> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/april-2024/feature-enhancements.md).

# Feature Enhancements

The Cortex XDR 3.10 and Cortex XDR Agent 8.4 releases include the following enhancements:

## Endpoint Security

| FEATURE                                                                                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>Enhanced Vulnerability Assessment</p><p> </p>                                                 | <p>Cortex XDR introduces the Enhanced VA mode that uses advanced algorithms and comprehensive databases to deliver in-depth analysis and extensive details on CVEs. The Enhanced VA mode is available on Windows and MacOS endpoints running Cortex XDR agent versions 8.3 and later.</p><p> </p>                                                                                                                                                                                            |
| <p>Root detection alerts on Android-based endpoints</p><p> </p>                                  | Cortex XDR now includes root detection alerts to help you identify Android devices where malicious tools could be installed using root access privileges.                                                                                                                                                                                                                                                                                                                                    |
| Analytics for Containerized Environments                                                         | <p>Cortex XDR enhances its container security capabilities with the introduction of a detection analytics pack designed for managed and unmanaged Kubernetes environments. This enhancement strengthens cloud workload protection by enabling proactive identification and mitigation of malicious content inside containerized applications.</p><p> </p>                                                                                                                                    |
| <p>New configuration options for the iOS malware profile</p><p> </p>                             | The endpoint iOS malware profile now includes options to configure the use of the Safari browser security module to monitor the browser traffic, and to configure the network security module options to restrict and block network traffic for unsanctioned apps on supervised iOS devices. These enhancements provide proactive gating of suspicious sites, and granular control and monitoring of network traffic.                                                                        |
| <p>Additional network filtering alerts for iOS-based endpoints</p><p> </p>                       | <p><strong>Network Shield</strong> and <strong>Safari Safeguard</strong> are two new protection modules in iOS that can help track malicious app activity, unwanted access to malicious web sites and URLs and monitoring of unsanctioned web access. New event alerts for these modules include:</p><ul><li>Malicious network activity</li><li>Malicious network activity - digest</li><li>Company restricted network activity</li><li>Company restricted network activity digest</li></ul> |
| <p>New dataset for auditing correlation executions</p><p>(Requires a Cortex XDR Pro license)</p> | <p>The new <code>correlations\_auditing</code> dataset provides visibility into your correlation rules by logging each rule execution. The dataset records the query times, correlation start/end times, retry attempts, failure reasons, and other useful metrics.</p><p> </p>                                                                                                                                                                                                              |
| <p>Cloud Security Agent</p><p>(Requires Cortex XDR Cloud per Host license)</p>                   | <p>Unified (single) agent that reduces maintenance and resource overheads while providing runtime security and vulnerability management capabilities for cloud native environments.</p><p>Requirements:</p><ul><li>Cortex XDR 3.10 Cloud per Host license</li><li>Prisma Cloud Compute</li><li>Cortex XDR agent 8.2.1 or above</li></ul><p>Supports:</p><ul><li>Host and Kubernetes Installers</li><li>Linux only</li></ul><p> </p>                                                          |

## XDR Collectors

Windows 1.4.1.1100 and Linux 1.4.1.1089

For more information on maintenance releases, see [Maintenance Releases](urn:resource:component:879155).

| FEATURE                             | DESCRIPTION                                                   |
| ----------------------------------- | ------------------------------------------------------------- |
| <p>XDR Collectors 1.4.1</p><p> </p> | This release includes performance improvements and bug fixes. |

## Broker VM

Version 23.0.33 (reboot required)

For more information on maintenance releases, see [Maintenance Releases](/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases.md)

| FEATURE                          | DESCRIPTION                                                   |
| -------------------------------- | ------------------------------------------------------------- |
| <p>Broker VM 23.0.33</p><p> </p> | This release includes performance improvements and bug fixes. |

## External Data Ingestion and Management

| FEATURE                                                                          | DESCRIPTION                                                                                                                                                                                                                  |
| -------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>TTL for lookup datasets</p><p>(Requires a Cortex XDR Pro license)</p><p> </p> | Cortex XDR now enables configuring Time To Live (TTL) for lookup datasets, which specify when lookup entries expire and are removed automatically from the dataset. The default value is forever, meaning they never expire. |
| <p>NGFW configuration log ingestion</p><p> </p>                                  | NGFW configuration logs are now ingested, to enrich the firewall data ingested into Cortex XDR.                                                                                                                              |

## Cortex Query Language (XQL)

| FEATURE                                                                                                 | DESCRIPTION                                                                                                                                                                                                                                                                      |
| ------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>New Parsing Rules regexcapture function</p><p>(Requires a Cortex XDR Pro per GB license)</p><p> </p> | Cortex XDR now supports using a new Parsing Rules function called regexcapture to extract fields using regular expression named groups from a given string and return a JSON object with capturing groups.This function simplifies the Parsing Rules code for fields extraction. |
| <p>Aligned XQL function descriptions and syntax</p><p>(Requires a Cortex XDR Pro license)</p><p> </p>   | The XQL query function and syntax descriptions in Cortex XDR are now aligned with the descriptions found in the Cortex XDR XQL Language Reference guide. This ensures that the same information is provided in both places.                                                      |

## Forensics

| FEATURE                                    | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| ------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>Forensics investigation</p><p> </p>     | <p>Cortex XDR introduces a new Forensic Investigations feature to the Forensics add-on. This includes:</p><ul><li>Method for grouping all evidence collections and investigate notes in a single location</li><li>User permissions to limit access to investigation assets</li><li>Collections page for monitoring the progress of evidence collections</li><li>An alerts table which is investigation specific</li><li>A timeline tab containing a normalized view of all tagged rows</li><li>A new Key Assets & Artifacts tab, which is generated from the Investigation Timeline data</li></ul> |
| <p>Export forensic collections</p><p> </p> | Cortex XDR can now export Hunt or Triage collections into single archives and enable users to track and manage the exported data from the server.                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p>Forensic hunting</p><p> </p>            | <p>Cortex XDR introduces a new Forensic Hunting feature to the Forensics add-on. This includes:</p><ul><li>Named collection of user-defined searches</li><li>Method for running artifact searches at scale</li><li>Support for custom search parameters across all supported artifacts</li><li>Configurable timeouts for each artifact search</li><li>Ability to schedule searches for specific days or time ranges</li><li>Replaces artifact and search collections in User Agent settings and Forensic searches in the Action Center</li></ul>                                                   |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/april-2024/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
