> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response.md).

# Active Response

Active Response is an add-on module for Cortex Xpanse Expander that provides built-in automation and playbooks to augment alert investigation and where applicable, fully remediate risks automatically. Each time Xpanse creates a new alert, Active Response runs a predefined playbook (which is a workflow that fully or partially automates the response to an alert.) The playbook execution changes dynamically based on the details of the alert (such as the type of service detected), integrations that have been configured (such as AWS or ServiceNow), and whether or not you have defined remediation path rules (which tell the playbook how to respond to specific alerts). For alerts that don't have remediation path rules, the playbook will prompt you for input at key points during the workflow, enabling you to make remediation decisions while still getting the benefits of an automated workflow.

Active Response enables you to proactively address your attack surface risks, which will in turn reduce the frequency and severity of security incidents. Additional benefits include the following:

* Automatically connects to all your security and IT tools to gather applicable context.
* Uses machine learning to analyze collected data to surface key insights to analysts.
* Includes built-in remediation playbooks to eliminate critical attack surface risks, such as exposed Remote Desktop Protocol (RDP) servers and insecure OpenSSH.
* Places security teams in control of how they want to address various types of risks by granting granular controls for choosing a remediation path.
* Validates that remediation was successful by rescanning assets.
* Ensures your security team is in control by auditing every action taken and rolling up investigation details into useful dashboards and reports.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
