IBM Security QRadar SOAR

 View Only
  • 1.  How to read attachment in Resilient function ?

    Posted Fri January 13, 2023 09:37 AM
    I have incident and attachment id as inputs to function, how I can get attachment file itself parse its content?

    I know resilient_lib.get_file_attachment but my understanding is that this is for external scripts hitting resilient api

    ------------------------------
    Irek Romaniuk
    ------------------------------


  • 2.  RE: How to read attachment in Resilient function ?

    Posted Mon November 27, 2023 11:55 AM

    Did you maybe manage to figure out how to do this? I'm looking for a way to parse an attached email.



    ------------------------------
    Maria Čapkovska
    ------------------------------



  • 3.  RE: How to read attachment in Resilient function ?

    Posted Thu January 11, 2024 02:23 PM

    Do you know how to get attachment file itself parse its content? I met same requirement.



    ------------------------------
    Sheng Bo Feng
    ------------------------------



  • 4.  RE: How to read attachment in Resilient function ?

    Posted Thu January 11, 2024 02:23 PM

    Do you know how to get attachment file itself in SOAR script? I want to send it to sandbox for anysis.



    ------------------------------
    Sheng Bo Feng
    ------------------------------



  • 5.  RE: How to read attachment in Resilient function ?

    Posted Fri January 12, 2024 02:58 AM

    I'm not sure if this is what you meant, but in my email parsing script I have this snippet:

    This adds the attachments from an email in the attachments tab in the incident and then you can make a playbook with either automatic or manual activation from an attachment. I haven't tried sending an attachment to a sandbox yet but it does work with getting attachment hashes. 



    ------------------------------
    Maria Czapkowska
    ------------------------------