> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/july-2025/feature-enhancements.md).

# Feature Enhancements

The Cortex XDR 4.2 release includes the following enhancements:

**General**

| FEATURE                                                  | DESCRIPTION                                                                                                                                                                                                                                                                                                                   |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Export filter JSON from the UI to ease writing API calls | Cortex public APIs require a proprietary JSON filter object for filtering assets, asset groups, policies, and other entities. To simplify API integration, you can now define your desired filter directly in the UI and export the exact JSON object for use in your API calls. This saves time and streamlines development. |
| German healthcare data control with Cortex XDR Cloud     | Maintaining control of data privacy and security for the public sector and regulated industries in Europe, Cortex XDR cloud region for Germany supports strict data privacy and service localization controls.                                                                                                                |

**API**

| FEATURE                                                        | DESCRIPTION                                                                                                                                                                                                                                                                           |
| -------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cases and Issues public APIs                                   | New public APIs are now available for managing cases and issues, providing capabilities to list and update cases, access related issues, assets, and artifacts, and to list, update, and create issues. This enables you to streamline and automate operations externally.            |
| Create Distributions API now supports Kubernetes installations | The Create Distributions API now supports Kubernetes installations, helping you automate and streamline the deployment of the agent in Kubernetes environments.                                                                                                                       |
| Identity Security Access Table Data                            | Facilitate advanced integrations, reporting, and analytics with the introduction of the CIEM Access Table Data API. It enables the retrieval of detailed access information using filters, with access details similar to the UI.                                                     |
| Unified Asset Inventory APIs                                   | Gain comprehensive API access to all your on-premises and cloud asset information. We've introduced new APIs for retrieving asset data from the Unified Asset Inventory, complete with powerful filtering capabilities. This provides flexible and precise access to your asset data. |
| APIs for managing API keys                                     | Gain more granular control and efficiency over your API keys. We've introduced new public API endpoints to get, create, and delete API keys, including the ability to delete API keys in bulk. This streamlines key management and enhances your security posture.                    |

**API Security**

| FEATURE                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| -------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cortex API security enhancements | <p>Cortex API security is enhanced with the following new capabilities:</p><p>- Boost your security and get a clearer picture of your API landscape with enhanced security scanning. By classifying API endpoints and their sub-types (like login, and checkout), you'll better understand each API's scope and sensitivity. This deeper insight paves the way for better detection of future threats and vulnerabilities, all while optimizing sensitive data protection.</p><p>- Beyond just observing live traffic, Cortex Cloud can automatically identify and extract API specifications from your AWS and Azure API gateway, proactively scanning them for misconfigurations and vulnerabilities, which gives you a more complete and secure inventory of all your API endpoints. Cortex also creates API endpoints from the specifications, which enables Cortex to uncover shadow APIs.</p><p>- Security coverage expands with the new integration option, F5 BIG-IP LTM.</p><p>- For better risk assessment and more effective remediation, Cortex expands its API security visibility by showing the gateways, workloads, and specifications related to the same endpoints, giving you a broader context of the API endpoint.</p><p>- Deep insights into the data profiles and patterns observed in your API endpoints' traffic can now be achieved with the integration of DSPM's unified, cross-platform data sensitivity scanning engine.</p> |

**Automations**

| FEATURE                                | DESCRIPTION                                                                                                                                                                                                                                                                                       |
| -------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Automation Exclusion Center            | Configure centralized automation exclusion policies to define which assets, such as users and endpoints, should be excluded from automated remediation. Use these policies to protect critical assets and ensure remediation actions are applied only to assets that are not explicitly excluded. |
| Automation menu navigation improvement | The Automation Rules menu item has been moved from Case Configuration to the Automation section of the main navigation, providing a streamlined user experience for automation configuration.                                                                                                     |

**Detection Rules**

| FEATURE                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New and improved Analytics tags | <p>New analytics suites:</p><ul><li>EDR Windows C2 Analytics: An innovative analytics detection suite that provides visibility into C2 and exfiltration traffic using our novel approach that fuses EDR process context and network-based features. This approach uncovers a broad range of attacks, from overt malicious communications to those involving seemingly benign implants or remote hosts.</li><li>EDR Linux Shell Analytics: A new, advanced Analytics-based generic detection suite that detects abnormal Linux shell executions, surfacing unknown exploits, stealthy backdoors, and post-exploitation activities. It also highlights attacker tools and powerful system commands run in unfamiliar contexts.</li><li>EDR MacOS Shell Analytics: A novel analytics-based detection suite tailored to the macOS domain that detects unusual spawned macOS shells. It uncovers unknown exploits, stealthy backdoors, and the uncommon AppleScript and information-gathering activities commonly leveraged by macOS infostealers.</li></ul><p>Improved analytics tags:</p><ul><li>NDR Lateral Movement Analytics: Upgrade to our network-based lateral movement detection suite, focusing on richer application logging for deeper protocol-based context. The suite's enhanced behavior-based analytics now provide earlier, more precise lateral movement detection, including SSH and improved Windows-native protocols.</li><li>EDR macOS AppleScript Analytics: Expanding our AppleScript attacks coverage by introducing visibility into module events.This enhancement extends our detection of suspicious AppleScript executions to trigger alerts also on executables loading AppleScript dynamic libraries (dylibs) for potential malicious use.</li></ul> |
| Enhanced Analytics Insights     | View the full list of detections behind the analytics and behavioral indicators of compromise (BIOCs) directly in the Cortex XDR console, so you can instantly understand why alerts were triggered.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |

