Cortex XSOAR Integration
Integration of AIR with Cortex XSOAR is possible via Plug-In.
Steps to Integrate
Step 1: Preparing API Token
Create a new API Token by clicking the Settings → API Tokens.
Give a Token Name.
Choose an expiration date.
Click Save and copy the token.
Step 2: Adding Integration to Cortex XSOAR
Sign in to Cortex XSOAR server.
Click “Marketplace” on the left bottom corner.
Search and install the Binalyze Integration to your instance.
Step 3: Setting up the Integration
Click “Settings” on the left bottom corner.
Find installed integration, and click “Add instance”
Fill in the AIR Server URL and API Key. Click “Test”, and you will see “Success”, which means Cortex XSOAR established the test connection with the AIR Server.
Save and Exit.
Usage
Isolation
You can use the integration in Automations, Playbooks, or War Room.
To execute an isolation task, write the following command at the bottom of the page:
To execute an acquisition task, write the following command at the bottom of the page:
Last updated