> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/may-2026/feature-enhancements.md).

# Feature Enhancements

These enhancements provide new and improved capabilities.

## General

| FEATURE                                           | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced notification forwarding                  | To help you prioritize and resolve security issues more effectively, issue notifications sent to Amazon S3, Amazon SQS, Webhook, Splunk, and email now provide additional asset and remediation information. Notification fields have been expanded to include the asset name, cloud resource name, asset tags, account name, region, and evidence.                                                                                 |
| Consolidated CaaS resource visibility             | Improve security oversight and simplify asset management by viewing CaaS (Containers as a Service) resources within a dedicated section of the Asset Inventory. This update organizes resources from Amazon ECS, Google Cloud Run, and Azure Container Instances into a single, purpose-built view under Compute assets, making it easier to locate, monitor, and assess the security posture of your cross-cloud CaaS deployments. |
| Administrator control for saved views and filters | Keep your workspace clean and relevant. Administrators can now remove unused or outdated saved views and filters, including those created by other users.                                                                                                                                                                                                                                                                           |

## Access Management

| FEATURE                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                      |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Granular per-object access       | Strengthen least-privilege access with granular permissions for user groups across report templates, playbooks, scripts, and saved queries.                                                                                                                                                                                      |
| Expanding SBAC with Account Name | Scope-Based Access Control (SBAC) has been enhanced to provide more granular control over your access policies. You can now define Asset Groups that include the **Account Name** attribute for scope-based access control. Continue to use the existing **Realm** attribute whenever you need to scope based on the Account ID. |

## Advanced Email Security

| FEATURE                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                                            |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Remediation quick actions          | Accelerate email threat response with single-click remediation actions from the email investigation view.                                                                                                                                                                                                                                              |
| New mailbox inventory              | <ul><li>Gain centralized visibility into your email security posture with a new dedicated inventory for email security assets within the Unified Asset Inventory (UAI).</li><li>Unlock deeper insights in the Email Command Center with the new mailbox metrics that provide a detailed breakdown of mailbox types and email directionality.</li></ul> |
| Detailed WildFire analysis reports | Access full, granular WildFire reports directly from the email causality card to gain deeper visibility into the behavior of suspicious email attachments, refine maliciousness assessments, and accelerate decision-making.                                                                                                                           |
| Sharpened investigation accuracy   | We’ve enhanced the accuracy of phishing detection by cross-referencing user-reported audit events directly with emails located in the M365 phishing mailbox.                                                                                                                                                                                           |

## Analytics Rules

| FEATURE                                        | DESCRIPTION                                                                                                                                                                                                                                                                                                                       |
| ---------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Scheduled Tasks Analytics                      | This new suite identifies malicious persistence by tracking the installation and execution of scheduled tasks, providing deep context and generating high-fidelity alerts.                                                                                                                                                        |
| NDR Insights Analytics                         | Our new network detection suite automatically correlates between low-fidelity network signals and existing alerts, transforming them into high-confidence security incidents.                                                                                                                                                     |
| Active Directory Federation Services Analytics | This new suite identifies suspicious and irregular behavior within your Active Directory Federation Services.                                                                                                                                                                                                                     |
| Google Workspace Analytics                     | This advanced suite detects attack attempts within Google Workspace, including through brute force, phishing, account manipulation, unauthorized policy modification, suspicious browser extension installations, credentials harvesting, and data collection.                                                                    |
| Linux Discovery Analytics                      | This novel suite, tailored to the Linux domain, identifies reconnaissance and host environment mapping activities. The suite detects adversaries and malicious scripts seeking to gather system-level intelligence, discover user credentials, and uncover pathways for lateral movement during the discovery phase of an attack. |
| Kubernetes Credentials Analytics               | This detection suite analyzes Kubernetes activity to identify credential harvesting techniques, including host file access from containers, kubelet credential file retrieval, and kubelet impersonation.                                                                                                                         |

