Skip to main content

ETD XSOAR Connector

Download With Dependencies

Cisco Email Threat Defense (ETD) Connector fetches message events and creates incidents, allowing analysts to reclassify email verdicts and perform remediation actions.

Cisco Email Threat Defense (ETD) Cortex XSOAR Connector

Overview

The Cisco Email Threat Defense (ETD) Cortex XSOAR Connector enables security teams to ingest Cisco ETD message events into Cortex XSOAR and automate email threat investigation and response.

Organizations using Cisco ETD can automatically create incidents for suspicious and malicious emails, allowing analysts to investigate threats, reclassify email verdicts, and perform remediation actions such as moving messages to quarantine, junk, inbox, trash, or delete

Use Cases

  • Fetch malicious and suspicious email events from Cisco ETD.

  • Create incidents in Cortex XSOAR for ETD email threats.

  • Reclassifies email verdicts.

  • Remediate emails by moving messages to different folders.

  • Support analyst-driven email investigation and response workflows.

What does this pack do?

Integration

ETDXsoarConnector fetches Cisco ETD message events and creates incidents in Cortex XSOAR.

ETDXsoarConnector

Fetches Cisco ETD message events and creates incidents in Cortex XSOAR.

Incident Type

ETD Malicious Email

Custom incident type used for Cisco ETD email incidents.

Incident Fields

ETD Message ID

Stores the Cisco ETD Message ID required for email remediation and reclassification actions.

Playbook

ETD Email Reclassification and Remediation**

Allows analysts to review ETD email incidents and perform remediation and reclassification actions.

Supported Reclassification Actions

  • bec

  • scam

  • malicious

  • phishing

  • spam

  • graymail

  • neutral

Supported Remediation Actions

  • quarantine

  • inbox

  • junk

  • trash

  • delete

Requirements

Cortex XSOAR Version

  • 6.10.0

Cisco ETD Requirements

  • Cisco Email Threat Defense tenant

  • Valid API credentials

  • API access enabled

Workflow

Incident Creation

  1. Cisco ETD generates a message event.

  2. The integration fetches the event.

  3. Cortex XSOAR creates an ETD Malicious Email incident.

Incident Response

  1. Analyst opens the incident.

  2. Analyst runs the ETD Email Reclassification and Remediation playbook.

  3. Analyst selects a new verdict and remediation action.

  4. Cortex XSOAR submits the action to Cisco ETD.

Author

Nusummit

PUBLISHER

PLATFORMS

Cortex XSOAR

INFO

Supported ByCommunity
CreatedAugust 5, 2026
Last ReleaseAugust 5, 2026
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
By downloading or using Marketplace content, you agree to the applicable Terms of Use and End User License Agreement. Third-party content is provided by its publisher, and Palo Alto Networks does not warrant, endorse, support, or assume responsibility for content not expressly identified as owned by Palo Alto Networks.