Cortex — Attack Surface Management
Cortex Xpanse
Attack Surface Management
Current release: Expander 2.14 (July 2026). See your attack surface the way attackers do. Xpanse scans the global internet to discover every internet-facing asset you own — including the ones your IT team doesn't know exist.
Overview
What is Cortex Xpanse?
Cortex Xpanse is PANW's External Attack Surface Management (EASM) and Active Attack Surface Management (AASM) platform. It continuously scans the global internet—indexing all IPv4 addresses multiple times daily and scanning over 500 billion ports daily—to identify and attribute every internet-facing asset belonging to an organization, including assets the IT team doesn't know exist.
Unlike legacy vulnerability scanners, Xpanse operates entirely from the attacker's perspective: no agents, no credentials, no firewall changes required. It then goes beyond discovery with Active Response capabilities to automatically remediate exposures through integrated playbooks.
Platform Capabilities
Key Capabilities
From discovery to active remediation — the only ASM platform that closes the loop automatically.
Latest Releases
2025–2026 Feature Updates
Current release is Expander 2.14 (July 2026).
- On-demand rescan — trigger a fresh scan of an asset or range instead of waiting for the next cycle
- Business-unit asset mapping — attribute assets to subsidiaries and business units for ownership and reporting
- Frontier-AI-informed detection coverage
- Misconfiguration and enumeration alerts in Threat Response Center for single-view prioritization
- Improved alert triage and disposition workflows
- AI infrastructure detections — MCP Servers, MCP Inspector
- Attack surface testing intrusiveness levels — safely adjust intensity per environment
- Faster triage with bulk alert and asset management
- Service version enumeration and filtering for hygiene work
- Default credential testing — 40+ IT/networking and business operations apps
- OS identification — fingerprinting internet-facing OS and version details
- High-confidence CVE inferences — auto-generates vulnerability findings on version match
- Digital Risk Protection — leaked credentials & brand impersonation detection
- Global Lookup — instant TI on any IP or domain for faster investigation
Differentiated Use Case
M&A Due Diligence Use Case
One of Xpanse's most powerful and defensible use cases — pre-acquisition security risk assessment from the outside in.
Because Xpanse operates entirely without agents or credentials, it can assess the internet-facing security posture of any organization—including a company your client is evaluating for acquisition. This gives M&A deal teams and risk officers an objective, outside-in view of target company cyber risk before signing.
Pre-Acquisition
Evaluate target company's exposed infrastructure, shadow IT, unpatched systems, and credential leaks before deal close. Quantify cyber risk as part of the deal valuation.
Post-Merger Integration
After acquisition, Xpanse continuously discovers newly inherited infrastructure as it's onboarded. Identifies unknown assets from the acquired entity that aren't yet under security management.
Optiv PS Opportunity
Optiv wraps M&A cyber due diligence as a professional service — Xpanse provides the data layer. This is a repeatable, high-margin service for clients with active deal pipelines.
Commercial Structure
Pricing & Deployment
- Packaging Standalone: Expander base plus a network-size SKU, with Active Response, Attack Surface Testing, Link and Third Party Assess as separate line items. Sized by network size / asset count.
- Entry price ~$100,000/year (£70,850 per UK G-Cloud listing ≈ $90–100K USD)
- Active Response Paid add-on module for automated remediation playbooks
- XSIAM route Attack Surface Management is available as an add-on module on Cortex XSIAM and Cortex XDR — organizations on XSIAM can get ASM capability without a separate standalone Xpanse contract. Exposure Management is a different, separately licensed module.
- Onboarding services PANW sells paid onboarding/deployment services for initial asset seeding and configuration — Optiv PS opportunity
Platform Synergy
PANW Ecosystem Integration
| Cortex XSIAM | ASM module natively integrated in XSIAM (current release 3.6). Xpanse feeds asset and alert data into XSIAM's unified incident view. Note that Exposure Management is a separate XSIAM/XDR module, not a rename of ASM — it is licensed in its own right and requires XSIAM Premium, Enterprise or NG-SIEM. |
| Cortex XDR | Discovered exposed assets correlate with XDR-protected endpoints. XDR can isolate Cortex-protected endpoints discovered as high-risk via Xpanse Active Response playbooks — automated loop from external discovery to endpoint containment. |
| Cortex XSOAR | Xpanse ASM alerts trigger XSOAR playbooks for investigation, remediation, owner notification, and validation re-scanning. XSOAR Marketplace has the full Cortex Attack Surface Management pack with prebuilt playbooks. |
| Palo Alto NGFW | Active Response can add firewall block rules on on-premises Palo Alto firewalls to cut internet access for exposed assets — direct NGFW integration is a key differentiator vs. competitors. |
| Prisma Cloud | Cloud-discovered assets from AWS/Azure/GCP via connectors enrich Xpanse's asset inventory. Prisma Cloud posture findings correlate with externally-facing exposures for a unified cloud risk picture. |
Pre-Sales
Scoping Checklist
Data points to collect before quoting Cortex Xpanse.
Sales Conversations
Discovery Questions
Questions to uncover external attack surface blind spots and qualify the Xpanse opportunity.