<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cofense Report Phishing - Extract zip files in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Cofense-Report-Phishing-Extract-zip-files/m-p/479923#M249</link>
    <description>&lt;P&gt;'deflate item' is available in 'phantom app'(Phantom App for Phantom)&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jan 2020 06:47:17 GMT</pubDate>
    <dc:creator>ansusabu</dc:creator>
    <dc:date>2020-01-08T06:47:17Z</dc:date>
    <item>
      <title>Cofense Report Phishing - Extract zip files</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Cofense-Report-Phishing-Extract-zip-files/m-p/479920#M246</link>
      <description>&lt;P&gt;We currently use Cofense Report Phishing to provide users with the ability to report potential phishing emails. When ingesting into Phantom these don't work as there isn't any method to extract and analyse the attached zip file which contains the original email message and any associated attachments.&lt;/P&gt;
&lt;P&gt;Does anyone have any experience with this product and any scripts or playbooks that would work to automate analysis?&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 17:17:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Cofense-Report-Phishing-Extract-zip-files/m-p/479920#M246</guid>
      <dc:creator>maxywalker1</dc:creator>
      <dc:date>2020-06-07T17:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cofense Report Phishing - Extract zip files</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Cofense-Report-Phishing-Extract-zip-files/m-p/479921#M247</link>
      <description>&lt;P&gt;The Phantom App for Phantom includes an action called 'deflate item' which can be used to extract the contents of a .zip file into the Vault of the same Container the .zip was ingested into, this can be automated upon ingest using a Playbook:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://my.phantom.us/4.6/docs/app_reference/phantom_phantom#deflate-item"&gt;https://my.phantom.us/4.6/docs/app_reference/phantom_phantom#deflate-item&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you'd like to do more advanced operation, that's where you would want to look at using custom Python code - the 'zipfile' python library can be used to open or manipulate a .zip file as needed within a Playbook.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 19:05:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Cofense-Report-Phishing-Extract-zip-files/m-p/479921#M247</guid>
      <dc:creator>cblumer_splunk</dc:creator>
      <dc:date>2020-01-07T19:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cofense Report Phishing - Extract zip files</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Cofense-Report-Phishing-Extract-zip-files/m-p/479922#M248</link>
      <description>&lt;P&gt;Thanks for that, I have started creating a playbook for this (to feed into another existing playbook) but don't seem to have any applications that support the actions 'get attachment' or 'deflate item'.&lt;/P&gt;

&lt;P&gt;Is there any way to actually search for applications by supported actions?&lt;/P&gt;

&lt;P&gt;There doesn't seem to be any clear information out there having looked through the documentation and splunkbase, but maybe I am not looking in the right places.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 22:45:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Cofense-Report-Phishing-Extract-zip-files/m-p/479922#M248</guid>
      <dc:creator>maxywalker1</dc:creator>
      <dc:date>2020-01-07T22:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cofense Report Phishing - Extract zip files</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Cofense-Report-Phishing-Extract-zip-files/m-p/479923#M249</link>
      <description>&lt;P&gt;'deflate item' is available in 'phantom app'(Phantom App for Phantom)&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 06:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Cofense-Report-Phishing-Extract-zip-files/m-p/479923#M249</guid>
      <dc:creator>ansusabu</dc:creator>
      <dc:date>2020-01-08T06:47:17Z</dc:date>
    </item>
  </channel>
</rss>

