> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/november-2025/feature-enhancements.md).

# Feature Enhancements

**General**

| Feature                                                                            | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| In-product support case creation                                                   | You can now open a support case directly within Cortex Cloud, making it easier to provide all the necessary context for a quicker resolution. This streamlined process allows you to record your screen to recreate the issue, and automatically includes relevant console logs and tenant details like license information. Providing these details upfront helps us resolve your issues even faster.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Oracle Cloud Infrastructure (OCI) support in Cloud ASM                             | You can now view and onboard unmanaged OCI services in Cloud ASM.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Expanded Asset Group scoping                                                       | Scope-Based Access Control (SBAC) has been enhanced to provide more granular control over your access policies. You can now define Asset Groups that include the Business Application Names attribute for scoping definitions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Support for existing AWS CloudTrail and S3 buckets                                 | To reduce extra costs and avoid data duplication, you can now onboard your AWS environment and configure Cortex Cloud to use your organization's existing CloudTrail and S3 buckets.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Cortex Cloud log ingestion and licensing update                                    | We’ve enhanced cloud log ingestion to align more closely with our licensing model, making data collection more streamlined and scalable. Customers now receive a GB allowance for log ingestion based on the number of licensed workloads, with Cortex Cloud customers able to purchase additional capacity. This update ensures log ingestion is tied directly to license entitlements while providing flexibility to scale log volume as organizational needs evolve.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Reduced manual setup time with automated configuration transfers from Prisma Cloud | <p>The Upgrade Helper now allows you to import the following Audit configurations from Prisma Cloud and map them to their Cortex Cloud equivalents:</p><ul><li>Reports: Preserves all custom reports for immediate compliance and reporting.</li></ul><p>Additionally, the Upgrade Helper now supports importing and mapping Application Security configurations from Prisma Cloud to Cortex Cloud. The following configurations are mapped to their new equivalents:</p><ul><li>Out-of-the-box policies labels are now categorized as default Application Security rules labels.</li><li>Custom policies are now categorized as custom Application Security rules.</li><li>Enforcement rules are now categorized as Application Security policies.</li><li>Developer suppressions remain categorized as Developer suppressions.</li><li>Git History & Validate Secrets remain categorized as Git History & Validate Secrets.</li><li>Scanned branches remain categorized as Scanned branches.</li><li>AppDNA Discovery criteria are now categorized as Applications Criteria.</li></ul> |

**CNAPP**

| Feature                           | Description                                                                                                                                                                                                                                                                                                                                      |
| --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| New one-click automations         | Instantly resolve critical security risks and misconfigurations like publicly accessible S3 buckets. This new feature helps teams streamline their security operations by automatically correcting risks across AWS, GCP, and Azure.                                                                                                             |
| Expanded cloud security playbooks | These playbooks provide automated, multi-step responses for cloud posture issues. They can be fully automated or include human approval, helping teams orchestrate comprehensive security responses.                                                                                                                                             |
| Unified cloud security platform   | This platform simplifies management and improves visibility across your entire environment. With an expanded asset inventory, 160+ new APIs and services, and a new XQL view-only feature for CSPM and CIEM rules, it's easier than ever to manage policies, track alerts, and ensure compliance for FedRAMP tenants and other security domains. |

**AI Security**

| Feature                                                                       | Description                                                                                                                                                                                                                                                                                                                              |
| ----------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Deep visibility and risk detection for AI agents                              | Cortex Cloud now offers deep visibility and risk detection for AI agents. Security teams can now identify overprivileged agents, uncover those accessing sensitive data, monitor agent tool usage, and detect misconfigurations—all from a single view. This helps reduce risk across the AI attack surface with confidence and control. |
| Full visibility into AI software packages, SDKs, and development dependencies | Cortex Cloud AI-SPM now brings full visibility into AI software packages, SDKs, and development dependencies—creating an AI Bill of Materials (AI BoM) that helps organizations detect vulnerabilities early, secure AI systems from code to cloud, and meet growing compliance demands for transparency and supply chain integrity.     |
| AI-SPM dashboard unifies AI posture and threat detection                      | The AI-SPM dashboard now unifies AI posture and threat detection. By integrating AI-DR capabilities, Cortex Cloud offers a single view of misconfigurations, risks, and active threats—streamlining AI security from development to production.                                                                                          |
| Azure AI Search support                                                       | Cortex Cloud now supports Azure AI Search, giving you visibility into AI datasets, identifying sensitive data, and detecting risky misconfigurations that could lead to exposure or compliance violations.                                                                                                                               |

