Skip to content
Back to skills

Xpanse

ASecurity

Expert agent for Palo Alto Cortex Xpanse EASM. Covers internet-wide scanning, exposure prioritization, automated remediation via XSOAR/Cortex, Xpanse API, and integration with Cortex XDR and Prisma Cloud. WHEN: \"Xpanse\", \"Cortex Xpanse\", \"Palo Alto EASM\", \"Xpanse attack surface\", \"internet scanning Palo Alto\", \"Xpanse automated remediation\".

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
devopspythonrustgosqlkubernetesawsazureapidatabasesecurity

Works with

  • api

Security analysis

A100/100

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill xpanse --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Xpanse?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Xpanse
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-xpanse/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-xpanse)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: xpanse
description: "Expert agent for Palo Alto Cortex Xpanse EASM. Covers internet-wide scanning, exposure prioritization, automated remediation via XSOAR/Cortex, Xpanse API, and integration with Cortex XDR and Prisma Cloud. WHEN: \"Xpanse\", \"Cortex Xpanse\", \"Palo Alto EASM\", \"Xpanse attack surface\", \"internet scanning Palo Alto\", \"Xpanse automated remediation\"."
license: MIT
---

# Palo Alto Cortex Xpanse

This skill covers Palo Alto Networks Cortex Xpanse (formerly Expanse, acquired by Palo Alto in 2021). It has expertise in Xpanse's internet-wide scanning approach, exposure discovery and prioritization, automated remediation via Cortex XSOAR, integration with Cortex XDR and Prisma Cloud, and the Xpanse API.

## How to Approach Tasks

1. **Classify** the request:
   - **Asset discovery / onboarding** -- Seed setup, discovery tuning, attribution
   - **Exposure analysis** -- Attack surface overview, risky exposures, prioritization
   - **Automated remediation** -- XSOAR playbooks, Cortex integration
   - **API / integration** -- Xpanse API, SIEM export, third-party ITSM
   - **Cortex platform convergence** -- XDR + Xpanse + Prisma Cloud unified view

2. **Apply Palo Alto ecosystem context** -- Xpanse integrates deeply with Cortex XDR (endpoint), Cortex XSOAR (SOAR), and Prisma Cloud (cloud security). Organizations on the Palo Alto platform get correlated external + internal exposure context.

## Product Overview

**Cortex Xpanse:** Palo Alto's EASM platform -- discovers and monitors internet-facing attack surface at scale.

**What differentiates Xpanse:**
- Conducts its own internet-wide scanning (doesn't just rely on third-party data -- Xpanse scans the entire internet continuously)
- Automated remediation workflows via Cortex XSOAR integration
- Tight integration with Cortex XDR (endpoint data) and Prisma Cloud (cloud posture)
- RiskIQ acquisition (2021) added domain/brand intelligence capabilities
- Used by the world's largest enterprises (multiple Fortune 100)

**Deployment model:** Pure SaaS. Onboard via organization seeds (domains, IP ranges, company names).

## Internet-Wide Scanning Approach

Xpanse maintains a continuous map of the entire internet:
- Scans all IPv4 address space (4.3 billion IPs) repeatedly
- Port scanning across common and uncommon ports
- Service identification and version fingerprinting
- Certificate transparency log monitoring
- DNS data analysis and passive DNS
- BGP/WHOIS data for IP ownership

**What this means:** When you onboard to Xpanse, it doesn't start scanning your assets from scratch. It queries its existing global internet database against your seeds. Initial discovery results are available within hours, not days.

## Asset Discovery and Attribution

### Onboarding Seeds

Configure seeds in Cortex Xpanse console:
- **Domains:** company.com, company.net, acquired-company.io
- **IP ranges:** 198.51.100.0/24 (BGP-announced ranges)
- **ASNs:** Autonomous System Numbers your org owns
- **Company names:** For discovering assets with loose domain association

### Attribution Engine

Xpanse links discovered assets to your organization via:
- **TLS certificates:** Subject CN/SANs matching your domains
- **HTML content:** Company name, copyright, logo references in page content
- **IP ownership:** BGP/WHOIS registration data
- **Reverse DNS:** PTR records pointing to your domains
- **Cookie names/values:** Known application fingerprints

**Attribution actions:**
- Accept: Confirmed as your asset, add to monitored inventory
- Remove: Not your asset, remove from scope
- Note: Flag for follow-up

### Asset Inventory

Once attributed, each asset tracked with:
- IP address and hostname
- Open ports and services
- Software versions and technologies (web server, OS, frameworks)
- SSL/TLS certificate details (expiry, issuer, strength)
- Geolocation and hosting provider (AWS, Azure, on-prem DC)
- Business unit / subsidiary association
- CVEs on detected software

## Exposure Prioritization

### Attack Surface Grade

Xpanse assigns an Attack Surface Grade (A-F) to each organization:
- Grade based on: critical exposures count, high-risk services exposed, SSL hygiene, known exploitable vulns
- Drill down by business unit, geography, cloud provider
- Compare against industry benchmark (Palo Alto's global dataset)

### Risk-Ranked Exposures

Findings ranked by:
- **Exploitability:** Active exploits in the wild, CISA KEV, threat actor use
- **Service risk:** RDP/SSH/DB ports > web services > certificate issues
- **Asset business context:** Is this a critical production system?
- **Palo Alto threat intelligence:** Unit 42 threat intelligence enrichment

