Palo Alto Networks Certified Security Automation Engineer (PCSAE)Automation and OrchestrationMedium
A security analyst is investigating a phishing alert in Cortex XSOAR. The playbook has automatically extracted URLs and file hashes from the phishing email. To determine if these indicators are malicious, the analyst needs to query multiple external threat intelligence sources (e.g., VirusTotal, URLhaus) and then aggregate the results to make an informed decision. Which XSOAR playbook command or function is best suited for executing these external queries and collecting their results?
- AexecuteCommand()
- BsetIncident()
- C!searchIndicators
- Ddemisto.results()
Show answer & explanationAnswer & explanation
Correct answer: A. executeCommand()
The `executeCommand()` function (or `!command` in the CLI/War Room) is used within playbooks to run integration commands, such as querying external threat intelligence sources like VirusTotal or URLhaus, and collecting the results for further processing.
Why the other options are wrong
- B. `setIncident()` is used to update incident fields, not to execute external queries.
- C. `!searchIndicators` is a specific command for searching indicators within XSOAR's own database, not for querying external sources via integrations.
- D. `demisto.results()` is used to output data from a script or command to the War Room or incident context, not to execute external queries.
Cortex XSOAR executeCommand()
A playbook function (or CLI equivalent `!command`) used to run integration commands, allowing XSOAR to interact with external security tools and services.
- Executes integration commands.
- Interacts with external tools (e.g., TI platforms).
- Retrieves results for playbook processing.
Memory trick: EXECUTE that COMMAND to get external info!