**Data Classification**

| Feature                  | Description                                                                                                                                                                                                                                                                                                               |
| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| False positive reporting | During the classification process, false positive classification can occur. You can now report any false positives directly from the specific object or in a new section in the Submit a Support Case feature of Cortex Cloud, located in the Help area. This feature will be available with Batch 4 (November 23, 2025). |

**Data Security**

| Feature                                                | Description                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Databricks support                                     | Cortex Cloud now integrates with Databricks to deliver enhanced visibility into data, configurations, and risks. This helps organizations monitor data flow, detect misconfigurations, and secure sensitive data in collaborative analytics environments—closing blind spots across the data lifecycle.                                         |
| Cortex Cloud Data Security for on-premise environments | The DSPM Fileshare applet is now available as part of the Broker VM applet options and supports the classification of NFS and SMB file shares.                                                                                                                                                                                                  |
| Scanning settings updated with cadence                 | Setting the classification cadence for assets according to asset type is now available in Cortex Cloud Data Security.                                                                                                                                                                                                                           |
| Backup discovery and risk analysis                     | Introducing New Backup Discovery and Risk Analysis: Cortex Cloud now automatically discovers cloud backups, maps them to their original assets, and classifies their contents to detect sensitive data. It also flags key risks—including orphaned, overshared, or outdated backups—helping teams reduce both exposure and cloud storage costs. |

**Identity Security**

| Feature                                       | Description                                                                                                                                                                                                                                               |
| --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Role chaining permissions                     | Allows the creation of role chaining policies. Role chaining permits one role to allow the assumption of another role, therefore creating possibilities of lateral movements and privilege escalations.                                                   |
| Access table simple and advanced mode         | An access table now meets the needs of two use cases: the high-level purpose of an asset, and a table that allows deeper investigations into which exact actions are granted. Access table views can now be switched accordingly from simple to advanced. |
| How to create custom identity detection rules | Now you can create custom detection rules, which allow you to customize identity and permissions scenarios.                                                                                                                                               |
| Google Workspace support                      | Enhanced Identity Security by integrating with Google Workspace IdP, giving teams comprehensive visibility into their users, groups, and organizational units.                                                                                            |

**XDR Collectors**

**XDR Collectors 1.5.1:** Windows 1.5.1.2048 and Linux 1.5.1.1950

**XDR Collectors 1.4.3:** Windows 1.4.3.1686

For more information on maintenance releases, see [Maintenance releases](/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/maintenance-releases.md)

| Feature                                            | Description                                                                                                                                                                                                                                                                    |
| -------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Enhanced visibility and auditing of XDR Collectors | Cortex Cloud now provides enhanced error visibility and auditing for XDR Collectors. This enables you to quickly identify and resolve application, connectivity, and processing errors, simplifying troubleshooting and ensuring your critical workflows remain uninterrupted. |

**Broker VM**

**Version 29.0.71 (reboot required)**

For more information on maintenance releases, see [Maintenance releases](/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/maintenance-releases.md)

| Feature                                                                                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| --------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced error visibility and auditing for additional Broker VM applets                       | Gain better insight into application, connectivity, and processing errors for the FTP Collector, Netflow Collector, Network Mapper, and Apache Kafka collector applets running on Broker VMs. Error messages are displayed on Apps of Broker VMs and Clusters, and applet status changes are logged in the collection\_auditing dataset, enabling detailed investigations through XQL queries.                                                                                                                                                                                                                |
| Broker VM support for Spain’s Esquema Nacional de Seguridad (ENS) National Security Framework | The Broker VM has been updated to comply with Spain’s Esquema Nacional de Seguridad (ENS) National Security Framework. You must enable the option Only use recommended cipher suites to meet the ENS regulation. This new setting is located in the Advanced Settings section, which you can access when configuring the Broker VM using its URL.                                                                                                                                                                                                                                                             |
| Enhanced Database Collector                                                                   | <p>The Database Collector applet now has a new Storage Method option, which offers more control over how the data is handled: </p><ul><li><strong>Append:</strong> This method adds new data to an existing dataset as this worked previously by default. </li><li><strong>Replace:</strong> This new method is only available for Snapshot datasets and overwrites the entire dataset with the newly collected data. This is necessary when the data that needs to be collected from the database is static data or reference data, such as a list of computers, IP addresses, or a list of users.</li></ul> |

