ReversingLabs TitaniumCloud Content Pack Setup
Overview
This document describes how to setup and configure the ReversingLabs TitaniumCloud content pack for Palo Alto Cortex XSOAR.
The content pack contains the following XSOAR content:
- 1 integration
- 4 example playbooks
Prerequisites
To use the content pack, you must meet the following prerequisites:
- Have a ReversingLabs Spectra Intelligence (formerly TitaniumCloud) username and password.
Installation
To install the content pack:
- From the XSOAR menu, select "Marketplace":
- Next, enter "ReversingLabs" in the search bar and press the Enter key to search
- Select the "ReversingLabs TitaniumCloud" content pack
- Click "Install"
- After the installation is completed, open the XSOAR menu and click "Settings"
- From the Integrations menu, enter "ReversingLabs" in the search box, then hit the Enter key to search for integrations.
- Look for the ReversingLabs TitaniumCloud integration, then click "Add instance"
- In the instance settings window, fill out the following required fields:
- Name: provide a friendly name for the instance
- ReversingLabs TitaniumCloud URL: leave this value as the default (https://data.reversinglabs.com)
- Credentials: enter your Spectra Intelligence (formerly TitaniumCloud) username
- Password: enter your Spectra Intelligence (formerly TitaniumCloud) password
- Click the "Test" button to validate the instance
The ReversingLabs TitaniumCloud integration is now ready to be used!
Playbooks
The content pack comes with 4 example playbooks that can be used to enrich XSOAR incidents.
Manually Call a Playbook
Playbooks can be run manually to provide enrich as needed. In this example, a security incident has been created that contains a SHA1 file hash indicator. A ReversingLabs playbook will provide additional context for the file hash.
NOTE
This playbook currently requires the indicator value to be in the "File SHA1" field.
- From the incident view, click the "Work Plan" tab.
- Enter "ReversingLabs" in the playbook search.
- Navigate to the "War Room" tab to view the output of the playbook.