implementing-soar-playbook-with-palo-alto-xsoar skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Build automated incident response playbooks in Cortex XSOAR (Demisto) Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/implementing-soar-playbook-with-palo-alto-xsoar/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-soar-playbook-with-palo-alto-xsoar, or copy the skill folder into ~/.claude/skills/implementing-soar-playbook-with-palo-alto-xsoar/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-soar-playbook-with-palo-alto-xsoar/SKILL.md

SKILL.md (verbatim)

name: implementing-soar-playbook-with-palo-alto-xsoar
description: Build automated incident response playbooks in Cortex XSOAR (Demisto)
  using its YAML playbook structure, integration commands, and task types to orchestrate
  phishing, malware, account-compromise, and DDoS response workflows across SOC tools.
  Use when authoring or wiring up an XSOAR playbook, adding custom XSOAR integration
  commands or Python automation scripts, or reducing manual SOC response time via
  orchestration.
domain: cybersecurity
subdomain: soc-operations
tags:
- xsoar
- soar
- palo-alto
- playbook
- automation
- incident-response
- orchestration
- cortex
mitre_attack:
- T1078
- T1685.002
- T1685.005
- T1566
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- DE.AE-02
- RS.MA-01
- DE.AE-06

Implementing SOAR Playbook with Palo Alto XSOAR

Overview

Cortex XSOAR (formerly Demisto) is Palo Alto Networks' Security Orchestration, Automation, and Response platform. Playbooks are the core automation engine in XSOAR, enabling SOC teams to automate repetitive incident response tasks. XSOAR provides 900+ prebuilt integration packs, 87 common playbooks, and a visual drag-and-drop editor for building custom workflows. Organizations using SOAR automation reduce mean time to respond (MTTR) by 80% on average.

When to Use

  • When deploying or configuring implementing soar playbook with palo alto xsoar capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Cortex XSOAR deployed (version 8.x or later, or XSOAR hosted)
  • Administrative access for playbook creation
  • Integration packs installed for relevant security tools
  • Incident types and layouts configured
  • API access to external tools (SIEM, EDR, TI platforms, ticketing)

Playbook Architecture

XSOAR Component Hierarchy

Incident Type (e.g., Phishing)
    |
    v
Incident Layout (UI display configuration)
    |
    v
Pre-Processing Rules (auto-classification, deduplication)
    |
    v
Playbook (automation logic)
    |-- Sub-Playbooks (modular reusable workflows)
    |-- Tasks (individual automation steps)
    |-- Conditional Tasks (decision branches)
    |-- Scripts (custom Python/JavaScript)
    |-- Integrations (external tool commands)
    |
    v
War Room (investigation timeline)
    |
    v
Closing Report

Playbook Task Types

Task Type Purpose Example
Standard Execute a command !ip ip=8.8.8.8
Conditional Branch logic If severity > high, escalate
Manual Require analyst input Approve containment action
Section Header Organize workflow "Enrichment Phase"
Data Collection Gather external data Ask user for additional details
Timer Wait for condition/time Wait 5 minutes then check

Building a Phishing Response Playbook

Step 1: Define Incident Type

incident_type: Phishing
playbook: Phishing Investigation - Full
severity_mapping:
  - condition: email contains executable attachment
    severity: high
  - condition: email from external domain with link
    severity: medium
  - condition: email reported by user
    severity: low
layout: Phishing Layout
sla: 60 minutes

Step 2: Playbook YAML Structure

id: phishing-investigation-full
version: -1
name: Phishing Investigation - Full
description: Automated phishing email investigation with enrichment, analysis, and response
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: start
    type: start
    nexttasks:
      '#none#':
      - "1"
  "1":
    id: "1"
    taskid: extract-indicators
    type: regular
    task:
      name: Extract Indicators from Email
      script: ParseEmailFiles
    nexttasks:
      '#none#':
      - "2"
      - "3"
      - "4"
  "2":
    id: "2"
    taskid: enrich-urls
    type: playbook
    task:
      name: URL Enrichment
      playbookName: URL Enrichment - Generic v2
  "3":
    id: "3"
    taskid: enrich-files
    type: playbook
    task:
      name: File Enrichment
      playbookName: File Enrichment - Generic v2
  "4":
    id: "4"
    taskid: enrich-ips
    type: playbook
    task:
      name: IP Enrichment
      playbookName: IP Enrichment - Generic v2
  "5":
    id: "5"
    taskid: determine-verdict
    type: condition
    task:
      name: Is Email Malicious?
    conditions:
      - label: "yes"
        condition:
          - - operator: isEqualString
              left: DBotScore.Score
              right: "3"
      - label: "no"
    nexttasks:
      "yes":
      - "6"
      "no":
      - "9"
  "6":
    id: "6"
    taskid: block-sender
    type: regular
    task:
      name: Block Sender Domain
      script: '|||o365-mail-block-sender'
    scriptarguments:
      sender_address: ${incident.emailfrom}
  "7":
    id: "7"
    taskid: search-mailboxes
    type: regular
    task:
      name: Search and Delete from All Mailboxes
      script: '|||o365-mail-purge-compliance-search'
    scriptarguments:
      query: "from:${incident.emailfrom} subject:${incident.emailsubject}"
  "8":
    id: "8"
    taskid: notify-user
    type: regular
    task:
      name: Notify Reporting User
      script: '|||send-mail'
    scriptarguments:
      to: ${incident.reporter}
      subject: "Phishing Report Confirmed - Action Taken"
      body: "The email you reported has been confirmed as malicious and removed."
  "9":
    id: "9"
    taskid: close-incident
    type: regular
    task:
      name: Close Incident
      script: closeInvestigation

