> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/july-2025/changed-features.md).

# Changed Features

The Cortex XDR 4.2 release includes the following changes to existing functionality:

| COMPONENT       | AREA                                              | DESCRIPTION                                                                                                                                                                                                                                                                                                                                    |
| --------------- | ------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Issue Counts    | Improved FW alert count labels                    | FW alert deduplication now shows up to 1,000 alert counts. To simplify visualization, larger quantities display as 1000+.                                                                                                                                                                                                                      |
| User Name Field | Expanded Character Limit for Case User Name Field | The character limit of the Case User Name field has been increased to accommodate longer user names and improve search functionality.                                                                                                                                                                                                          |
| BAS tools       | BAS (Breach and Attack simulation) tools          | <p>Changed product behavior, when BAS (Breach and Attack simulation) tools are identified.</p><p>Currently, only the simulation itself is terminated, while the BAS tool continues to run.</p><p>New Behavior: BAS tools will be treated like any other malicious process, unless the new BAS tool mode in malware profile is switched on.</p> |
| Broker VM       | Agent installer and content caching               | When using the Broker VM for the agent installer and content caching, you must use a minimum of an 8-core processor and increase the disk requirement to 1024 GB, instead of the previous 512 GB minimum requirement.                                                                                                                          |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/july-2025/changed-features.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
