> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/april-2025/feature-enhancements.md).

# Feature Enhancements

The Cortex Cloud Runtime Security 1.1 release includes the following enhancements:

**General**

| FEATURE                                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New Container Instance Asset type                | Introducing the Container Instance Asset, a new cloud workload asset type that offers deep visibility and enhanced security posture management for individual container instances. With built-in drift detection, you can effortlessly monitor unexpected changes and potential vulnerabilities that may impact system integrity and security.                                                                                                                                                 |
| Kubernetes connector automatic upgrade           | Never miss a Kubernetes connector update by enabling the connector to automatically upgrade when new versions are released.                                                                                                                                                                                                                                                                                                                                                                    |
| Enhanced security with agentless scanning        | Agentless scanning is now available for Cortex Cloud Runtime Security, enabling rapid assessment of cloud environments for security risks without agent installation or management. It provides quick discovery, deployment, vulnerability detection, comprehensive visibility, and streamlined risk mitigation in your cloud environment, all without the need for software agents.                                                                                                           |
| Vulnerability management enhancements            | <ul><li><strong>Vulnerability fix dates:</strong> Vulnerability Intelligence now includes a fix date for each vulnerability.</li><li><strong>Base Image Filtering</strong>: Filter and exclude vulnerabilities found in base images in issues, dashboards, reports, and policies.</li><li><strong>New dashboard widgets</strong>: New time-based and content-based filters, and new widgets for vulnerable base images and packages.</li></ul>                                                 |
| New widget capabilities                          | <p>Dashboard and report widgets are enhanced with the following new capabilities:</p><ul><li>Create dynamic widgets for more complex calculations using new script widgets</li><li>Format your text using Markdown with the free Text and Script widgets</li><li>Present time and duration-based results in your widgets with new time fields in the widget chart editor</li><li>Refresh individual widgets on demand, while gaining visibility with an improved last updated status</li></ul> |
| Enhanced security with agentless scanning        | Agentless scanning is now available for Cortex Cloud Runtime Security, enabling rapid assessment of cloud environments for security risks without agent installation or management. It provides quick discovery, deployment, vulnerability detection, comprehensive visibility, and streamlined risk mitigation in your cloud environment, all without the need for software agents.                                                                                                           |
| Secure cloud access with dedicated IP allocation | You can now allocate dedicated IP addresses in Azure, GCP, and AWS cloud services for secure cloud access simplifying integration and enhancing security by providing predictable access points. This capability provides transparent tracking with detailed telemetry and audit logs for IP reservations and usage.                                                                                                                                                                           |

**Detection Rules**

| FEATURE                                                    | DESCRIPTION                                                                                                                                                                                                                                                         |
| ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Granular exception handling with automated recommendations | Enhanced exception capabilities allow you to define precise exceptions for a specific scenario or leverage Cortex Cloud’s automated recommendations ensuring smoother operations without compromising on security.                                                  |
| Analytics tags highlights                                  | Cortex Cloud Runtime Security has added multiple new tags to the Cloud Data Asset Analytics suite. The new tags detect anomalous behavior involving data assets as public exposure, exfiltration, protection tampering, configuration, and disaster recovery risks. |

**AI Security**

| FEATURE                                    | DESCRIPTION                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Cortex Cloud AI Security dashboard updates | New functionality and a new look and feel have been added to the Cortex Cloud AI Security dashboard. Now key insights into the AI ecosystem and top security issues related to AI pipelines provide better security posture management.                                                                                                                |
| Support for self-managed models            | You now have visibility into data stored in AI models hosted on disks and volumes. Cortex Cloud AI Security performs model detection for multiple AI models as part of Agentless Disk Scanning (ADS). You can view AI model findings and prioritize issues, enhancing your data security posture through informed decisions and efficient remediation. |