## API

| FEATURE                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Application Security Policy API | The Application Security Policy API (GET and POST /public\_api/appsec/v1/policies) now includes expanded support for scanning across the pre-runtime (code, build, and deploy) lifecycles. This API enhancement enables you to define a single policy that covers multiple stages. The **triggers** field adds **ciImage** for CI pipeline image scans and **imageRegistry** for registry image scans. A new **blockCiImage** action enables you to block CI pipelines when image findings match policy conditions. The **findingTypes** field now uses a unified set of values: CICD\_RISKS, VULNERABILITY, SECRETS, IAC\_MISCONFIGURATION, CODE\_WEAKNESS, LICENSES, OPERATIONAL\_RISK, MALWARE, and DRIFT. An optional userSbac field has been added to the POST method for scoped access control during policy creation. |
| Billing Contributors API        | A new public API endpoint is introduced to retrieve a list of unique active contributors factored into your billing. This allows you to gain full transparency into your billable seats.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |

## Asset Inventory

| FEATURE                                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Drift detection highlight in Container Instances | Container Instances asset cards in Asset Inventory now include a Security Drift Detected highlight and a dedicated Security Drift tab, making it easy to identify containers that have deviated from their base image. These drifts expose vulnerabilities, misconfigurations, compliance violations, and other security risks introduced at runtime that were not part of the base image.                                                                                                                                                                                                        |
| Base Image Visibility for Container Images       | You can now identify the base image for any Build, Registry, or Runtime container image directly from its asset details page. With the **new has base reference** and **is base reference for** relationships in Security Graph, you can trace image lineage and assess vulnerability impact in a single query. Define custom Base Image Rules to mark foundational Registry Images, create targeted asset groups and policies, and quickly determine whether vulnerabilities originate from a base image layer. This streamlines your security investigations and accelerates incident response. |

## Automation

| FEATURE                                            | DESCRIPTION                                                                                                                                                                                                                |
| -------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Performance improvements for scripts and playbooks | Enhance the user experience when managing security workflows with modernized interface improvements and optimized memory usage across the Scripts and Playbooks pages to maintain a seamless and cohesive user experience. |

## Broker VM

**Version 31.0.57 (reboot required)**

For more information on maintenance releases, see [Maintenance Releases](/cortex-xdr-5.x-rn/release-information/maintenance-releases.md).

| FEATURE                                | DESCRIPTION                                                                                                                                                                                                                                                                                                   |
| -------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Legacy server connectivity             | You can now easily configure OpenSSL compatibility settings directly from the Broker VM web interface to ensure uninterrupted communication with legacy servers. We added **Advanced Settings** options to allow legacy SSL renegotiation and accept certificates without an Authority Key Identifier (AKID). |
| Import Configuration tool enhancements | The Import Configuration tool has been enhanced to streamline the Broker VM migration process to the new Broker VM image. You can now migrate your current Broker VMs to the new Debian 13 based image. **Note:** Both source and target brokers should be running the latest Broker VM 31.x version.         |

## Cortex Agentic Assistant

| FEATURE                                                  | DESCRIPTION                                                                                                                                                                                                     |
| -------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Chat with the Cortex Agentic Assistant directly in Slack | Access Agentic Assistant more easily across your daily applications. You can now trigger the Agentic Assistant from your Slack, give it tasks, interact with it and get the results on your existing workspace. |
| Natural language visualizations                          | Turn questions into charts in seconds, identify security trends, and build custom widgets without writing a line of code using the Cortex Agentic Assistant.                                                    |
| Enhanced AI product support                              | The upgraded Help Center agent delivers instant how-to support and helps you navigate in-product support cases. It stays aware of your support issues to provide more relevant guidance in context.             |

## Cortex Query Language (XQL)

| FEATURE                                       | DESCRIPTION                                                                                                                                                                                                                                                                                                                   |
| --------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Real-time query management                    | Save time and resources by analyzing your query results as soon as you see the initial findings, instead of waiting for a long query to finish. You can then refine, validate, or stop running queries.                                                                                                                       |
| New XQL mathematical and analytical functions | The new mathematical and analytical functions in XQL provide analysts with richer query capabilities for advanced threat hunting and data analysis.                                                                                                                                                                           |
| XQL workflow enhancements                     | <ul><li>The Query Builder now automatically caches your active code and results within a session to prevent data loss during navigation or refreshes.</li><li>Your preferred timeframe and table layout settings now persist across logins, ensuring a consistent and personalized workspace every time you return.</li></ul> |

