# demisto/content

Demisto is now Cortex XSOAR. Automate and orchestrate your Security Operations with Cortex XSOAR's ever-growing Content Repository. Pull Requests are always welcome and highly appreciated!

Repository: https://github.com/demisto/content
Canonical: https://ross.abutalabs.com/products/demisto-content
Homepage: https://xsoar.pan.dev/
Language: Python
License: MIT
License Family: permissive
Topics: xsoar-content, active-repository
Last push: 2026-09-03T00:22:53+00:00

## Health v2 (maintenance only)
Score: 68/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 100, release rhythm 8, longevity 100
- inputs: {"age_days": 3740, "days_push": 0, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1304, forks 1985 (observed 2026-09-03T02:15:11.271088+00:00)

## What it is
The official content repository for Cortex XSOAR (formerly Demisto), a security orchestration, automation and response (SOAR) platform. It contains a large collection of community- and vendor-contributed playbooks, integrations, automation scripts, incident layouts, and report templates packaged as Content Packs.

## Use cases
- automate incident response playbooks in a SOC
- integrate security products into a SOAR workflow
- find prebuilt playbooks for phishing or threat intel triage
- contribute a new integration pack for a security product
- enrich indicators from threat intelligence feeds
- push incidents from Splunk into XSOAR
- automate user provisioning with identity lifecycle management

## When to choose
- you run Cortex XSOAR and want ready-made playbooks and integrations
- you are a security vendor building a certified pack for the XSOAR Marketplace
- you want community-maintained SOAR automation content to customize
- you need reference examples for writing XSOAR integrations and scripts

## When to avoid
- you need a standalone SOAR engine - this repo is content, not the platform itself
- you use a different SOAR product like Splunk SOAR without porting effort
- you want a general-purpose workflow automation tool outside security operations

## Facets
- artifact type: plugin
- maturity: active
- function: security, workflow-automation, developer-tools
- domain: security, developer-tools
- platform: python, self-hosted, cloud
- tags: soar, xsoar, demisto, playbooks, content-packs, incident-response, security-orchestration, integrations, soc, automation, docker

## Member repositories
- demisto/content (main) score 68

## Provenance
- Observed fields: from GitHub, fetched 2026-09-03T02:15:11.271088+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:51:07.409241+00:00, confidence not recorded.
  - readme: https://github.com/demisto/content (fetched 2026-09-03T02:15:11.271088+00:00, sha 1ffb55efd662)
  - homepage: https://xsoar.pan.dev/ (fetched 2026-08-29T12:09:18.812089+00:00, sha 49a5621a6a70)
  - site_page: https://xsoar.pan.dev/docs/welcome (fetched 2026-08-29T12:09:18.820957+00:00, sha 2cb82919b4c9)
  - site_page: https://xsoar.pan.dev/docs/reference/articles (fetched 2026-08-29T12:09:18.823055+00:00, sha b5cc40d37979)
  - site_page: https://xsoar.pan.dev/docs/reference/index (fetched 2026-08-29T12:09:18.825245+00:00, sha 3034941cb892)
  - site_page: https://xsoar.pan.dev/docs/partners/why-xsoar (fetched 2026-08-29T12:09:18.832604+00:00, sha bdf2ca2c010c)
  - site_page: https://xsoar.pan.dev/docs/partners/become-a-tech-partner (fetched 2026-08-29T12:09:18.835713+00:00, sha 722132f29812)
  - site_page: https://xsoar.pan.dev/docs/partners/adopt (fetched 2026-08-29T12:09:18.838293+00:00, sha be00c9a53e95)
  - site_page: https://xsoar.pan.dev/docs/partners/certification (fetched 2026-08-29T12:09:18.840291+00:00, sha 28767e7c8019)
  - site_page: https://xsoar.pan.dev/docs/partners/office-hours (fetched 2026-08-29T12:09:18.841905+00:00, sha 9bf007865462)
- Data as of 2026-08-30T08:39:29.467469+00:00.
