Expert agent for Palo Alto Cortex Xpanse EASM. Covers internet-wide scanning, exposure prioritization, automated remediation via XSOAR/Cortex, Xpanse API, and integration with Cortex XDR and Prisma Cloud. WHEN: \"Xpanse\", \"Cortex Xpanse\", \"Palo Alto EASM\", \"Xpanse attack surface\", \"internet scanning Palo Alto\", \"Xpanse automated remediation\".
Scanned 9/24/2026
npx -y skills add chrishuffman5/domain-expert --skill xpanse --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Xpanse?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/chrishuffman5-xpanse)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: xpanse
description: "Expert agent for Palo Alto Cortex Xpanse EASM. Covers internet-wide scanning, exposure prioritization, automated remediation via XSOAR/Cortex, Xpanse API, and integration with Cortex XDR and Prisma Cloud. WHEN: \"Xpanse\", \"Cortex Xpanse\", \"Palo Alto EASM\", \"Xpanse attack surface\", \"internet scanning Palo Alto\", \"Xpanse automated remediation\"."
license: MIT
---
# Palo Alto Cortex Xpanse
This skill covers Palo Alto Networks Cortex Xpanse (formerly Expanse, acquired by Palo Alto in 2021). It has expertise in Xpanse's internet-wide scanning approach, exposure discovery and prioritization, automated remediation via Cortex XSOAR, integration with Cortex XDR and Prisma Cloud, and the Xpanse API.
## How to Approach Tasks
1. **Classify** the request:
- **Asset discovery / onboarding** -- Seed setup, discovery tuning, attribution
- **Exposure analysis** -- Attack surface overview, risky exposures, prioritization
- **Automated remediation** -- XSOAR playbooks, Cortex integration
- **API / integration** -- Xpanse API, SIEM export, third-party ITSM
- **Cortex platform convergence** -- XDR + Xpanse + Prisma Cloud unified view
2. **Apply Palo Alto ecosystem context** -- Xpanse integrates deeply with Cortex XDR (endpoint), Cortex XSOAR (SOAR), and Prisma Cloud (cloud security). Organizations on the Palo Alto platform get correlated external + internal exposure context.
## Product Overview
**Cortex Xpanse:** Palo Alto's EASM platform -- discovers and monitors internet-facing attack surface at scale.
**What differentiates Xpanse:**
- Conducts its own internet-wide scanning (doesn't just rely on third-party data -- Xpanse scans the entire internet continuously)
- Automated remediation workflows via Cortex XSOAR integration
- Tight integration with Cortex XDR (endpoint data) and Prisma Cloud (cloud posture)
- RiskIQ acquisition (2021) added domain/brand intelligence capabilities
- Used by the world's largest enterprises (multiple Fortune 100)
**Deployment model:** Pure SaaS. Onboard via organization seeds (domains, IP ranges, company names).
## Internet-Wide Scanning Approach
Xpanse maintains a continuous map of the entire internet:
- Scans all IPv4 address space (4.3 billion IPs) repeatedly
- Port scanning across common and uncommon ports
- Service identification and version fingerprinting
- Certificate transparency log monitoring
- DNS data analysis and passive DNS
- BGP/WHOIS data for IP ownership
**What this means:** When you onboard to Xpanse, it doesn't start scanning your assets from scratch. It queries its existing global internet database against your seeds. Initial discovery results are available within hours, not days.
## Asset Discovery and Attribution
### Onboarding Seeds
Configure seeds in Cortex Xpanse console:
- **Domains:** company.com, company.net, acquired-company.io
- **IP ranges:** 198.51.100.0/24 (BGP-announced ranges)
- **ASNs:** Autonomous System Numbers your org owns
- **Company names:** For discovering assets with loose domain association
### Attribution Engine
Xpanse links discovered assets to your organization via:
- **TLS certificates:** Subject CN/SANs matching your domains
- **HTML content:** Company name, copyright, logo references in page content
- **IP ownership:** BGP/WHOIS registration data
- **Reverse DNS:** PTR records pointing to your domains
- **Cookie names/values:** Known application fingerprints
**Attribution actions:**
- Accept: Confirmed as your asset, add to monitored inventory
- Remove: Not your asset, remove from scope
- Note: Flag for follow-up
### Asset Inventory
Once attributed, each asset tracked with:
- IP address and hostname
- Open ports and services
- Software versions and technologies (web server, OS, frameworks)
- SSL/TLS certificate details (expiry, issuer, strength)
- Geolocation and hosting provider (AWS, Azure, on-prem DC)
- Business unit / subsidiary association
- CVEs on detected software
## Exposure Prioritization
### Attack Surface Grade
Xpanse assigns an Attack Surface Grade (A-F) to each organization:
- Grade based on: critical exposures count, high-risk services exposed, SSL hygiene, known exploitable vulns
- Drill down by business unit, geography, cloud provider
- Compare against industry benchmark (Palo Alto's global dataset)
### Risk-Ranked Exposures
Findings ranked by:
- **Exploitability:** Active exploits in the wild, CISA KEV, threat actor use
- **Service risk:** RDP/SSH/DB ports > web services > certificate issues
- **Asset business context:** Is this a critical production system?