## DLP

| FEATURE                        | DESCRIPTION                                                                                                                                                                                                                                                                                                                 |
| ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DLP local application profiles | Prevent data loss during remote access and file transfer sessions. You can now easily apply Data Loss Prevention (DLP) policies to widely used SSH, FTP, and RDP applications. We added built-in local applications for common tools like FileZilla, PuTTY, and Windows Remote Desktop to ensure your data stays protected. |

## Endpoint Security

| FEATURE                           | DESCRIPTION                                                                                                                                                                                                                                                                                                        |
| --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Shared objects file examination   | Secure your Linux environment against hidden threats. You can now automatically block malicious code from executing through non-standard loading methods. We updated the Cortex XDR agent to examine and stop harmful shared object files before they impact your system.                                          |
| On-write malicious file detection | Stop cross-platform threats from entering your network. You can now detect malicious mach-o files and non-native macOS binaries (such as Windows PEs and Linux ELFs) the moment they are saved to your system. We updated the Cortex XDR agent to provide comprehensive on-write detection for these binary types. |
| Advanced Java malware protection  | Prevent cyberattacks from compromising your applications. You can now automatically detect and block malicious Java-based threats the moment they appear or are saved to your system. We added real-time on-write protection for all Java files.                                                                   |

## Exposure Management

| FEATURE                                             | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                             |
| --------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Vulnerability & Exposure Management: Unified Module | <p>Streamline risk assessment and remediation with a consolidated workspace designed to minimize time-to-action.<br>We combined these tools into one navigation structure to eliminate context switching and speed up remediation. You can now use quick links for high-priority triage and pivot instantly between Findings and Issues to resolve threats faster.</p>                  |
| `Refine your risk accuracy`                         | Focus your resources on real threats by eliminating inaccurate and inflated risk scores. You can now recalibrate calculations to reflect your true security posture by accounting for custom or third-party security controls—such as Network or Web Application Firewalls. We added features to define control effectiveness and automate risk labeling across your cloud environment. |
| Tenable.sc vulnerability ingest                     | Streamline your workflow and reduce the need to switch between tools by ingesting assets and vulnerabilities from Tenable.sc directly into Cortex Exposure Management.                                                                                                                                                                                                                  |
| Vulnerability Ingest API                            | You can now bring your own scanner to the table. Ingest vulnerabilities and related assets from third-party tools directly into your asset inventory and vulnerability management workflows.                                                                                                                                                                                            |

## Exposure Management: Network Scanner

| FEATURE                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Streamline network scans           | Optimize your security workflows by reusing existing organizational data. You can now select previously saved Asset Groups as targets when creating new scans, eliminating the need to redefine external groups manually.                                                                                                                                                                                                                   |
| Automate cloud compliance auditing | Secure your cloud environment by automatically verifying that your assets meet industry standards like CIS Benchmarks for Windows 11 and Windows Server 2022. You can now run **Policy Compliance Assessment** scans to instantly identify misconfigurations or weak security controls across your Asset Groups. We added this dedicated scan type to help you maintain continuous governance and simplify your routine audit preparations. |
| Deepen device scan visibility      | Cortex Network Scanner now supports authenticated scans over Simple Network Management Protocol (SNMP). You can now use pre-configured SNMP credentials to authenticate various services on a target device. Add SNMP v2 or v3 credentials to authenticate configured services. We added this support to ensure your asset inventory reflects the true state of your network based on the specific permissions you assign.                  |
| Easily access Network Scanner      | Cortex UI enhancements allow you to easily access the Network Scanner functionality as part of the unified Vulnerability and Exposure Management module. Scanner functionality has migrated from and Settings->Configurations to Modules->Vulnerability & Exposure Management.                                                                                                                                                              |

## External Data Ingestion and Management

| FEATURE                    | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                            |
| -------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New Cloud NGFW data source | Gain complete visibility into your cloud-native network security with the new **CNGFW** (Cloud NGFW) data source. You can now stream traffic and application logs directly to Cortex XDR with support to cross-region and cross-account connections. We introduced this distinct connector to handle unique cloud-native identifiers, ensuring seamless log ingestion and analysis for your managed security services. |

