> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/navigation-cheat-sheet.md).

# Navigation Cheat Sheet

Cortex Xpanse provides an easy-to-use interface. By default, Cortex Xpanse displays the **Home** dashboard when you log in. If desired, you can change the default dashboard. See the [Dashboards](/cortex-xpanse/dashboards-and-reports/dashboards.md) section for more information.

Depending on your assigned role, you can explore the following areas in Expander.

#### Main Menu

| Menu Item             | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| --------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Dashboards**        | <p>From the <strong>Dashboard</strong> menu, you can view the out-of-the-box dashboards and create, edit, and view custom dashboards.</p><ul><li>Out-of-the-box dashboards—Provide high-level statistics about your assets and incidents. Out-of-the-box dashboards include the <strong>Home</strong>, <strong>Attack Surface Management</strong>, <strong>Incident Management</strong>, <strong>Unmanaged Cloud</strong>, <strong>Security Rating</strong>, and <strong>Websites</strong> dashboards.</li><li><strong>Other Dashboards</strong>—Additional out-of-the-box dashboards that aren't listed in the top-level dashboards menu, including <strong>Security Admin</strong>, <strong>My Overview</strong>, and <strong>Attack Surface Compliance Violations</strong> dashboards.</li><li><strong>My Dashboards</strong>—Custom dashboards that you created.</li><li><strong>Dashboards Manager</strong>—Add new dashboards with customized widgets to surface the statistics that matter to you most</li><li><strong>Widget Library</strong>—Search, view, edit, and create widgets based on predefined widgets and user-created custom widgets.</li></ul>              |
| **Reports**           | <p>From the <strong>Reports</strong> menu, you can view and manage your existing reports, create new reports, and schedule reports.</p><ul><li><strong>Reports</strong>—View and download existing reports.</li><li><strong>Reports Templates</strong>—Build reports using pre-defined templates, or customize a report. Reports can be generated on-demand scheduled</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Incident Response** | <p>From the <strong>Incident Response</strong> menu, you can view, manage, investigate and take action on all incidents.</p><ul><li><strong>Incidents</strong>—Investigate, manage, and resolve your incidents and alerts.</li><li><strong>Threat Response Center</strong>—Review emergent and global threat events, assess the impact to your organization, and build a remediation plan.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Asset Inventory**   | <p>From the <strong>Assets Inventory</strong> menu, you can view and investigate the assets and other inventory items attributed to your organization.</p><ul><li><strong>Unified Inventory</strong>—Comprehensive list of all domains, certificates, cloud compute instances, and unassociated responsive IPs.</li><li><strong>Domains</strong>—List of domains and subdomains attributed to your organization.</li><li><strong>Certificates</strong>—List of certificates attributed to your organization.</li><li><strong>Owned Responsive IPs</strong>—List of IP addresses that expose a service and are part of an IP range that has been attributed to your organization.</li><li><strong>Cloud Inventory</strong>—List of assets that were reported by a cloud provider or Prisma Cloud integration.</li><li><strong>Services</strong>—List of external services, which are servers running on an IP:port or a domain:port that respond to scanners on some protocol.</li><li><strong>Owned IP Ranges</strong>—List of IP address ranges attributed to your organization</li><li><strong>Websites</strong>—List of web assets attributed to your organization.</li></ul> |
| **Rules**             | <p>From the <strong>Policies and Rules</strong> menu, you can customize the way Expander creates, prioritizes, and responds to alerts.</p><ul><li><strong>Attack Surface Rules</strong>—View and manage the list of attack surface rules that trigger alerts.</li><li><strong>Risk Scoring</strong>—Enable or disable Xpanse Risk Scoring and configure User Scoring Rules.</li><li><strong>Alert Exclusions</strong>—Create rules to filter out alerts and incidents from the Expander UI.</li><li><strong>Remediation Path Rules</strong>—Create rules to tell the Active Response module which remediation approach to take when responding to alerts.</li><li><strong>Asset Tag Rules</strong>—Create rules to automatically tag existing and new assets.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Automation**        | <p>From the <strong>Automation</strong> menu, you can configure integrations and playbooks.</p><ul><li><strong>Configuration</strong>—View and configure your automation integrations.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Marketplace**       | **Marketplace** provides access to integrations that extend the functionality of Cortex Xpanse and allow communication with third-party services.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

#### Settings

You can find many of the system-wide settings under **Settings** in the main menu.

| Menu Item                                                                                                            | Description                                                                                                   |
| -------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- |
| <p><img src="/files/ByEpICVZhE1z5PX1Fuok" alt="dark-mode.png" data-size="original"></p><p>(Dark Mode/Light Mode)</p> | Toggle between dark mode and light mode by using the sun and moon icons next to the **Settings** menu option. |
| Cortex Xpanse License                                                                                                | View information about your Expander license, expiry dates, AUM, and Addon modules.                           |
| Management Audit Logs                                                                                                | View and export a historical audit trail of user actions in Expander.                                         |
| **Configurations**                                                                                                   |                                                                                                               |
| Server Settings                                                                                                      | Configure keyboard shortcuts, timestamp format, ingestion evaluation mode, and other custom server settings.  |
| Security Settings                                                                                                    | Manage sessions, user expiration, and allowed domains.                                                        |
| Notifications                                                                                                        | Set up notifications for alerts and management audit logs.                                                    |
| Collection Integrations                                                                                              | Configure installed collection integrations.                                                                  |
| Automation Integrations                                                                                              | Configure installed automation integrations.                                                                  |
| API Keys                                                                                                             | Generate Cortex Xpanse API keys.                                                                              |
| Users                                                                                                                | View and manage users. Add/edit roles, user groups, accumulated permissions, import multiple user roles, etc. |
| Roles                                                                                                                | View, create, edit, and delete user roles.                                                                    |
| User Groups                                                                                                          | View and manage user groups. Import a group from Active Directory and manage user groups                      |
| Single-Sign On                                                                                                       | Set up SSO using SAML 2.0.                                                                                    |

#### Notifications

View Cortex Xpanse notifications.

#### User (Username)

Click on your username to see the following options:

* **About** to view additional version and tenant ID information.
* **What's New in This Release** to learn about the key features in the latest release.
* **Xpanse What’s New** to view an overview of Cortex Xpanse functionality.
* **Log Out** to terminate the connection with Cortex Xpanse Expander.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xpanse/reference/navigation-cheat-sheet.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
