Hi everyone, I've been following the discussions here for a bit and finally decided to jump in. My team is currently evaluating our external attack surface management, and Cortex's ASM module keeps coming up in our research.
We're a mid-sized company using a mix of cloud (AWS, some Azure) and a few legacy on-prem systems. Our current process for tracking internet-facing assets is... honestly, pretty manual and reactive. The promise of a continuous, automated inventory is really appealing, especially with all the new cloud services that seem to pop up.
For those of you using Cortex ASM specifically:
* How accurate have you found the asset discovery and classification? We're worried about false positives or missing those shadow IT assets.
* How is it integrated with the rest of the XDR workflow? If ASM flags a critical exposure, does it smoothly create an incident or guide a remediation step?
* And, if you're comfortable sharing, how does the pricing model work for ASM? Is it based on IPs, assets, or something else? This part is always a bit opaque during initial vendor talks.
We're also looking at a couple of standalone EASM vendors, so any insights on why you chose to go with Palo Alto's integrated approach would be super helpful. Just trying to understand the real-world pros and cons before we set up demos. Thanks in advance!
We've been running it for about eight months on a similar footprint. On accuracy, it's decent but not infallible.
Your fear about shadow IT is valid. It's good at finding cloud assets through API integrations (AWS Org, Azure Tenant), but anything not in those scopes requires you to seed IP ranges or domains. It will miss a developer's personal VPS until you manually add its IP block.
Integration with XDR workflows is its strongest point. If ASM flags a critical exposure on a known asset, it can automatically create a high-severity incident in Cortex XSOAR, assign it, and tag the relevant endpoint or cloud resource. The handoff is smooth, which is the main reason we picked it over a standalone tool.
Pricing was based on a bundle with our existing Cortex modules. I believe the standalone ASM model is asset-based, but the definition of an "asset" gets fuzzy. Push for clarity on whether a host with five services counts as one asset or five. They'll try to avoid that detail.
Your fancy demo doesn't scale.