> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/november-2025/feature-enhancements.md).

# Feature Enhancements

These enhancements provide new and improved capabilities across various XSIAM modules.

**General**

| Feature                           | Description                                                                                                                                                                                                                                                                                                       |
| --------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Expanded Asset Group scoping      | Scope-Based Access Control (SBAC) has been enhanced to provide more granular control over your access policies. You can now define Asset Groups that include the **Business Application Names** attribute for scoping definitions.                                                                                |
| New SBAC support for dataset rows | Security administrators can now define policies that grant Security Operations Center (SOC) teams access to only the relevant row data for their specific roles. This new granular scoping capability applies to product areas that reference dataset rows, such as XQL queries and custom widgets in dashboards. |

**API**

| Feature            | Description                                                                                                                                                                                                    |
| ------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| User and role APIs | These new APIs enable you to manage user roles, update API keys, and add or remove role and scope assignments for users, which gives greater flexibility to automate and scale your user management workflows. |

**Attack Surface Management**

| Feature                                                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| ----------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Attack Surface Testing Intrusiveness Levels                 | Safely test all your environments by adjusting the intensity of exposure checks.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Alerts for Attack Surface Testing misconfiguration findings | Attack Surface Testing will now generate issues for confirmed positive misconfiguration findings, enabling you to identify and secure your attack surface against these types of risks.                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Attack Surface Management dashboard                         | This new dashboard provides a visual overview of your attack surface and can be used for reporting or as the starting point for ASM workflows.                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Global Lookup improvements                                  | <p>The following improvements were introduced to provide more comprehensive and actionable insights from internet scan data beyond your own attack surface:</p><ul><li>View the services that have been open on a given IP address over the last 6 months.</li><li>Query certificate hashes (MD5, SHA1, and SHA256) in addition to IP addresses and domains.</li><li>Pivot to Global Lookup directly from IP addresses, domains, and certificates found in ASM or vulnerability issues.</li><li>View up to 30 days of data, and select up to a 30-day range to search at any point in the last 6 months.</li></ul> |
| Additional ASM enhancements                                 | <ul><li>You can now limit access to ASM data in Cortex XSIAM with role-based access control (RBAC).</li><li>A new Attribution Reason field indicates whether an ASM asset was discovered or provided.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                    |

**Automations**

| Feature                                                           | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ----------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Auto-populate command and Quick Action parameters                 | <p>On-demand enrichment from the Unified Asset Inventory (UAI) enables commands and Quick Actions to remain dynamic and adaptable. Any attribute in the UAI, not just those hardcoded into the issue schema, can be accessed when needed for automation execution. This improves flexibility and reduces the need for playbooks to retrieve relevant data.</p><p>This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that has the Cloud Posture Management or Cloud Runtime Security add-on.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Dismiss alerts for non-configured playbook components             | When setting up playbooks, you can now dismiss alerts for components you don't need, such as specific sub-playbooks, scripts, and commands. Alerts can be dismissed in both system and custom playbooks, and you do not need to edit or duplicate a system playbook to dismiss an alert. This enables you to reduce visual noise, making it easier to focus on tasks that require configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Recommended Quick Actions                                         | <p>Recommended Quick Actions enable you to receive contextual and diverse automation recommendations directly within issue response workflows. Recommendations accelerate issue response and drive automation adoption by guiding users to the most relevant and efficient actions.</p><p>This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that has the Cloud Posture Management or Cloud Runtime Security add-on.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Unique task logos                                                 | Boost clarity and quickly distinguish between integration commands, custom scripts, and system actions with playbooks that display unique logos and content pack indicators.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Streamlined playbook development with drag-and-drop functionality | Streamline your playbook development by using drag-and-drop to build automation flows. This enables you to create and organize your playbooks faster by simply dragging tasks from the side panel directly onto the canvas.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| AI Script Generator                                               | Generate high-quality Python scripts quickly and efficiently with the AI Script Generator. It's built-in testing panel lets you validate and refine the code generated from natural language, ensuring accuracy and significantly reducing the time spent on manual development.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Choose an integration instance for Quick Actions                  | When running a Quick Action on demand or as part of an automation rule, you can now select a specific integration instance to use, enabling a more efficient and targeted response.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Automation health issues                                          | New automation health issues help you quickly identify and resolve potential automation configuration issues, enabling you to maintain peak system performance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Automation Exclusion Center enhancements                          | <p>The automation exclusion center now allows for more dynamic and flexible policies:</p><ul><li>Hard user remediation and soft user remediation automation exclusion policies can now reference asset groups. User accounts are automatically categorized into asset groups, eliminating the need for manual list updates and ensuring that automation exclusion policies remain up-to-date.</li><li>Reference multiple lists and asset groups in the same policy, providing maximum flexibility.</li><li>New role permissions enable you to allow non-admin users the ability to view or edit policies in the Automation Exclusion Center. Admins can delegate policy management to non-admin users without granting full admin-level system access, giving admins more time to focus on other critical responsibilities.</li><li>Automation Exclusion policy overrides provide greater control and responsiveness. You can now permit policy overrides on specific automation exclusion policies, enabling analysts to run commands on critical assets as needed. You can also configure policies without overrides, providing a balance of security and operational flexibility.</li><li>With RBAC for lists, you can now define one or more roles that can view or edit a list, mitigating the risk of unauthorized or accidental changes to lists of critical assets.</li><li>New condition-based policies offer more versatility and precision for enforcing automation exclusions. You can now use lists with dynamic matching operators, such as starts with, ends with, and doesn’t include. Dynamic matching operators allow you to apply automation exclusion policies to entire naming patterns, such as regional endpoints or internal domains, simplifying management and improving coverage.</li></ul> |