**Data Security**

| FEATURE                                      | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| -------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Updated Cortex Cloud Data Security dashboard | New functionality has been added to the Cortex Cloud Data Security dashboard.                                                                                                                                                                                                                                                                                                                                                                              |
| Azure SQL data classification                | Cortex Cloud Data Security performs data classification on Azure SQL instances, providing visibility into data stored in Azure SQL instances. You can view Azure SQL findings and prioritize issues by considering data patterns and data profiles that are found in them. This enhances your data security posture through informed decisions and efficient remediation.                                                                                  |
| AWS DynamoDB data classification             | Now you can access information from AWS DynamoDB. Cortex Cloud Data Security conducts data classification on AWS DynamoDB databases. You have the ability to review findings from AWS DynamoDB databases and address issues based on data patterns and profiles discovered within them. This boosts your data security by enabling well-informed actions and effective remediation.                                                                        |
| Self-managed databases data classification   | You have gained visibility into the data stored in databases located on disks and volumes. Cortex Cloud Data Security performs data classification on multiple database engines as part of Agentless Disk Scanning (ADS). You can access findings from self-managed databases and prioritize issues by examining their data patterns and profiles. This strengthens your data security posture through informed decisions and efficient remediation.       |
| Snowflake databases data classification      | Access data stored in Snowflake databases with newfound visibility. Cortex Cloud Data Security carries out data classification on Snowflake databases. You can review findings from Snowflake databases and prioritize issues by examining data patterns and profiles identified within them. This enhances your data security posture by facilitating informed decisions and streamlined remediation processes.                                           |
| Data pattern inventory                       | You can now view all of the inventory from the perspective of data patterns such as IP addresses, email addresses, billing information, and PII details. From this page, you can see where each of your data patterns is stored, how many assets of that pattern Cortex Cloud Data Security has discovered, and what are the risk levels associated with it. You can also access a map view of the active regions in which these data patterns are stored. |
| Error logging and visibility                 | You now have the ability to review errors that are hindering Cortex Cloud Data Security from conducting data classification for supported data assets. For each asset, you can access detailed error information and corresponding remediation steps.                                                                                                                                                                                                      |

**Identity Security**

| FEATURE                                              | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Entra ID permissions                                 | Gain full visibility into Entra ID permissions regarding various permissions in your environment. You can now identify admins as well as analyze and assess risk in your Entra ID identities and permissions.                                                                                                                                                                                                                                                           |
| Last access                                          | Track the last usage of cloud identities and permissions to reduce excessive and unused privileges.                                                                                                                                                                                                                                                                                                                                                                     |
| Additional identity attributes                       | New attributes have been added to the several identity assets (inactive human identity, last used cloud service accounts, counting access to services and resources).                                                                                                                                                                                                                                                                                                   |
| Logging inactive human identity information on Azure | Support was added for logging inactive human identity information on Azure. Awareness of inactive human identities is crucial for maintaining a strong identity security posture and protecting sensitive information from unauthorized access or misuse. Being mindful of inactive human identities in Identity security is essential to mitigate security risks, comply with regulations, optimize resources, prevent insider threats, and enhance incident response. |

**Application Security**

| FEATURE                                                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ---------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Third-party data ingestion for Cortex Cloud Application Security | <p>Cortex Cloud now supports ingesting findings from third-party AppSec vendors:</p><ul><li>Semgrep, SonarQube, and Veracode for native SAST data ingestion</li><li>Users can upload SAST data in SARIF format via the UI or API to enable integration with a wider range of vendors</li><li>Semgrep for SCA data findings</li></ul><p>Once the findings are ingested, Cortex Cloud Application Security applies policies to create actionable issues.</p> |
| Application Security default policies                            | Default Cortex Cloud Application Security policies have been added. Based on industry best practices, these policies help you get up and running quickly by enabling immediate detection of vulnerabilities in your SDLC. This allows you to focus on and prioritize critical application security issues while also supporting automated blocking of pull requests and CI builds.                                                                         |
| Cortex Cloud Application Security dashboard                      | The Cortex Cloud Application Security dashboard new version aligns with the needs of the AppSec practitioner, prioritizing AppSec workflows and data to enable faster insights and decision-making. It now provides a summary of application security assets and top associated risks, with issue and policy widgets for detailed insights.                                                                                                                |
| Data source instance health status                               | You can now proactively monitor the health of your Application Security data source instances, including the status of individual or multiple repositories, with the data source instance health status feature. This enables rapid identification and resolution of potential issues, ensuring continuous data source reliability.                                                                                                                        |
| Repository scan configurations                                   | <p>You can now customize repository scans to tailor your scans to your specific needs:</p><ul><li>Enable/disable specific scanner types</li><li>Control your pull request security by enabling scans and configuring error handling</li><li>Exclude specific file paths</li></ul>                                                                                                                                                                          |

**API Security**

| FEATURE                                                             | DESCRIPTION                                                                                                                                                                                       |
| ------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Real-time API threat detection and prevention with Cortex XDR Agent | Cortex XDR agent can now detect and block malicious API requests and risky API responses in real-time, and provides continuous endpoint monitoring and protection against malicious event chains. |

