> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/automated-remediation-capabilities-matrix.md).

# Automated Remediation Capabilities Matrix

This document describes the Active Response fully automated remediation and enrichment coverage for attack surface alerts discovered by Cortex Xpanse.

The following definitions are used:

* *Attack Surface Rule*—The Attack Surface Rule that triggered the creation of an alert.
* *Automated Remediation Method*—The method Cortex Xpanse uses to automatically remediate or rectify an attack surface alert.
* *Automated Remediation Criteria*—The conditions that must be met for the automated remediation options to be available for execution.

This document contains the following information:

* [Automated remediation options and criteria](#UUID-8de97a57-0ad7-40ec-cc78-86b24045fb5d_UUID-34bbc422-0bdd-c650-bc13-e8ce21250507)
* [Automated Remediation Methods](#UUID-8de97a57-0ad7-40ec-cc78-86b24045fb5d_UUID-36fb72c9-bc1f-7ecc-67d5-f7f469141af5)
* [Supported Automation Integrations](#UUID-8de97a57-0ad7-40ec-cc78-86b24045fb5d_UUID-7104d590-d1a9-d4a3-6fa3-320c333c9c77)
* [Active response templates](#UUID-8de97a57-0ad7-40ec-cc78-86b24045fb5d_UUID-0cf03215-40b3-e613-74f0-863f9f41bcf0)

## Automated remediation options and criteria

The table below lists the fully automated remediation options that are currently available with Active Response, including the remediation methods, relevant attack surface rules, and automated remediation criteria.

| Attack Surface Rule                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | Automated Remediation Method      | Automated Remediation Criteria                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <ul><li>Elasticsearch</li><li>Insecure Bitvise SSH Server</li><li>Insecure OpenSSH</li><li>Insecure SFTPGo</li><li>Kubernetes ControlPlane Component</li><li>LDAP Server</li><li>Libssh</li><li>MongoDB Server</li><li>MySQL Server</li><li>Netbios Name Server</li><li>Nfs Rpcbind Server</li><li>OpenSSH</li><li>Postgres Server</li><li>RDP Server</li><li>Rpcbind Server</li><li>Smb Server</li><li>SNMP Server</li><li>SSH Server</li><li>SSH Terrapin Attack</li><li>Telnet</li><li>TFTP Server</li><li>Unencrypted FTP Server</li></ul> | Restrict port access              | <p>1. Service must be running on an AWS EC2 instance, Google GCE instance, or Azure VM on an account that has been configured with read/write access. Additionally, we can support On Prem assets that are managed with Palo Alto Networks Firewalls.</p><p>2. At least one potential service owner must have been discovered.</p><p>3. The associated service or asset must be a non-production instance. This is determined by either:</p><p>1. A tag on the associated asset that is indicative of being a development server, from a CSP or VM integration. Development servers have no external users and run no production workflows. These servers may be tagged “dev” or other non-production terms like “pre-production”, “user acceptance testing”, or “qa”.</p><p>2. Xpanse attributing the “Development Environment” service classification to the associated service using purely public information.</p><ul><li>This can be disabled by setting the <strong>BypassDevCheck</strong> playbook input.</li></ul><p>4. A tag on the associated asset that is indicative of being a development server, from a CSP or VM integration. Development servers have no external users and run no production workflows. These servers may be tagged “dev” or other non-production terms like “pre-production”, “user acceptance testing”, or “qa”.</p><p>5. Xpanse attributing the “Development Environment” service classification to the associated service using purely public information.</p><ul><li>This can be disabled by setting the <strong>BypassDevCheck</strong> playbook input.</li></ul> |
| Insecure OpenSSH                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | Patching vulnerable software      | <p>1. Service must be running on an AWS EC2 instance.</p><p>2. Attack surface rule ID has to be Insecure OpenSSH.</p><p>3. AWS EC2 of platform type Linux Ubuntu.</p><p>4. AWS SSM agent is active.</p><p>5. At least one potential service owner must have been discovered.</p><p>6. The associated service or asset must be a non-production instance. This is determined by either:</p><ul><li>A tag on the associated asset that is indicative of being a development server, from a CSP or VM integration. Development servers have no external users and run no production workflows. These servers may be tagged “dev” or other non-production terms like “pre-production”, “user acceptance testing”, or “qa”.</li><li><p>Xpanse attributes the “Development Environment” service classification to the associated service using purely public information.</p><ul><li>This can be disabled by setting the <em>BypassDevCheck</em> playbook input.</li></ul></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <ul><li>Elasticsearch</li><li>Insecure Bitvise SSH Server</li><li>Insecure OpenSSH</li><li>Insecure SFTPGo</li><li>Kubernetes ControlPlane Component</li><li>LDAP Server</li><li>Libssh</li><li>MongoDB Server</li><li>MySQL Server</li><li>Netbios Name Server</li><li>Nfs Rpcbind Server</li><li>OpenSSH</li><li>Postgres Server</li><li>RDP Server</li><li>Rpcbind Server</li><li>Smb Server</li><li>SNMP Server</li><li>SSH Server</li><li>SSH Terrapin Attack</li><li>Telnet</li><li>TFTP Server</li><li>Unencrypted FTP Server</li></ul> | Isolate endpoint from the network | <p>1. Service must NOT be running on an AWS EC2 instance, Google GCE instance, Azure Compute VM, or managed On-Premise with Palo Alto Networks Firewalls.</p><p>2. The asset must be managed by Cortex XSIAM Endpoint Security or Cortex XDR Prevent or Pro.</p><p>3. At least one potential service owner must have been discovered.</p><p>4. The associated service or asset must be a non-production instance. This is determined by either:</p><ul><li>A tag on the associated asset that is indicative of being a development server, from a CSP or VM integration. Development servers have no external users and run no production workflows. These servers may be tagged “dev” or other non-production terms like “pre-production”, “user acceptance testing”, or “qa”.</li><li><p>Xpanse attributes the “Development Environment” service classification to the associated service using purely public information.</p><ul><li>This can be disabled by setting the <em>BypassDevCheck</em> playbook input.</li></ul></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Unclaimed S3 Bucket                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | Placeholder S3 Bucket Created     | The AWS S3 integration has been configured with read/write access.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |

#### Automated Remediation Methods

The table below provides details about each of the Active Response fully automated remediation methods.

| Automated Remediation Method      | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Restrict Port Access              | <p>This method varies based on the available control surface and the asset associated with the alert.</p><ul><li><p><strong>AWS</strong></p><p>EC2: Replaces the security group that is allowing the risky service to be exposed to the public internet with a new security group that only allows access via an internal network. See additional playbook details <a href="https://github.com/demisto/content/blob/master/Packs/AWS-Enrichment-Remediation/Playbooks/AWS_-_Security_Group_Remediation_README.md">here</a>.</p></li><li><p><strong>Google Cloud</strong></p><p>GCE: The remediation steps for risks exposed on Google Cloud GCE operate by tagging the GCE instance with a network tag referencing two new firewall rules—one to allow internal traffic to the exposed port and the other to block the port from internet access. The new firewall rules follow this naming convention <strong>remediation-\<allow</strong></p></li></ul> |
| Isolate Endpoint from the Network | <p>This method is available when the requirements for the Restrict Port Access method have not been met and the asset associated with the alert has a Cortex XDR or XSIAM endpoint security agent.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>This remediation method operates by isolating the asset that is exposed to the public internet and halting all network access on the endpoint except for traffic to Cortex XSIAM or XDR. See additional playbook details <a href="https://github.com/demisto/content/blob/master/Packs/CortexAttackSurfaceManagement/Playbooks/Cortex_ASM_-_Cortex_Endpoint_Remediation_README.md">here</a>.</p></div>                                                                                                                                                                                                                            |
| Patch vulnerable software         | <p>This method is available when the AWS Systems Manager agent is active, platform requirements (Ubuntu) are met and for attack surface Insecure OpenSSH.</p><p>The remediation is applied by upgrading the existing vulnerable Insecure OpenSSH software to a newer, patchable version.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Create placeholder S3 Bucket      | <p>This method is used solely for remediating Unclaimed S3 Bucket alerts.</p><p>These alerts are resolved by creating an empty S3 bucket with no external access that matches the organization’s undefined DNS CNAME record. See additional playbook details <a href="https://github.com/demisto/content/blob/master/Packs/AWS-Enrichment-Remediation/Playbooks/AWS_-_Unclaimed_S3_Bucket_Remediation_README.md">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