Step 3: Integration Commands

Email Analysis

!ParseEmailFiles entryid=${File.EntryID}
!rasterize url=${URL.Data} type=png

Threat Intelligence Enrichment

!url url=${URL.Data}
!file file=${File.SHA256}
!ip ip=${IP.Address}
!domain domain=${Domain.Name}

Containment Actions

!o365-mail-block-sender sender=${incident.emailfrom}
!o365-mail-purge-compliance-search query="from:${incident.emailfrom}"
!pan-os-block-ip ip=${IP.Address} log_forwarding="default"
!cortex-xdr-isolate-endpoint endpoint_id=${Endpoint.ID}

Ticketing Integration

!jira-create-issue summary="Phishing Incident - ${incident.id}" type="Incident" priority="High"
!servicenow-create-ticket short_description="Security Incident" urgency="2"

Common SOC Playbook Templates

1. Malware Investigation Playbook

Trigger: Malware alert from EDR
Steps:
  1. Extract file hash, process details, host info
  2. Enrich hash via VirusTotal, Hybrid Analysis
  3. Check if file is on allowlist
  4. If malicious:
     a. Isolate endpoint via EDR
     b. Block hash on all endpoints
     c. Search for hash across environment
     d. Create incident ticket
  5. If clean: Close as false positive

2. Account Compromise Playbook

Trigger: Impossible travel or suspicious login alert
Steps:
  1. Get user details from Active Directory
  2. Get login history for past 30 days
  3. Check for impossible travel (geo-distance vs time)
  4. Check for known VPN/proxy IP
  5. If compromised:
     a. Disable AD account
     b. Revoke all OAuth tokens
     c. Reset MFA
     d. Notify user's manager
     e. Search for lateral movement
  6. If false positive: Document and close

3. DDoS Mitigation Playbook

Trigger: Network anomaly alert
Steps:
  1. Verify traffic spike from network monitoring
  2. Identify source IPs and geolocation
  3. Check if source IPs are known botnets
  4. Implement rate limiting on WAF
  5. If sustained attack:
     a. Enable upstream DDoS protection
     b. Activate CDN scrubbing
     c. Notify ISP if needed
  6. Monitor and document

Custom XSOAR Scripts

Python Automation Script Example

# XSOAR Automation Script: CalculateRiskScore
def calculate_risk_score():
    """Calculate composite risk score for an incident."""
    severity = demisto.incident().get('severity', 0)
    indicator_count = len(demisto.get(demisto.context(), 'DBotScore', []))
    malicious_count = len([
        i for i in demisto.get(demisto.context(), 'DBotScore', [])
        if i.get('Score', 0) == 3
    ])

    base_score = severity * 20
    indicator_boost = min(indicator_count * 5, 25)
    malicious_boost = malicious_count * 15

    risk_score = min(100, base_score + indicator_boost + malicious_boost)

    return_results(CommandResults(
        outputs_prefix='RiskScore',
        outputs={'Score': risk_score, 'Level': 'Critical' if risk_score > 80 else 'High' if risk_score > 60 else 'Medium'},
        readable_output=f'Risk Score: {risk_score}/100'
    ))

calculate_risk_score()

Playbook Performance Metrics

Metric Before SOAR After SOAR Improvement
Phishing MTTR 45 min 5 min 89% reduction
Malware MTTR 60 min 8 min 87% reduction
Account Compromise MTTR 30 min 4 min 87% reduction
Alerts Handled per Shift 50 200+ 300% increase
False Positive Handling 10 min 30 sec 95% reduction

References

Other files in this skill

assets/template.md (verbatim)

