We’re planning some file enrichment / manipulation in a SOAR playbook and it looks like we can “get the file on the SOAR case wall.” Where is this file actually?
Example - using the Gmail integration and able to put eml file on wall.
Context is what if the file is malicious - what’s in the immediate environs of the file - i.e. what’s the blast radius?