**External Data Ingestion and Management**

| Feature                                 | Description                                                                                                                                                                                                              |
| --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Unified integration error notifications | Instead of being inundated with multiple notifications, all data collector errors are now grouped into a single notification. This new, non-dismissible notification alerts all users to data source integration errors. |

**Cortex Query Language (XQL)**

| Feature                     | Description                                                                                                                                                                                                                                                                                                 |
| --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Lookup datasets enhancement | Cortex Cloud has implemented a fix to improve lookup dataset queries and provide better flexibility with managing your data. Now, when you create or add data to a lookup dataset using the target stage, the \_time field won't be included by default unless you explicitly add it with the fields stage. |

**API**

| Feature            | Description                                                                                                                                                                                                                                           |
| ------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| User and role APIs | We are introducing new APIs to give you greater flexibility to automate and scale your user management workflows. Included are new APIs that allow you to manage user roles, update API keys, and add or remove role and scope assignments for users. |

**CWP**

| Feature                                                                                            | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| New SBAC Support for Cloud Workload Policies                                                       | Security administrators can now use Scope-Based Access Control (SBAC) to manage access to Cloud Workload Policies. This new functionality, used in conjunction with required RBAC permissions, ensures that when users are scoped they can only view policies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Secure your Windows VM disks (NTFS) in OCI before deployment                                       | Gain zero-day security for your Windows VM disk images in Oracle Cloud Infrastructure (OCI). The agentless scanning capability has been extended to analyze Windows (NTFS) disk images in OCI. This allows you to find and remediate vulnerabilities and misconfigurations in the base OS and software before an instance is ever run, reducing operational overhead and eliminating risk.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Track image source and registry-related risks with the enhanced container information model        | Gain deep, actionable insight into your container supply chain by instantly tracing the exact registry and repository source for any running image. Enhancements to the container image model enable powerful, precise graph searches that immediately link runtime security findings back to their source repository and registry. This means you can now answer complex audit and security questions such as, which registry images are deployed in runtime, instantly.                                                                                                                                                                                                                                                                                                                                                                                                            |
| Improved scanning of GKE nodes with agentless scanning of Container-Optimized OS (COS) from Google | Agentless Disk Scans (ADS) can now scan GKE nodes with COS partitions for vulnerabilities, malware, secrets, and compliance issues.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Address security coverage blind spots with new filters for compute assets                          | <p>Gain immediate visibility into your workload security status and ensure zero gaps in coverage. The following new filters are available on the Container Images, VM Instances, and VM Images tabs of the Inventory > All Assets page: </p><ul><li><strong>Scanners</strong>: Filter assets that are being monitored by specific security scanners (example: Agentless, XDR for Cloud, Registry, and CI). If the asset has not been scanned by one of this scanners the column value will be empty. This column is hidden from the view by default. </li><li><strong>Last Scan</strong>: Filter assets by when they were last scanned by any scanner. This allows you to pinpoint workloads that have not been scanned recently, ensuring continuous security and compliance. If the asset has not been scanned, this field is hidden from the view.</li></ul>                      |
| Agentless Scanning for Container Registries                                                        | <p>Cortex Cloud now supports direct integration with various container registries to enable agentless scanning of container images. This enhancement helps ensure consistent security and comprehensive protection for containerized applications across all environments by identifying vulnerabilities, malware, and secrets. The integrations are independent of the cloud account onboarding process and includes a streamlined, user-friendly connector configuration experience.</p><p>You can now connect Cortex Cloud to the following container registries:</p><ul><li>Docker Hub</li><li>GitLab Container Registry</li><li>Harbor Registry</li><li>Sonatype Nexus Repository Manager</li></ul>                                                                                                                                                                             |
| Registry Scanning for OCI Artifact Registry                                                        | <p>You can now enable and configure container registry scanning for Oracle Cloud Infrastructure (OCI) Artifact Registry when onboarding cloud accounts. This capability helps enhance security posture across your containerized workloads. </p><p>With registry scanning enabled, you can: </p><ul><li>Identify and remediate risks early in the development cycle.</li><li>Enforce security policies for container images. </li><li>Prevent non-compliant images from being deployed to production environments. </li></ul><p>You can configure registry scanning in two ways:</p><ul><li><strong>During onboarding:</strong> Select the Registry Scanning option under Additional Security Capabilities when adding a new OCI cloud account. </li><li><strong>Post-onboarding:</strong> Edit the settings of an existing onboarded account to enable registry scanning.</li></ul> |
| Defining container image trust compliance policies                                                 | Using the new Trusted Images policy wizard, you can select the trust criteria that are important to your organization. Policies can be defined with criteria like the image source, base image, and security scan status. Cortex can alert you about attempts to run untrusted images, or even block untrusted images from running, ensuring your images meet your defined standards and align with security guidance.                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Policies & Rules: Support CWP Collections Groups & Improved Policies Flow                          | We've enhanced CWP Policy management with a streamlined user experience and enhanced integration of CWP Asset Groups. This update makes policy definition more intuitive, efficient, and easier to scope precisely to your cloud workloads. Key improvements include a redesigned UI, support for creating new asset groups, default predefined asset scopes, support for multi rules selection, and dynamic policy summaries.                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Support for Scanning Azure legacy images.                                                          | We have added support for scanning Azure legacy images. This update enhances image scanning coverage and helps ensure compliance across older VM images.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |

