> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/february-2026/feature-enhancements.md).

# Feature Enhancements

These enhancements provide new and improved capabilities.

## General

| FEATURE                                              | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| ---------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New forwarding integrations for cases and issues     | Streamline issue and case management workflows by forwarding cases and issues to new destinations such as Splunk, Amazon SQS, Amazon S3, and Webhook, allowing you to manage investigations in external systems or meet strict data retention requirements.                                                                                                                                                                                                                                        |
| Compliance improvements                              | <ul><li><strong>Asset Card Compliance Tab</strong>: Gain a detailed understanding of an asset's alignment with security standards by using the new compliance tab, which displays an asset's overall compliance score and compliance against individual controls.</li><li><strong>Compliance Assessment CSV Report improvements</strong>: Compliance Assessment CSV reports now include more actionable data such as remediation guidance for failed rules, tags, and cloud account IDs.</li></ul> |
| Autodetect Palo Alto Networks VM-Series Firewalls    | Gain visibility and insights into your internet-exposed assets with automatic detection of VM-Series Firewalls deployed with AWS Gateway Load Balancers (GWLB) in isolated mode.                                                                                                                                                                                                                                                                                                                   |
| Service Level Agreements (SLAs) for issue resolution | Reduce security risk and ensure accountability with SLAs for issue resolution. These SLAs ensure teams resolve critical issues within a consistent, predictable timeframe.                                                                                                                                                                                                                                                                                                                         |
| Asset-level rule configuration                       | Support for asset-based rules allows Exclusion, Starring, Scoring, and Playbook rules to be configured for specific asset objects, enabling tailored automation and notifications per account or asset group.                                                                                                                                                                                                                                                                                      |

## Analytics rules

| FEATURE                                  | DESCRIPTION                                                                                                                                                                                                                    |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Process Anomaly Analytics                | Detect malicious processes by identifying abnormal behavior patterns in your Windows environment. We added a new analytics suite that monitors process history to expose hidden threats.                                       |
| Enhanced RDP Analytics                   | Protect your network from unauthorized access by automatically flagging unusual remote desktop (RDP) activity. We introduced new alerts that combine session data with behavior analysis to create actionable incidents.       |
| EDR Linux & macOS Abnormal Communication | Spot unusual data transmissions that often signal a security breach on Linux and macOS. We launched a detection suite that profiles network baselines to expose "Command and Control" behavior.                                |
| EDR macOS Generic Persistence            | Keep your endpoints clean by detecting the subtle methods hackers use to remain hidden after an initial breach. We expanded our coverage to identify new techniques used by infostealers and advanced threats.                 |
| Webshell Analytics                       | Protect both managed and unmanaged servers from unauthorized web-based control. We expanded our detection capabilities and integrated network protocol inspection to cover more server types.                                  |
| Linux Credential Grabbing                | Stop attackers from stealing sensitive configuration files and user credentials through brute-force or system abuse. We improved our behavioral analytics to highlight and block unauthorized attempts to access secret files. |

## Attack Surface Management

| FEATURE                               | DESCRIPTION                                                                                                                                                                                                                       |
| ------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Improved asset attribution evidence   | Validate asset ownership more quickly and easily with more detailed attribution evidence, including details about IP address and domain registration, domain redirects, ASN records, and assets attributed based on observations. |
| Identify your website vulnerabilities | Identify vulnerabilities associated with your websites with the new vulnerabilities tab in the asset details.                                                                                                                     |

## Broker VM

**Version 30.0.52 (reboot required)**

For more information on maintenance releases, see [Maintenance Releases](/cortex-xsiam-rn/cortex-xsiam-release-information/maintenance-releases.md).

| FEATURE             | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                          |
| ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New Broker VM image | <p>Experience improved security and system stability with our new Broker VM image. New Broker VM deployments now run on a modern operating system (Debian 13) to ensure long-term support. While currently available for new setups, we are finalizing a migration path for existing brokers in a future update.</p><p>This feature will be available in your tenant starting February 22, 2026.</p> |

## Cortex Agentic Assistant

| FEATURE                                                     | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                       |
| ----------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Native agent interoperability via MCP                       | Cortex Agentic Assistant now supports native interaction with external environments via the Model Context Protocol (MCP). Cortex AI Agents can seamlessly communicate with third-party MCP servers to discover available tools and automatically generate agentic actions, enabling you to automate more complex security tasks and accelerate incident response. |
| Increased transparency into agent execution                 | Gain visibility into your AI workflows by accessing the specific data generated when agents create objects or retrieve information. JSON artifacts are available directly in the agent’s plan view to provide technical context for results.                                                                                                                      |
| Manage your AI prompts in one place with the Prompt Library | Speed up your development process and ensure consistency by using a single library to manage all your AI prompts. You can now add these prompts directly to playbooks as AI tasks or register them as specific agent actions. To keep your workspace clean, the Prompt Library remains hidden unless Agentic Assistant is enabled in the server settings.         |
| Cortex Agentic Assistant new supported regions              | <p>The Cortex Agentic Assistant is currently available for tenants in the following regions:</p><ul><li>United States (US)</li><li>Europe (EU)</li><li>Canada (CA)</li><li>United Kingdom (UK)</li><li>South Korea (KR)</li><li>Singapore (SG)</li><li>Australia (AU)</li><li>Japan (JP)</li><li>India (IN)</li><li>Germany (DE)</li><li>France (FR)</li></ul>    |
| Automation Engineer Agent                                   | Accelerate script creation through an intuitive, conversational chat experience. Use natural language prompts to build and refine secure, high-quality Python scripts. The agent applies security best practices and uses the Agentix Automation SDK to ensure high-quality results.                                                                              |

