3. Add the API key.

  4. Click Test and then Save & exit.

Active Directory Query v2
  1. Go to SettingsINTEGRATIONSInstances and search for Active Directory Query v2.

  2. Click Add instance.

  3. Add the Server IP address, Port, Credentials, Password, and Base DN.

  4. Click Test and then Save & Exit.