**KSPM**

| Feature                           | Description                                                                                                                                                                                                                                                                                                                                                                                                       |
| --------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Support of self-managed OpenShift | We've expanded our Kubernetes Security Posture Management solution’s capabilities to include self-managed OpenShift clusters, enabling comprehensive discovery of their resources into the Unified Asset Inventory, and full support for CWP compliance rules. This enhancement provides greater discoverability and visibility and strengthens the security posture of your self-managed OpenShift environments. |
| Unified Kubernetes onboarding     | We’ve streamlined the Kubernetes onboarding process into a single, easy-to-use wizard. Now you can discover all available security capabilities based on your license, configure everything in one flow, and deploy your entire solution with one consolidated installer.                                                                                                                                         |
| Kubernetes support on ARM nodes   | You can now extend your Kubernetes posture management solution’s coverage to environments running on ARM architecture.                                                                                                                                                                                                                                                                                            |
| Kubernetes support for proxy      | Extend your security coverage to more of your clusters, regardless of their network configuration. The Kubernetes Security Posture Management solution can now be installed in Kubernetes environments behind an HTTP/HTTPS proxy gateway with no authentication, as well as with basic authentication.                                                                                                           |

**Automations**

| Feature                                                           | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Install content from Marketplace                                  | You can now browse and install content packs directly from the Marketplace page, which provides improved visibility into all available content. This allows you to easily discover and install the right content packs to fit your specific security workflows.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Recommended Quick Actions                                         | Recommended Quick Actions enable you to receive contextual and diverse automation recommendations directly within issue response workflows. Recommendations accelerate issue response and drive automation adoption by guiding users to the most relevant and efficient actions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Auto populate command and Quick Action parameters                 | On-demand enrichment from the Unified Asset Inventory (UAI) enables commands and Quick Actions to remain dynamic and adaptable. Any attribute in the UAI, not just those hardcoded into the issue schema, can be accessed when needed for automation execution. This improves flexibility and reduces the need for playbooks to retrieve relevant data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Automation Exclusion Center enhancements                          | <p>The automation exclusion center now allows for more dynamic and flexible policies: </p><ul><li>Hard user remediation and soft user remediation automation exclusion policies can now reference asset groups. User accounts are automatically categorized into asset groups, eliminating the need for manual list updates and ensuring that automation exclusion policies remain up-to-date. </li><li>Reference multiple lists and asset groups in the same policy, providing maximum flexibility. </li><li>New role permissions enable you to allow non-admin users the ability to view or edit policies in the Automation Exclusion Center. This allows admins to delegate policy management to non-admin users without granting full admin level system access, and provides admins more time to focus on other critical responsibilities. </li><li>Automation Exclusion policy overrides provide greater control and responsiveness. You can now permit policy overrides on specific automation exclusion policies, enabling analysts to manually run commands on critical assets as needed. You can also configure policies without overrides, providing a balance of security and operational flexibility.</li><li> With RBAC for lists, you can now define one or more roles that can view or edit a list, mitigating the risk of unauthorized or accidental changes to lists of critical assets. </li><li>New condition-based policies offer more versatility and precision for enforcing automation exclusions. You can now use lists with dynamic matching operators, such as starts with, ends with, and doesn’t include. Dynamic matching operators allow you to apply automation exclusion policies to entire naming patterns, such as regional endpoints or internal domains, simplifying management and improving coverage.</li></ul> |
| Dismiss alerts for non-configured playbook components             | When setting up playbooks, you can now dismiss alerts for components you don't need, such as specific scripts, and commands, in addition to sub-playbooks. This allows you to reduce visual noise and makes it easier to focus on the tasks that require configuration. Alerts can be dismissed in both system and custom playbooks, and you do not need to edit or duplicate a system playbook to dismiss an alert.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Unique task logos                                                 | Boost clarity, quickly distinguish between integration commands, custom scripts, and system actions with playbooks that display unique logos and content pack indicators.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Streamlined playbook development with drag-and-drop functionality | Streamline your playbook development using drag-and-drop to build automation flows. This enhancement enables creating and organizing your playbooks faster by simply dragging tasks from the side panel directly onto the canvas.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Conflict-free playbook editing                                    | Prevent concurrent playbook editing with this enhancement, ensuring your team can build and modify automation workflows without conflicts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Choose integration instance for Quick Actions                     | When running a Quick Action on demand or as part of an automation rule, you can now select a specific integration instance to use, enabling more efficient and targeted response.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Enhanced automation for cloud security                            | To expand your ability to automate responses in the cloud, new commands and Quick Actions are now available for AWS, GCP, and Azure integrations. This enables building more comprehensive playbooks to manage and remediate cloud security issues.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

