<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic O365 Integration for SOAR (Ingest emails?) in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/O365-Integration-for-SOAR-Ingest-emails/m-p/570195#M711</link>
    <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;Is there any app, method or guidance for ingesting emails directly form a O365 mailbox?&lt;BR /&gt;&lt;BR /&gt;So a use case for us would be:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have a mailbox which receives Phishing Reports&lt;/LI&gt;&lt;LI&gt;SOAR logs onto the mailbox, downloads the unread mails + turns them into "Events"&lt;/LI&gt;&lt;LI&gt;Playbook begins working on these events - checking URL's, checking to/from addresses, maybe further triage based on o365 logs or whatever&lt;/LI&gt;&lt;LI&gt;Detonate mail/attachments in Sandbox, capture networks/process/file related results, e.g. Cuckoo&lt;/LI&gt;&lt;LI&gt;Playbook decides if mail is okay, suspicious, or phishing (or integrates with another tool to get that information - e.g. Proofpoint&lt;/LI&gt;&lt;LI&gt;All information made available to the analyst who reviews&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In order to kick these off we'd need to be able to INGEST the email to begin with, but don't see any way to do that at present.&lt;BR /&gt;&lt;BR /&gt;If it doesn't exist I will write my own app for it - but don't want to reinvent the wheel if I don't have to &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Oct 2021 10:49:48 GMT</pubDate>
    <dc:creator>EdgeSync</dc:creator>
    <dc:date>2021-10-08T10:49:48Z</dc:date>
    <item>
      <title>O365 Integration for SOAR (Ingest emails?)</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/O365-Integration-for-SOAR-Ingest-emails/m-p/570195#M711</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;Is there any app, method or guidance for ingesting emails directly form a O365 mailbox?&lt;BR /&gt;&lt;BR /&gt;So a use case for us would be:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have a mailbox which receives Phishing Reports&lt;/LI&gt;&lt;LI&gt;SOAR logs onto the mailbox, downloads the unread mails + turns them into "Events"&lt;/LI&gt;&lt;LI&gt;Playbook begins working on these events - checking URL's, checking to/from addresses, maybe further triage based on o365 logs or whatever&lt;/LI&gt;&lt;LI&gt;Detonate mail/attachments in Sandbox, capture networks/process/file related results, e.g. Cuckoo&lt;/LI&gt;&lt;LI&gt;Playbook decides if mail is okay, suspicious, or phishing (or integrates with another tool to get that information - e.g. Proofpoint&lt;/LI&gt;&lt;LI&gt;All information made available to the analyst who reviews&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In order to kick these off we'd need to be able to INGEST the email to begin with, but don't see any way to do that at present.&lt;BR /&gt;&lt;BR /&gt;If it doesn't exist I will write my own app for it - but don't want to reinvent the wheel if I don't have to &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 10:49:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/O365-Integration-for-SOAR-Ingest-emails/m-p/570195#M711</guid>
      <dc:creator>EdgeSync</dc:creator>
      <dc:date>2021-10-08T10:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: O365 Integration for SOAR (Ingest emails?)</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/O365-Integration-for-SOAR-Ingest-emails/m-p/570199#M712</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239379"&gt;@EdgeSync&lt;/a&gt;&amp;nbsp;there is an O365 App already that will be able to poll the inbox and create the necessary events:&lt;/P&gt;&lt;P&gt;&lt;A href="https://my.phantom.us/4.10/docs/app_reference/phantom_office365" target="_blank" rel="noopener"&gt;https://my.phantom.us/4.10/docs/app_reference/phantom_office365&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actions:&lt;BR /&gt;&lt;A target="_blank"&gt;&lt;SPAN class="link"&gt;run query&lt;/SPAN&gt;&amp;nbsp;&lt;/A&gt;&lt;SPAN&gt;- Search emails&lt;BR /&gt;&lt;/SPAN&gt;&lt;A target="_blank"&gt;&lt;SPAN class="link"&gt;delete email&lt;/SPAN&gt;&amp;nbsp;&lt;/A&gt;&lt;SPAN&gt;- Delete emails&lt;BR /&gt;&lt;/SPAN&gt;&lt;A target="_blank"&gt;&lt;SPAN class="link"&gt;copy email&lt;/SPAN&gt;&amp;nbsp;&lt;/A&gt;&lt;SPAN&gt;- Copy an email to a folder&lt;BR /&gt;&lt;/SPAN&gt;&lt;A&gt;&lt;SPAN class="link"&gt;move email&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;- Move an email to a folder&lt;BR /&gt;&lt;/SPAN&gt;&lt;A&gt;&lt;SPAN class="link"&gt;block sender&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;- Add the sender email into the block list&lt;/SPAN&gt;&lt;BR /&gt;&lt;A&gt;&lt;SPAN class="link"&gt;unblock sender&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;- Remove the sender email from the block list&lt;/SPAN&gt;&lt;BR /&gt;&lt;A&gt;&lt;SPAN class="link"&gt;get email&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;- Get an email from the server&lt;/SPAN&gt;&lt;BR /&gt;&lt;A&gt;&lt;SPAN class="link"&gt;list addresses&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;- Get the email addresses that make up a Distribution List&lt;/SPAN&gt;&lt;BR /&gt;&lt;A&gt;&lt;SPAN class="link"&gt;lookup email&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;- Resolve an Alias name or email address, into mailboxes&lt;/SPAN&gt;&lt;BR /&gt;&lt;A&gt;&lt;SPAN class="link"&gt;update email&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;- Update an email on the server&lt;/SPAN&gt;&lt;BR /&gt;&lt;A&gt;&lt;SPAN class="link"&gt;on poll&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;- Action handler for the ingest functionality&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The on-poll action is run outside of a playbook and can be scheduled in the asset settings under the "ingest setting" tab when creating the asset to communicate with the 365 servers.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All you need is a playbook set to work on the label you assign to the ingested email events and if you want it to run automatically just set it to active and watch the magic &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Apps are also now available on splunkbase now too:&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/5829/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/5829/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 11:46:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/O365-Integration-for-SOAR-Ingest-emails/m-p/570199#M712</guid>
      <dc:creator>phanTom</dc:creator>
      <dc:date>2021-10-08T11:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: O365 Integration for SOAR (Ingest emails?)</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/O365-Integration-for-SOAR-Ingest-emails/m-p/570208#M713</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222170"&gt;@phanTom&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;This is an excellent start, thank you very much. I was searching in SOAR App's window and it's not there, and also checked splunkbase, but found nothing.&lt;BR /&gt;&lt;BR /&gt;Best,&lt;BR /&gt;&lt;BR /&gt;EdgeSync&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 12:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/O365-Integration-for-SOAR-Ingest-emails/m-p/570208#M713</guid>
      <dc:creator>EdgeSync</dc:creator>
      <dc:date>2021-10-08T12:36:26Z</dc:date>
    </item>
  </channel>
</rss>

