Skip to main content

Cortex ASM - Remediation Path Rules

This Playbook is part of the Cortex Attack Surface Management Pack.#

Supported versions

Available on Cortex XSIAM and Cortex XPANSE.

This playbook returns "RemediationAction" options based on the return from the Remediation Path Rules API, or defaults to data collection task.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • CortexAttackSurfaceManagement

Scripts#

  • GetTime
  • GridFieldSetup
  • Set
  • RemediationPathRuleEvaluation

Commands#

  • asm-list-remediation-rule

Playbook Inputs#


NameDescriptionDefault ValueRequired
ExternallyDetectedProvidersProviders of external service.Optional
BypassDevCheckDetermine whether to bypass the Dev Check in automated remediation criteria: https://docs-cortex.paloaltonetworks.com/r/Cortex-XPANSE/Cortex-Xpanse-Expander-User-Guide/Automated-Remediation-Capabilities-Matrix

Set to "True" if you want to bypass. "
FalseOptional

Playbook Outputs#


PathDescriptionType
RemediationActionRemediation action to be taken.string
RPR_TimestampTimestamp of when the remediation path rule action was determined.string

Playbook Image#


Cortex ASM - Remediation Path Rules