## Supported Automation Integrations

The table below lists the supported Active Response automation integrations, the possible enrichment values for each integration, and the permission requirements.

| Integration Name                           | Category                   | Utilization                                                                                                                                                                                                                                                                                                                                                                                                                                             | Required Permission                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ------------------------------------------ | -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Active Directory Query v2 (on-prem)        | Active Directory           | <p>Enrichment</p><ul><li>User’s display name</li><li>User’s manager display name</li><li>User’s manager email</li><li>Service Owner details</li></ul>                                                                                                                                                                                                                                                                                                   | <p>This integration requires an engine to be configured. Documentation for engine deployment and configuration can be found <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XPANSE/Cortex-Xpanse-Expander-User-Guide/Engines">here</a>.</p><p>Enrichment requires the following:</p><ul><li>Ability to get detailed information about user accounts from on-prem AD.</li></ul><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/active-directory-query-v2">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Atlassian Jira v2/v3                       | ITSM                       | <p>Enrichment</p><ul><li>N/A</li></ul><p>Also used to create Jira issues (i.e. tickets)</p>                                                                                                                                                                                                                                                                                                                                                             | <p>If using the on-premises version of Jira (Jira Server), this integration requires an engine to be configured. Documentation for engine deployment and configuration can be found <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XPANSE/Cortex-Xpanse-Expander-User-Guide/Engines">here</a>.</p><p>Task creation requires the following:</p><ul><li>The "Create Issues" permission must be granted to the user or service account used for authentication.</li></ul><p>Learn more about <a href="https://support.atlassian.com/jira-service-management-cloud/docs/overview-of-jira-cloud-permissions/">Jira permissions</a>.</p><p>For details on the configuration of this integration, see:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/jira-v2#configure-jira-v2-on-cortex-xsoar">Atlassian Jira v2</a></li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/jira-v3#authentication">Atlassian Jira v3</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| AWS - EC2                                  | Cloud                      | <p>Enrichment</p><ul><li>Internal IP Addresses</li><li>EC2 Instance ID</li><li>EC2 Instance tags</li><li>Associated EC2 NIC ID(s)</li><li>Associated EC2 Security Group ID(s)</li><li>Associated EC2 VPC ID(s)</li><li>Cloud Region, AZ and Network ID(s)</li></ul><p>Also used for remediation.</p>                                                                                                                                                    | <p>Enrichment requires the following actions:</p><ul><li>ec2:DescribeInstances</li><li>ec2:DescribeSecurityGroups</li></ul><p>Remediation requires the following actions:</p><ul><li>ec2:DescribeInstances</li><li>ec2:DescribeSecurityGroups</li><li>ec2:CreateSecurityGroup</li><li>ec2:AuthorizeSecurityGroupIngress</li><li>ec2:AuthorizeSecurityGroupEgress</li><li>ec2:RevokeSecurityGroupIngress</li><li>ec2:RevokeSecurityGroupEgress</li><li>ec2:ModifyNetworkInterfaceAttribute</li></ul><p>Learn more about AWS EC2 actions <a href="https://docs.aws.amazon.com/ec2/index.html">here</a>.</p><p>To associate EC2 instances that are associated with a public IP address, use the<a href="https://aws.amazon.com/about-aws/whats-new/2023/11/amazon-vpc-address-manager-free-features-tier/">AWS Public IP Insights API</a>.</p><p>To be able to make API calls from a single AWS user for all accounts in an organization, an AssumeRole must be configured to allow access. The AssumeRole must then be added as a parent playbook input AWSAssumeRoleName.</p><p>Required Permissions (for organizational scope only):</p><ul><li>AssumeRole with these permissions (and others listed) for all accounts in organization</li><li>ec2:DescribeRegions - Enrichment</li><li>ec2:DescribeIpamResourceDiscoveries - Enrichment</li><li>ec2:GetIpamDiscoveredPublicAddresses - Enrichment</li></ul><p>See more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/aws---ec2">here</a>.</p> |
| AWS - Organizations                        | Cloud                      | <p>Enrichment</p><ul><li>Account hierarchy details</li></ul>                                                                                                                                                                                                                                                                                                                                                                                            | <p>Enrichment requires the following actions:</p><ul><li>organizations:ListRoots</li><li>organizations:ListAccounts</li><li>organizations:ListParents</li><li>organizations:DescribeOrganization</li><li>organizations:DescribeOrganizationalUnit</li><li>organizations:DescribeAccount</li></ul><p>See more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/aws---organizations">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| AWS - S3                                   | Cloud                      | <p>Enrichment</p><ul><li>N/A</li></ul><p>Used for validation and remediation</p>                                                                                                                                                                                                                                                                                                                                                                        | <p>Remediation requires the following:</p><ul><li>s3:CreateBuckets</li><li>3:ListAllMyBuckets</li></ul><p>Learn more about AWS S3 actions <a href="https://docs.aws.amazon.com/AmazonS3/latest/API/API_Operations.html">here</a>.