**Broker VM**

**Version 29.0.71 (reboot required)**

For more information on maintenance releases, see [Maintenance releases](/cortex-xsiam-rn/cortex-xsiam-release-information/maintenance-releases.md)

| Feature                                                                                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| --------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced error visibility and auditing for additional Broker VM applets                       | Gain better insight into application, connectivity, and processing errors for the FTP Collector, Netflow Collector, Network Mapper, and Apache Kafka collector applets running on Broker VMs. Error messages are displayed on Apps of Broker VMs and Clusters, and applet status changes are logged in the `collection_auditing` dataset, enabling detailed investigations through XQL queries.                                                                                                                                                                                                                  |
| Broker VM support for Spain’s Esquema Nacional de Seguridad (ENS) National Security Framework | The Broker VM has been updated to comply with Spain’s Esquema Nacional de Seguridad (ENS) National Security Framework. You must enable the option **Only use recommended cipher suites** to meet the ENS regulation. This new setting is located in the **Advanced Settings** section, which you can access when configuring the Broker VM using its URL.                                                                                                                                                                                                                                                        |
| Enhanced Database Collector                                                                   | <p>The Database Collector applet now has a new <strong>Storage Method</strong> option, which offers more control over how the data is handled:</p><ul><li><strong>Append:</strong> This method adds new data to an existing dataset, as it worked previously by default.</li><li><strong>Replace:</strong> This new method is only available for Snapshot datasets and overwrites the entire dataset with the newly collected data. This is necessary when the data to be collected from the database is static data or reference data, such as a list of computers, IP addresses, or a list of users.</li></ul> |

**Cortex Query Language (XQL)**

| Feature                                      | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced XQL query monitoring and governance | <p>Introducing significant updates to XQL query management that deliver a more responsive, holistic, and powerful Query Center experience. Key enhancements:</p><ul><li><strong>Improved performance:</strong> Experience faster and more responsive page load and filtering times in the Query Center.</li><li><strong>Real-time tracking and management:</strong> Get full visibility into active queries across your tenant, with the power to instantly cancel running queries.</li><li><strong>Expanded query coverage:</strong> Monitor queries from all XQL query sources, including Dashboards with XQL widgets, Correlation rules, BIOC rules, and more.</li><li><strong>Administrator governance:</strong> Prevent resource strain and optimize tenant performance by setting query limits for all users.</li><li><strong>New default query limit:</strong> To prevent long-running queries and ensure optimal tenant performance, queries will automatically stop after 60 minutes. (This value can be overridden using the <code>max\_runtime\_minutes</code> command.)</li><li><strong>Updated query retention:</strong> Query retention is now aligned with issue retention.</li></ul> |
| Lookup datasets enhancement                  | Cortex XSIAM has implemented a fix to improve lookup dataset queries and provide better flexibility in managing your data. Now, when you create or add data to a lookup dataset using the `target` stage, the `_time` field won't be included by default unless you explicitly add it with the `fields` stage.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |

**Detection Rules**

| Feature                         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New and improved Analytics tags | <p>New analytics suites</p><ul><li>EDR Windows Disguised Processes: A novel analytics detection suite designed to detect Windows process masquerading techniques and their diverse sub-techniques, such as common process name impersonation and renaming of legitimate system utilities by attackers. The suite achieves this through its comprehensive analytic capabilities, featuring dynamic baselines and anomaly scoring.</li><li>EDR Linux Credential Grabbing: A behavior-based analytics detection suite to identify uncommon access to sensitive files that are frequently targeted for credential discovery. The suite monitors processes interacting with files such as SSH private keys, password and group files, shell history, and other configuration artifacts commonly used to store credentials. By analyzing access patterns across environments, the detector suite highlights rare or anomalous behavior, helping uncover otherwise unnoticed credential-harvesting activity.</li><li>EDR macOS Generic Persistence: An innovative analytics detection suite tailored to the macOS domain to detect unusual activities to secure a persistent foothold and execution in macOS endpoints. This suite highlights abused persistence mechanisms and supports the hunt for novel persistence techniques, commonly leveraged by macOS infostealers and APTs.</li><li>Microsoft Teams Analytics: An advanced analytics suite for detecting attack attempts within Microsoft Teams. The suite uncovers a broad range of different sub-techniques, such as phishing, malicious link sharing in chats, unauthorized policy modification, malicious application installation, and data collection. The suite uses dynamic baselines and anomaly scoring to provide comprehensive analytics, identifying abnormal user and communication patterns.</li></ul><p>Improved analytics tags:</p><ul><li>DLL Hijacking Analytics: We've expanded and improved our coverage for DLL Hijacking techniques. Using advanced analytic capabilities, we significantly enhanced detection logic for important threats, including Microsoft process hijacking and DLL sideloading.</li></ul> |

