> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2025-releases/release-210-july-2025.md).

# Release 2.10 (July 2025)

The table below describes the features and enhancements introduced in the Cortex Xpanse Expander 2.10 (July 2025) release.

Cortex Xpanse typically upgrades customers over a three-week time frame. Contact customer success to find out your specific upgrade date.

| Feature                                     | Description                                                                                                                                                                                                                                                                                       |
| ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Dynamic Protocol Detection for 65k Ports    | Now all 65k IPv4 ports will undergo dynamic port protocol detection, resulting in improved service discovery. This will be released by the end of July for all customers.                                                                                                                         |
| Integrated Attack Surface Testing           | Gain immediate visibility and decisive insights into confirmed exploitability for emerging vulnerabilities, now available in a unified view within the Threat Response Center.                                                                                                                    |
| New post-compromise detections              | Expand detection coverage for Ransomware activity, Cryptojacking, and Webshells to deliver an additional layer of defense and identify ongoing attacks and potential lateral movement by attackers.                                                                                               |
| Provided and Discovered Attribution Reasons | Provided and Discovered tags will now be listed as Attribution Reason (AR) tags, instead of the previous Asset Tags and IPR Tags. These tags will be applied automatically and are not modifiable. At this time, assets uploaded through the in-product feature will not receive the new AR tags. |
| New attack surface rules                    | Enable users to identify internet-facing applications that leak full or partial credential information.                                                                                                                                                                                           |
| Improved user record management             | Only users with at least one role or user group assigned are saved to Cortex Gateway, ensuring that the Gateway contains only relevant user data. This enhances data security and system efficiency.                                                                                              |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/features-introduced-before-2026/2025-releases/release-210-july-2025.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