## Cortex Query Language (XQL)

| FEATURE                      | DESCRIPTION                                                                                                                                                                                                                                                                            |
| ---------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Secure, personalized queries | Protect sensitive investigation data and ensure users only see their own query syntax and results, preventing unauthorized access to private data. We added a restriction setting for administrators to streamline the Query Center for non-admin users.                               |
| Clearer query accountability | Audit your searches accurately. Instantly see if a query was run by a person, a system, or an API key to speed up troubleshooting and security reviews. We standardized field labels and updated the "Issued by" field to clearly distinguish between who owns a query and who ran it. |
| Federated Search             | Seamlessly query across external datasets stored in AWS, GCP, or Azure. Search and analyze remote data directly from XSIAM using XQL - without ingesting it or incurring additional storage costs. To use Federated Search, please see our documentation.                              |

## CSPM

| FEATURE                        | DESCRIPTION                                                                                                                                                                                                                                                                            |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| XQL-based Cloud Security rules | Customize your cloud defenses with greater precision and speed using XQL-based Cloud Security rules. This enhancement provides a quick, easy-to-use flow for the most common Cloud Security rule use cases and an XQL free form editor for more flexible, advanced query capabilities. |

## Data Loss Prevention

| FEATURE                                      | DESCRIPTION                                                                                                                                                                                                                                                                                                                                      |
| -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| New Cortex Data Loss Prevention (DLP) module | Protect your sensitive data across all web and local channels, even when endpoints are offline. The Cortex Data Loss Prevention (DLP) module offers a unified and flexible solution to continuously safeguard your data to ensure your critical information remains secure and highlights Cortex's commitment to protecting your digital assets. |

## Endpoint

| FEATURE                                                     | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                |
| ----------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Secure Linux workloads with broader protection coverage     | Prevent malicious activity on more Linux systems without requiring kernel-level access. We expanded Child Process Protection to support User Mode, ensuring your workloads stay secure even when kernel modules aren't available. This update provides broader coverage and simpler deployment for diverse Linux environments.                                                                                             |
| Block cross-platform threats on Linux instantly             | Stop cross-platform threats the moment they land on your Linux systems. We expanded on-write protection to offer automatic scanning of ELF, PE, and Mach-O files. This prevents malicious binaries from being stored on your environment, regardless of their original operating system.                                                                                                                                   |
| Block malicious USB device attacks on macOS                 | Protect your macOS systems from unauthorized hardware attacks and malicious USB devices. We launched the Malicious Device Prevention module to identify and block tools like the "USB Rubber Ducky" that exploit device trust to inject unauthorized keystrokes and similar actions. This update reduces your physical attack surface and prevents hardware-based social engineering threats from compromising your data.  |
| Isolate compromised supervised iOS devices from the console | Stop potential threats from spreading by instantly cutting off network access for compromised supervised iOS devices with Network Shield enabled. You can now isolate supervised iPhones and iPads directly from the management console to block all unauthorized traffic. Your users will see clear notifications upon isolation activation, and on their lock and home screens while the device is in this secure state. |
| Amazon ECS EC2 agent installer                              | Expanded runtime protection for AWS ECS, EC2 workloads improves real-time defense against malware, exploits, and behavioral threats using the XDR agent to help teams stop attackers.                                                                                                                                                                                                                                      |
| Simplify endpoint tag management                            | Organize your environment more efficiently. Using APIs, you can now maintain the available tag list by permanently removing unused endpoint tags from your system.                                                                                                                                                                                                                                                         |

## Exposure Management

| FEATURE                                 | DESCRIPTION                                                                                                                                                                                                                               |
| --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Rescan vulnerable assets                | Rescan vulnerable assets from the issues and findings views, without configuring a new scan definition, with the Cortex Network Scanner. Efficiently assess remediation efforts or validate system changes, through the UI or public API. |
| Improved Cortex Network Scanner reports | Analyze and share your network scanner data with ease. Export the findings from a specific scan to a CSV file for offline reporting or external audits.                                                                                   |
| Rapid7 integration                      | Ingest discovered assets and vulnerabilities that have a CVE or Vendor Advisory ID with the Cortex Exposure Management Rapid7 VM integration.                                                                                             |

