> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2023-releases/expander-release-22-june.md).

# Expander Release 2.2 (June 2023)

The table below describes the features and enhancements introduced in the Expander 2.2 (June 2023) release.

| Feature                                               | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ----------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Active Response Module Launch                         | <p>The free community trial for the Active Response add-on module continues through the end of July 2023. Beginning August 1, customers must purchase an Active Response license in addition to the Expander license.</p><p>You can try out Active Response with a 60-day free trial that you activate from within Expander.</p><p>See <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XPANSE/Cortex-Xpanse-Expander-User-Guide/Active-Response-License">Active Response License</a> to activate your 60-day free trial. See <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XPANSE/Cortex-Xpanse-Expander-User-Guide/Active-Response-for-Incidents">Active Response</a> for information about Active Response.</p> |
| Active Response Enhancements                          | <p>Active Response enhancements include the following:</p><ul><li>Prisma Cloud integration for service owner identification.</li><li>Jira Cloud integration for ticket creation.</li><li>Automated remediation support for Mongo Server, PostgreSQL Server, MySql Server, and ElasticSearch Server.</li></ul><p>See <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XPANSE/Cortex-Xpanse-Expander-User-Guide/Active-Response-for-Incidents">Active Response</a> for information.</p>                                                                                                                                                                                                                                           |
| Remediation Confirmation Scanning for Active Response | Improved scan to validate the resolution of alerts . This scan utilizes the same payloads and global scanning infrastructure that was used for service discovery to ensure that the risk has been addressed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Threat Response Center Enhancements                   | <ul><li>Reporting—You can now share information about global threat events directly from the Threat Response Center by downloading a PDF report from the threat event details page.</li><li>Trending charts—New trending charts enable you to track your progress in remediating alerts from global threat events.</li></ul><p>See <a href="/pages/cpUkJvIyN6PVlp94wLCx">title\_title</a> for more information.</p>                                                                                                                                                                                                                                                                                                                       |
| Prisma Cloud Integration                              | <p>Use the Prisma Cloud integration to Identify rogue cloud and shadow IT instances and bring unmanaged assets under management. Xpanse ingests cloud context from Prisma Cloud for Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft (MS) Azure, Alibaba Cloud, and Oracle Cloud Infrastructure.</p><p>See <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XPANSE/Cortex-Xpanse-Expander-User-Guide/Ingest-Cloud-Resources-from-Prisma-Cloud">Ingest Cloud Resources from Prisma Cloud</a> and <a href="/pages/cpUkJvIyN6PVlp94wLCx">title\_title</a> for details.</p>                                                                                                                                        |
| Xpanse Security Rating                                | <p>The Cortex Xpanse Security Rating represents the overall hygiene of your organization’s external-facing attack surface. The Security Rating Dashboard enables you to track your security rating over time, compare your rating to industry peers, and break down your security rating by geography, business unit, and hosting provider.</p><p>See <a href="urn:resource:component:777231">Security Rating</a> for details.</p>                                                                                                                                                                                                                                                                                                        |
| Python Software Development Kit (SDK)                 | <p>The new Python SDK consists of a collection of tools bundled together in a single, easy-to-install package. The SDK supports the following Expander functionality:</p><ul><li>Asset Management</li><li>Incident Management</li><li>Tag Management</li><li>Attack Surface Rules</li></ul><p>See <a href="https://cortex-xpanse-python-sdk.readthedocs.io/en/latest/">Cortex Xpanse Python SDK</a> for more information.</p>                                                                                                                                                                                                                                                                                                             |
| Expander API Enhancements                             | <p>The following APIs were improved with additional fields and filter options:</p><ul><li>Asset Management APIs</li><li>Alerts API</li><li>Incidents API</li></ul><p>The following APIs were introduced in this release:</p><ul><li>Tag Management APIs</li><li>Remediation Scanning APIs</li><li>Attack Surface Rules API</li><li>Get All Websites API</li><li>Get Website Details API</li><li>Get Websites Last Assessment</li></ul><p>See the <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-Xpanse-REST-API/Cortex-Xpanse-REST-API">Cortex Xpanse API Reference</a> for details.</p>                                                                                                                                      |
| Asset Tag Rules                                       | <p>Define custom tag rules that apply tags automatically to assets that match your rule criteria, including new assets that are attributed to your organization. Tag rules are supported for IP addresses and IP ranges, enabling you to define custom IP ranges.</p><p>See <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XPANSE/Cortex-Xpanse-Expander-User-Guide/Asset-Tagging">Asset Tagging</a> for more information.</p>                                                                                                                                                                                                                                                                                                |
| Asset Notes                                           | <p>Add notes to individual assets in Expander.</p><p>See <a href="/pages/cpUkJvIyN6PVlp94wLCx">title\_title</a> for details.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Bulk edit attack surface rules                        | Enable or disable attack surface rules in bulk.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Improvements to the Inventory navigation              | <ul><li>The Asset Inventory has been renamed Inventory.</li><li>The All Assets page was renamed Unified Inventory.</li><li>The Inventory navigation was reorganized to indicate more clearly which asset types are included on the Unified Inventory page.</li><li>Cloud Inventory, which include Cloud Compute Instances and Prisma Cloud Resources, was introduced.</li></ul>                                                                                                                                                                                                                                                                                                                                                           |
| Incident Risk Score Improvements                      | <ul><li>Risk scores for active incidents will be recalculated when a scoring rule is created or changed. The updated score will appear in Expander within a few hours.</li><li>Risk scores and risk explainers will now be available as part of the Incident API.</li><li>Additional options were introduced for creating risk scoring rules based on service information.</li></ul>                                                                                                                                                                                                                                                                                                                                                      |
| Configure Access Control in the Cortex Gateway        | <p>In the Cortex Gateway, you can view and manage permissions, role-based access control (RBAC), and user group settings across all Cortex products.</p><p>See the <a href="https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Gateway-Administrator-Guide">Cortex Gateway Administrator Guide</a> for details.</p>                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Other Usability Enhancements                          | <ul><li>Domain-level filters were introduced.</li><li>IPv4 address filter that enables a CIDR/Range/Wildcard search.</li><li>Ability to download data in CSV format for most list-view pages in Expander.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2023-releases/expander-release-22-june.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