</p><p>See more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/aws---s3">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| AWS - SSM                                  | Cloud                      | <p>Enrichment</p><ul><li>SSM Instance ID</li><li>SSM Agent status</li><li>SSM Platform Name</li><li>SSM Platform Type</li><li>SSM Platform Version</li></ul><p>Remediation</p><ul><li>Upgrade package to new patched version.</li></ul>                                                                                                                                                                                                                 | <p>Enrichment requires the following:</p><ul><li>ssm:ListInventoryEntries</li></ul><p>Remediation requires the following:</p><ul><li>ssm:SendCommand</li><li>ssm:ListInventoryEntries</li><li>ssm:ListCommands</li></ul><p>See more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/aws---system-manager">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Azure Active Directory Identity And Access | Cloud                      | <p>Enrichment</p><ul><li>Global Admins role details and IDs</li></ul>                                                                                                                                                                                                                                                                                                                                                                                   | <p>Enrichment requires the following Azure permissions:</p><ul><li>RoleManagement.Read.Directory</li><li>Directory.Read.All</li><li>RoleManagement.ReadWrite.Directory</li><li>Directory.ReadWrite.All</li></ul><p>Learn more about Azure Active Directory permissions <a href="https://learn.microsoft.com/en-us/graph/permissions-reference">here</a>.</p><p>Find more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-identityand-access">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Azure Active Directory Users               | Active Directory           | <p>Enrichment</p><ul><li>Global Admins Names and Emails</li><li>User's display name</li><li>Service Owner details</li></ul>                                                                                                                                                                                                                                                                                                                             | <p>Enrichment requires the following Azure permissions:</p><ul><li>User.Read.All</li><li>User.ReadWrite.All</li><li>Directory.Read.All</li><li>Directory.ReadWrite.All</li></ul><p>Learn more about MS Graph User permissions <a href="https://learn.microsoft.com/en-us/graph/permissions-reference">here</a>.</p><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-user">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Azure Compute v2                           | Cloud                      | <p>Enrichment</p><ul><li>Azure Compute instance name</li><li>Azure Compute instance Resource Group</li><li>Azure Compute instance associated NIC</li><li>Azure Compute private IP</li><li>Azure Compute instance ID</li><li>Azure Cloud region</li><li>Azure Cloud subscription</li></ul>                                                                                                                                                               | <p>Enrichment requires the following Azure permissions:</p><ul><li>Microsoft.Compute/virtualMachines/read</li><li>Microsoft.Network/networkInterfaces/read</li><li>Microsoft.Network/ipAllocations/read</li></ul><p>Learn more about Azure <a href="https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftcompute">permissions</a>.</p><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/azure-compute-v2">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Azure Network Security Groups              | Cloud                      | <p>Enrichment</p><ul><li>N/A</li></ul><p>Used for Azure remediation</p>                                                                                                                                                                                                                                                                                                                                                                                 | <p>Remediation requires the following Azure permissions:</p><ul><li>Microsoft.Network/networkSecurityGroups/read</li><li>Microsoft.Network/networkSecurityGroups/write</li></ul><p>Learn more about Azure Network Security Group <a href="https://learn.microsoft.com/en-us/azure/virtual-network/manage-network-security-group?tabs=network-security-group-portal#permissions">permissions</a>.</p><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/azure-network-security-groups">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Azure Resource Graph                       | Cloud                      | <p>Enrichment</p><ul><li>Asset hierarchy details</li></ul>                                                                                                                                                                                                                                                                                                                                                                                              | <p>To use Resource Graph, you must have appropriate rights in <a href="https://learn.microsoft.com/en-us/azure/role-based-access-control/overview">Azure role-based access control (Azure RBAC)</a> with at least read access to the resources you want to query. No results are returned if you don't have at least read permissions to the Azure object or object group.</p><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/azure-resource-graph">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Cortex Attack Surface Management           | Vulnerability Management   | This integration authenticates the limited XSOAR functionality Active Response is built on to access service and asset details stored in your ASM instance. It is also used for internal API calls such as those used for remediation guidance, remediation path rules, and remediation confirmation scanning.                                                                                                                                          | <p>Within the Xpanse interface, navigate to <strong>Settings</strong> → <strong>Integrations</strong> → <strong>API Keys</strong> to create a new API key for this integration. It will need to be a standard API key with a minimum role of “analyst”.