Command buttons allow you to take the following actions related to the threat.
Assignee—Assign the threat to a user.
Status—Open, close, or suppress a threat. Send feedback on a correlation, as described in Sending feedback about alert correlations.
Export—Export the data on the page to a CSV or JSON file.
Actions—Request that the threat be contained or removed from containment.
Fix Now—Execute a response action to trigger the playbook tailored to the threat. The red menu contains critical actions and the gray menu contains routine actions. See Selecting a response action to execute.
Trigger Playbook—Manually trigger playbooks that you select from the full list of playbooks. This action is available for threats with no matching response actions. See Selecting a playbook to execute.