> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/june-2024/feature-enhancements.md).

# Feature Enhancements

The Cortex XDR 3.11 and Cortex XDR Agent 8.5 release includes the following enhancements:

## General

| FEATURE                   | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Analytics Tags Highlights | <p>Cortex XDR has updated the detectors inventory, introducing new analytics into both new and existing tags:</p><ul><li>Chromium Extensions Analytics (New) - Detection of malicious browser extensions being loaded or installed, identifying anomalous extensions and installation methods.</li><li>Malicious Service Analytics (New) - Detection of malicious services being loaded or installed.</li><li>NDR Lateral Movement Analytics - Advanced lateral movement detection, leveraging Analytics capabilities to identify anomalies in protocols that are used for lateral movement.</li><li>NDR C2 Analytics - Advanced detection for abnormal network communication that resembles C2 traffic using protocols analysis, local and cross-customer machine learning, and threat intel.</li></ul> |

## Investigation and Response

| FEATURE                                                                     | DESCRIPTION                                                                                                                                           |
| --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
| Combined alerts using correlation rules (Requires a Cortex XDR Pro license) | Using the `transaction` stage in scheduled correlation rules, you can now group events that come from different datasets to trigger a combined alert. |

## Endpoint Security

| FEATURE                            | DESCRIPTION                                                                                                                                                                                                                                                |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Device control enhancements        | <p>Device control profiles for Windows and macOS endpoints now provide granular control for print jobs, in certain conditions.</p><p>This additional control hardens communication with these types of peripheral devices or operations.</p>               |
| Benign with low confidence actions | On macOS-based endpoints, new actions are available for executable files that are reported as “benign with low confidence”. This feature adds more granularity to malware detection, and provides enhanced protection against potentially malicious files. |

## XDR Collectors

Windows 1.4.1.1100 and Linux 1.4.1.1089

For more information on maintenance releases, see [Maintenance Releases](urn:resource:component:879155).

| FEATURE              | DESCRIPTION                                                   |
| -------------------- | ------------------------------------------------------------- |
| XDR Collectors 1.4.1 | This release includes performance improvements and bug fixes. |

## Broker VM

Version 24.2.8

For more information on maintenance releases, see [Maintenance Releases](urn:resource:component:879155).

| FEATURE                                     | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New ability to increase Broker VM disk size | Cortex XDR now supports extending the disk space allocated for data caching in the Broker VM to attain better resilience during network and connectivity issues. Read more in [Increase Broker VM storage allocated for data caching](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Increase-Broker-VM-storage-allocated-for-data-caching). |

## External Data Ingestion and Management

| FEATURE                                                                                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ----------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>Update lookup datasets using Correlation Rules</p><p>(Requires a Cortex XDR Pro license)</p> | Cortex XDR now enables updating lookup datasets using Correlation Rules. This includes adding and removing lookup entries so you can better correlate data from a data source you provide with the events in your environment. Read more in [Create a Correlation Rule](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-a-Correlation-Rule).                                                                                                                                                         |
| Update lookup datasets using the API                                                            | <p>Cortex XDR now supports using the API to update lookup datasets, which makes it easier to correlate data from the data source to the events in your environment. The following new APIs are supported:</p><ul><li>add\_data - Adds or updates data in a lookup dataset</li><li>remove\_data - Removes data from a lookup dataset</li><li>get\_data - Gets data from a lookup dataset</li><li>add\_dataset - Adds a lookup dataset</li><li>delete\_dataset - Deletes a dataset</li><li>get\_datasets - Gets a list of available datasets</li></ul> |

## Cortex Query Language (XQL)

| FEATURE                                                                                                                                   | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ----------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>New XQL standard deviation comp aggregate functions</p><p>(Requires a Cortex XDR Pro license)</p>                                      | <p>Cortex XDR now supports using the following XQL standard deviation (STD) comp aggregate functions:</p><ul><li>stddev\_pop: Returns the population (biased) variance of a field.</li><li>stddev\_sample: Returns the sample (unbiased) standard deviation of a field.</li></ul>                                                                                                                                                                                                                                                                                                                    |
| <p>Aligned XQL stages descriptions, syntax, and XQL Helper</p><p>(Requires a Cortex XDR Pro license)</p>                                  | The XQL query stages, syntax descriptions, and descriptions in the XQL Helper in Cortex XDR are now aligned with the descriptions found in the Cortex XDR XQL Language Reference guide. This ensures that the same information is provided in all places.                                                                                                                                                                                                                                                                                                                                            |
| <p>Enhancements to XQL <code>incidr</code> and <code>incidr6</code> functions and operators</p><p>(Requires a Cortex XDR Pro license)</p> | <p>Cortex Query Language (XQL) now supports defining multiple CIDRs with comma separated syntax in the following functions and operators:</p><ul><li><code>incidr</code> and <code>incidr6</code> functions, where it is now possible to run the function on comma separated CIDRs.</li><li><code>incidr</code>, <code>not incidr</code>, <code>incidr6</code>, and <code>not incidr6</code> operators, where it is now possible to run the operator on comma separated CIDRs.</li></ul><p>These changes are only supported building a XQL query with the Query Builder or in Correlation Rules.</p> |

## Forensics

| FEATURE                                        | DESCRIPTION                                                                                                                                                                                            |
| ---------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Support Browser Collections in Agent for macOS | Cortex XDR now supports Web History searches in Forensic Hunts. Browsers supported are Chrome, Edge, Firefox, Internet Explorer, and Safari along with custom searches for any Chromium-based browser. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2024-xdr/june-2024/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
