> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/july-2025/feature-enhancements.md).

# Feature Enhancements

The Cortex Cloud Runtime Security 1.2 release includes the following enhancements:

**General**

| Feature                                                                | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ---------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced driver threat prevention for Windows                          | Strengthen your defense against driver abuse by gaining unique visibility into user-to-kernel interactions to detect and block privilege escalation attempts at the source.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Flexible control over agent auto upgrades                              | Set custom upgrade schedules for every endpoint profile, allowing individual groups of endpoints to receive version upgrades on your own schedule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Kernel module examination in Linux                                     | Detect and prevent malicious kernel modules from being loaded in Linux, stopping sophisticated attacks.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Extended Scope-Based Access Control (SBAC)                             | Adhere to your company’s security policies by specifying which groups of assets users can access and what actions they can perform.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Extended Role-Based Access Control (RBAC)                              | Cortex Cloud is introducing a new set of roles in AI Security, Data Security, and Identity Security. These roles are aimed at helping security teams manage security operations while upholding the Least Privilege Access principle. The new administrator roles allow the management of all aspects of a given security module. For example, the Data Security Admin is able to view and secure all information related to the Data Security module. The viewer roles similarly allow access to a given module, but do not allow actions to be taken.                                                                                                                                                                                                                                                                                                                                             |
| Agentless Scanning for ARM and ARM64 Container Images and VM Instances | Cortex Cloud now supports agentless scanning of container images and virtual machine (VM) instances built on both ARM and ARM64 architectures. This capability ensures consistent security across cloud environments that use ARM processors. By scanning ARM and ARM64-based container images and VM instances, Cortex Cloud helps identify vulnerabilities, risks, and posture issues on x86-64, ARM, and ARM64 architectures. This capability is automatically enabled for both new and existing deployments.                                                                                                                                                                                                                                                                                                                                                                                    |
| Scanning of Virtual Machine Images                                     | To provide consistent security across your environments, Cortex Cloud now supports scanning of x86-64 and ARM64 virtual machine disk images across major cloud providers, focusing on private disk images. This scan ensures you identify vulnerabilities, misconfigurations, and other security risks before deployment, earlier in the development lifecycle. This capability is automatically enabled for all existing and new deployments.                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Export filter JSON from the UI to ease writing API calls               | Cortex public APIs require a proprietary JSON filter object for filtering assets, asset groups, policies, and other entities. To simplify API integration, you can now define your desired filter directly in the UI and export the exact JSON object for use in your API calls. This saves time and streamlines development.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| A Remediation section for Cloud Workload Rules                         | <p>Remediation information is now displayed for Cloud Workload Rules. The Remediation section provides detailed, step-by-step instructions to manually resolve issues triggered by violations of these rules.</p><p>When creating a custom misconfiguration rule, you can optionally define remediation steps to address the detected misconfiguration.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| A new widget panel for the Cloud Workload Rules Dashboard page         | A new Widget section has been introduced for the Cloud Workload Rules Dashboard. This section will provide a graphical representation of various rules, categorized by their respective platforms, type, and selected scanner types.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Agentless Disk Scanning Control                                        | <p>The Agentless Disk Scanning (ADS) capability for cloud accounts can now be disabled during initial onboarding or at a later time, offering enhanced flexibility and control over security configurations.</p><p>By default, ADS is enabled for new cloud accounts. To disable it during onboarding, clear the Agentless disk scanning option.</p><p>To disable it after onboarding, edit the onboarded cloud account's configuration and clear the Agentless disk scanning option.</p><ul><li>Disabling ADS during onboarding removes the requirement for ADS-related permissions.</li><li>Disabling ADS after onboarding will immediately stop and remove any ongoing scans and associated resources.</li><li>Disabling ADS prevents scanning of cloud compute instances and will not discover self-managed databases and AI models. It is generally recommended to keep ADS enabled.</li></ul> |
| Scanning of Virtual Machine Images                                     | To provide consistent security across your environments, Cortex Cloud now supports scanning of x86-64 and ARM64 virtual machine disk images across major cloud providers, focusing on private disk images. This scan ensures you identify vulnerabilities, misconfigurations, and other security risks before deployment, earlier in the development lifecycle. This capability is automatically enabled for all existing and new deployments                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Vulnerability Management Dashboard Enhancements                        | Reduce risks faster with actionable intelligence and new visualizations on the Vulnerability Management dashboard. Enhancements include filtering by asset group, a new widget for emerging vulnerabilities, and count of open issues by duration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Introducing Cloud Attack Surface Management (ASM)                      | The new Cloud ASM capabilities scan the internet to discover unmanaged assets, running external services, and external web applications across AWS, Azure, and GCP environments. With over 800 built-in rules, it detects exposed vulnerabilities, misconfigurations and other risk signals that increase your external attack surface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |

**AI Security**

| Feature                     | Description                                                                                                                                                                                                                                                                                         |
| --------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Amazon SageMaker support    | Strengthen AI security with full asset inventory, risk insights, and supply chain protection—plus governance and compliance mapping for scalable development.                                                                                                                                       |
| Datasets inventory          | Now you can get a complete picture of your AI data with the new datasets inventory, covering both training and inference datasets. This powerful new capability lets you easily discover, investigate, and trace the usage of all your datasets, ultimately helping you better manage your AI data. |
| Identify inactive AI models | Detect stale AI models to reduce risk, cut cloud costs, and focus security efforts on what’s active.                                                                                                                                                                                                |

**Data Classification**

| Feature                                             | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| --------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Data Classification - Enable/ Disable Data Profiles | You can now enable or disable specific data profiles, providing you with enhanced flexibility and more precise control over your data classification settings. You can now turn off both custom and out-of-the-box data profiles according to your security needs.                                                                                                                                                                                                 |
| Data Classification - Custom Data Patterns          | Now you can create custom sensitive data definitions based on regex, context words, and proximity. This new capability allows you to validate your custom patterns before saving, ensuring they accurately capture the intended data and do not negatively impact system performance.Custom data patterns provide flexibility and speed in identifying sensitive data, enabling you to classify and monitor unique, organization-specific patterns with precision. |
| Data Classification - Custom Data Profiles          | The new Custom Data Profiles feature provides you with the flexibility to define and manage sensitive data precisely. These custom profiles allow you to tailor sensitive data definitions to your unique needs, applicable to both files and tables. You can now edit, duplicate, enable, disable, or even delete your custom profiles, ensuring your data classification strategy is aligned with your organizational requirements.                              |

**Data Security**

| Feature                          | Description                                                                                                                                                                                                                                                                                                             |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CosmosDB data classification     | Cortex Cloud Data Security empowers you with visibility into data residing within Azure CosmosDB through data classification. Review CosmosDB findings, data patterns, and data profiles to prioritize security risks, leading to an improved data security posture using strategic and efficient remediation efforts.  |
| GCP Bigtable data classification | By classifying data within GCP Bigtable, Cortex Cloud Data Security grants you increased visibility into your stored information. Analyze findings, data patterns, and data profiles to prioritize security concerns, ultimately strengthening your overall data security through well-informed remediation strategies. |
| MIP label integration            | Use existing Microsoft Information Protection labels to prioritize remediation and streamline compliance with context-aware data classification.                                                                                                                                                                        |
| Tables in object inventory       | Cortex Cloud Data Security has added a table inventory, allowing customers to see all tables residing in structured and semi-structured data assets. The tables represented in this inventory table are the basis for sensitive data classification that is represented by data profiles and patterns.                  |
| Microsoft 365 support            | Gain visibility into sensitive data in SharePoint and OneDrive, detect misconfigurations, and reduce the risk of data leaks.                                                                                                                                                                                            |

**Identity Security**

| Feature                                                                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ----------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Relationship table view added for Cortex Cloud Identity Security assets | All identity assets have various types of relationships with other identity assets, such as group membership, role assumption, and policy attachment. The relationship tables show all connections that the asset has with other assets. For example, a user’s relationship table will show all the groups they’re a member of, all the roles they can assume, and all the policies attached to them.                                                                                                    |
| Review Unused Permissions                                               | You can use the new Review Unused Permissions feature (previously known as "Suggest Least Privilege Access" in Prisma Cloud) to help you intelligently analyze audit logs in order to identify and revoke excessive permissions. This allows you to generate precise IAM policies based on actual usage, significantly reducing your attack surface and strengthening your overall security posture. You can customize the time frame for used permissions according to your specific operational needs. |
| Enhanced custom rule support                                            | Create custom detections across identity, data, AI rules.                                                                                                                                                                                                                                                                                                                                                                                                                                                |

**Application Security**

| Feature                                    | Description                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Streamlined cloud automation configuration | Simplify adopting cloud automation capabilities by integrating automation instance management directly into the cloud onboarding process for AWS, GCP, and Azure. Now, all automation setup configurations are integrated into Terraform, providing seamless enablement and visibility into instance health. |

