Hello guys!
i have a scenario to trigger playbook to extract IOCs from file, so i follow:
1- create an indicator with type file
2- import file to indicator module
3- write playbook to extract IOCs
Now, i want to import that file from MAIL to fully automated my whole playbook
anyone has an idea to do that.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello, yes that process is possible. Where are these emails coming from? If you're pulling from something like exchange or graph mail, files will automatically be pulled out from the emails and created as IOC's.
I have integrated with Exchange, I need to import them from the attached file.
please, mention the steps to have it done.
Thanks in advance!
Have you ran through the data ingestion wizard for exchange? Open the connector for Exchange, and Click "Configure Data Ingestion". Finish the rest of the steps in the wizard and then see if you start to see IOC's being created with attachments from your emails.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.