</p><p>See more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/cortex-attack-surface-management">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Cortex XDR                                 | Endpoint                   | <p>Enrichment</p><ul><li>Internal IP Addresses</li><li>XDR Endpoint ID</li><li>XDR Endpoint and Server Tags</li><li>XDR Endpoint Asset ID</li><li>XDR Endpoint Asset Name</li><li>Service Owner details (currently logged in user)</li></ul>                                                                                                                                                                                                            | <p>Enrichment requires the following:</p><ul><li>Advanced API key configured on XDR</li><li>Minimal role is Viewer</li><li>Click “Copy API URL” to get the server URL for the integration</li></ul><p>For more information see this <a href="https://xsoar.pan.dev/docs/reference/integrations/cortex-xdr---ir#configuration">documentation</a>.</p><p>See more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/cortex-xdr---ir">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| CSCDomainManager                           | IT services                | <p>Enrichment</p><ul><li>Service Owner details</li><li>Account number</li></ul>                                                                                                                                                                                                                                                                                                                                                                         | <p>Find information about setting up access <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-Xpanse-REST-API/Cortex-Xpanse-API-Overview">here</a>.</p><p>Find additional details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/csc-domain-manager">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| GCP IAM                                    | Cloud                      | <p>Enrichment</p><ul><li>Service Owner details</li><li>Folder hierarchy details</li><li>Folder labels</li></ul>                                                                                                                                                                                                                                                                                                                                         | <p>Enrichment requires the following IAM permissions:</p><ul><li>resourcemanager.projects.getIamPolicy</li></ul><p>See more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/gcp-iam">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Google Cloud Compute                       | Cloud                      | <p>Enrichment</p><ul><li>Associated Firewall ID</li><li>Internal IP Addresses</li><li>VM instance tags</li><li>Cloud Project and Zone</li><li>VM instance ID</li><li>Associated VPC ID</li><li>Potential offending firewall rule names</li><li>Associated Network ID(s)</li><li>Associated Zone ID(s)</li></ul><p>Used for GCP remediation</p>                                                                                                          | <p>Enrichment requires the following compute permissions:</p><ul><li>compute.instances.list</li><li>compute.instances.get</li></ul><p>Remediation requires the following compute permissions:</p><ul><li><p>compute.instances.list</p><p>compute.instances.get</p><p>compute.firewalls.list</p><p>compute.firewalls.create</p><p>compute.instances.setTags</p></li></ul><p>For support at the Folder/Organization level, we also recommend adding the <a href="https://cloud.google.com/asset-inventory/docs/access-control#roles">Cloud Asset Owner</a> role to the Service Account.</p><p>See more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/google-cloud-compute">here.</a></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Palo Alto Networks PAN-OS                  | Network Security           | <p>Enrichment</p><ul><li>Firewall Rule Name</li></ul><p>Used for NGFW remediation</p>                                                                                                                                                                                                                                                                                                                                                                   | <p>This integration requires an engine to be configured in order to use. Documentation for engine deployment and configuration can be found <a href="/pages/khAhx4c33VFrhh001YKs">here</a>.</p><p>Enrichment requires the following permissions:</p><ul><li>Configuration</li></ul><p>Remediation requires the following permissions:</p><ul><li>Configuration</li><li>Commit</li></ul><p>These permissions are best fulfilled by the <a href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-role-types">Device Administrator</a>role. Learn more about the <a href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-panorama-api">PAN-OS and Panorama API</a>.</p><p>See more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/panorama">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Prisma Cloud                               | Cloud                      | <p>Enrichment</p><ul><li>Cloud Resource Information (Instance identifier)</li><li>CSP tags</li><li>Service Ownership details from CSP logs in PrismaCloud</li></ul>                                                                                                                                                                                                                                                                                     | <p>Enrichment requires the following:</p><ul><li>“Investigate.Running Queries” permission and access to designated accounts within Prisma Cloud.</li></ul><p>The minimum available roles is “Account Group Read Only”. Learn more about <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/manage-prisma-cloud-administrators/prisma-cloud-administrator-roles#id437b5c4a-3dfa-4c70-8fc7-b6d074f5dffc">Prisma Cloud roles</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Qualys                                     | Vulnerability Management   | <p>Enrichment</p><ul><li>Qualys asset information (OS, Name, Scan details, Owner)</li><li>Qualys asset tags</li></ul>                                                                                                                                                                                                                                                                                                                                   | <p>Enrichment requires the following:</p><ul><li>The “view vulnerabilities” permission which is minimally scoped to the “Remediation User” role.