**Compliance**

| Feature                                                                                       | Description                                                                                                                                                                                                                                                                                                                                                    |
| --------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Compliance assessment now shows UAI-supported asset fields                                    | The asset fields in your assessment profile reports now include fields from the Unified Asset Inventory (UAI). This enhancement provides a more comprehensive view of your assets, giving you more data to analyze and report on, which strengthens your compliance posture.                                                                                   |
| New compliance standards                                                                      | <p>Compliance standards added to the catalog include: </p><ul><li>CIS Amazon Linux 2 STIG</li><li>CIS Microsoft Windows 11 Enterprise </li><li>CIS Windows Server 2016</li></ul>                                                                                                                                                                               |
| Updated compliance standards                                                                  | <p>We have released newer versions of the following compliance standards: </p><ul><li>CIS AKS Benchmark </li><li>CIS EKS Benchmark</li><li>CIS GKE Benchmark</li></ul>                                                                                                                                                                                         |
| Immediate initial view of compliance results without configuration                            | You can now immediately view your compliance posture without any initial configuration. A new default policy automatically displays compliance results and generates issues according to common industry standards. Previously, you had to define an assessment profile before viewing compliance posture and generated issues in the Compliance Results view. |
| New policy to generate issues for all workload security rules with "Critical & High" severity | A new, out-of-the-box misconfiguration policy automatically creates Issues for workload rules with Critical or High severity ratings. This feature allows you to immediately prioritize and address the most significant compliance risks, helping you improve your security posture with no configuration required.                                           |
| Improved compliance rule migration                                                            | When migrating rules from Prisma Cloud to Cortex Cloud, you'll now receive error codes for clearer troubleshooting. Additionally, the rule severity is now accurately based on the original rule definition, not the highest severity found in Prisma Cloud, ensuring your compliance data is more precise post-migration.                                     |

**Endpoint Security**

| Feature                            | Description                                                                                                                                                                                                                                                  |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| File examination on-load for macOS | Detect and prevent execution of malicious Mach-O files when being loaded on macOS-based endpoints, using this new Cortex XDR agent capability.                                                                                                               |
| ML-based JScript file examination  | Enhance your defense against script-based threats with a new machine-learning protection module for the XDR Agent on Windows, trained to analyze and block malicious JScript files before they can execute or when written to disk.                          |
| Malicious LDAP Query Protection    | Identify and block malicious reconnaissance activity targeting Windows Domain Controllers. Customers with the ITDR add-on can now use the XDR agent for real-time prevention against attack techniques used by tools like BloodHound's SharpHound collector. |
| Child Process Protection for Linux | Cortex XDR introduces an additional prevention module for Linux that examines the relations between parent and child processes to detect suspicious relations. This module provides improved detection and protection coverage capabilities.                 |
| Operating systems                  | Extend agent deployments to Windows devices running on ARM64 architecture, including Microsoft Surface devices.                                                                                                                                              |

