Cortex — Attack Surface Management

Cortex Xpanse
Attack Surface Management

Current release: Expander 2.14 (July 2026). See your attack surface the way attackers do. Xpanse scans the global internet to discover every internet-facing asset you own — including the ones your IT team doesn't know exist.

500B+
Ports Scanned Daily
All IPv4
Scanned Multiple × / Day
Zero
Agents or Credentials
Active
Response Automation

Overview

What is Cortex Xpanse?

Cortex Xpanse is PANW's External Attack Surface Management (EASM) and Active Attack Surface Management (AASM) platform. It continuously scans the global internet—indexing all IPv4 addresses multiple times daily and scanning over 500 billion ports daily—to identify and attribute every internet-facing asset belonging to an organization, including assets the IT team doesn't know exist.

Unlike legacy vulnerability scanners, Xpanse operates entirely from the attacker's perspective: no agents, no credentials, no firewall changes required. It then goes beyond discovery with Active Response capabilities to automatically remediate exposures through integrated playbooks.

Best-fit: Large enterprises ($1B+ revenue) with complex, distributed IT environments — multiple subsidiaries, heavy M&A activity, hybrid cloud, or distributed remote workforces. Six-figure entry pricing; not suited for SMB.
Do not confuse ASM with Exposure Management. Exposure Management is now a distinct module in Cortex XSIAM and Cortex XDR, separate from Xpanse and from the Attack Surface Management (ASM) module. Xpanse/ASM is outside-in discovery and attribution of internet-facing assets; Exposure Management is the broader prioritization, controls-verification and virtual-patching module and is licensed on its own (it requires XSIAM Premium, Enterprise or NG-SIEM). Quote them separately.
Two ways to buy: standalone Xpanse — Expander base plus a network-size SKU, with Active Response, Attack Surface Testing, Link and Third Party Assess as additions — or as the ASM module inside Cortex XSIAM / Cortex XDR.

Platform Capabilities

Key Capabilities

From discovery to active remediation — the only ASM platform that closes the loop automatically.

Continuous Internet-Wide Discovery
Scans all IPv4 space multiple times per day; scans customer-attributed assets daily for the most common ports. Optional Known Assets Monitoring (KAM) adds weekly scans of ~2,800 ports.
Agentless Asset Attribution
Uses OSINT, DNS, SSL certificate analysis, payload-based handshakes, and ML to attribute assets to the organization—including subsidiaries and shadow IT—without any internal access.
Active Attack Surface Testing
Tests exposures for exploitability with configurable intrusiveness levels. Includes default credential testing for 40+ applications—IT/networking devices and business operations systems.
AI Risk Prioritization
ML-enhanced attribution reduces false positives. Contextual risk scoring based on exposure type, exploitability data, CVE correlation, and business context. High-confidence CVE inferences generate vulnerability findings automatically.
Active Response (Add-On)
Built-in automation playbooks that fully remediate risks without manual ticket creation—removes risky services from the internet, notifies owners, and validates remediation via re-scanning.
Shadow IT & Supply Chain Visibility
Identifies unsanctioned cloud resources, rogue IT assets, and vendor/supply chain exposure risks. Digital Risk Protection uncovers leaked credentials and brand impersonation on the open internet.
AI Infrastructure Detections (2.11)
New in November 2025: detections for MCP Servers, MCP Inspector, and emerging AI infrastructure components — critical as organizations deploy AI tooling without proper security controls.
Cloud Asset Discovery
Native connectors to AWS, Azure, and GCP discover cloud-native assets and attribute them to the organization. Correlates with Prisma Cloud posture findings for full cloud exposure picture.

Latest Releases

2025–2026 Feature Updates

Current release is Expander 2.14 (July 2026).

Expander 2.14
July 2026 — current
  • On-demand rescan — trigger a fresh scan of an asset or range instead of waiting for the next cycle
  • Business-unit asset mapping — attribute assets to subsidiaries and business units for ownership and reporting
  • Frontier-AI-informed detection coverage
Xpanse 2.10
July 2025
  • Misconfiguration and enumeration alerts in Threat Response Center for single-view prioritization
  • Improved alert triage and disposition workflows
Xpanse 2.11
November 2025
  • AI infrastructure detections — MCP Servers, MCP Inspector
  • Attack surface testing intrusiveness levels — safely adjust intensity per environment
  • Faster triage with bulk alert and asset management
  • Service version enumeration and filtering for hygiene work
XSIAM 3.x Integration
2025–2026
  • Default credential testing — 40+ IT/networking and business operations apps
  • OS identification — fingerprinting internet-facing OS and version details
  • High-confidence CVE inferences — auto-generates vulnerability findings on version match
  • Digital Risk Protection — leaked credentials & brand impersonation detection
  • Global Lookup — instant TI on any IP or domain for faster investigation

Differentiated Use Case

M&A Due Diligence Use Case

One of Xpanse's most powerful and defensible use cases — pre-acquisition security risk assessment from the outside in.

Because Xpanse operates entirely without agents or credentials, it can assess the internet-facing security posture of any organization—including a company your client is evaluating for acquisition. This gives M&A deal teams and risk officers an objective, outside-in view of target company cyber risk before signing.