</li><li>Access to the asset allowed via TBUS.</li></ul><p>Learn more about Qualys <a href="https://qualysguard.qg2.apps.qualys.com/qwebhelp/fo_portal/index.htm#t=user_accounts%2Fsetting_user_permissions.htm">permissions</a> and <a href="https://qualysguard.qg2.apps.qualys.com/qwebhelp/fo_portal/index.htm#t=tbus%2Ftag_based_user_scoping.htm&#x26;rhtocid=_4_7">scope controls</a>.</p><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/qualys-v2">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Rapid7 InsightVM                           | Vulnerability Management   | <p>Enrichment</p><ul><li>Rapid7 asset information (OS, Name, Asset Site)</li><li>Rapid7 asset tags</li></ul>                                                                                                                                                                                                                                                                                                                                            | <p>Enrichment requires the following:</p><ul><li>The “View Group Asset Data” permission which can minimally be scoped to the “User” role.</li></ul><p>Learn more about Rapid7 permissions and roles <a href="https://docs.rapid7.com/nexpose/managing-users-and-authentication/#user">here</a>.</p><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/rapid7-nexpose">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ServiceNow CMDB                            | Asset Management           | <p>Enrichment</p><ul><li>CMDB CI Sys ID</li><li>CMDB Parent Sys ID</li><li>CMDB NIC Sys ID</li><li>CMDB Assignment Sys ID</li></ul>                                                                                                                                                                                                                                                                                                                     | <p>Enrichment requires the following:</p><ul><li>A minimum of the cmdb\_read role.</li></ul><p>Learn more about ServiceNow <a href="https://docs.servicenow.com/bundle/utah-platform-administration/page/administer/roles/reference/r_BaseSystemRoles.html">roles</a>.</p><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/service-now-cmdb">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ServiceNow v2                              | ITSM                       | <p>Enrichment</p><ul><li>Service owner details based on identified “assigned\_to” values</li></ul><p>Also used to create ServiceNow incidents (i.e. tickets).</p><p>Note: Setting the "NotificationTicketType" input field from “incident” to “sn\_si\_incident” will allow this integration to create new incidents within the ServiceNow SIR product. If this input field is left unchanged the incident will be created within the ITSM product.</p> | <p>Incident creation requires the following:</p><ul><li>A minimum of the itil role.</li></ul><p>Learn more about ServiceNow <a href="https://docs.servicenow.com/bundle/utah-platform-administration/page/administer/roles/reference/r_BaseSystemRoles.html">roles</a>.</p><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/service-now-v2">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Slack v3                                   | Messaging and Conferencing | <p>Enrichment</p><ul><li>N/A</li></ul><p>Also used to create Slack messages.</p>                                                                                                                                                                                                                                                                                                                                                                        | <p>Messaging requires the creation of a custom app that is added to one or more channels and with the following minimal permissions:</p><ul><li>chat:write</li></ul><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/slack-v3">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Splunk                                     | SIEM                       | <p>Enrichment</p><ul><li>Service Owner details</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                | <p>Enrichment requires the splunk “user” role at a minimum and access to any necessary indexes.</p><p>Learn more about Splunk <a href="https://docs.splunk.com/Documentation/Splunk/latest/Security/Aboutusersandroles">roles</a>.</p><p>See more details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/splunk-py">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Tenable.io                                 | Vulnerability Management   | <p>Enrichment</p><ul><li>Tenable Asset ID</li><li>Tenable asset tags</li><li>Service Owner details</li></ul>                                                                                                                                                                                                                                                                                                                                            | <p>Enrichment requires the following:</p><ul><li>Asset.view privilege must be assigned to the user role</li><li>The assigned user must have access to the asset via permissions</li></ul><p>Learn more about Tenable.io <a href="https://docs.tenable.com/vulnerability-management/Content/Settings/access-control/TenableRolePrivileges.htm">privileges</a>and <a href="https://docs.tenable.com/vulnerability-management/Content/Settings/access-control/Permissions.htm">permissions</a>.</p><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/tenableio">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Venafi                                     | Identity                   | Enrichment                                                                                                                                                                                                                                                                                                                                                                                                                                              | <p>Enrichment requires the following permissions:</p><ul><li>Read access with scope:certificates</li></ul><p>Find more information about scope <a href="https://docs.venafi.com/Docs/current/TopNav/Content/SDK/AuthSDK/r-SDKa-OAuthScope.php?TocPath=REST%20APIs%7CAuth%20REST%20for%20token%20management%7C_____1">here</a>.</p><p>Find details on the configuration of this integration <a href="https://xsoar.pan.dev/docs/reference/integrations/venafi-tls-protect">here</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