- **Palo Alto threat intelligence:** Unit 42 threat intelligence enrichment
### High-Risk Service Categories
| Service | Default Risk | Notes |
|---|---|---|
| RDP (3389) | Critical | Most common ransomware entry point |
| SMB (445) | Critical | EternalBlue, ransomware propagation |
| SSH (22) | High | Brute force, weak key risks |
| Telnet (23) | Critical | Unencrypted; should never be internet-facing |
| Database ports | Critical | MySQL 3306, MSSQL 1433, Postgres 5432, MongoDB 27017 |
| Kubernetes API (6443, 8080) | Critical | Publicly exposed K8s = critical risk |
| Jenkins / admin panels | Critical | Default creds, RCE vulnerabilities common |
| Expired SSL certs | High | Trust violations, potential MITM |
## Automated Remediation (Cortex XSOAR)
Xpanse + Cortex XSOAR enables automated response to attack surface findings.
### XSOAR Xpanse Integration
**Pre-built Xpanse playbooks in XSOAR:**
**Playbook: New Critical Exposure Response**
```
Trigger: Xpanse detects new Critical exposure
Step 1: Enrich -- Get asset details from Xpanse API
Step 2: Correlate -- Check Cortex XDR for endpoint on this IP
Step 3: Check CMDB -- Is this a known/expected asset?
→ If known: Assign ticket to asset owner, set 24h SLA
→ If unknown (shadow IT): Escalate to security team immediately
Step 4: Notify -- Slack + email to relevant team
Step 5: Track -- Monitor for remediation in XSOAR case
Step 6: Verify -- 48h after ticket created, re-check Xpanse for exposure
```
**Playbook: Expired SSL Certificate**
```
Trigger: Certificate expires in < 30 days
Step 1: Identify certificate owner (CMDB lookup, domain registration)
Step 2: Create ServiceNow change request for renewal
Step 3: Assign to PKI/infrastructure team
Step 4: Escalation ladder: 30d → 14d → 7d → 1d notifications
Step 5: Verify renewal via Xpanse monitoring
```
**Playbook: Shadow IT Discovery**
```
Trigger: New asset discovered with no CMDB match
Step 1: Enrich IP/domain with threat intel (VirusTotal, Xpanse intel)
Step 2: Check cloud provider (AWS/Azure account discovery)
Step 3: Create Security incident (P2)
Step 4: Notify: IT, Cloud team, Security
Step 5: Investigate ownership (who stood this up?)
Step 6: Remediation: Shut down, document, or accept with controls
```
### REST API
Xpanse exposes a comprehensive REST API for integration:
```python
import requests
BASE_URL = "https://api-xpanse.paloaltonetworks.com"
HEADERS = {
"Authorization": f"Bearer {API_KEY}",
"Content-Type": "application/json"
}
# Get all critical attack surface issues
response = requests.post(
f"{BASE_URL}/v1/incidents/alerts/get_incidents_info",
headers=HEADERS,
json={
"filters": [
{
"field": "incident_types",
"operator": "in",
"value": ["Unmanaged Internet Asset", "Risky Flow"]
},
{
"field": "severity",
"operator": "in",
"value": ["critical", "high"]
}
],
"search_from": 0,
"search_to": 100
}
)
incidents = response.json()
for incident in incidents["reply"]["incidents"]:
print(f"ID: {incident['incident_id']}, "
f"Severity: {incident['severity']}, "
f"Asset: {incident.get('involved_assets', ['N/A'])[0]}")
```
## Cortex Platform Integration
### Xpanse + Cortex XDR
XDR integration provides:
- "This internet-exposed IP: Is there a Cortex XDR-protected endpoint at this IP?"
- Cross-correlation: External exposure + active internal threat = escalated priority
- Unified timeline: External attack observed at same time as internal anomaly
### Xpanse + Prisma Cloud
- External exposure (Xpanse) + cloud posture (Prisma Cloud) unified view
- "This public cloud resource is exposed externally AND has a critical CSPM misconfiguration"
- AppDNA context: Map external asset back to the application it belongs to
### Xpanse + Strata (Firewall)
- Exposed services can trigger Palo Alto NGFW policy changes
- Automated: "New unauthorized service detected → Create firewall block rule"
- Requires Panorama integration
## Integrations
**ITSM:**
- ServiceNow: Auto-create incidents for Critical/High exposures
- Jira: Development team workflows for remediation tracking
**SIEM:**
- Cortex XSIAM: Native integration (Palo Alto's AI-driven SOC platform)
- Splunk: Xpanse findings via Splunk Add-on
- Microsoft Sentinel: REST API connector
**Notifications:**
- Slack, Microsoft Teams
- PagerDuty for Critical exposures
- Email
## Use Case: Post-Acquisition Attack Surface Review
When an organization acquires a new company, Xpanse is commonly used for rapid attack surface discovery:
1. Add acquired company's domains and IP ranges as seeds
2. Xpanse queries global internet database -- results within hours
3. Review: What internet-facing services does the acquired company have?
4. Prioritize: Critical exposures (RDP, databases) for immediate remediation
5. Roadmap: Plan phased remediation/decommission/integration
6. Ongoing: Monitor acquired company's attack surface during integration period
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!