> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/exposure-management/exposure-management-command-center.md).

# Exposure Management Command Center

The Exposure Management Command Center dashboard provides a dynamic, overall view of your exposure management operation with visualizations, key performance indicators, and actionable data that is useful to both executives and vulnerability management teams.

You can click on many elements in the command center to drill down to more focused dashboards or pages displaying data that is filtered by your selection.

![command\_center.png](/files/X4MUDCosrZ0zR6MrE5Vv)

The table below describes each section of the visualization, from left to right.

| Section                | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Sources                | <p>Each vulnerability data source is displayed along with number of vulnerabilities findings.</p><p>Click on this section to open the <a href="#UUID-7d445ab5-f47e-f599-879a-ac69bd47bcbe_sidebar-idm234990248637481">Source Coverage and Optimization</a> page, which displays details about the overlap in vulnerabilities across the sources.</p>                                                                                                                                                    |
| Vulnerabilities        | The total number of vulnerability findings from all sources.                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Unique Vulnerabilities | <p>The total number of vulnerability findings after deduplication.</p><p>Deduplication removes duplicate findings, which are defined as findings for the same CVE on the same asset.</p><p>Click on Unique Vulnerabilities to display the <a href="#UUID-7d445ab5-f47e-f599-879a-ac69bd47bcbe_sidebar-idm234990488505729">Prioritization</a> page, which shows how findings are deduplicated, prioritized, and grouped into cases.</p>                                                                  |
| Cases                  | <p>The number of cases created after the system has prioritized the findings, created vulnerability issues, and groups the issues into cases.</p><p>Vulnerability issues are grouped into cases based on the fix for resolving the vulnerability. Issues with the same fix are grouped together into a single case.</p>                                                                                                                                                                                 |
| Active Cases           | <p>Number of active cases, broken down into the following categories:</p><ul><li>Require Attention: Cases with the status <strong>New</strong>.</li><li>In Progress: Cases with the status <strong>In Progress</strong></li></ul><p>Click on any of these Active Cases categories to display the list of cases along with case details, status, and recommended actions.</p>                                                                                                                            |
| Resolved Cases         | <p>Total number of resolved cases, number of resolved cases by severity, and resolved cases broken down into the following categories:</p><ul><li>Resolved: Cases with any <strong>Resolved</strong> status except <strong>Accepted Risk</strong>.</li><li>Accepted Risk: Cases with the status <strong>Resolved - Accepted Risk</strong>.</li></ul><p>Click on either of these Resolved Cases categories to display the list of cases along with case details, status, and additional information.</p> |

The following table explains the data points displayed along the bottom of the Exposure Management Command Center.

| Data Point           | Description                                                                                                              |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| Vulnerable Assets    | Number of assets with one or more active vulnerability issues.                                                           |
| Active Cases         | Number of cases in an active status, broken down by case severity.                                                       |
| Mean Time to Resolve | Mean of the creation date to the date when the case was assigned a terminal closed status, broken down by case severity. |

The following sections describe the focused dashboards that appear when clicking on specific elements in the command center.

<details>

<summary>Source Coverage &#x26; Optimization</summary>

The **Source Coverage & Optimization** page shows a breakdown of the vulnerability findings from each source and the overlap in findings between third-party sources and Palo Alto Networks sources. The data and and visualizations on this page show you which of your sources are most effective and help determine if you can consolidate vulnerability tools.

| Section                              | Description                                                                                                                                                                                                               |
| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Vulnerabilities Before Deduplication | Total number of vulnerability findings from all sources before deduplication.                                                                                                                                             |
| Overlap with \<source>               | Highest amount of vulnerability overlap between Palo Alto Networks sources and a third-party product. The label **HIGH** indicates a greater than 30% overlap between the Palo Alto Networks and this third-party vendor. |
| Findings bar                         | Number of vulnerability findings from Palo Alto Network sources, not deduplicated. Hover over the different sections of the bar to see the breakdown of findings come from each Palo Alto Networks source.                |
| Overlap                              | List of third-party sources and the number of vulnerability findings from each source that overlap with Palo Alto Networks sources.                                                                                       |
| Findings                             | Total number of vulnerability findings from each third-party source.                                                                                                                                                      |

</details>

<details>

<summary>Prioritization</summary>

The **Prioritization** page breaks down how Cortex XDR starts with the total number of raw vulnerability findings in your environment and deduplicates, prioritizes, and consolidates them into a manageable number of cases that require attention. Percentages that appear next to some values indicate the change over the last 30 days. The table below explains each part of visualization, from left to right.

| Section                                                                                                                                                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Vulnerabilities                                                                                                                                         | The total number of vulnerability findings across all sources.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Duplicative Findings                                                                                                                                    | Number of duplicate findings that were eliminated. Duplicate findings are findings for the same CVE on the same asset.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Unique Vulnerabilities                                                                                                                                  | The number of vulnerability findings after deduplication.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p>Not Internet Exposed</p><p>Low Business Impact</p><p>No Known Public Exploits</p><p>Low and Medium CVSS Base Score</p><p>Deprioritized by Policy</p> | <p>These are the low-priority findings that did not result in the creation of an issue. The reason for deprioritization is provided along with the count.</p><ul><li><strong>Not Internet Exposed</strong>: ASM and CNA data indicates that these vulnerabilities are not exposed to the internet.</li><li><strong>Low Business Impact</strong>: The asset group for the vulnerability is dev, test, internal, or low business criticality.</li><li><strong>No Known Public Exploits</strong>: These vulnerabiliities have an EPSS score less than 80% or other public data indicating the vulnerability hasn't been exploited.</li><li><strong>Low and Medium CVSS Base Score</strong>: CVSS severity is Low or Medium.</li><li><strong>Deprioritized by Policy</strong>: These vulnerabilities were deprioritized by custom policies created by your organization. Typically this is any policy that specifies not to create an issue for a specific type of vulnerability.</li></ul> |
| Open Issues                                                                                                                                             | The number of open vulnerability issues.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Issues Consolidated into Cases                                                                                                                          | Number of issues that were consolidated into open cases. Issues are grouped together into cases based on whether they share the same fix.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Cases                                                                                                                                                   | Total number of vulnerability cases after vulnerability issues were grouped into cases.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Require Attention                                                                                                                                       | Number of cases with the status **New**. Click to pivot to a filtered view of the cases that includes detailed information to help you investigate and remediate each case.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| In Progress                                                                                                                                             | Number of cases with the status I**n Progress**. Click to pivot to a filtered view of the cases that includes detailed information to help you investigate and remediate each case.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Resolved                                                                                                                                                | Number of cases with the status **Closed - Remediated** or **Closed - No Longer Observed**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Accepted Risk                                                                                                                                           | Number of cases with the status **Accepted Risk.**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/exposure-management/exposure-management-command-center.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
