Use the Deployment Wizard to Configure Your Integration Instances and Main Playbook - Tutorials - 6.x - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR 6.x Tutorials

Product
Cortex XSOAR
Version
6.x
Creation date
2022-10-13
Last date published
2023-06-05
Category
Tutorials

In the Deployment Wizard, follow the list of What needs to be done in each step to guide you through the required configurations, including the relevant API credentials.

  1. Configure your fetching integration.

    For this tutorial, configure a Palo Alto Networks Cortex XDR - Investigation and Response integration instance for endpoint detection.

    1. In Cortex XDR, generate the API key.

      1. Under SettingsIntegrationsAPI Keys , click New Key to generate the API Key and API Key ID.

      2. Copy the server URL for your integration instance by clicking Copy URL from the API Keys page.

      3. In the Security Level field, select Advanced.

      4. In the Role field, select the appropriate role for your required actions, for example Instance Administrator.

      5. Click Save.

      6. Copy the API key.

      7. Copy the ID from the API keys table.

    2. In the Deployment Wizard, paste the API API Key and ID into the fetching integration settings and follow the list of What needs to be done .

  2. Set up your playbook to process incoming incidents.

    Use the Malware Investigation & Response Incident Handler playbook (recommended) with the out of the box settings. You can later modify it as needed to optimize your investigation. See Review the Malware Investigation & Response Incident Handler Playbook and Customize the Malware Investigation & Response Incident Handler Playbook.

  3. Set up any supporting integrations.

    For this tutorial, configure integration instance settings for:

    • Palo Alto Networks Wildfire v2 (forensics and malware analysis)

    • EWS V2 (mail sender)

    • Palo Alto Networks Autofocus v2 (data enrichment and threat intelligence)

    • VirusTotal (API v3) (data enrichment and threat intelligence)

  4. Enable your the Palo Alto Networks Cortex XDR - Investigation and Response integration instance to start fetching incidents.