**XDR Collectors**

**XDR Collectors 1.5.0**: Windows 1.5.0.1733 and Linux 1.5.0.1695

**XDR Collectors 1.4.3**: Windows 1.4.3.1686

For more information on maintenance releases, see [Maintenance Releases](urn:resource:component:1294300).

| FEATURE                        | DESCRIPTION                                                   |
| ------------------------------ | ------------------------------------------------------------- |
| XDR Collectors 1.5.0 and 1.4.3 | This release includes performance improvements and bug fixes. |

**Broker VM**

Version 27.0.47 (reboot required)

For more information on maintenance releases, see [Maintenance releases](/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/maintenance-releases.md)

| FEATURE           | DESCRIPTION                                                   |
| ----------------- | ------------------------------------------------------------- |
| Broker VM 27.0.47 | This release includes performance improvements and bug fixes. |

**External Data Ingestion and Management**

| FEATURE                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| ------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Granular data ingestion metrics | New granular metrics offer improved precision in tracing data collection, support breakdown by data source, and provide insight into the data pipeline. The metrics are available for XQL querying and monitoring with correlation rules. These metrics are saved in the metrics\_source dataset and metrics\_view preset, and are reflected on the Ingestion dashboard.                                                                                                                                                                           |
| New RBAC Dataset Views          | Cortex Cloud Runtime Security now supports creating Dataset Views in the Dataset Management page to enhance data efficiency and security. Dataset Views provide a virtual representation of data from one or more datasets, based on the XQL query defined, and provide multiple benefits, such as joining datasets into logical subsets through defined queries, manipulating data without altering underlying datasets, and segregating data for specific user needs or access privileges through the Role-based access control (RBAC) settings. |

**Cortex Query Language (XQL)**

| FEATURE                                       | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                              |
| --------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced XQL time picker                      | <p>When building Cortex Query Language (XQL) queries, the time picker now includes:</p><ul><li>Additional time range options to easily select from, such as last 5 minutes and last 3 hours.</li><li>Recent selections from your previous queries.</li></ul>                                                                                                                                                                             |
| XQL auto-suggestion improvements              | <p>When creating a Cortex Query Language (XQL) query, you can now:</p><ul><li>Use the up and down arrow keys to navigate through the auto-suggestion commands and definitions.</li><li>Select an auto-suggestion command by pressing either the Enter or Tab key.</li><li>Press Shift+Enter to add a new line, and easily ignore the auto-suggestion output.</li><li>Close the auto-suggestion output by pressing the Esc key.</li></ul> |
| New XQL series based graph results in Widgets | Custom Cortex Query Language (XQL) widget creation now includes enhanced graph results with the ability to define an optional parameter known as Series in the **Chart Editor**. This feature allows users to specify a field (column) to group chart results based on y-axis values. Additionally, the Series parameter is now integrated into the view graph type stage for improved functionality.                                    |
| New datasets for XQL queries                  | <p>New customers can leverage XQL for flexible and adjustable playbook and script tracking. The following datasets are available for querying and dashboards:</p><ul><li>Playbook tasks (playbook\_tasks)</li><li>Playbook runs (playbook\_runs)</li><li>Scripts and commands metrics (scripts\_and\_commands\_metrics)</li></ul>                                                                                                        |

**API**

| FEATURE                                                   | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                        |
| --------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| New API capabilities                                      | <p>Cortex now provides the following capabilities using the public API for automating common processes:</p><ul><li>Cloud onboarding</li><li>List, create, and update issues</li></ul>                                                                                                                                                                                                                              |
| Download Software Bill of Materials (SBOM) using the API  | Identify risks on your assets by downloading an SBOM for any asset in JSON or XML formats, using the API.                                                                                                                                                                                                                                                                                                          |
| Streamlined automation with new Application Security APIs | Enhance your security operations and automation capabilities using the new Application Security APIs to optimize the management of data sources, rules, policies, and scans.                                                                                                                                                                                                                                       |
| API Specification Management                              | The API Security module now includes a comprehensive API specification inventory, with automatic static analysis to identify misconfiguration risks effortlessly. This enhancement provides customers with a more detailed and organized overview of their APIs definitions ensuring the early detection of configuration issues that could lead to security vulnerabilities.                                      |
| API Testing in Cortex CLI                                 | API testing capabilities have been added to the Cortex CLI tool, enhancing the efficiency and effectiveness of API security assessments. This new feature allows users to seamlessly integrate API testing into their existing workflows, ensuring that APIs are robust and secure. Customers benefit from streamlined testing processes and quicker identification of potential security flaws within their APIs. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/april-2025/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
