Skip to main content

Cortex ASM - On Prem Enrichment

This Playbook is part of the Cortex Attack Surface Management Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.8.0 and later.

Given an IP address, port, and protocol of a service, this playbook enriches on-prem integrations to find the related firewall rule and other related information.


  • Multiple integration instances configured at the same time are not supported (Panorama or standalone NGFW).
  • !pan-os-security-policy-match fails if any firewall is disconnected (Panorama).
  • Matching on different rules for different firewalls not supported (Panorama).


This playbook uses the following sub-playbooks, integrations, and scripts.


This playbook does not use any sub-playbooks.


  • Panorama


  • GridFieldSetup
  • Set


  • pan-os-security-policy-match
  • pan-os-platform-get-device-groups
  • pan-os-list-rules
  • pan-os-show-device-version

Playbook Inputs#

NameDescriptionDefault ValueRequired
RemoteIPIP address of the service.alert.remoteipRequired
RemotePortPort number of the service.alert.remoteportRequired
RemoteProtocolProtocol of the service.alert.appidRequired

Playbook Outputs#

There are no outputs for this playbook.

Playbook Image#

Cortex ASM - On Prem Enrichment