Pre-Acquisition

Evaluate target company's exposed infrastructure, shadow IT, unpatched systems, and credential leaks before deal close. Quantify cyber risk as part of the deal valuation.

Post-Merger Integration

After acquisition, Xpanse continuously discovers newly inherited infrastructure as it's onboarded. Identifies unknown assets from the acquired entity that aren't yet under security management.

Optiv PS Opportunity

Optiv wraps M&A cyber due diligence as a professional service — Xpanse provides the data layer. This is a repeatable, high-margin service for clients with active deal pipelines.

Commercial Structure

Pricing & Deployment

Enterprise-only: Quote-based, not publicly disclosed. ~$100K/year entry price. Not suitable for SMB accounts — require enterprise-scale deal teams.
  • Packaging Standalone: Expander base plus a network-size SKU, with Active Response, Attack Surface Testing, Link and Third Party Assess as separate line items. Sized by network size / asset count.
  • Entry price ~$100,000/year (£70,850 per UK G-Cloud listing ≈ $90–100K USD)
  • Active Response Paid add-on module for automated remediation playbooks
  • XSIAM route Attack Surface Management is available as an add-on module on Cortex XSIAM and Cortex XDR — organizations on XSIAM can get ASM capability without a separate standalone Xpanse contract. Exposure Management is a different, separately licensed module.
  • Onboarding services PANW sells paid onboarding/deployment services for initial asset seeding and configuration — Optiv PS opportunity

Platform Synergy

PANW Ecosystem Integration

Cortex XSIAM ASM module natively integrated in XSIAM (current release 3.6). Xpanse feeds asset and alert data into XSIAM's unified incident view. Note that Exposure Management is a separate XSIAM/XDR module, not a rename of ASM — it is licensed in its own right and requires XSIAM Premium, Enterprise or NG-SIEM.
Cortex XDR Discovered exposed assets correlate with XDR-protected endpoints. XDR can isolate Cortex-protected endpoints discovered as high-risk via Xpanse Active Response playbooks — automated loop from external discovery to endpoint containment.
Cortex XSOAR Xpanse ASM alerts trigger XSOAR playbooks for investigation, remediation, owner notification, and validation re-scanning. XSOAR Marketplace has the full Cortex Attack Surface Management pack with prebuilt playbooks.
Palo Alto NGFW Active Response can add firewall block rules on on-premises Palo Alto firewalls to cut internet access for exposed assets — direct NGFW integration is a key differentiator vs. competitors.
Prisma Cloud Cloud-discovered assets from AWS/Azure/GCP via connectors enrich Xpanse's asset inventory. Prisma Cloud posture findings correlate with externally-facing exposures for a unified cloud risk picture.

Pre-Sales

Scoping Checklist

Data points to collect before quoting Cortex Xpanse.

Internet-Facing IP Count — Owned and leased IP ranges, including cloud-assigned addresses. Drives the network-size SKU band on standalone Xpanse.
Domain and Certificate Inventory — Registered domains, subdomains and certificate authorities in use, plus who controls DNS.
Subsidiary and Business-Unit Scope — Which legal entities and business units are in scope. Expander 2.14 adds business-unit asset mapping, so capture the intended ownership hierarchy up front.
M&A Pipeline — Recent and pending acquisitions, divestitures and their timing — pre-acquisition assessment and post-merger integration are the strongest Xpanse use cases.
Buying Route — Standalone Xpanse (Expander base + network-size SKU) or the Attack Surface Management module inside Cortex XSIAM / Cortex XDR. Confirm which contract the customer wants.
Add-On Modules — Which of Active Response, Attack Surface Testing, Link and Third Party Assess are required, and what testing intrusiveness level is permitted.
Exposure Management Requirement — Separately confirm whether the account needs the Exposure Management module — it is a distinct XSIAM/XDR module, not part of Xpanse/ASM, and requires XSIAM Premium, Enterprise or NG-SIEM.
Third-Party and Supplier Scope — Number of vendors or suppliers to assess with Third Party Assess, and who consumes the findings.
Remediation Ownership — Who fixes exposures (IT, cloud platform team, subsidiary IT) and whether Active Response may act automatically or must open a ticket.
Integration Targets — Where findings must land — XSIAM or XDR console, ServiceNow, Jira, or a CMDB — and whether asset attribution must reconcile with an existing CMDB of record.

Sales Conversations

Discovery Questions

Questions to uncover external attack surface blind spots and qualify the Xpanse opportunity.

01 Do you have a complete, accurate inventory of all your internet-facing assets today — including assets from subsidiaries, acquisitions, and cloud development?
02 How often are you running external vulnerability scans, and do those scans require credentials or agents on the target systems?
03 Have you discovered any internet-exposed assets recently that weren't in your CMDB — exposed RDP, unpatched VPNs, or cloud storage buckets?
04 Do you have any pending or recent M&A activity where you need to assess the cyber risk of an acquisition target before deal close?
05 How are you managing shadow IT and unauthorized cloud resources that developers spin up outside of IT oversight?
06 Does your cyber insurance renewal require you to document and attest to your external attack surface posture and remediation activity?
07 What would it mean for your security team if they could automatically remediate internet-exposed services without opening tickets and waiting for manual action?
08 Are you currently using Cortex XSIAM? If so, are you aware that ASM is available as a module within XSIAM Premium — potentially without a separate Xpanse license?