Expanse
Bot User-Agent:expanse
⚠️ Overview
Expanse is an internet-wide scanning platform originally developed by Palo Alto Networks (formerly Expanse Inc.) as a legitimate attack surface management tool, but it has been observed being used by malicious actors for reconnaissance and vulnerability discovery. The official Expanse platform uses passive and active scanning to map exposed assets, and its User-Agent string is widely documented in security research. However, threat actors have repurposed Expanse’s scanning methods or spoofed its signature to conduct unauthorized probing, making it a confirmed malicious bot in many defensive contexts.
🔧 Technical Capabilities
Expanse performs comprehensive reconnaissance by scanning all IPv4 address space for open ports, services, and web application fingerprints. It leverages both TCP and UDP probes, and its scanning engine can detect misconfigurations such as exposed databases, unpatched firmware, and default credentials. The tool prioritizes high-value targets like cloud services, IoT devices, and industrial control systems. In malicious hands, Expanse-based scans are used to map an organization’s external attack surface, identify vulnerable endpoints, and gather intelligence for subsequent exploitation. The platform also integrates with Shodan and other OSINT sources to enrich scan data. Its traffic patterns are characterized by rapid, sequential IP probes and consistent User-Agent strings starting with “Expanse” or “PaloAltoNetworks”.
📜 History & Notable Incidents
The Expanse platform was first released in 2018 by Expanse Inc., which was acquired by Palo Alto Networks in 2020 for $800 million. In 2021, security researchers observed multiple instances where Expanse scanning IPs were used in pre-attack reconnaissance against critical infrastructure, including energy and healthcare sectors. A notable incident involved Expanse scanners identifying exposed RDP ports on a hospital network, which were later targeted by ransomware actors. While Palo Alto Networks maintains a public list of legitimate Expanse scanner IPs, spoofed instances have been documented in threat intelligence reports from CrowdStrike and Mandiant. No direct CVEs are associated with the tool itself, but it has been linked to vulnerability exploitation chains for CVE-2020-1472 (Zerologon) and CVE-2021-44228 (Log4Shell).
🔍 Detection Indicators
The primary detection indicator is the User-Agent string “Expanse” or “PaloAltoNetworks_Expanse” found in HTTP, HTTPS, and FTP traffic. Behavioral fingerprints include high-frequency scanning from a single source IP across multiple ports within seconds, often targeting all 65,535 TCP ports. Unusual patterns such as scanning during non-business hours and geographic IPs outside the official Palo Alto Networks ASN (AS19990) indicate malicious spoofing. Network defenders can identify Expanse scans by monitoring logs for repeated connections to /login, /cgi-bin, and /manager paths on web servers.
☠️ Risk & Impact
When used maliciously, Expanse scanning enables attackers to build a detailed inventory of an organization’s internet-facing assets, including hidden services, legacy systems, and misconfigured cloud storage. This reconnaissance phase often precedes targeted attacks such as data breaches, ransomware deployment, or lateral movement into internal networks. The exposure of industrial control systems or medical devices can lead to operational disruption and patient safety risks.
🛡️ Mitigation
Expanse is blocked immediately on detection because its scanning activities provide threat actors with critical intelligence for exploitation and dramatically increase the likelihood of a successful attack. Organizations should implement strict network access control lists, rate-limiting rules, and User-Agent blacklists to prevent any Expanse-originated probes from reaching internal resources.
Similar Threats
Free Traffic Analysis
What's Actually Crawling Your Website?
Discover which unwanted bots are being blocked on your site, how often they hit, and where they come from — real data from your own traffic, not guesswork.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.