**ASPM**

| Feature                      | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ---------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ASPM Command Center          | The ASPM Command Center provides single, centralized visibility for all application security risks. By consolidating data from various sources, it offers a unified view of your entire AppSec posture.                                                                                                                                                                                                                                                                                   |
| Coverage                     | Coverage provides a comprehensive overview of your security posture coverage across the SDLC (code, build, deploy). It visualizes security coverage across repositories, pipelines, and registries, showing precisely how many repositories are onboarded versus total and which scanners were applied to each. This offers critical visibility into scanned/unscanned assets and active scanners, enabling you to identify and address security coverage gaps for continuous protection. |
| Backlog/ baseline management | Backlog helps manage overwhelming security tech debt by automatically marking all initial scan findings as backlog. Users can then set policies to block or alert on new issues only, or all issues.                                                                                                                                                                                                                                                                                      |
| Application asset            | The new Application asset inventory side card provides a high-level overview of application lifecycle risks. It offers actionable insights and enables quick navigation to deeper views in relevant tabs such as CVEs, IaC misconfigurations and sensitive data.                                                                                                                                                                                                                          |

**CI/CD Module**

| Feature                                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Supply Chain tools                         | Supply Chain security provides in-depth inventory and control over all VCS and CI/CD tools. It offers detailed insights, including tools' deployments, non-use areas, and functionality, enabling comprehensive visibility and risk management to safeguard the SDLC from third-party vulnerabilities.                                                                                                                                                                            |
| VCS Organizations as an asset              | Cortex Cloud now supports VCS organizations (such as GitHub Organizations) as distinct assets within the Cortex Unified Asset Inventory (UAI). This provides a centralized view of all integrated VCS organizations, including their repositories and properties, enabling insights and analysis to contextualize their importance and assess their risk posture within your ecosystem.                                                                                           |
| Collaborators as an asset                  | Cortex Cloud now supports Version Control System (VCS) collaborators (such as code developers and other VCS users) as distinct assets within the UAI. This provides a centralized view of all integrated VCS collaborators, enabling efficient tracking and management, comprehensive insights, and analysis to contextualize their importance and assess their risk posture within your ecosystem.                                                                               |
| CI/CD instances as an asset                | <p>Cortex Cloud now supports CI/CD instances (such as Jenkins and GitHub Actions) as distinct assets within the UAI.</p><p>This provides a centralized view of all CI/CD instances across your environment, enabling efficient tracking, management, comprehensive insights, and analysis to contextualize their importance, assess configurations, and identify potential security issues to assess their CI/CD security posture.</p>                                            |
| CI/CD rules, findings, issues & compliance | Cortex Cloud has enhanced its CI/CD security rules coverage by adding support for new Supply Chain assets (such as GitLab and Bitbucket). This update also expands compliance to include CIS GitHub, CIS GitLab, and CI/CD OWASP Top 10 benchmarks, allowing you to assess and maintain compliance with industry-leading security guidelines directly within Cortex. You can view findings generated from the rules, as well as remediate issues generated by the CI/CD policies. |
| CI/CD risk-based policy management         | You can now create policies based on CI/CD risks, defining both the scope and conditions under which CI/CD issues are generated. This enables targeted policy enforcement that reduces CI/CD risks and significantly improves your pipeline's security posture.                                                                                                                                                                                                                   |

**Code Scanners**

| Feature                                                      | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Software Composition Analysis (SCA) Package Operational Risk | SCA Package Operational Risk provides deeper visibility into the health and maintenance status of your open source dependencies. This feature provides key package level insights like deprecation status, maintainer activity and popularity, to help you identify outdated or unmaintained components that could introduce long term risk, even in the absence of known CVEs.                                                                                                                                                                                                                                                          |
| CI tools integration                                         | <p>Cortex Cloud now supports integrating code scanning directly into your CI\CD pipelines. You can automatically scan code as part of you build process, helping to catch issues earlier and enforce standards consistently across projects. To simplify your setup, Cortex provides ready-to-use code snippets for popular CI tools - just copy and paste them directly into your pipeline configuration for quick integration.</p><p>Cortex Cloud also supports integration with Terraform Cloud Run Tasks and Terraform Enterprise Run Task, enabling dynamic, automated, and context-specific scans in your Terraform workspace.</p> |
| CI scans management                                          | Continuous Integration (CI) scans management empowers you to maintain a strong security posture in your CI/CD pipelines by providing comprehensive visibility and control over your CI security scans. It delivers critical insights into your pipeline's security health and status, and also provides a detailed breakdown of detected issues and findings.                                                                                                                                                                                                                                                                            |
| New Application Security APIs                                | New ASPM and Application Security public APIs have been added, allowing you to programmatically automate and integrate scan management, policies, operational risk assessment, third-party ingestion, and application management capabilities into your workflows                                                                                                                                                                                                                                                                                                                                                                        |
| New DevSecOps role for Application Security                  | The DevSecOps role is specifically designed as an intermediary, possessing more permissions than a Developer but fewer than an AppSec Admin. This role actively manages security processes and tools to embed security directly into development and operations workflows. Responsibilities include managing and resolving security issues, performing scan management, and improving the overall application security posture by integrating security practices throughout the development and operations lifecycle.                                                                                                                    |

