Install the Phishing Content Pack and Configure the EWS Email Gateway - Tutorials - 6.x - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR 6.x Tutorials

Product
Cortex XSOAR
Version
6.x
Creation date
2022-10-13
Last date published
2023-06-05
Category
Tutorials
  1. Go to Marketplace, search for Phishing and install the Phishing content pack.

  2. During installation, select Microsoft Exchange Online as the email gateway. The Microsoft Exchange Online content pack will install at the same time as the Phishing content pack.

  3. After the content packs are installed, go to SettingsINTEGRATIONSInstances and search for EWS O365.

  4. Add the EWS O365 integration instance, which fetches events, attachments, original emails from an inbox, and searches and deletes emails.

    1. Click Add instance.

    2. Choose Fetches incidents.

    3. Verify the classifier is set to EWS - Classifier , which classifies incoming incidents as Phishing. If you were configuring an integration instance that did not have a classifier available, you would select Phishing for the Incident type (if classifier doesn’t exist) option.

    4. Follow the instructions to authorize the Demisto app and enter the ID, Token, and Key that you receive.

    5. Add the email address of the designated phishing inbox from which to fetch incidents.

    6. If you want to designate a specific folder from which to fetch emails as phishing incidents, enter that folder name. Otherwise, leave the default as Inbox.

    7. Add any other options as required.

    8. After you click Test, Cortex XSOAR attempts to connect to EWS. If you receive an error message that auto discovery failed, you need to add details manually (the exchange server hostname, the domain username, the exchange server version, and the Advanced Mode Override Authentication type).

      phishing-ews.png
    9. Save & exit

    The system starts ingesting incidents from EWS. Every email creates an incident in Cortex XSOAR.