> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets.md).

# External Surface assets

The **External Surface** inventory provides a searchable, filterable view of the internet-facing assets that Cortex XSIAM has discovered and attributed to your organization, including certificates, domains, services, and websites. Navigate to **Inventory** → **All Assets** → **External Surface** to access the **All External Surface Assets** view, or specific categories including **Services**, **Websites**, **Domains**, and **Certificates**.

{% hint style="info" %}

### Notice

Requires the Attack Surface Management (ASM) add-on.
{% endhint %}

The following sections provide information about each External Surface asset type. For information about external IP address ranges, see Network configuration.

**External asset categories**

There are four categories of external assets:

* **Services:** Any internet-facing device or software communicating on an application-level protocol over the public internet. The services table includes detailed fields such as Active classifications, Business units, Discovery type, Externally inferred CVEs, and an Externally inferred vulnerability score.
* **Websites:** Represents the content and the software stack that was used to generate a website.
* **Domains:** All root domains and subdomains that Cortex XSIAM has attributed to your organization. Subdomains are automatically grouped under a wildcard domain asset if they resolve to the same IP address, and are collapsed under a parent domain if more than 1,000 subdomains are observed.
* **Certificates:** Cortex XSIAM tracks "cryptographic health" checks, flagging issues such as self-signed or expired certificates, and weak signature algorithms.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management/asset-classes/external-surface-assets.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