**API**

| Feature                                                        | Description                                                                                                                                                                                                                                                                           |
| -------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cases and Issues public APIs                                   | New public APIs are now available for managing cases and issues, providing capabilities to list and update cases, access related issues, assets, and artifacts, and to list, update, and create issues. This enables you to streamline and automate operations externally.            |
| Create Distributions API now supports Kubernetes installations | The Create Distributions API now supports Kubernetes installations, helping you automate and streamline the deployment of the agent in Kubernetes environments.                                                                                                                       |
| Identity Security Access Table Data API                        | Facilitate advanced integrations, reporting, and analytics with the introduction of the CIEM Access Table Data API. It enables the retrieval of detailed access information using filters, with access details similar to the UI.                                                     |
| Unified Asset Inventory APIs                                   | Gain comprehensive API access to all your on-premises and cloud asset information. We've introduced new APIs for retrieving asset data from the Unified Asset Inventory, complete with powerful filtering capabilities. This provides flexible and precise access to your asset data. |
| <p>Compliance report and assessment APIs</p><p>\[empty]</p>    | Simplify and automate your compliance reporting and assessment workflows using new public APIs for compliance. They provide API access to list, download, and delete reports, and retrieve assessments by ID, boosting your operational efficiency.                                   |
| APIs for managing API keys                                     | Gain more granular control and efficiency over your API keys. We've introduced new public API endpoints to get, create, and delete API keys, including the ability to delete API keys in bulk. This streamlines key management and enhances your security posture.                    |
| Streamlined automation with new Application Security APIs      | Enhance your security operations and automation using our new Application Security public APIs. They allow for the programmatic management of data sources, rules, policies, and scans, helping you optimize and streamline your application security workflows.                      |

**API Security**

| Feature                          | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cortex API security enhancements | <p>Cortex API security is enhanced with the following new capabilities:</p><ul><li>Boost your security and get a clearer picture of your API landscape with enhanced security scanning. By classifying API endpoints and their sub-types (like login, and checkout), you'll better understand each API's scope and sensitivity. This deeper insight paves the way for better detection of future threats and vulnerabilities, all while optimizing sensitive data protection.</li><li>Beyond just observing live traffic, Cortex Cloud can automatically identify and extract API specifications from your AWS and Azure API gateway, proactively scanning them for misconfigurations and vulnerabilities, which gives you a more complete and secure inventory of all your API endpoints. Cortex also creates API endpoints from the specifications, which enables Cortex to uncover shadow APIs.</li><li>Security coverage expands with the new integration option, F5 BIG-IP LTM.</li><li>For better risk assessment and more effective remediation, Cortex expands its API security visibility by showing the gateways, workloads, and specifications related to the same endpoints, giving you a broader context of the API endpoint.</li><li>Deep insights into the data profiles and patterns observed in your API endpoints' traffic can now be achieved with the integration of DSPM's unified, cross-platform data sensitivity scanning engine.</li></ul> |

**Automations**

| Feature                                    | Description                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Streamlined cloud automation configuration | Simplify adopting cloud automation capabilities by integrating automation instance management directly into the cloud onboarding process for AWS, GCP, and Azure. Now, all automation setup configurations are integrated into Terraform, providing seamless enablement and visibility into instance health. |
| Automation menu navigation improvement     | The Automation Rules menu item has been moved from Case Configuration to the Automation section of the main navigation, providing a streamlined user experience for automation configuration.                                                                                                                |
| Automation Exclusion Center                | Configure centralized automation exclusion policies to define which assets, such as users and endpoints, should be excluded from automated remediation. Use these policies to protect critical assets and ensure remediation actions are applied only to assets that are not explicitly excluded.            |

**Broker VM**

**Version 28.0.96 (reboot required)**

For more information on maintenance releases, see [Maintenance releases](/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/maintenance-releases.md)

Deprecation of Broker VM Pathfinder applet

The Broker VM Pathfinder applet is now deprecated.

