Exposure Management - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-11
Category
Administrator Guide

Notice

Requires the Exposure Management add-on.

Exposure Management inCortex XDR is a collection of features, capabilities, integrations, and content designed to help defenders holistically assess, consolidate, prioritize, and proactively respond to exposures in their organization.

  • Comprehensive Visibility

    Through a robust set of Cortex sensors and third-party integrations, along with the Cortex XDR data stitching and normalization engine, Exposure Management provides a normalized, deduplicated view of exposures across multiple different sources.

  • Actionable Prioritization

    Exposure Management Precision Filtering, compensating control identification, and the Exposure Management Command Center enable defenders to view their risks through a number of different dimensions and start each day with only the most critical cases. Fix-oriented case grouping makes it easier to maximize the impact of security and IT team’s remediation efforts by identifying common remediation actions to address the largest number of prioritized vulnerabilities.

  • Automation-first Remediation

    Platform automation capabilities and specialized exposure management content enable teams to augment their existing triage workflows, and in permissible situations, automate them entirely. Automation content comes ready out of the box to take actions such as:

    • Send notifications through a number of business and developer focused tools

    • Create tickets in third-party IT management software

    • Leverage AI-embedded remediation owner discovery

    • Take fully automated remediation actions through available control surfaces

Supported data sources

Cortex Exposure Management gathers vulnerability data from the sources listed below.

Palo Alto Networks sensors:

  • Cortex Agent

  • Cortex Attack Surface Management

  • Cortex Attack Surface Testing

  • Cortex Cloud Agentless Scanner

  • Cortex Container Registry Scanner

  • Cortex Serverless Function Scanner

  • Cortex Network Scanner

Third party sensors (using built-in integrations):

  • Qualys VMDR

  • Rapid7 InsightVM

  • Tenable.io

  • Tenable.sc

Third-party sensors (using the Vulnerability Ingest API):

  • Ingest vulnerabilities and related assets from any third-party scanner directly into your asset inventory and vulnerability management workflows.