Expanse Enrich Cloud Assets

This Playbook is part of the Cortex Xpanse by Palo Alto Networks Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Subplaybook for Handle Expanse Incident playbooks. This Playbook is used to enrich Public Cloud Assets by:

  • Searching the corresponding Region and Service from IPRange feeds retrieved from Cloud Providers
  • Searching IPs and FQDNs in Prisma Cloud


This playbook uses the following sub-playbooks, integrations, and scripts.


  • Prisma Cloud - Find Public Cloud Resource by Public IP
  • Prisma Cloud - Find Public Cloud Resource by FQDN
  • Expanse Find Cloud IP Address Region and Service


This playbook does not use any integrations.


This playbook does not use any scripts.


  • setIncident
  • associateIndicatorToIncident

Playbook Inputs#

NameDescriptionDefault ValueRequired
IPIP to enrichincident.expanseipOptional
FQDNFQDN to enrichincident.expansedomainOptional
ProviderCloud Providerincident.expanseproviderOptional
AWSIndicatorTagsTags to identify AWS IP RangesAWSOptional
GCPIndicatorTagsTags to identify GCP IP RangesGCPOptional
AzureIndicatorTagsTags to identify Azure IP RangesAzureOptional
Update IncidentFlag to check whether to update incident

Update means:
- Set Expanse Region and Expanse Service to the values found from indicators
- Link found indicators to the incident

Playbook Outputs#

PrismaCloud.AttributionPrisma Cloud Asset Attributionunknown

Playbook Image#

Expanse Enrich Cloud Assets