cortex-xpanse
Cortex Xpanse is a cloud‑based attack surface management (ASM) platform developed and maintained by Palo Alto Networks. It is designed to continuously discover, assess, and monitor internet‑facing assets for potential security exposures. The tool is officially documented on Palo Alto Networks’ website and is commonly used by security teams to identify misconfigurations and vulnerabilities, but it is also frequently observed scanning networks without explicit permission, leading many organizations to classify it as a malicious or unauthorized scanner.
Cortex Xpanse performs massive‑scale reconnaissance by scanning public IPv4 address ranges for open ports, services, and SSL/TLS certificates using its proprietary “Xpanse” engine. It can detect exposed databases (e.g., MongoDB, Elasticsearch), unsecured remote access protocols (RDP, SSH), and misconfigured cloud storage buckets. The platform also integrates with threat intelligence feeds to correlate discovered assets with known vulnerabilities, including CVEs like CVE‑2023‑22527 (Atlassian Confluence) and CVE‑2024‑27198 (JetBrains TeamCity). It uses a combination of HTTP requests, DNS lookups, and banner grabbing to build a comprehensive asset inventory without requiring credentials.
Originally developed as part of Palo Alto Networks’ Cortex product suite, Xpanse was publicly launched in 2020 after the acquisition of the startup “Expanse” (which was later rebranded). Notable incidents include widespread scanning campaigns detected by network administrators in 2021 and 2023, where Xpanse probes were observed targeting government and critical infrastructure IP ranges. Palo Alto Networks itself publishes data on these scans in its annual “Attack Surface Threat Report,” acknowledging that some scans may be mistaken for malicious activity. No critical CVEs have been assigned to Xpanse itself, but it is frequently used as a tool to identify hosts vulnerable to attacks such as Log4Shell (CVE‑2021‑44228).
The primary detection indicator is the User‑Agent string used by Xpanse scanning services: Mozilla/5.0 (compatible; PaloAltoNetworks‑ASM/1.0; +https://www.paloaltonetworks.com/asm) and variations containing “Cortex Xpanse” or “Expanse”. Network traffic patterns include high‑frequency SYN scans from a wide range of IP addresses (often AWS or Google Cloud) targeting common ports (22, 443, 3389, 27017) with consistent timing intervals. Behavioral fingerprints also include repeated HTTP requests to non‑existent endpoints (e.g., /phpmyadmin, /.env) in a predictable pattern.
While not inherently malicious, unauthorized scanning by Cortex Xpanse can reveal sensitive asset information to third parties, including internal‑facing systems accidentally exposed externally, unpatched software versions, and weak configurations. This exposure can be leveraged by attackers to plan targeted intrusions. The impact is especially high for organizations that rely on security‑by‑obscurity, as Xpanse systematically catalogs every reachable service.
Cortex Xpanse is blocked immediately on detection because its scanning activity represents an unauthorized reconnaissance attempt that could prelude actual attacks. Network defenders should apply firewall rules to drop traffic originating from known Palo Alto Networks ASM IP ranges (maintained in public blocklists) and validate that any such scanning is not part of an approved penetration test.
Similar Threats
Free Bot Analysis
Find out exactly how much of your traffic is automated — and which bots are draining your bandwidth and skewing your analytics.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.