**API security**

| Feature                                            | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| -------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Connecting API Endpoints to Applications with ASPM | Users can now clearly see which applications their APIs are part of, streamlining application-centric security management and understanding the broader impact of API vulnerabilities. This is achieved by integrating API endpoints with ASPM through agents deployed on servers where APIs reside, leveraging customer-defined application mappings to establish these crucial connections in the security graph and asset cards.                                                       |
| Sensitive Data Detection for API Traffic           | Gain critical insights into the type and location of sensitive data flowing through your APIs, ensuring better compliance with regulations like GDPR or PCI and proactive risk mitigation. Utilizing Cortex Cloud DSPM's powerful data scanning engine, this feature identifies sensitive data based on predefined profiles (e.g., PII, PCI) and patterns (e.g., credit cards), displaying this information directly within API endpoint inventory, asset cards, and investigation views. |
| Enhanced API Endpoint Relations in Search Graph    | Improve your ability to investigate and understand the interconnectedness of your API infrastructure by visually exploring relationships between API endpoints, servers, and gateways. API endpoints are now fully integrated into the search graph, allowing users to craft advanced queries and visualize their connections to servers and API gateways, with these relations also accessible in asset and issue cards.                                                                 |
| Advanced Issue Investigation Experience            | Accelerate incident response and simplify root cause analysis with a significantly enhanced investigation experience that provides immediate access to relevant information and guided next steps. The redesigned issue side panel offers pre-built queries and filters for XQL and alert pages, enabling users to seamlessly delve deeper into issues and gather comprehensive context without manual exploration.                                                                       |

**ASPM**

| Feature                                              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ---------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Expanded Supply Chain security and visibility        | <p>The <strong>Supply Chain Catalog</strong> has been enhanced to provide deeper visibility, risk assessment, and contextual insights for your application delivery environments:</p><ul><li><strong>Added the Supply Chain Catalog</strong>: Provides a centralized registry of recognized supply chain tools and their associated risk factors. You can cross-reference Cortex Cloud–recognized tools with those detected in your environment to identify coverage gaps and benchmark the effectiveness and security posture of your supply chain</li><li><p><strong>Expanded tool coverage</strong>: Expanded the supported tool types recognized within the catalog to provide comprehensive coverage across your cloud environments and custom scripts:</p><ul><li><strong>Azure Extensions</strong>: Visibility and risk assessment for components integrated via Azure DevOps (ADO) extensions</li><li><strong>Remote Scripts/URLs</strong>: Recognition and analysis of security implications from external or remote scripts and URLs referenced in your pipelines</li><li><strong>CircleCI Orbs</strong>: Comprehensive scanning and cataloging of reusable CircleCI configuration components (Orbs)</li></ul></li><li><p><strong>New risk assessment capabilities</strong>: Introduced these features to help you assess and manage your supply chain risks:</p><ul><li><strong>Risk Factors</strong>: Identify and prioritize risks for cataloged tools and components by potential impact and exploitability</li><li><strong>PAN Insights</strong>: Mitigation recommendations based on risk factors to address relevant supply-chain threats</li><li><strong>Comments</strong>: Support for adding comments directly to catalog items, enabling collaboration and internal notes between security and development teams regarding component usage, justification, or deprecation status</li></ul></li></ul> |
| Automated bulk application creation using cloud tags | <p>You can now automatically create multiple applications in bulk by defining Application Criteria, which allows you to set rules that automatically group assets into applications based on cloud tags.</p><p><strong>Highlights</strong> </p><ul><li><strong>Automatic asset enrichment</strong>: All generated applications are enriched with code, build, deploy, and runtime assets using a relationship algorithm</li><li><strong>Dedicated Criteria page</strong>: A single view allowing you to define and manage criteria with full transparency and traceability</li><li><strong>Automated business metadata</strong>: Map tags to automatically populate key business fields, such as criticality, owner, and business unit</li></ul><p>This feature makes it faster and easier to scale application visibility, ensuring consistent grouping and reducing manual effort.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Application-based scope & policy enforcement         | <p>Application-based scope elevates management of security permissions and application context. Administrators gain precise control over user visibility and actions, ensuring each user accesses only the security data relevant to their role.</p><p><strong>Key values</strong> </p><ul><li><strong>Granular access control (Blacklisting)</strong>: Users are implicitly denied access to any data they aren't explicitly entitled to. Permissions are consistently enforced across all actions, limiting access to authorized applications only</li><li><strong>Application-level policy enforcement</strong>: Policies can be scoped by Application Name, ensuring that findings become issues only when they are tied to assets that belong to an application. This allows users to reduce noise and control overhead by focusing enforcement on the most relevant assets</li><li><strong>Richer contextual visibility</strong>: An Application Name filter lets you scope dashboards, assets, issues, and scan results by a specific application, enabling focused investigations, faster remediation, and easier compliance monitoring</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Issue severity SLAs                                  | <p>Administrators can now define and manage Service Level Agreements (SLAs) for different issue severities. This allows you to quickly and clearly understand your organization's security posture, helping teams prioritize and address issues before they become overdue.</p><p><strong>Key features</strong>  </p><ul><li><strong>Flexible SLA definitions</strong>: Set a number of days for an issue to become Overdue if not addressed</li><li><strong>Approaching status</strong>: Define how many days before an issue is overdue to mark it as Approaching. This acts as an early warning so you can prioritize issues before they become overdue</li><li><strong>Track your progress</strong>: Monitor the status of each issue to ensure it stays On Track. This provides a high-level overview of issue health, preventing them from falling through the cracks</li></ul><p><strong>Enhanced issue visibility in the tenant</strong> </p><ul><li><strong>New SLA Status column</strong>: The Application Security issues tables now include a sortable and filterable SLA status column</li><li><strong>Improved context</strong>: Use the new SLA status alongside the existing Creation Time column to better understand which issues need immediate attention</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Runtime-context policies                             | <p>You can now create policies based on a repository's real-world context. This includes factors such as whether assets are deployed, whether these deployed assets are exposed to the internet, have access to sensitive data, or can leverage privileged capabilities.</p><p><strong>Improved policy experience</strong>:</p><ul><li><strong>Improved policy flow in the policy wizard</strong>: Added a clear distinction between code scanner and CI/CD configuration risks, and a summary stage, to better understand a policy's impact</li><li><strong>Efficiency summary in a policy side-card</strong>: The new summary shows how many actions each policy has taken in total and in the last seven days</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Enhanced prioritization with the new Urgency metric  | <p><strong>Urgency</strong> helps you prioritize issues detected by our Application Security <strong>SAST</strong>, <strong>SCA</strong>, <strong>Secrets</strong> and <strong>IaC</strong> scanners in your SDLC. Unlike traditional severity, Urgency analyzes the unique context of your code-to-cloud data including the impact and probability of exploitation, to provide a dynamic and more accurate prioritization. It focuses on the specific issues that pose the greatest real-world risk, ensuring you address the most critical problems first.</p><p>To leverage this code-to-cloud context, each issue's side card now includes two new sections that provide you with the full context you need for smarter decisions:</p><ul><li><strong>Urgency details</strong>: Explains the specific code-to-cloud data used to determine the issue's urgency</li><li><strong>Code-to-Cloud graph</strong>: A new visualization that maps the relationships between your code and cloud assets, illustrating the exact connections that led to the urgency value</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |

**Code Scanners**

| Feature                                      | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Added SCA support for PHP and Rust languages | <p>Application Security has expanded its Software Composition Analysis (SCA) capabilities to provide deep dependency security for both PHP and Rust projects.</p><p><strong>PHP support</strong> </p><ul><li>Discovers dependencies by parsing <code>composer.json</code> and <code>composer.lock</code></li><li>Provides full SBOM coverage, including transitive dependencies</li><li>Detects vulnerabilities and license risks</li><li>Offers guided remediation for identified vulnerabilities</li></ul><p><strong>Rust support</strong> </p><ul><li>Discovers dependencies by parsing <code>Cargo.toml</code> and <code>Cargo.lock</code></li><li>Provides full SBOM coverage, including transitive dependencies</li><li>Detects vulnerabilities, licenses, and operational risks</li><li>Offers guided remediation for identified vulnerabilities</li></ul> |
| Integrate Secrets scans into Git Hooks       | <p>You can now integrate Application Security scanners directly into your Git workflows as hooks for secrets scanning:</p><ul><li><strong>Pre-Commit hooks</strong> (client-side): Integrate scanners as pre-commit hooks into your developer workflows to scan for secrets issues on your machine before you complete a local commit</li><li><strong>Pre-Receive hooks</strong> (server-side): Integrate scanners as pre-receive hooks into your repository settings to scan for secrets exposure before code is accepted into the remote repository</li></ul>                                                                                                                                                                                                                                                                                                   |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/cortex-cloud-runtime-security-release-information/features-introduced-in-2025-cloud/november-2025/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
