Tech Partner Integration Guide Synack Cortex Xpanse.pdf
Technology Partner Program
Use Case Documentation
Author: Synack
| Revision History | |
|---|---|
| Sept 23rd 2024 | Initial Integration Release |
| July 18th 2025 | Updated to reflect support in FedRAMP deployments |
| Table 1: Partner information | |
|---|---|
| Date | Sept 23rd, 2024 |
| Partner Name | Synack |
| Website | www.synack.com |
| Product Name | Synack Platform |
| Partner Contact | Greg Copeland-gcopeland@synack.com |
| Support Contact | Synack Support-help@synack.com |
| Product Description | Synack's Penetration Testing as a Service platform manages security testing for critical vulnerabilities and gains visibility into the root causes of security risks. We are committed to making the world more secure by harnessing a talented, vetted community of security researchers to deliver continuous penetration testing and vulnerability management, with actionable results. |
Use Case for Integration with Palo Alto Networks
Integrate Attack Surface Management & Penetration Testing
Synack’s integration with Palo Alto Networks (PANW) Cortex Xpanse Attack Surface Management allows customers to manually or automatically import Assets present in their PANW Cortex Xpanse Inventory, into their Synack Platform Asset list. Once in the Synack Asset List, Assets are eligible for human-led penetration & other security testing by the Synack Red Team (SRT). Synack testing helps you find Exploitable Vulnerabilities including recommendations of how to close security gaps before bad actors can exploit them. PANW Cortex Xpanse filters can optionally be used to control scope of which assets are imported into Synack. Assets can be imported One-Time or checked Daily for new in-scope discovered assets.
Table 2: Palo Alto Networks Products for Integration
| Palo Alto Networks Product | Integration Status | Palo Alto Networks Versions Tested | Synack Versions Tested |
|---|---|---|---|
| Xpanse | Validated | Xpanse V2.9 | Synack Platform July 25 |
Integration Benefits
• Integrate penetration and other security testing with your Attack Surface Management workflows.
• Make sure your security testing stays current with newly discovered assets.
• Automate security testing to ensure exploitable vulnerabilities are identified & remediated before bad actors can exploit them.
• Leverage PANW Cortex Xpanse tagging and filtering with the integration, to prioritize testing of your most important assets.
Integration Diagram
!
Synack products use the following data:
• PANW Cortex Xpanse Assets (Domain, Owned Responsive IP) from the PANW Cortex Xpanse Unified Inventory
• Synack calls the PANW Cortex Xpanse Asset Management API
• PANW Cortex Xpanse Assets are added to the Synack Pentesting as a Service Platform’s Asset List
• Synack Asset List entries are eligible for testing by the Synack Red Team (SRT)
Before You Begin
• Requires PANW Cortex Xpanse account level access capable of generating an API Key.
• Requires Synack admin level account access to enable the integration with PANW Cortex Xpanse.
• Integration has been tested with current version of Synack Platform, and PANW Cortex Xpanse V2.6
• Identify PANW Cortex Xpanse Tags and Business Units that you may wish to use for Asset import filtering
• Identify whether your Synack and PANW Cortex Xpanse deployments are in a FedRAMP environment. If FedRAMP, substitute https://login.synack.us wherever https://login.synack.com is indicated in this document.
Palo Alto Networks Configuration
Generate and save PANW Cortex Xpanse API Key
• Login to your PANW Cortex Xpanse account via https://cortex-gateway.paloaltonetworks.com/accounts
• From Settings -> Configurations screen, click API Keys under the Integrations section.
| CREATION TIME | ID | CREATED BY | COMMENT | SECURITY LEVEL | ROLES | |
|---|---|---|---|---|---|---|
| Aug 28th 2024 16:36:48 | 29 | Partner Synack | Standard | Viewer + API edit acc | ||
| Aug 28th 2024 16:15:56 | 28 | Partner Synack | Advanced | Viewer + API edit acc | ||
| Aug 23rd 2024 14:05:22 | 27 | Standard | Viewer + API edit acc | |||
| Jul 24th 2024 08:15:10 | 26 | Standard | Viewer + API edit acc | |||
| Jul 19th 2024 11:05:33 | 25 | Standard | Viewer + API edit acc |
• Click ‘New Key’
• Select Security Level Advanced, and Role (e.g. Viewer + API edit access), then click ‘Generate’
• Your Generated API Key will pop up, you MUST SAVE A COPY of this Key now, you will not have access to it later.
• Close the Key pop up to return to the list of API Keys.
• Make a note of the ID associated with the API Key which you just created.
• Click ‘Copy API URL’ and save this information.
Partner Product Configuration
Configure PANW Cortex Xpanse integration in Synack
• Login to the Synack Portal at http://login.synack.com.
• Click Profile Icon at Top Right corner of the Synack Portal, and then click Settings.
• Next, click on the Integrations tab. Then click on the ‘Connect to Cortex Xpanse’ button.
• Enter API URL, API ID, and API Key information which was provided by your PANW Cortex Xpanse admin.
• You must also specify one, or both, of the PANW Cortex Xpanse Asset Types which the Synack integration currently supports (Domain, Owned Responsive IP), then click ‘Save.’