XSOAR Playbook Design Template

Playbook Metadata

Field Value
Playbook Name
Version
Incident Type
Description
Author
Created Date
SLA Target

Playbook Logic Flow

Phase 1: Enrichment

  • Extract indicators from alert/incident
  • Enrich IPs via threat intelligence
  • Enrich domains via threat intelligence
  • Enrich file hashes via sandbox/TI
  • Query asset database for affected hosts
  • Query identity store for affected users

Phase 2: Analysis

  • Determine verdict (malicious/benign/unknown)
  • Calculate risk score
  • Check against allowlists/blocklists
  • Correlate with existing incidents

Phase 3: Response

  • Manual approval gate for destructive actions
  • Containment actions
  • Eradication actions
  • Recovery actions

Phase 4: Documentation

  • Update incident fields
  • Generate closing report
  • Update ticketing system
  • Notify stakeholders

Integrations Required

Integration Commands Used Purpose

Error Handling

Task Error Type Handling

Testing Checklist

  • Test with known malicious sample
  • Test with known benign sample
  • Test error handling paths
  • Verify manual gates function correctly
  • Confirm notifications are sent
  • Validate closing report content

references/api-reference.md (verbatim)

API Reference: Palo Alto Cortex XSOAR SOAR Playbook

Libraries Used

Library Purpose
requests HTTP client for XSOAR REST API
json Parse incident and playbook payloads
os Read XSOAR_URL and XSOAR_API_KEY environment variables

Installation

pip install requests

Authentication

import requests
import os

XSOAR_URL = os.environ["XSOAR_URL"]  # e.g., "https://xsoar.example.com"
headers = {
    "Authorization": os.environ["XSOAR_API_KEY"],
    "Content-Type": "application/json",
    "Accept": "application/json",
}

REST API Endpoints

Method Endpoint Description
POST /incident Create a new incident
POST /incident/search Search incidents
GET /incident/{id} Get incident details
POST /incident/close Close an incident
POST /playbook/search Search playbooks
GET /playbook/{id} Get playbook details
POST /entry/execute/{playbook} Run a playbook on an incident
POST /automation/search Search automation scripts
POST /automation/execute Execute an automation command
GET /settings/integration/search List integrations
POST /indicators/search Search indicators (IOCs)
POST /indicators Create indicators
GET /health System health check
GET /user Get current user info

Core Operations

Create an Incident

incident = {
    "name": "Phishing Alert - Suspicious Email",
    "type": "Phishing",
    "severity": 3,  # 0=Unknown, 1=Low, 2=Medium, 3=High, 4=Critical
    "labels": [
        {"type": "Email/from", "value": "attacker@evil.com"},
        {"type": "Email/subject", "value": "Urgent: Verify Account"},
    ],
    "customFields": {
        "sourceemail": "attacker@evil.com",
        "reportedby": "soc-analyst-1",
    },
}
resp = requests.post(
    f"{XSOAR_URL}/incident",
    headers=headers,
    json=incident,
    timeout=30,
)
incident_id = resp.json()["id"]

Search Incidents

search = {
    "filter": {
        "query": "type:Phishing AND severity:>=3",
        "period": {"fromValue": "7 days ago"},
    },
    "page": 0,
    "size": 50,
}
resp = requests.post(
    f"{XSOAR_URL}/incident/search",
    headers=headers,
    json=search,
    timeout=30,
)
incidents = resp.json().get("data", [])

Execute a Playbook on an Incident

resp = requests.post(
    f"{XSOAR_URL}/entry/execute/{playbook_name}",
    headers=headers,
    json={"investigationId": incident_id},
    timeout=30,
)

Search Playbooks

resp = requests.post(
    f"{XSOAR_URL}/playbook/search",
    headers=headers,
    json={
        "query": "name:*phishing*",
        "page": 0,
        "size": 20,
    },
    timeout=30,
)
playbooks = resp.json().get("playbooks", [])
for pb in playbooks:
    print(f"{pb['name']} — tasks: {len(pb.get('tasks', {}))}")

Run an Automation Command

resp = requests.post(
    f"{XSOAR_URL}/automation/execute",
    headers=headers,
    json={
        "script": "!ip ip=8.8.8.8",
        "investigationId": incident_id,
    },
    timeout=60,
)

Search Indicators (IOCs)

resp = requests.post(
    f"{XSOAR_URL}/indicators/search",
    headers=headers,
    json={
        "query": "type:IP AND verdict:malicious",
        "size": 100,
    },
    timeout=30,
)
indicators = resp.json().get("iocObjects", [])