**Email Security**

| Feature                                     | Description                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New Advanced Email Security response engine | <p>A lightweight, real-time remediation engine enabling automated, policy-driven actions to quickly respond to email threats before they manifest. All remediation actions initiated by automatic policies are tracked in the Remediation Action Center, where you can review the emails and actions taken.</p><p>This feature requires an Email Security Module add-on.</p> |

**Endpoint Security**

| Feature                              | Description                                                                                                                                                                                                                                                  |
| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| File examination on-load for macOS   | Detect and prevent execution of malicious Mach-O files when loaded on macOS-based endpoints, using this new Cortex XDR agent capability.                                                                                                                     |
| JScript file examination for Windows | Detect and prevent malicious JScript files from being executed or written to disk on Windows-based endpoints, using this new capability provided by the Cortex XDR agent.                                                                                    |
| LDAP Query Protection for Windows    | Identify and block malicious reconnaissance activity targeting Windows Domain Controllers. Customers with the ITDR add-on can now use the XDR agent for real-time prevention against attack techniques used by tools like BloodHound's SharpHound collector. |
| Child Process Protection for Linux   | Cortex XDR introduces an additional prevention module for Linux that examines the relations between parent and child processes to detect suspicious relations. This module provides improved detection and protection coverage capabilities.                 |
| XDR Agent for Windows on ARM64       | Extend agent deployments to Windows devices running on ARM64 architecture, including Microsoft Surface devices.                                                                                                                                              |

**Exposure Management**

| Feature                                | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| -------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Cortex XDR Security Controls Detection | Gain enhanced visibility into XDR agent profile configurations and exploit protection status, improving vulnerability risk identification, protection efficacy assessment, and prioritization.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Cortex Network Scanner enhancements    | <p>The following enhancements were introduced:</p><ul><li><strong>Target Groups management:</strong> Configure network scans more efficiently and consistently by leveraging saved and reused Target Groups.</li><li><strong>Multi-scanner support:</strong> Reduce the amount of time it takes to complete large network scans by assigning multiple scanners to the task.</li><li><strong>Multiple credentials:</strong> You can now configure multiple credentials of the same type for each scan. The scanner will try each one until authentication is successful.</li><li><strong>Credential testing:</strong> Test credentials stored in the system before starting a large scan and identify gaps in the authentication.</li></ul> |

**External Data Ingestion and Management**

| Feature                                 | Description                                                                                                                                                                                                              |
| --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Unified integration error notifications | Instead of being inundated with multiple notifications, all data collector errors are now grouped into a single notification. This new, non-dismissible notification alerts all users to data source integration errors. |

**Vulnerability Management**

| Feature                                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| --------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cortex Vulnerability Block Grace Period | Enhancements to Cortex Vulnerability Management allow you to establish a block grace period when creating prevention policies. Grace periods are based on a fixed date and temporarily override the blocking action of a policy when new vulnerabilities are found. You can configure a uniform grace period for all severities or provide different settings for each severity. When grace periods are configured, findings trigger as normal, notifying you that a vulnerability exists in your environment. The block action is suppressed for the number of days specified, giving you time to mitigate the vulnerability.                                 |
| Cortex Vulnerability Risk Score         | The Cortex Vulnerability Risk Score (CVRS) is a dynamic vulnerability risk-scoring approach that helps you prioritize vulnerabilities. CVRS uses critical organization-specific information along with public vulnerability intelligence to provide a tailored, accurate risk score for each vulnerability alert and finding.                                                                                                                                                                                                                                                                                                                                  |
| Vulnerability Management Enhancements   | <p>Updates to the Vulnerability Management UI help you contextualize risk and prioritize remediations. The following enhancements are included:</p><ul><li>The side-panel now includes actionable insights such as Issue Details, Recommended Actions, and Remediations to help you quickly triage and resolve issues.</li><li>Right-click on any issue to take quick actions and generate a CSV export if required.</li><li>You can access the Vulnerabilities tab on any Kubernetes worker or master node to view the max severity associated with the node, the top three nodes by severity, plus a graphical view of vulnerabilities by severity</li></ul> |

**XDR Collectors**

**XDR Collectors 1.5.1:** Windows 1.5.1.2048 and Linux 1.5.1.1950

**XDR Collectors 1.4.3:** Windows 1.4.3.1686

For more information on maintenance releases, see [Maintenance releases](/cortex-xsiam-rn/cortex-xsiam-release-information/maintenance-releases.md)

| Feature                                            | Description                                                                                                                                                                                                                                                                    |
| -------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Enhanced visibility and auditing of XDR Collectors | Cortex XSIAM now provides enhanced error visibility and auditing for XDR Collectors. This enables you to quickly identify and resolve application, connectivity, and processing errors, simplifying troubleshooting and ensuring your critical workflows remain uninterrupted. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2025-xsiam/november-2025/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