* From this release, the Pathfinder applet can no longer be activated in new tenants or existing tenants that have never implemented this applet before.
* If this applet has been implemented in your tenant, it will remain available until January 25, 2026, which is the official deprecation date. To ensure complete coverage and protection, we recommend deploying XDR Agents on all endpoints by this date.
* Migration guidance and deployment resources for XDR Agents are available [here](https://docs-cortex.paloaltonetworks.com/r/Cortex-CLOUD/Cortex-Cloud-Runtime-Security-Documentation/Install-and-manage-endpoints).
* For questions or transition support, contact your [Customer Support team](https://support.paloaltonetworks.com/Support/Index).

| Feature                                                                 | Description                                                                                                                                                                                                                                                                                                                              |
| ----------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Broker VM applet configurations preserved when deactivated              | Cortex Cloud now provides the ability to maintain the Broker VM applet configurations whenever an applet is deactivated. This ensures that whenever the applet is reactivated the saved configuration is restored.                                                                                                                       |
| Enhanced error visibility and auditing for additional Broker VM applets | Gain better insight into application, connectivity, and processing errors for the File and DB collector applets running on Broker VMs. Error messages are displayed on Apps of Broker VMs and Clusters, and applet status changes are logged in the `collection_auditing` dataset, enabling detailed investigations through XQL queries. |
| Broker VM applets license enforcement                                   | License enforcement for the Broker VM applets has been enhanced to ensure that only applets aligned with the purchased product and licensed capabilities are available for activation and use.                                                                                                                                           |

**External Data Ingestion and Management**

| Feature                                         | Description                                                                                                                   |
| ----------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- |
| OCI support                                     | Gain visibility, compliance, and governance over assets and configurations in Oracle Cloud Infrastructure (OCI) environments. |
| VNET flow log support for Azure Network Watcher | Azure Network Watcher now supports VNET flow logs.                                                                            |

**Compliance**

| Feature                                       | Description                                                                                                                                                                                                                                                                                |
| --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Out-of-the-box compliance assessment profiles | Get immediate, personalized compliance insights with new automated compliance assessments that kick off as soon as you onboard modules. These assessments are tailored to your activated products and add-ons, with results appearing directly in your module dashboards for quick access. |

**CWP**

| Feature                                   | Description                                                                                                                                                                                                                                                                               |
| ----------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Direct Docker image scanning with CWP CLI | Added support for direct container image scanning using the CWP CLI. Previously, image scanning required exporting images to an archive file. Now, you can scan images residing directly in your local Docker daemon's repository, eliminating the need for an intermediate archive file. |

**Endpoint Security**

| Feature                                       | Description                                                                                                                                                                                                                                                                                    |
| --------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| File integrity monitoring add-on              | Detect unauthorized changes to files and folders in Windows, Linux, and Kubernetes environments to fully replace legacy anti-virus solutions with XDR.                                                                                                                                         |
| Cloud-based host policies                     | Cortex Cloud with Cortex XDR agent 8.9 enables cloud-based hosts to define policies based on important cloud attributes, such as cluster name, region, and provider. This gives the capability to define different security policies based on geography, responsibility, or specific clusters. |
| Enhanced driver threat prevention for Windows | Strengthen your defense against driver abuse by gaining unique visibility into user-to-kernel interactions to detect and block privilege escalation attempts at the source.                                                                                                                    |
| Linux packages in use detection               | For enhanced vulnerability management and visibility on Linux servers and workloads, Cortex Cloud with Cortex XDR agent 8.9 gives the ability to detect Linux GO packages in use.                                                                                                              |

**Gateway**

| Feature                         | Description                                                                                                                                                                                          |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Improved user record management | Only users with at least one role or user group assigned are saved to Cortex Gateway, ensuring that the Gateway contains only relevant user data. This enhances data security and system efficiency. |

**Graph Search**

| Feature                          | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Graph Search enhancements (Beta) | <p>Graph Search now enables customers to:</p><ul><li>Investigate real-time activity and identify critical events, such as access to sensitive information typically contained in a Storage Bucket, which generate issues and cases. This is now possible by the 100 most recent runtime events added to the graph results.</li><li>Track assets with internet exposure that could be targeted for external surface attacks, and the exposure path is also available.</li></ul> |

**Cortex Query Language (XQL)**

| Feature              | Description                                                                                                                                                                                           |
| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New XQL IP functions | Cortex Query Language (XQL) now supports new functions for IP manipulations. These functions verify whether an input is a valid IPv4/IPv6 address and if the IPv4/IPv6 address is a known private IP. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/july-2025/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
