.png)
Cortex XSOAR Integration Guide
Integrate Cortex XSOAR with enterprise systems through versioned REST APIs, selected webhook-style mechanisms, API-key authentication, and Martini workflows.
Cortex XSOAR integration options at a glance
Cortex XSOAR provides versioned REST APIs for creating, searching, updating, and closing Incidents; managing Indicators; retrieving investigation data; monitoring Jobs; and interacting with supported Playbook and automation operations. Selected integrations also support webhook-style ingestion or outbound callbacks, although coverage varies by event and resource. Bulk, asynchronous, file, and entry operations are available for applicable use cases and should be verified against the deployed version. Martini can consume these APIs, receive external alerts through a controlled API, transform payloads, apply validation and business rules, and route results to downstream systems. API keys can be stored securely as Martini secrets.
Common Cortex XSOAR integration patterns
Common Cortex XSOAR data objects used in integrations
Authentication and security considerations
API-key authentication
Cortex XSOAR REST API access is generally authenticated with an API key in the Authorization header. The key inherits the permissions of its associated Cortex XSOAR user.
Least privilege and secret protection
- Use a dedicated service account with only the roles required by the integration.
- Store the API key in Martini Secrets Management rather than in workflow definitions or mappings.
- Use HTTPS, validate the target tenant or server URL, and rotate keys according to policy.
- Ensure error handling and logs do not expose authorization headers, evidence, or sensitive War Room content.
Version-aware security
Confirm tenant-specific headers, routing requirements, endpoint behavior, and permissions against the deployed Cortex XSOAR version. OAuth 2.0, JWT bearer authentication, and Basic Authentication should not be assumed for the XSOAR REST API unless separately documented for the deployment.
Operational considerations for Cortex XSOAR integrations
Version and schema differences
Cortex XSOAR API paths, request bodies, pagination behavior, bulk limits, Job responses, and file operations can vary by version. Validate the deployed version and keep mappings configurable for custom Incident fields, layouts, classifications, and integration outputs.
Pagination and rate control
Use server-side filters, time windows, explicit limits, and pagination for Incident and Indicator searches. Control concurrency and use exponential backoff for transient failures because effective capacity depends on the deployment, endpoint, and other analyst or automation activity.
Idempotency and asynchronous work
Use stable source alert IDs, Cortex XSOAR Incident IDs, or correlation keys to distinguish new Incidents, updates, duplicate deliveries, and replays. Treat accepted Job, Playbook, investigation, or bulk requests as potentially incomplete and poll the documented status mechanism.
Evidence and observability
- Separate Incident metadata, War Room entries, file metadata, and file contents.
- Apply content-type, size, retention, and malware-handling controls to evidence.
- Record sanitized correlation IDs, Incident IDs, Job IDs, HTTP status codes, and processing outcomes.
- Test authentication, pagination, retries, duplicate events, custom fields, and version-specific responses before production release.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration beyond point-to-point calls
Martini provides a reusable workflow layer for receiving alerts, calling Cortex XSOAR APIs, enriching Indicators, synchronizing Incidents, monitoring asynchronous Jobs, and distributing controlled response results. This avoids duplicating authentication, mapping, retry, and correlation logic across individual scripts.
Controlled APIs and transformations
Martini can expose a normalized API to internal applications while keeping Cortex XSOAR-specific credentials and request details inside reusable workflows. It can validate payloads, transform different alert schemas, apply state and routing rules, and limit sensitive investigation content before it reaches downstream systems.
Maintainability and operations
- Centralize environment-specific URLs, API keys, and configuration.
- Use explicit mappings for status, severity, ownership, custom fields, and identifiers.
- Apply consistent retries, checkpoints, idempotency, and error classification.
- Monitor workflow execution and troubleshoot version-dependent API behavior without embedding integration logic in every application.