## Graph Search

| FEATURE                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                               |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SBAC enforcement in Graph Search | Safely explore your environment in Graph Search with precise permission management. We introduced Scope-Based Access Control (SBAC) to give you granular control over user scope. You can now assign users to **User Groups** and **Asset Groups**, ensuring they only see authorized graph nodes and relationships. Requires the Cortex Cloud Posture Management add-on. |

## Investigation and Response

| FEATURE                                              | DESCRIPTION                                                                                                                                                                                                                                                                                                        |
| ---------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Case Timeline view                                   | Streamline the entire investigation lifecycle with an automatically generated, end-to-end case timeline that captures every action, artifact, and piece of evidence in one place, saving time and eliminating manual work.                                                                                         |
| Integrated asset context for investigations          | Provides richer investigation context by connecting asset data directly to cases and issues.                                                                                                                                                                                                                       |
| MSSP support for new cases experience                | Multi-tenant users can now leverage the new cases experience in parent and child tenants for improved efficiency and consistency.                                                                                                                                                                                  |
| Centralized issue resolution                         | Simplified issue-level remediation by centralizing all remediation actions in one place. From the Resolution tab, you can access recommended and pending actions, run playbooks, and complete manual playbook tasks, with seamless sync to the case's Resolution Center.                                           |
| Service Level Agreements (SLAs) for issue resolution | Reduce security risk and ensure accountability with SLAs for issue resolution. These SLAs ensure teams resolve critical issues within a consistent, predictable timeframe.                                                                                                                                         |
| Issue exceptions                                     | Formalize risk deferrals and align security alerts with operational constraints using issue exceptions. This feature allows you to "snooze" or exempt specific issues while maintaining oversight through documented justifications and an approval workflow.                                                      |
| Centralized Identity Security for domain controllers | Simplify your security management with the new Identity Profile to streamline the configuration and enforcement of identity security policies across Windows Domain Controllers. Monitor LDAP protection and Active Directory (AD) misconfiguration using the purpose-built unified hub. Requires the ITDR add-on. |
| Faster Unit42 service updates                        | Accelerate your response with Unit42. You can now update escalation contacts and authorize specific security actions directly within the platform. This streamlined process ensures the Unit42 managed services team can act on your behalf without manual delays.                                                 |

## Vulnerability Management

| FEATURE                                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ----------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Trace Vulnerabilities with Contextual Asset IDs | Streamline triage and remediation across complex environments, with the Contextual Asset ID column available in the Vulnerabilities and Packages table views. Eliminate ambiguity when inspecting top-level assets (such as VMs or Kubernetes nodes) by explicitly identifying the origin of a finding—whether it resides in the host OS or a nested workload like a specific Container Image or Instance. Click any Contextual Asset ID to jump directly to the detailed Vulnerabilities tab for that specific nested asset. |
| Support for CVSS V4                             | Cortex Vulnerability Management now offers support for Common Vulnerability Scoring System (CVSS) Version 4 framework. This update enhances vulnerability assessment by introducing higher granularity, reducing ambiguity between systems.                                                                                                                                                                                                                                                                                   |
| SBOM-Based vulnerability evaluation for CaaS    | We have extended our vulnerability management capabilities to include Container as a Service (Service) assets. Cortex XDR now performs automated vulnerability evaluations by analyzing Software Bill of Materials (SBOMs) associated with your CaaS workloads. This update ensures that your serverless container environments receive the same rigorous security scanning as your traditional infrastructure, providing a unified view of your risk posture.                                                                |

## XDR Collectors

**XDR Collectors 1.5.2:** Windows 1.5.2.2326 and Linux 1.5.2.2173

**XDR Collectors 1.4.3:** Windows 1.4.3.1686

| FEATURE                        | DESCRIPTION                                                   |
| ------------------------------ | ------------------------------------------------------------- |
| XDR Collectors 1.5.2 and 1.4.3 | This release includes performance improvements and bug fixes. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x/may-2026/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