## Active response templates

The table below describes the default format and wording for emails and tickets created by Cortex Xpanse for ASM alerts. To create custom emails and tickets, see [Playbook Configuration](/cortex-xpanse/active-response/set-up-active-response/playbook-configuration.md).

| Field                                    | Value                                                                                                                                                                                                                                                                                                                                                               |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Notification Email Subject               | A new security risk was identified on an external service owned by your team                                                                                                                                                                                                                                                                                        |
| Notification Email Body HTML             | <p>Infosec identified a security risk on an external service potentially owned by your team:</p><p><code>${alert.details}\<br>\<br>Remediation Guidance: ${Remediation Guidance}</code></p>                                                                                                                                                                         |
| Remediation Notification Email Subject   | A new security risk was addressed on an external service owned by your team                                                                                                                                                                                                                                                                                         |
| Remediation Notification Email Body HTML | `<!DOCTYPE html> <html lang="en"> <body> <p> Infosec identified a security risk on an external service potentially owned by your team:<br><b>${alert.name}</b> </p> <p> <b>Alert Details:</b> ${alert.details}<br> <b>Action Taken:</b> ${alert.asmremediation.[0].Action}<br> <b>Action Outcome:</b> ${alert.asmremediation.[0].Outcome}<br> </p> </body> </html>` |
| ServiceNow Incident Title                | <p>Cortex ASM Alert:</p><p><code>${alert.name}</code></p>                                                                                                                                                                                                                                                                                                           |
| ServiceNow Incident Description          | <p>Infosec identified a security risk on an external service potentially owned by your team:</p><p><code>${alert.name}\<br>\<br></code></p><p>Description:</p><p><code>${alert.details}\<br>\<br>Remediation Guidance: ${Remediation Guidance}</code></p>                                                                                                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xpanse/active-response/automated-remediation-capabilities-matrix.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
