IBM QRadar SOAR

 View Only

Decrypt attachments outside Resilient

  • 1.  Decrypt attachments outside Resilient

    Posted Tue February 21, 2023 02:41 PM

    I would like to find out how to decrypt attachments inside OS i.e. two "dat" files in the example below. I believe 369755 is incident number. Please point me into documentation

    $ sudo ls -lh /crypt/attachments/org_301/INCIDENT/obj_369755
    -rw-rw----. 1 co3 res-attachments 480K Feb 15 17:35 ab8a6c77-37f4-4b4c-9296-13f1e6359a38.dat
    -rw-rw----. 1 co3 res-attachments 481K Feb 15 17:35 b51a0699-d6fa-4058-abeb-71037b18f95a.dat



    ------------------------------
    Irek Romaniuk
    ------------------------------