Notice
Requires the Exposure Management add-on.
Exposure Management inCortex XDR is a collection of features, capabilities, integrations, and content designed to help defenders holistically assess, consolidate, prioritize, and proactively respond to exposures in their organization.
Comprehensive Visibility
Through a robust set of Cortex sensors and third-party integrations, along with the Cortex XDR data stitching and normalization engine, Exposure Management provides a normalized, deduplicated view of exposures across multiple different sources.
Actionable Prioritization
Exposure Management Precision Filtering, compensating control identification, and the Exposure Management Command Center enable defenders to view their risks through a number of different dimensions and start each day with only the most critical cases. Fix-oriented case grouping makes it easier to maximize the impact of security and IT team’s remediation efforts by identifying common remediation actions to address the largest number of prioritized vulnerabilities.
Automation-first Remediation
Platform automation capabilities and specialized exposure management content enable teams to augment their existing triage workflows, and in permissible situations, automate them entirely. Automation content comes ready out of the box to take actions such as:
Send notifications through a number of business and developer focused tools
Create tickets in third-party IT management software
Leverage AI-embedded remediation owner discovery
Take fully automated remediation actions through available control surfaces
Supported data sources
Cortex Exposure Management gathers vulnerability data from the sources listed below.
Palo Alto Networks sensors:
Cortex Agent
Cortex Attack Surface Management
Cortex Attack Surface Testing
Cortex Cloud Agentless Scanner
Cortex Container Registry Scanner
Cortex Serverless Function Scanner
Cortex Network Scanner
Third party sensors (using built-in integrations):
Qualys VMDR
Rapid7 InsightVM
Tenable.io
Tenable.sc
Third-party sensors (using the Vulnerability Ingest API):
Ingest vulnerabilities and related assets from any third-party scanner directly into your asset inventory and vulnerability management workflows.