Tenzai - Agentic Issue Validation

Runs the Tenzai Agentic Issue Validation playbook on High/Critical ASM-discovered vulnerability/configuration exposures (VULNERABILITY or CONFIGURATION category, HIGH/CRITICAL severity, DOMAIN_POSTURE domain, finding source CORTEX_ATTACK_SURFACE_MANAGEMENT). Warning: when enabled, each matching alert triggers ACTIVE penetration testing against the live production asset and consumes Tenzai credits. Because ASM attribution can occasionally be wrong, the playbook gates on analyst approval by default (RequireAnalystApproval). The filter does not exclude already-validated exposures, so re-triggering is possible; disable the trigger or run validation ad-hoc from the Validate button if you do not want automatic testing.

Tenzai

Details

ID3468bd4543c0fb9f0883702500781cda
From Version6.10.0
Runs PlaybookTenzai Agentic Issue Validation
Suggestion ReasonValidate exploitability of High/Critical ASM-discovered exposures with Tenzai agentic testing. Warning: enabling this trigger runs active penetration testing against the live production asset and consumes Tenzai credits; keep the playbook's RequireAnalystApproval input set to true so an analyst approves each run.

Alert conditions (all must match)

Field Operator Value
alert_domain EQ DOMAIN_POSTURE
xdm.finding_sources EQ CORTEX_ATTACK_SURFACE_MANAGEMENT
{
    "trigger_id": "3468bd4543c0fb9f0883702500781cda",
    "trigger_name": "Tenzai - Agentic Issue Validation",
    "playbook_id": "Tenzai Agentic Issue Validation",
    "suggestion_reason": "Validate exploitability of High/Critical ASM-discovered exposures with Tenzai agentic testing. Warning: enabling this trigger runs active penetration testing against the live production asset and consumes Tenzai credits; keep the playbook's RequireAnalystApproval input set to true so an analyst approves each run.",
    "description": "Runs the Tenzai Agentic Issue Validation playbook on High/Critical ASM-discovered vulnerability/configuration exposures (VULNERABILITY or CONFIGURATION category, HIGH/CRITICAL severity, DOMAIN_POSTURE domain, finding source CORTEX_ATTACK_SURFACE_MANAGEMENT). Warning: when enabled, each matching alert triggers ACTIVE penetration testing against the live production asset and consumes Tenzai credits. Because ASM attribution can occasionally be wrong, the playbook gates on analyst approval by default (RequireAnalystApproval). The filter does not exclude already-validated exposures, so re-triggering is possible; disable the trigger or run validation ad-hoc from the Validate button if you do not want automatic testing.",
    "alerts_filter": {
        "filter": {
            "AND": [
                {
                    "OR": [
                        {
                            "SEARCH_FIELD": "alert_category",
                            "SEARCH_TYPE": "EQ",
                            "SEARCH_VALUE": "VULNERABILITY"
                        },
                        {
                            "SEARCH_FIELD": "alert_category",
                            "SEARCH_TYPE": "EQ",
                            "SEARCH_VALUE": "CONFIGURATION"
                        }
                    ]
                },
                {
                    "OR": [
                        {
                            "SEARCH_FIELD": "severity",
                            "SEARCH_TYPE": "EQ",
                            "SEARCH_VALUE": "SEV_050_CRITICAL"
                        },
                        {
                            "SEARCH_FIELD": "severity",
                            "SEARCH_TYPE": "EQ",
                            "SEARCH_VALUE": "SEV_040_HIGH"
                        }
                    ]
                },
                {
                    "SEARCH_FIELD": "alert_domain",
                    "SEARCH_TYPE": "EQ",
                    "SEARCH_VALUE": "DOMAIN_POSTURE"
                },
                {
                    "SEARCH_FIELD": "xdm.finding_sources",
                    "SEARCH_TYPE": "EQ",
                    "SEARCH_VALUE": "CORTEX_ATTACK_SURFACE_MANAGEMENT"
                }
            ]
        }
    },
    "fromVersion": "6.10.0",
    "supportedModules": [
        "cloud_posture",
        "cloud",
        "cloud_runtime_security",
        "edr",
        "agentix",
        "asm",
        "xsiam",
        "exposure_management",
        "tim",
        "xti"
    ]
}