> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/may-2026/feature-enhancements.md).

# Feature Enhancements

These enhancements provide new and improved capabilities.

## General

| FEATURE                                               | DESCRIPTION                                                                                                                                                                                                                                                                                                                                         | LICENSE/ADD-ON |
| ----------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------- |
| Administrator control for saved views and filters     | Keep your workspace clean and relevant. Administrators can now remove unused or outdated saved views and filters, including those created by other users.                                                                                                                                                                                           | All licenses   |
| Enhanced notification forwarding                      | To help you prioritize and resolve security issues more effectively, issue notifications sent to Amazon S3, Amazon SQS, Webhook, Splunk, and email now provide additional asset and remediation information. Notification fields have been expanded to include the asset name, cloud resource name, asset tags, account name, region, and evidence. | All licenses   |
| Import method selection for Bring Your Own Key (BYOK) | You can now select the method for importing your own encryption keys, providing greater data sovereignty and control. This update simplifies key management while ensuring strict adherence to internal and regulatory compliance requirements.                                                                                                     | All licenses   |

## Access Management

| FEATURE                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                      | LICENSE/ADD-ON |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------- |
| Expanding SBAC with Account Name | Scope-Based Access Control (SBAC) has been enhanced to provide more granular control over your access policies. You can now define Asset Groups that include the **Account Name** attribute for scope-based access control. Continue to use the existing **Realm** attribute whenever you need to scope based on the Account ID. | All licenses   |

## Advanced Email Security

| FEATURE                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                                            | LICENSE/ADD-ON                 |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------ |
| Malicious emails inventory         | Streamline email threat triage with a purpose-built view for malicious email analysis. Quickly understand why emails were flagged and perform preliminary remediation actions before launching a full investigation.                                                                                                                                   | Advanced Email Security add-on |
| Remediation quick actions          | Accelerate email threat response with single-click remediation actions from the email investigation view.                                                                                                                                                                                                                                              | Advanced Email Security add-on |
| New Email Security agent           | Leverage the power of AI to analyze user-reported phishing and suspicious emails, understand why messages were flagged, and determine the appropriate next steps for triage, investigation, or remediation.                                                                                                                                            | Advanced Email Security add-on |
| New mailbox inventory              | <ul><li>Gain centralized visibility into your email security posture with a new dedicated inventory for email security assets within the Unified Asset Inventory (UAI).</li><li>Unlock deeper insights in the Email Command Center with the new mailbox metrics that provide a detailed breakdown of mailbox types and email directionality.</li></ul> | Advanced Email Security add-on |
| Detailed WildFire analysis reports | Access full, granular WildFire reports directly from the email causality card to gain deeper visibility into the behavior of suspicious email attachments, refine maliciousness assessments, and accelerate decision-making.                                                                                                                           | Advanced Email Security add-on |
| Sharpened investigation accuracy   | We’ve enhanced the accuracy of phishing detection by cross-referencing user-reported audit events directly with emails located in the M365 phishing mailbox.                                                                                                                                                                                           | Advanced Email Security add-on |

## Analytics Rules

| FEATURE                                        | DESCRIPTION                                                                                                                                                                                                                                                                                                                       | LICENSE/ADD-ON |
| ---------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------- |
| Scheduled Tasks Analytics                      | This new suite identifies malicious persistence by tracking the installation and execution of scheduled tasks, providing deep context and generating high-fidelity alerts.                                                                                                                                                        | All licenses   |
| NDR Insights Analytics                         | Our new network detection suite automatically correlates between low-fidelity network signals and existing alerts, transforming them into high-confidence security incidents.                                                                                                                                                     | All licenses   |
| Active Directory Federation Services Analytics | This new suite identifies suspicious and irregular behavior within your Active Directory Federation Services.                                                                                                                                                                                                                     | All licenses   |
| Google Workspace Analytics                     | This advanced suite detects attack attempts within Google Workspace, including through brute force, phishing, account manipulation, unauthorized policy modification, suspicious browser extension installations, credentials harvesting, and data collection.                                                                    | All licenses   |
| Linux Discovery Analytics                      | This novel suite, tailored to the Linux domain, identifies reconnaissance and host environment mapping activities. The suite detects adversaries and malicious scripts seeking to gather system-level intelligence, discover user credentials, and uncover pathways for lateral movement during the discovery phase of an attack. | All licenses   |
| Kubernetes Credentials Analytics               | This detection suite analyzes Kubernetes activity to identify credential harvesting techniques, including host file access from containers, kubelet credential file retrieval, and kubelet impersonation.                                                                                                                         | All licenses   |

## API

| FEATURE                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | LICENSE/ADD-ON                                                                  |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| Application Security Policy API | The Application Security Policy API (GET and POST /public\_api/appsec/v1/policies) now includes expanded support for scanning across the pre-runtime (code, build, and deploy) lifecycles. This API enhancement enables you to define a single policy that covers multiple stages. The **triggers** field adds **ciImage** for CI pipeline image scans and **imageRegistry** for registry image scans. A new **blockCiImage** action enables you to block CI pipelines when image findings match policy conditions. The **findingTypes** field now uses a unified set of values: CICD\_RISKS, VULNERABILITY, SECRETS, IAC\_MISCONFIGURATION, CODE\_WEAKNESS, LICENSES, OPERATIONAL\_RISK, MALWARE, and DRIFT. An optional userSbac field has been added to the POST method for scoped access control during policy creation. | Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license |
| Billing Contributors API        | A new public API endpoint is introduced to retrieve a list of unique active contributors factored into your billing. This allows you to gain full transparency into your billable seats.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license |