## External Data Ingestion and Management

| FEATURE                             | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Unified data onboarding experience  | <p>Save time and reduce complexity by managing all data sources and Marketplace integrations from a single, streamlined location. We renamed the <strong>Data Sources</strong> page to <strong>Data Sources & Integrations</strong> to eliminate the need for multiple portals when configuring content like correlation rules, dashboards, and playbooks. This unified workflow creates a more efficient experience for managing all your ingestion and automation needs.</p><p>This change merges the functional scope of existing permissions. Users, user groups, and API keys with <strong>View/Edit</strong> permissions for either <strong>Data Sources</strong> or <strong>Integrations</strong> now have full access to manage both on the unified page. Review your administrative assignments to ensure they align with this expanded access.</p> |
| Accurate Authentication Story logic | Improve your detection precision. Identify threats more accurately with refined logic that ensures only high-quality, fully contextualized data generates authentication stories. We updated the mandatory field requirements, including making the outcome reason field optional, to focus on the most relevant data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |

## Playbooks

| FEATURE                                       | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                     |
| --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Conflict-free playbook editing                | Prevent concurrent playbook editing to ensure your team can build and modify automation workflows without conflicts. The system now locks a playbook during edits and automatically releases the lock when you log out or your session expires. Additionally, a new permission allows designated users to manually unlock playbooks directly from the Playbooks page or editor. |
| Improved Playbooks and Scripts access control | Improve access control granularity for Playbooks and Scripts by enabling administrators to set Playbooks or Scripts permissions to **None** in certain scenarios.                                                                                                                                                                                                               |

## RBAC and SBAC permissions

| FEATURE                                                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| --------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Manage access to objects                                        | Enforce least privileged access by managing individual instances of dashboards. New, optional object-based permissions provide granular control over specific items. This unified **Objects** approach allows you to decide exactly who can view or edit each specific dashboard by sharing it with others as **Viewer** or **Editor**.                                                                                                                                                                                                                                                                                                                                                                   |
| Enhanced Asset SBAC logs                                        | Gain a more complete and transparent record of your environment configurations with expanded tracking. We updated Management Audit Logs to include all changes related to asset-led Scope-Based Access Control (SBAC).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| SBAC for cases and issues without inventory assets or endpoints | <p>Secure your data visibility with stricter default access for cases and issues without specific asset or endpoint references. You can now separately configure which users have access to issues and cases that lack an asset reference or where the referenced asset is not in All Assets and All Endpoints inventories. We added a new optional setting to ensure authorized users can still view all relevant data.</p><p><strong>Note</strong>: This change affects users who previously had visibility into these items by default. To restore access, administrators must manually enable the new setting in the user's role configuration. For detailed instructions, see Manage User Scope.</p> |
| Secure issue exclusion access                                   | Keep sensitive data private while managing Issues effectively. When defining user roles, you can now restrict access to the Issue Exclusions page, so only authorized users can view and manage Issue Exclusion rules, protecting the associated data.                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

## Vulnerability Management

| FEATURE                                             | DESCRIPTION                                                                                                                                                                                                                                                          |
| --------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Remediation guidance for clear issue resolution     | Fix vulnerabilities faster and eliminate guesswork with built-in remediation guidance. Slash research time and prevent manual errors during the remediation process, with specific, actionable steps directly within your issues and findings views.                 |
| Vulnerability Exposure Graph                        | Leverage the Vulnerability Exposure Graph to get a risk-based visualization of how a vulnerability is affecting a workload.                                                                                                                                          |
| Accelerate remediation with resolution actions      | Expedite issue resolution with Vulnerability Management resolution actions. Resolution actions are suggested quick actions, such as creating a ticket, deploying an XDR agent, or notifying users, that can be executed through the UI, AI, automation, or APIs.     |
| Enhancements to vulnerability findings              | Prioritize and remediate vulnerability findings faster and with greater confidence using additional details like remediation guidance, Cortex Vulnerability Risk Scores, and intelligence score sources. Vulnerability findings are also accessible via XQL queries. |
| Vendor advisory links in Vulnerability Intelligence | Speed up your threat response with quick access to in-depth technical details and direct links to vendor advisories within the Vulnerability Intelligence pages.                                                                                                     |

## XDR Collectors

**XDR Collectors 1.5.1:** Windows 1.5.1.2048 and Linux 1.5.1.1950

**XDR Collectors 1.4.3:** Windows 1.4.3.1686

| FEATURE                                            | DESCRIPTION                                                                                                                                                                                                                                                                    |
| -------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Enhanced visibility and auditing of XDR Collectors | Cortex XSIAM now provides enhanced error visibility and auditing for XDR Collectors. This enables you to quickly identify and resolve application, connectivity, and processing errors, simplifying troubleshooting and ensuring your critical workflows remain uninterrupted. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/february-2026/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