Check Integration Health

resp = requests.get(
    f"{XSOAR_URL}/settings/integration/search",
    headers=headers,
    timeout=30,
)
integrations = resp.json().get("instances", [])
for inst in integrations:
    status = "healthy" if inst.get("enabled") else "disabled"
    print(f"{inst['name']} — brand: {inst['brand']} — {status}")

Output Format

{
  "id": "12345",
  "name": "Phishing Alert - Suspicious Email",
  "type": "Phishing",
  "severity": 3,
  "status": 1,
  "created": "2025-01-15T10:30:00Z",
  "phase": "Triage",
  "playbooks": ["Phishing Investigation - Generic v2"],
  "labels": [
    {"type": "Email/from", "value": "attacker@evil.com"}
  ]
}

references/standards.md (verbatim)

Standards and References - SOAR Playbook with XSOAR

SOAR Industry Standards

Gartner SOAR Definition

Security Orchestration, Automation and Response (SOAR) combines:

  • Security Orchestration and Automation (SOA)
  • Security Incident Response Platforms (SIRP)
  • Threat Intelligence Platforms (TIP)

NIST SP 800-61 Rev 2 - Incident Handling

SOAR playbooks implement the NIST incident response lifecycle:

  1. Preparation
  2. Detection and Analysis
  3. Containment, Eradication, and Recovery
  4. Post-Incident Activity

MITRE ATT&CK for Response

Playbooks should map containment actions to specific MITRE ATT&CK techniques being mitigated.

XSOAR Architecture Standards

Content Pack Structure

content-pack/
  Integrations/
    integration-name/
      integration-name.py
      integration-name.yml
      integration-name_test.py
  Playbooks/
    playbook-name.yml
  Scripts/
    script-name/
      script-name.py
      script-name.yml
  IncidentTypes/
  Layouts/
  Classifiers/

Playbook Design Principles

  1. Modular sub-playbooks for reusability
  2. Error handling on every integration command
  3. Manual review gates for destructive actions
  4. SLA timers for response targets
  5. Closing report generation for documentation

Integration Best Practices

Integration Category Examples Usage
SIEM Splunk, Sentinel, QRadar Alert ingestion, log queries
EDR CrowdStrike, Defender, SentinelOne Endpoint isolation, hash blocking
Email Security O365, Proofpoint, Mimecast Email analysis, sender blocking
Threat Intelligence VirusTotal, MISP, OTX IOC enrichment
Ticketing Jira, ServiceNow Incident tracking
Communication Slack, Teams, PagerDuty Notifications, approvals

references/workflows.md (verbatim)

Workflows - SOAR Playbook with XSOAR

Playbook Development Lifecycle

1. Identify Manual Process
   - Document current analyst workflow
   - Measure time per step
   |
   v
2. Design Playbook Logic
   - Map decision points
   - Identify automation candidates
   - Define manual review gates
   |
   v
3. Build in XSOAR
   - Create playbook in visual editor
   - Configure integration commands
   - Add conditional branches
   - Write custom scripts if needed
   |
   v
4. Test with Sample Data
   - Create test incidents
   - Verify each task executes correctly
   - Test error handling paths
   |
   v
5. Pilot in Production
   - Run on subset of incidents
   - Compare automated vs manual results
   - Gather analyst feedback
   |
   v
6. Full Deployment
   - Enable for all matching incidents
   - Monitor playbook performance
   - Track MTTR improvements
   |
   v
7. Continuous Improvement
   - Review failed tasks monthly
   - Update integrations as needed
   - Add new sub-playbooks

Incident Lifecycle in XSOAR

Alert Ingestion (SIEM/EDR/Email)
    |
    v
Pre-Processing (Classification, Deduplication)
    |
    v
Incident Created (Type, Severity, Owner assigned)
    |
    v
Playbook Triggered Automatically
    |
    +-- Enrichment Phase (parallel)
    |   |-- IP/Domain/Hash lookup
    |   |-- User/Asset lookup
    |   |-- TI feed correlation
    |
    +-- Analysis Phase
    |   |-- Verdict determination
    |   |-- Risk scoring
    |
    +-- Response Phase
    |   |-- Containment actions (auto or manual approval)
    |   |-- Eradication steps
    |   |-- Recovery procedures
    |
    +-- Documentation Phase
    |   |-- War room timeline
    |   |-- Closing report
    |   |-- Ticket update
    |
    v
Incident Closed

ROI Measurement Workflow

Before SOAR:
  Count manual hours per incident type per month

After SOAR:
  Measure automated handling time
  Calculate: Saved Hours = Manual Hours - Automated Hours
  Calculate: ROI = (Saved Hours * Analyst Hourly Cost) / SOAR License Cost

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.