**Adaptive Response Actions** allow ES to automatically take action when a Correlation Search triggers, or allow an analyst to take action manually from the Incident Review dashboard.
Common actions include: emailing the SOC, sending the event to a SOAR platform, pinging a host, or actively blocking an IP address on a firewall.