> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/active-response-faq.md).

# Active Response FAQ

Below are answers to the most frequently asked questions about the Cortex Xpanse Active Response Module.

* [1. What is the Active Response module?](#id34331)
* [2. How does Active Response work?](#id34337)
* [3. How many playbooks do I get?](#id34345)
* [4. How can I edit the playbooks?](#id34352)
* [5. How do I make sure I have the latest content?](#id34360)
* [6. Why don’t I see an option to automatically remediate?](#id34370)
* [7. Can I disable Active Response?](#id34385)
* [8. I see a playbook error; what do I do?](#id34390)
* [9. When will you support X, Y, Z integration?](#id34395)
* [10. Can I get the Active Response module if I’m an XSOAR customer?](#id34401)
* [11. Can I get the Active Response module if I’m an XSIAM customer?](#id34407)

<table><thead><tr><th width="92.5"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td>What is the Active Response module?</td></tr><tr><td></td><td>The Active Response module is an add-on for Cortex Xpanse Expander that provides built-in automation capabilities and playbooks to augment alert investigation and where applicable, fully remediate risks automatically. See <a href="/pages/op3BiHtYzLUEscIQi4JO">Active Response</a> for more information.</td></tr><tr><td><strong>2.</strong></td><td>How does Active Response work?</td></tr><tr><td></td><td><p>The Active Response module works by starting an automation playbook as soon as a new alert is created. This happens regardless of the type of Attack Surface Rule that causes an alert to be generated. The automation playbook progresses through a set of stages in which various automation integrations may be utilized to collect data, send Xpanse data to another system, or take a remediation action. See <a href="/pages/GnEByJ3nVKIAFstdHjkU">How Active Response Works</a> for details.</p><p>The primary Active Response playbook, <strong>Cortex ASM - ASM Alert</strong>, contains sub-playbooks that organize all of the playbook content for maintenance and legibility purposes. This Active Response playbook also supports many different branches or paths that can be taken depending on the types of configured integrations, the type of alert, and input provided by the analyst.</p></td></tr><tr><td><strong>3.</strong></td><td>How many playbooks do I get?</td></tr><tr><td></td><td><p>There is only one playbook that gets assigned to all ASM alerts, regardless of type. It’s named <strong>Cortex ASM - ASM Alert</strong>.</p><p>The Active Response module also includes many sub-playbooks to accomplish various component tasks.The Xpanse team recommends measuring the value of the Active Response module based on outcomes and capabilities rather than the total number of included playbooks.</p></td></tr><tr><td><strong>4.</strong></td><td>How can I edit the playbooks?</td></tr><tr><td></td><td><p>The Active Response module does not allow editing of playbooks directly, but you can configure custom email and ticketing notifications that the playbook will send. See <a href="/pages/bxLpLCumhHkEsx828711">Playbook Configuration</a>.</p><p>If you have any feedback for functionality you’d like to see included in Active Response, please let your Customer Success manager know. The Xpanse team is eager to hear your feedback.</p><p>For organizations with automation needs that require sufficient customization, Cortex XSIAM with the Attack Surface Management module or Cortex XSOAR combined with Cortex Xpanse Expander may be promising solutions.</p></td></tr><tr><td><strong>5.</strong></td><td>How do I make sure I have the latest content?</td></tr><tr><td></td><td><p>New content for the Active Response module is published as soon as it becomes available, with updates as frequently as every week. Your content will update automatically once a week.</p><p>If you'd like to update your content before the automatic update happens or to check whether new content is available, you can go to <strong>Marketplace</strong> in Expander, and select the <strong>Installed Content Packs</strong> tab.</p><p>Here the “Cortex Attack Surface Management” pack should be listed and will indicate if an update is available. Selecting the pack and clicking the update button will force the Active Response content to be updated.</p><p>Updating the content does not automatically restart playbooks that have already begun execution on an alert.</p></td></tr><tr><td><strong>6.</strong></td><td>Why don’t I see an option to automatically remediate?</td></tr><tr><td></td><td><p>For the various attack surface rules that support fully automated remediation, there are specific criteria that must be met in order for these options to be available. This extra precaution helps ensure that your critical production services are not unintentionally interrupted.</p><p>As an example, the automated remediation criteria for RDP on AWS includes:</p><ul><li>Service must be running on an AWS EC2 instance from an account that has been configured with read/write access.</li><li>At least one potential service owner must have been discovered.</li><li>The associated service or asset must be a non-production instance. This is determined by a tag on the associated asset that contains the term “dev” that is found via a CSP or VM integration and Xpanse attributing the “Development Environment” service classification to the associated service.</li></ul><p>See <a href="/pages/CLcvHtjjGeovyXnJrrTI">Automated Remediation Capabilities Matrix</a> for details about automated remediation options and requirements.</p></td></tr><tr><td><strong>7.</strong></td><td>Can I disable Active Response?</td></tr><tr><td></td><td>Active Response cannot currently be disabled. However, if you don’t configure any automation integrations the playbooks will not be able to take any actions on your behalf and can safely be ignored.</td></tr><tr><td><strong>8.</strong></td><td>I see a playbook error; what do I do?</td></tr><tr><td></td><td>The suggested troubleshooting action for a playbook error is to restart the playbook. You can do this by navigating to the playbook sub-tab for the alert, and clicking the Restart button in the playbook view. Once you confirm this action, the playbook will be restarted. Any data collected by the previous playbook execution may be lost.</td></tr><tr><td><strong>9.</strong></td><td>When will you support X, Y, Z integration?</td></tr><tr><td></td><td><p>The Xpanse team will continually deliver on a roadmap of integrations to be incorporated into the Active Response module. We will regularly reassess and make sure that this roadmap reflects customer needs.</p><p>If you have any feedback regarding functionality you’d like to see included in Active Response or integrations you’d like to see supported, please let your Customer Success manager know. The Xpanse team is eager to hear your feedback.</p></td></tr><tr><td><strong>10.</strong></td><td>Can I get the Active Response module if I’m an XSOAR customer?</td></tr><tr><td></td><td><p>Unfortunately, no. The primary playbook that has been developed for Active Response is intended to only be executed within Expander or XSIAM.</p><p>However, much of the content that has been developed for Active Response is also available for XSOAR customers to utilize as the building blocks for their own playbooks. The AWS Enrichment and Remediation pack is an example of one of these utility packs.</p></td></tr><tr><td><strong>11.</strong></td><td>Can I get the Active Response module if I’m an XSIAM customer?</td></tr><tr><td></td><td>XSIAM customers who have purchased the Attack Surface Management module add-on can install Active Response content from the Marketplace. All content and dependencies can be added by installing the Cortex Attack Surface Management pack.</td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/active-response-faq.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