• Optionally, you can also specify Business Units, and Tags used in your PANW Cortex Xpanse implementation. These are used to limit scope of Synack Asset Import to a desired subset of PANW Cortex Xpanse Assets. If you make changes to these settings click ‘Save’ afterwards.
• Next you must initiate the Import of Assets from PANW Cortex Xpanse to Synack. From the Synack Cortex Xpanse Integration screen where you just Saved PANW Cortex Xpanse Account Details, you have 2 options to choose from;
Option A) Click on the ‘One-Time Import’
Option B) Check ‘Enable daily import’, then click ‘Save’
After several minutes, the table will start to populate with Import History (note: Daily Import, or large One-Time imports may take significantly longer to populate)
| Import History | |||||
|---|---|---|---|---|---|
| Created | Activity | Status | Total Assets | Newly Imported | Un-imported |
| 07/18/2025;10:45 AM | One-Time Import | Complete | 370 | 369 | -- |
• From the Synack Portal, click the ‘Assets’ tab. Then click ‘Asset List’ (you may Search the Asset List to re-confirm details of specific assets that have been imported from PANW Cortex Xpanse). PANW Cortex Xpanse ‘Domain’ assets will appear in the Synack list as ‘FQDNs’, while PANW Cortex Xpanse ‘Owned Responsive IP’ assets will appear in the Synack list as ‘IPs’)
Viewing Assets imported from PANW Cortex Xpanse in Synack
!
| Asset | IP Address | FQDN | Open Ports | Providers | Technologies | Asset Criticality | Asset Tags |
|---|---|---|---|---|---|---|---|
| mail.toysrus.com | - | mail.toysrus.com | N/A | MarkMonitor Inc. | - | High | Untagged |
| 87.249.1.35 | 87.249.1.35 | Not Found | 21 +8 | OOO Suntel | - | Unassigned | Untagged |
| 173.251.33.89 | 173.251.33.89 | Not Found | 123 +1 | Cablevision Systems ... | - | High | Untagged |
| 166.76.253.44 | 166.76.253.44 | Not Found | 443 | Transform SR Holding ... | - | Unassigned | Untagged |
| 93.187.20.29 | 93.187.20.29 | Not Found | 443 | MASERGY | - | Unassigned | Untagged |
| 65.152.90.227 | 65.152.90.227 | Not Found | 69 | CenturyLink Communi... | - | Unassigned | Untagged |
| 95.177.124.73 | 95.177.124.73 | Not Found | None | Datacamp Limited | - | Unassigned | Untagged |
Note: Reference documentation about Synack usage can be found within your Synack Portal in the Help Center
Troubleshooting
Common troubleshooting steps
• When entering Xpanse Account details into Synack Integration page I get an invalid API error message.
○ Double check all three of API Key, API ID, and API URL are correct as originally saved from Xpanse
○ Check Xpanse API Key list, to check API Key which you generated in Xpanse used ‘Advanced’ security level
• I followed the instructions in this guide, but I am still not able to see any data. How long should this take?
o If this is the initial configuration of the app, it can take some time for the initial data to be imported. Depending on the scope of assets imported during ‘One-Time Import’ this may take between several minutes to hours. In the case of scheduled recurring imports and depending on the time of day you ‘Enable Daily Import’ it may take up to 24 hours until the next daily import cycle kicks off.
• My integration used to work but I am no longer able to import assets.
o If you see a Failed Import message, this could be because of the API token being expired or being inadvertently deleted. Please check the Palo Xpanse platform to verify the API token still exists and is active. (if the token has expired or was deleted, you will need obtain a new token from Xpanse, and then reconfigure the Synack Integration for Xpanse with a valid API Token and ID)
• I saw an Asset in my Synack Asset list before, but now it’s gone, why might that be?
o Assets imported during discovery of Palo Xpanse Inventory will be removed from the Synack Asset List if they are not discovered in subsequent imports. For example;
§ A particular asset is discovered during a Daily Import, but in subsequent Daily Import that asset is no longer in the Palo Xpanse Inventory - Synack also removes the Asset from our list to keep in sync.
§ A particular asset is discovered during One-Time Import, but in subsequent Daily Import that asset is no longer in the Palo Xpanse Inventory - Synack also removes the Asset from our list to keep in sync.
§ In your first import you specified Asset Type ‘Domain’. In subsequent import you changed the Asset Type to ‘Owned Responsive IP’. This would cause the previously discovered ‘Domain’ assets to disappear from the Synack Asset List. If you want to retain the ‘Domain’ assets, instead run the subsequent Import with BOTH ‘Domain’ and ‘Owned Responsive IP’.
§ You have been running Daily Import and importing assets into the Asset List. Later you uncheck the Enable Daily Import, and click Save. Daily discovered assets will expire and be removed from the Asset List starting within 10 minutes.
• Yesterday’s Daily Import shows 100 Assets in the Import History, but today’s import only shows 15, why could that be?
o Only newly discovered (not previously present) Xpanse assets get added to the Synack Asset List and are reflected in the daily Import History counter.
• Note: If you are a Synack FedRAMP customer, please login to Synack Platform at https://login.synack.us
Helpful Resources
Synack:
● Synack Knowledge Base
Palo Alto Networks:
● Cortex XPANSE documentation portal
Contact Information for Support
For Synack specific issues:
For Palo Alto Networks specific issues:
● Palo Alto Networks Live Community ● Palo Alto Networks Customer Support