> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/july-2026/feature-enhancements.md).

# Feature Enhancements

These enhancements provide new and improved capabilities.

## API

| FEATURE                            | DESCRIPTION                                                                                                                                                                                                                                  |
| ---------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Manage Broker VMs programmatically | You can now manage and configure your Broker VMs programmatically. Use the Public API to retrieve broker details and health status, manage applets, and perform broker actions such as register, remove, reboot, upgrade, and download logs. |

## Broker VM

**Version 32.0.51 (reboot required)**

For more information on maintenance releases, see [Maintenance Releases](/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases.md).

| FEATURE                             | DESCRIPTION                                                                                                                                                                                                                                                  |
| ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Upgrade applets independently       | Deploy updates faster and with minimum dependences. You can now update individual Broker VM applets independently without upgrading the entire Broker VM. This reduces management overhead and delivers immediate enhancements without system-wide downtime. |
| Enforce TLS 1.3 communication       | Meet emerging compliance demands and secure your data transmissions against modern threats. Cortex XDR now supports TLS 1.3 communication between the Broker VM and the server to ensure your environment aligns with strict cybersecurity standards.        |
| DB collector Windows authentication | We have added Windows Authentication support to the (MSSQL) Database collector applet to enable secure connectivity in domain environments. The new authentication method supports Kerberos, NTLM and the standard SQL internal authentication.              |

## Extended Analytics Detection Coverage

| FEATURE                                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| ----------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| LOLBIN Execution Analytics                      | Catch hidden threats by detecting adversaries abusing Living-Off-The-Land-Binaries (LOLBin) system tools for proxy execution of malicious code and evade signature-based defenses. The suite leverages behavioral baselines and anomaly scoring to surface uncommon command-line patterns, unusual child processes, and rare network connections originating from LOLBins.                                                                                                                                                                                                                                                                                         |
| NDR Unmanaged Subnet Analytics                  | Detects malicious activity instantly from blind spots created by new or unmanaged devices. We added NDR Unmanaged Subnet Analytics to analyze the collective behavior of the subnets, eliminating the need for a historical baseline and detecting attacks on unmanaged hosts.                                                                                                                                                                                                                                                                                                                                                                                     |
| EDR Linux Sensitive Information Theft Analytics | A novel analytics-based detection tailored to the Linux domain, designed to identify anomalous or uncommon attempts by processes to access and extract data from sensitive system files and configuration directories. By profiling behavioral baselines, it automatically filters out standard administrative noise while exposing sophisticated adversaries, Webshells, and malicious scripts seeking to gather system-level intelligence, discover credentials, and uncover pathways for lateral movement.                                                                                                                                                      |
| SSM Remote Management Analytics                 | Detects suspicious activity involving AWS Systems Manager (SSM), including command execution, session access, parameter store operations, and SSM agent behavior on endpoints.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Cloud Log Tampering Analytics                   | Detects adversaries attempting to disable, delete, or modify cloud audit and activity logs to cover their tracks across AWS, Azure, and GCP. The suite leverages behavioral baselines and anomaly scoring to surface uncommon log-configuration changes, rare API calls targeting logging services, and unusual identities interacting with cloud telemetry pipelines.                                                                                                                                                                                                                                                                                             |
| OCI Analytics                                   | Detects malicious activity in Oracle Cloud Infrastructure (OCI) tenants by extending Cortex cloud analytics to OCI, giving customers a unified detection layer across all four major cloud providers.                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Extended EDR macOS AppleScript Analytics        | The upgraded analytics detection suite uncovers adversaries abusing AppleScript to proxy malicious behavior on macOS, a technique increasingly leveraged by macOS infostealers and other threats. The suite surfaces uncommon command-line patterns and high-risk script intent across the attack lifecycle, including data exfiltration, credential and credential-file theft, cryptocurrency wallet access, sensitive application data collection, screen and clipboard capture, system information discovery (including VM/sandbox evasion checks), persistence via Launch Agents/Daemons, defense evasion and Gatekeeper bypass, and command-line obfuscation. |

## External Data Ingestion and Management

| FEATURE                        | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Device Security data collector | <p>Introducing a new data collector called <strong>Device Security</strong>, which collects alerts and device data from Strata Device Security using a new Strata Cloud Manager authentication method. Existing IoT Security data collectors will continue to operate using the legacy authentication method, now labeled <strong>IoT Security (Deprecated)</strong>.</p><p>Legacy IoT Security data collectors will be discontinued in the near future. We recommend migrating to the new Device Security data collector to ensure uninterrupted data collection.</p> |
| Continuous data parsing        | Avoid data gaps and keep collecting critical logs when datasets grow unexpectedly. When a dataset reaches its 2,000-field limit, you can now add a parsing rule stage to explicitly select the fields you need, which resumes the parsing. The updated error messages provide exact steps to resume data flow.                                                                                                                                                                                                                                                         |

## Investigation and response

| FEATURE                                                              | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Enhanced security and simplified access with ITDR Conditional Access | The new Conditional Access Policy for ITDR introduces a dynamic, context-driven security model to protect your organization's most sensitive assets. By creating granular "if-then" rules, you can now manage and control who can access systems based on real-time conditions like user identity, device status, and authentication risk. This policy balances security with user convenience, enabling you to enforce Multi-Factor Authentication (MFA) or block access for anomalous logins, significantly reducing the risk of identity-based attacks. Requires the ITDR add-on. |

## XDR Collectors

**XDR Collectors 1.5.3:** Windows 1.5.3.2503 and Linux 1.5.3.2371

**XDR Collectors 1.4.3:** Windows 1.4.3.1686

| FEATURE                      | DESCRIPTION                                                                                                                                                                                                                                                             |
| ---------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| XDR Collectors 1.5.3 upgrade | Protect your environment with the latest security enhancements and system stability. Cortex XDR now supports XDR Collectors version 1.5.3.XXXX for Windows and version 1.5.3.XXXX for Linux.                                                                            |
| Upgraded Winlogbeat          | Cortex XDR now supports version 9.3.2 Winlogbeat for 64-bit XDR Collectors. Live 64-bit XDR Collectors receive this update automatically, while 32-bit XDR Collectors remain unaffected, as this independent update is not tied to any specific XDR Collectors version. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr/july-2026/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
