> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2023-releases/expander-release-21-march.md).

# Expander Release 2.1 (March 2023)

The table below describes the features and enhancements introduced in the Expander 2.1 release in March 2023.

| Feature                                                | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Threat Response Center                                 | <p>The Threat Response Center in Cortex Xpanse Expander simplifies and streamlines your response to threat events by aggregating the most important information about a threat and its impact on your organization in one place. From the Threat Response Center, you can:</p><ul><li><em>Review a curated list of emergent and global threat events</em>, and quickly identify the events that impact your organization.</li><li><em>Research a threat event.</em> The Xpanse Security Research Team provides a threat summary, potential exploit consequences, previous exploit activity, and links to other reputable sources for additional information.</li><li><em>Assess the impact of a threat event on your organization.</em> Review a detailed list of the affected software, turn on relevant attack surface rules, identify relevant incidents and alerts, and see how the risk is distributed across your organization.</li><li><em>Build a Remediation Plan.</em> The Threat Response Center provides remediation guidance for the event, lists of relevant alerts and incidents by status and assignee, and click-throughs to incident and alert pages to begin remediation.</li></ul><p>See <a href="/pages/SYAWSt32evqJf1ousIwd">title\_title</a> in the Cortex Xpanse Expander User Guide for more information.</p> |
| Automation Configuration Wizard                        | <p>The Automation Configuration Wizard simplifies the automation integration configuration process by providing s a step-by-step, guided experience for installing and configuring the integrations.</p><p>See <a href="/pages/SYAWSt32evqJf1ousIwd">title\_title</a> for more information.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Remediation Path Rules                                 | <p>Cortex Xpanse Active Response automates ASM alert investigation and resolution. You can now create Remediation Path Rules to customize Active Response to automatically respond to alerts with actions that meet your specific business requirements and context.</p><p>See <a href="/pages/SYAWSt32evqJf1ousIwd">title\_title</a> for more information.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Remediation Content                                    | <p>The Active Response module has been enhanced to include support for the following:</p><ul><li>Use case coverage for SSH Servers, OpenSSH, Unencrypted FTP, and Unclaimed S3, SMTP servers</li><li>Azure and Google cloud service providers</li><li>Enrichment integrations with Tenable.io, Rapid7, splunk</li></ul><p>See the <a href="/pages/SYAWSt32evqJf1ousIwd">title\_title</a> for more information.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Web Attack Surface Management Enhancements             | <ul><li><p>Expander now supports alerts and incidents for websites. Two categories of Attack Surface Rules have been created for websites:</p><ul><li>Web Security Assessments—Detect website security best practice failures.</li><li><p>Web Technology CVE Inferences—Alert on web technologies that have inferred CVEs that are both high-confidence matches and high-severity CVEs.</p><p>An important benefit of Web Technology CVE Inferences is that when they are enabled, Xpanse creates an alert on any new CVE that matches on these criteria. This means you will be notified immediately about zero-day vulnerabilities that are an exact version match.</p></li></ul><p>Attack Surface Rules for website are disabled by default.</p></li><li>Business Unit (BU) tags are now applied to websites, enabling you to filter and sort websites by BU and to provide scope-based access control by BU.</li></ul><p>See <a href="/pages/SYAWSt32evqJf1ousIwd">title\_title</a> for details.</p>                                                                                                                                                                                                                                                                                                                               |
| Asset Explainability                                   | <p>Cortex Xpanse provides attribution information about each asset in your asset inventory, so you know at-a-glance why Xpanse believes an asset belongs to your organization. Xpanse displays the following attribution data on the asset details panel and on the assets tab in an incident:</p><ul><li>Asset Attribution Evidence—Explains how and why an asset was attributed to your organization.</li><li>Asset Confidence Labels—Enable you to quickly see how confident Xpanse is that an asset belongs to your organization based on specific attribution criteria.</li><li>Attribution-Related Tags—Enables you to use attribution criteria to filter and sort assets and incidents and to provide scope-based access control.</li></ul><p>Asset attribution information is provided for all asset types except websites and services.</p><p>See <a href="/pages/SYAWSt32evqJf1ousIwd">title\_title</a> for details.</p>                                                                                                                                                                                                                                                                                                                                                                                                     |
| Risk Scoring                                           | <p>You can now prioritize incidents and quantify your organization's relative risk using Risk Scoring. By default, Expander assigns an Xpanse Risk score to every incident using threat and exploit intelligence relevant to the alerts in the incident. In addition to the Xpanse Risk Score that is assigned to each incident, you can also create custom risk-scoring rules and manually assign risk scores.</p><p>See the following documents for more information about Xpanse Risk Scoring:</p><ul><li><a href="/pages/SYAWSt32evqJf1ousIwd">title\_title</a></li><li><a href="urn:resource:component:708668">Customize Risk Scoring</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| XSOAR support for Expander 2.x                         | A new XSOAR Pack has been released to support the new Expander 2.x APIs. This Pack includes the necessary commands and incident fetching capabilities to support Expander 2.x customers who would like to automate the response to Expander findings as well as enrich their incidents with ASM asset and service details.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Asset Name Changes                                     | <p>The following changes were made to asset names in the Asset Inventory and some dashboards in Expander and the Expander API:</p><ul><li>Owned Responsive IPs—Previously called Unassociated Responsive IPs</li><li>Owned IP Ranges—Previously called External IP Ranges</li></ul><p>You may still see some references to the old names. These will be updated in the next release.</p><p>See <a href="/pages/SYAWSt32evqJf1ousIwd">title\_title</a> for more information about ASM assets.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Syslog Forwarding for Alerts and Management Audit Logs | <p>Cortex Xpanse now supports the ability to forward alerts and management audit logs to a syslog receiver.</p><p>See <a href="/pages/SYAWSt32evqJf1ousIwd">title\_title</a> for details.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Cortex Xpanse Expander API Reference, 2.x              | The [Cortex Xpanse API Reference, 2.x](https://docs-cortex.paloaltonetworks.com/r/Cortex-XPANSE/Cortex-Xpanse-API-Reference), for Expander 2.x is now available.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2023-releases/expander-release-21-march.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
