> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/november-2025/feature-enhancements.md).

# Feature Enhancements

**Broker VM**

**Version 29.0.71 (reboot required)**

For more information on maintenance releases, see [Maintenance Releases](/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases.md)

| Feature                                                                                                            | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Enhanced error visibility and auditing for additional Broker VM applets (Requires a Cortex XDR Pro per GB license) | Gain better insight into application, connectivity, and processing errors for the FTP Collector, Netflow Collector, Network Mapper, and Apache Kafka collector applets running on Broker VMs. Error messages are displayed on Apps of Broker VMs and Clusters, and applet status changes are logged in the `collection_auditing` dataset, enabling detailed investigations through XQL queries.                                                                                                                                                                                            |
| Broker VM support for Spain’s Esquema Nacional de Seguridad (ENS) National Security Framework                      | The Broker VM has been updated to comply with Spain’s Esquema Nacional de Seguridad (ENS) National Security Framework. You must enable the option **Only use recommended cipher suites** to meet the ENS regulation. This new setting is located in the **Advanced Settings** section, which you can access when configuring the Broker VM using its URL.                                                                                                                                                                                                                                  |
| Enhanced Database Collector (Requires a Cortex XDR Pro per GB license)                                             | <p>The Database Collector applet now has a new <strong>Storage Method</strong> option, which offers more control over how the data is handled:</p><ul><li>Append: This method adds new data to an existing dataset as this worked previously by default.</li><li>Replace: This new method is only available for Snapshot datasets and overwrites the entire dataset with the newly collected data. This is necessary when the data that needs to be collected from the database is static data or reference data, such as a list of computers, IP addresses, or a list of users.</li></ul> |

**Cortex Query Language (XQL)**

| Feature                                      | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced XQL query monitoring and governance | <p>Introducing significant updates to XQL query management that deliver a more responsive, holistic, and powerful Query Center experience. Key enhancements:</p><ul><li><strong>Improved performance:</strong> Experience faster and more responsive page load and filtering times in the Query Center.</li><li><strong>Real-time tracking and management:</strong> Get full visibility into active queries across your tenant, with the power to instantly cancel running queries.</li><li><strong>Expanded query coverage:</strong> Monitor queries from all XQL query sources, including Dashboards with XQL widgets, Correlation rules, BIOC rules, and more.</li><li><strong>Administrator governance:</strong> Prevent resource strain and optimize tenant performance by setting query limits for all users.</li><li><strong>New default query limit:</strong> To prevent long-running queries and ensure optimal tenant performance, queries will automatically stop after 60 minutes. (This value can be overridden using the <code>max\_runtime\_minutes</code> command.)</li><li><strong>Updated query retention:</strong> Query retention is now aligned with issue retention.</li></ul> |
| Lookup datasets enhancement                  | Cortex XDR has implemented a fix to improve lookup dataset queries and provide better flexibility with managing your data. Now, when you create or add data to a lookup dataset using the target stage, the \_time field won't be included by default unless you explicitly add it with the fields stage.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

**Detection rules**

| Feature                         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New and improved Analytics tags | <p>New analytics suites:</p><ul><li> EDR Windows Disguised Processes: A novel analytics detection suite designed to detect Windows process masquerading techniques and their diverse sub-techniques, such as common process name impersonation and renaming of legitimate system utilities by attackers. The suite achieves this through its comprehensive analytic capabilities, featuring dynamic baselines and anomaly scoring.</li><li> EDR Linux Credential Grabbing: A behavior-based analytics detection suite to identify uncommon access to sensitive files that are frequently targeted for credential discovery. The suite monitors processes interacting with files such as SSH private keys, password and group files, shell history, and other configuration artifacts commonly used to store credentials. By analyzing access patterns across environments, the detector suite highlights rare or anomalous behavior, helping uncover otherwise unnoticed credential-harvesting activity.</li><li> EDR macOS Generic Persistence: An innovative analytics detection suite tailored to the macOS domain to detect unusual activities to secure persistent foothold and execution in macOS endpoints. This suite highlights abused persistence mechanisms and support the hunt for novel persistence techniques, commonly leveraged by macOS infostealers and APTs.</li><li>Microsoft Teams Analytics: An advanced analytics suite for detecting attack attempts within Microsoft Teams. The suite uncovers a broad range of different sub-techniques, such as phishing, malicious link sharing in chats, unauthorized policy modification, malicious application installation, and data collection. The suite uses dynamic baselines and anomaly scoring to provide comprehensive analytics, identifying abnormal user and communication patterns.</li></ul><p> Improved analytics tags: </p><ul><li>DLL Hijacking Analytics: We've expanded and improved our coverage for DLL Hijacking techniques. Using advanced analytic capabilities, we significantly enhanced detection logic for important threats, including Microsoft process hijacking and DLL sideloading.</li></ul> |

**Endpoint Security**

| Feature                            | Description                                                                                                                                                                                                                                               |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| File examination on-load for macOS | Detect and prevent execution of malicious Mach-O files when being loaded on macOS-based endpoints, using this new Cortex XDR agent capability.                                                                                                            |
| Child Process Protection for Linux | Cortex XDR introduces an additional prevention module for Linux (in KM mode) that examines the relations between parent and child processes to detect suspicious relations. This module provides improved detection and protection coverage capabilities. |
| CaaS distribution                  | Cortex XDR now supports Goggle Kubernetes Engine (GKE) Autopilot.                                                                                                                                                                                         |

**External Data Ingestion and Management**

| Feature                                 | Description                                                                                                                                                                                                              |
| --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Unified integration error notifications | Instead of being inundated with multiple notifications, all data collector errors are now grouped into a single notification. This new, non-dismissible notification alerts all users to data source integration errors. |

**XDR Collectors**

**XDR Collectors 1.5.1:** Windows 1.5.1.2048 and Linux 1.5.1.1950

**XDR Collectors 1.4.3:** Windows 1.4.3.1686

For more information on maintenance releases, see [Maintenance Releases](/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases.md)

| Feature                                                                                       | Description                                                                                                                                                                                                                                                                  |
| --------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced visibility and auditing of XDR Collectors (Requires a Cortex XDR Pro per GB license) | Cortex XDR now provides enhanced error visibility and auditing for XDR Collectors. This enables you to quickly identify and resolve application, connectivity, and processing errors, simplifying troubleshooting and ensuring your critical workflows remain uninterrupted. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/november-2025/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
