Customize the Malware Investigation and Response Incident Layout - Tutorials - 6.x - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR 6.x Tutorials

Product
Cortex XSOAR
Version
6.x
Creation date
2022-10-13
Last date published
2023-06-05
Category
Tutorials

Customize the Malware Investigation and Response incident layout by adding custom fields to the layout.

  1. Go to SettingsOBJECTS SETUPIncidentsLayouts.

  2. Select the Malware Investigation and Response layout checkbox.

  3. Click Detach.

    Note

    When an incident layout is detached, it no longer receives layout updates from the content pack. If you want to receive updates, duplicate the layout instead.

  4. Select the Malware Investigation and Response layout and click Edit.

  5. In the Case info tab, add the custom fields to a new section.

    We can add these custom fields to any section, and in this example, we want to create a new section.

    1. From the Library section, in the Sections tab, drag and drop the New Section onto the Case info tab.

    2. Rename the section to Quick Actions, by editing the settings.

    3. In the Fields and Buttons tab, drag and drop the custom buttons we created.

      malware-quick.png
  6. Click the “New”/”Edit” Form tab, add the custom fields, as required.

    You can see below we have added the majority of the fields to the Basic Information section.

    malware-basic.png
  7. Click the “Close” Form tab and add the XDR Tuning Required field we created earlier to the Custom Fields section.

    malware-close.png
  8. Click Save Version.

    Save Version enables you to restore any changes.