> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2024-releases/expander-release-25-april-2024.md).

# Expander Release 2.5 (April 2024)

The table below describes the features and enhancements introduced in the Expander 2.5 (April 2024) release.

| Feature                                                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Attack Surface Testing (GA)                             | Cortex Xpanse can now confirm the presence of vulnerabilities through customer-authorized, benign Attack Surface Testing. Confirming or disproving the presence of a vulnerability allows Xpanse to prioritize risks with more precision and confidence. Attack surface tests are run daily on services exposed to the public internet and can be configured to automatically include new directly-discovered services. This narrows the automation gap between attackers and defenders and enables you to focus on the most impactful remediations.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ASN data                                                | Gain additional context for investigating alerts with Autonomous System Number (ASN) data filters and details. Xpanse now supports filtering based on ASN data in the Inventory and provides ASN details on the details pane for IPv4 ranges and responsive IPs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| New incident and alert pivots                           | You can now pivot from an incident or alert to related alerts, services, and websites based on the associated IP address or domain.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| New outbound integrations                               | <ul><li>Rapid7 InsightVM—This integration replicates Attack Surface Management (ASM) assets (IP addresses, domains) within Rapid7 to be used as scan targets.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Active Response enhancement                             | Building on the XDR enrichment added to Active Response in release 2.4, Cortex Xpanse now supports endpoint-based mitigation playbooks on some ASM alert types, giving defenders flexibility in how they respond to internet-exposed risks.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| API Key with multiple roles                             | Create a single API key with multiple roles allowing you to use dynamic RBAC management, reduce administrative overhead, and improve security by minimizing key proliferation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Custom incident and alert statuses and resolution types | To help align the incident and alert management process with your organization's security practices, you can now create custom statuses and custom resolution types.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| New authentication controls                             | <p>New authentication control options provide additional security features to help prevent security breaches.</p><ul><li><p><strong>Passwordless Authentication</strong></p><p>You now have the option to require non-password credentials for SSO authentication. If selected, this option requires users to choose intrinsically safer authentication factors, such as biometric authentication, to access Cortex Xpanse.</p></li><li><p><strong>Force Authentication</strong></p><p>You now have the option to require users to reauthenticate to access the Cortex Xpanse tenant, even if they have already authenticated to access other applications.</p></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Cortex Xpanse API updates                               | <p>Following are some of the key updates to the Cortex Xpanse API.</p><p>The following endpoints were introduced:</p><ul><li><strong>Get Vulnerability Tests</strong></li><li><strong>Bulk Update Vulnerability Tests</strong></li><li><strong>Override Business Units for Assets</strong></li></ul><p>The following fields were added to the <strong>Get All Services</strong> response:</p><ul><li>vulnerability test status</li><li>confirmed\_vulnerable\_cve\_ids</li><li>confirmed\_not\_vulnerable\_cve\_ids</li></ul><p>The <strong>Get Service Details</strong> endpoint will now return vulnerability test results from the last 14 days for all the service IDs provided. These results can be found in the vulnerability\_test\_results fields in the response.</p><p>The following fields were added to the <strong>Get All Assets</strong> response:</p><ul><li>aws\_cloud\_tags</li><li>azure\_cloud\_tags</li><li>certificate\_details</li><li>certificate\_expiry\_date</li><li>creation\_time</li><li>date\_added</li><li>extended\_properties</li><li>external\_ips</li><li>gcp\_cloud\_tags</li><li>geo\_region</li><li>hierarchy</li><li>internal\_ips</li><li>hierarchy,</li><li>open\_ports</li><li>project\_name</li><li>sub\_region</li><li>vpc\_name\_id</li></ul><p>The following filters were added to <strong>Get All Assets</strong> endpoint:</p><ul><li>asm\_id\_list</li><li>aws\_cloud\_tags</li><li>gcs\_cloud\_tags</li><li>azure\_cloud\_tags</li></ul><p>The following fields were added to the <strong>Get Asset Details</strong> response:</p><ul><li>certificate\_expiry\_date</li><li>date\_added</li></ul> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2024-releases/expander-release-25-april-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
