Palo Alto Networks Cortex Xpanse
DARPA-derived internet scanning platform, now Palo Alto Networks' EASM module, that continuously maps and attributes internet-facing assets.
Visit Website ↗Overview
Cortex Xpanse traces back to Qadium, founded in 2012 out of DARPA-funded research, which rebranded as Expanse in 2018 before Palo Alto Networks acquired it for roughly $800 million in late 2020. The underlying technology continuously scans the entire public IPv4 space and correlates ownership signals (certificates, WHOIS, ASN data, hosting relationships) to attribute internet-facing assets back to an organization, including ones security teams never knowingly provisioned.
Since the acquisition, Xpanse has been folded into the Cortex product family alongside XSIAM and XSOAR, positioned as the “outside-in” discovery layer that feeds detection and response workflows rather than a standalone product line. Its differentiator at launch was internet-scale, agentless attribution without requiring customer input — the system infers what belongs to an organization rather than relying on a declared asset list, which is still the core value proposition today.
Innovation Matrix Assessment
Feature pace is now set by the broader Cortex/XSIAM roadmap rather than independent EASM innovation; most recent announcements are platform integrations, not net-new discovery capability.
Agentless, DARPA-derived internet attribution is a proven approach for finding genuinely unknown exposed assets, which is the core operational promise of EASM.
Distribution benefits from Palo Alto Networks' scale and bundling into Cortex, though there is little independently reported ASM-specific growth data since the 2020 acquisition.
Was genuinely disruptive as Expanse/Qadium (pioneered internet-scale attribution); as an absorbed module in a much larger suite it is now more evolutionary than disruptive.
Widely deployed and cited in Palo Alto Networks' Unit 42 incident response engagements as the discovery layer for exposure-driven breaches.
Embedded in one of the industry's dominant SOC platforms, giving it durable distribution regardless of standalone ASM market dynamics.
Why CISOs Should Care
A CISO already standardized on Cortex gets internet-scale asset attribution feeding directly into detection and response workflows without deploying a separate discovery tool.
What Makes It Different
Instead of asking customers to declare their asset inventory, Xpanse scans the full public internet daily and uses ownership-attribution heuristics to infer what belongs to the organization, surfacing shadow IT and forgotten infrastructure the customer never listed.
The Matrix Verdict
70/100 — MEANINGFUL INNOVATOR
A pioneering technology that has matured into a well-integrated but no longer independently disruptive module of a much larger security suite — solid operational value and durable relevance, tempered by slower net-new innovation now that it is a feature of Cortex rather than a standalone company.
Editorial Note: Claims vs. Verified Findings
Acquisition price, founding history, and product positioning are corroborated by Palo Alto Networks press releases and independent reporting (TechCrunch, SEC filings); specific current customer counts and efficacy statistics for Xpanse alone are not independently published and are largely vendor-sourced.
Sources
- Company site — https://www.paloaltonetworks.com/cortex/cortex-xpanse
- Palo Alto Networks Completes Acquisition of Expanse — https://www.paloaltonetworks.com/company/press/2020/palo-alto-networks-completes-acquisition-of-expanse
- TechCrunch — https://techcrunch.com/2020/11/11/palo-alto-networks-to-acquire-expanse-in-deal-worth-800m/
Alternatives to Palo Alto Networks Cortex Xpanse
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
Assetnote (Searchlight Cyber)
Offensive-security-researcher-built EASM platform from Brisbane, profitable and self-funded until its 2025 acquisition by dark-web intelligence firm Searchlight Cyber.
IONIX
EASM vendor, formerly Cyberpion, that maps not just an organization's own internet-facing assets but the chain of third-party…
Detectify
Stockholm-based EASM and DAST platform that feeds its scanner with vulnerability research crowdsourced from a network of ethical…