Skip to main content

Cortex XDR IOCs - Disable expired IOCs in XDR

This Playbook is part of the Cortex XDR by Palo Alto Networks Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.10.0 and later.

This is a sub-playbook of "Cortex XDR IOCs - Push new IOCs to XDR (Main)". This playbook disables indicators in Cortex XDR after they expire from Cortex XSOAR using a loop and querying on the "xdr_pushed" tag.


This playbook uses the following sub-playbooks, integrations, and scripts.


This playbook does not use any sub-playbooks.


Cortex XDR - IOC


  • Set
  • GetIndicatorsByQuery
  • DeleteContext
  • ReadFile


  • appendIndicatorField
  • xdr-iocs-disable

Playbook Inputs#

NameDescriptionDefault ValueRequired
batch_sizeThis parameter will set the batch size to be pushed into Cortex XDR with every iteration of the loop.4000Optional
queryThe query used to search for IOCs from Cortex XSOAR to be set as disabled in Cortex XDR. This query must include `tags:xdr_pushed` in order to work properly.Required

Playbook Outputs#

There are no outputs for this playbook.

Playbook Image#

Cortex XDR IOCs - Disable expired IOCs in XDR