### High-Risk Service Categories

| Service | Default Risk | Notes |
|---|---|---|
| RDP (3389) | Critical | Most common ransomware entry point |
| SMB (445) | Critical | EternalBlue, ransomware propagation |
| SSH (22) | High | Brute force, weak key risks |
| Telnet (23) | Critical | Unencrypted; should never be internet-facing |
| Database ports | Critical | MySQL 3306, MSSQL 1433, Postgres 5432, MongoDB 27017 |
| Kubernetes API (6443, 8080) | Critical | Publicly exposed K8s = critical risk |
| Jenkins / admin panels | Critical | Default creds, RCE vulnerabilities common |
| Expired SSL certs | High | Trust violations, potential MITM |

## Automated Remediation (Cortex XSOAR)

Xpanse + Cortex XSOAR enables automated response to attack surface findings.

### XSOAR Xpanse Integration

**Pre-built Xpanse playbooks in XSOAR:**

**Playbook: New Critical Exposure Response**
```
Trigger: Xpanse detects new Critical exposure
Step 1: Enrich -- Get asset details from Xpanse API
Step 2: Correlate -- Check Cortex XDR for endpoint on this IP
Step 3: Check CMDB -- Is this a known/expected asset?
  → If known: Assign ticket to asset owner, set 24h SLA
  → If unknown (shadow IT): Escalate to security team immediately
Step 4: Notify -- Slack + email to relevant team
Step 5: Track -- Monitor for remediation in XSOAR case
Step 6: Verify -- 48h after ticket created, re-check Xpanse for exposure
```

**Playbook: Expired SSL Certificate**
```
Trigger: Certificate expires in < 30 days
Step 1: Identify certificate owner (CMDB lookup, domain registration)
Step 2: Create ServiceNow change request for renewal
Step 3: Assign to PKI/infrastructure team
Step 4: Escalation ladder: 30d → 14d → 7d → 1d notifications
Step 5: Verify renewal via Xpanse monitoring
```

**Playbook: Shadow IT Discovery**
```
Trigger: New asset discovered with no CMDB match
Step 1: Enrich IP/domain with threat intel (VirusTotal, Xpanse intel)
Step 2: Check cloud provider (AWS/Azure account discovery)
Step 3: Create Security incident (P2)
Step 4: Notify: IT, Cloud team, Security
Step 5: Investigate ownership (who stood this up?)
Step 6: Remediation: Shut down, document, or accept with controls
```

### REST API

Xpanse exposes a comprehensive REST API for integration:

```python
import requests

BASE_URL = "https://api-xpanse.paloaltonetworks.com"
HEADERS = {
    "Authorization": f"Bearer {API_KEY}",
    "Content-Type": "application/json"
}

# Get all critical attack surface issues
response = requests.post(
    f"{BASE_URL}/v1/incidents/alerts/get_incidents_info",
    headers=HEADERS,
    json={
        "filters": [
            {
                "field": "incident_types",
                "operator": "in",
                "value": ["Unmanaged Internet Asset", "Risky Flow"]
            },
            {
                "field": "severity",
                "operator": "in",
                "value": ["critical", "high"]
            }
        ],
        "search_from": 0,
        "search_to": 100
    }
)

incidents = response.json()
for incident in incidents["reply"]["incidents"]:
    print(f"ID: {incident['incident_id']}, "
          f"Severity: {incident['severity']}, "
          f"Asset: {incident.get('involved_assets', ['N/A'])[0]}")
```

## Cortex Platform Integration

### Xpanse + Cortex XDR

XDR integration provides:
- "This internet-exposed IP: Is there a Cortex XDR-protected endpoint at this IP?"
- Cross-correlation: External exposure + active internal threat = escalated priority
- Unified timeline: External attack observed at same time as internal anomaly

### Xpanse + Prisma Cloud

- External exposure (Xpanse) + cloud posture (Prisma Cloud) unified view
- "This public cloud resource is exposed externally AND has a critical CSPM misconfiguration"
- AppDNA context: Map external asset back to the application it belongs to

### Xpanse + Strata (Firewall)

- Exposed services can trigger Palo Alto NGFW policy changes
- Automated: "New unauthorized service detected → Create firewall block rule"
- Requires Panorama integration

## Integrations

**ITSM:**
- ServiceNow: Auto-create incidents for Critical/High exposures
- Jira: Development team workflows for remediation tracking

**SIEM:**
- Cortex XSIAM: Native integration (Palo Alto's AI-driven SOC platform)
- Splunk: Xpanse findings via Splunk Add-on
- Microsoft Sentinel: REST API connector

**Notifications:**
- Slack, Microsoft Teams
- PagerDuty for Critical exposures
- Email

## Use Case: Post-Acquisition Attack Surface Review

When an organization acquires a new company, Xpanse is commonly used for rapid attack surface discovery:

1. Add acquired company's domains and IP ranges as seeds
2. Xpanse queries global internet database -- results within hours
3. Review: What internet-facing services does the acquired company have?
4. Prioritize: Critical exposures (RDP, databases) for immediate remediation
5. Roadmap: Plan phased remediation/decommission/integration
6. Ongoing: Monitor acquired company's attack surface during integration period

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…