**XDR Collectors**

**XDR Collectors 1.5.0:** Windows 1.5.0.1733 and Linux 1.5.0.1695

**XDR Collectors 1.4.3:** Windows 1.4.3.1686

For more information on maintenance releases, see [Maintenance releases](/cortex-xdr-5.x-rn/release-information/maintenance-releases.md)

| Feature                        | Description                                                   |
| ------------------------------ | ------------------------------------------------------------- |
| XDR Collectors 1.5.0 and 1.4.3 | This release includes performance improvements and bug fixes. |

**Broker VM**

**Version 28.0.96 (reboot required)**

For more information on maintenance releases, see [Maintenance releases](/cortex-xdr-5.x-rn/release-information/maintenance-releases.md)

Deprecation of Broker VM Pathfinder applet

The Broker VM Pathfinder applet is now deprecated.

* From this release, the Pathfinder applet can no longer be activated in new tenants or existing tenants that have never implemented this applet before.
* If this applet has been implemented in your tenant, it will remain available until January 25, 2026, which is the official deprecation date. To ensure complete coverage and protection, we recommend deploying XDR Agents on all endpoints by this date.
* Migration guidance and deployment resources for XDR Agents are available [here](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Cloud-Documentation/Install-Cortex-XDR-agents).
* For questions or transition support, contact your [Customer Support team](https://support.paloaltonetworks.com/Support/Index).

| FEATURE                                                                 | DESCRIPTION                                                                                                                                                                                                                                                                                                                              |
| ----------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Broker VM applet configurations preserved when deactivated              | Cortex XDR now provides the ability to maintain the Broker VM applet configurations whenever an applet is deactivated. This ensures that whenever the applet is reactivated the saved configuration is restored.                                                                                                                         |
| Enhanced error visibility and auditing for additional Broker VM applets | Gain better insight into application, connectivity, and processing errors for the File and DB collector applets running on Broker VMs. Error messages are displayed on Apps of Broker VMs and Clusters, and applet status changes are logged in the `collection_auditing` dataset, enabling detailed investigations through XQL queries. |
| Broker VM applets license enforcement                                   | License enforcement for the Broker VM applets has been enhanced to ensure that only applets aligned with the purchased product and licensed capabilities are available for activation and use.                                                                                                                                           |

**External Data Ingestion and Management**

| FEATURE                                         | DESCRIPTION                                                                                                                   |
| ----------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- |
| OCI support                                     | Gain visibility, compliance, and governance over assets and configurations in Oracle Cloud Infrastructure (OCI) environments. |
| VNET flow log support for Azure Network Watcher | Azure Network Watcher now supports VNET flow logs.                                                                            |

**Cortex Query Language (XQL)**

| FEATURE              | DESCRIPTION                                                                                                                                                                                           |
| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New XQL IP functions | Cortex Query Language (XQL) now supports new functions for IP manipulations. These functions verify whether an input is a valid IPv4/IPv6 address and if the IPv4/IPv6 address is a known private IP. |

**Investigation and Response**

| FEATURE                             | DESCRIPTION                                                                                                                                                                         |
| ----------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ITDR Issues and Insights Navigation | A new navigation entry for ITDR Issues and Insights enables you to quickly review all ITDR-related issues, including INFO, at a glance, with filtering, sorting, and other options. |
| Unified Identity Inventory          | A unified inventory for identities features dedicated sections for investigating each domain: cloud, enterprise, and code.                                                          |

**Endpoint Security**

| FEATURE                   | DESCRIPTION                                                                                                                                                                                                                                                                                  |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cloud-based host policies | Cortex XDR with agent 8.9 and later, enables cloud-based hosts to define policies based on important cloud attributes, such as cluster name, region, and provider. This gives the capability to define different security policies based on geography, responsibility, or specific clusters. |
| VBScript enhancement      | Cortex XDR with agent 8.9 supports the ability to detect malicious VBScript files being written to disk.                                                                                                                                                                                     |

**Gateway**

| FEATURE                         | DESCRIPTION                                                                                                                                                                                          |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Improved user record management | Only users with at least one role or user group assigned are saved to Cortex Gateway, ensuring that the Gateway contains only relevant user data. This enhances data security and system efficiency. |

**Graph Search**

| FEATURE                                                                     | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| --------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Graph Search enhancements (Beta) (Requires a Cortex XDR with Cloud license) | Graph Search now enables customers to: -Investigate real-time activity and identify critical events, such as access to sensitive information typically contained in a Storage Bucket, which generate issues and cases. This is now possible by the 100 most recent runtime events added to the graph results. -Track assets with internet exposure that could be targeted for external surface attacks, and the exposure path is also available. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2025-xdr-4x/july-2025/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