## Asset Inventory

| FEATURE                                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | LICENSE/ADD-ON                                                                  |
| ------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| Drift detection highlight in Container Instances | Container Instances asset cards in Asset Inventory now include a Security Drift Detected highlight and a dedicated Security Drift tab, making it easy to identify containers that have deviated from their base image. These drifts expose vulnerabilities, misconfigurations, compliance violations, and other security risks introduced at runtime that were not part of the base image.                                                                                                                                                                                                        | Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license |
| Base Image Visibility for Container Images       | You can now identify the base image for any Build, Registry, or Runtime container image directly from its asset details page. With the **new has base reference** and **is base reference for** relationships in Security Graph, you can trace image lineage and assess vulnerability impact in a single query. Define custom Base Image Rules to mark foundational Registry Images, create targeted asset groups and policies, and quickly determine whether vulnerabilities originate from a base image layer. This streamlines your security investigations and accelerates incident response. | Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license |
| Consolidated CaaS resource visibility            | Improve security oversight and simplify asset management by viewing CaaS (Containers as a Service) resources within a dedicated section of the Asset Inventory. This update organizes resources from Amazon ECS, Google Cloud Run, and Azure Container Instances into a single, purpose-built view under Compute assets, making it easier to locate, monitor, and assess the security posture of your cross-cloud CaaS deployments.                                                                                                                                                               | Cloud Posture Security, Cloud Runtine Security, or Cortex XSIAM Premium license |

## Automation

| FEATURE                                            | DESCRIPTION                                                                                                                                                                                                                | LICENSE/ADD-ON |
| -------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------- |
| Performance improvements for scripts and playbooks | Enhance the user experience when managing security workflows with modernized interface improvements and optimized memory usage across the Scripts and Playbooks pages to maintain a seamless and cohesive user experience. | All licenses   |

## Broker VM

**Version 31.0.57 (reboot required)**

For more information on maintenance releases, see [Maintenance Releases](/cortex-xsiam-rn/cortex-xsiam-release-information/maintenance-releases.md).

| FEATURE                                | DESCRIPTION                                                                                                                                                                                                                                                                                                               | LICENSE/ADD-ON |
| -------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------- |
| Legacy server connectivity             | You can now easily configure OpenSSL compatibility settings directly from the Broker VM web interface to ensure uninterrupted communication with legacy servers. We added **Advanced Settings** options to allow legacy SSL renegotiation and accept certificates without an Authority Key Identifier (AKID).             | All licenses   |
| Import Configuration tool enhancements | <p>The <strong>Import Configuration</strong> tool has been enhanced to streamline the Broker VM migration process to the new Broker VM image. You can now migrate your current Broker VMs to the new Debian 13 based image.</p><p>Both source and target brokers should be running the latest Broker VM 31.x version.</p> | All licenses   |

## Cortex Agentic Assistant

| FEATURE                                           | DESCRIPTION                                                                                                                                                                                                     | LICENSE/ADD-ON |
| ------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------- |
| Chat with the Agentic Assistant directly in Slack | Access Agentic Assistant more easily across your daily applications. You can now trigger the Agentic Assistant from your Slack, give it tasks, interact with it and get the results on your existing workspace. | All licenses   |
| Enhanced AI product support                       | The upgraded Help Center agent delivers instant how-to support and helps you navigate in-product support cases. It stays aware of your support issues to provide more relevant guidance in context.             | All licenses   |

## Cortex Query Language (XQL)

| FEATURE                                       | DESCRIPTION                                                                                                                                                                                                                                                                                                                   | LICENSE/ADD-ON |
| --------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------- |
| New XQL mathematical and analytical functions | The new mathematical and analytical functions in XQL provide analysts with richer query capabilities for advanced threat hunting and data analysis.                                                                                                                                                                           | All Licenses   |
| XQL workflow enhancements                     | <ul><li>The Query Builder now automatically caches your active code and results within a session to prevent data loss during navigation or refreshes.</li><li>Your preferred timeframe and table layout settings now persist across logins, ensuring a consistent and personalized workspace every time you return.</li></ul> | All Licenses   |

## Endpoint Security

| FEATURE                                                   | DESCRIPTION                                                                                                                                                                                                                                                                                                        | LICENSE/ADD-ON                               |
| --------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------- |
| Container as a Service (CaaS) support for AWS ECS Fargate | Embed the XDR Agent within the container image for CaaS workloads and get real-time monitoring and protection against active threats.                                                                                                                                                                              | Cortex XSIAM Premium and Enterprise licenses |
| Advanced prevention for macOS                             | New macOS kernel behavioural monitoring identifies and neutralizes privilege escalation attempts in near-real-time.                                                                                                                                                                                                | Cortex XSIAM Premium and Enterprise licenses |
| Shared objects file examination                           | Secure your Linux environment against hidden threats. You can now automatically block malicious code from executing through non-standard loading methods. We updated the Cortex XDR agent to examine and stop harmful shared object files before they impact your system.                                          | Cortex XSIAM Premium and Enterprise licenses |
| On-write malicious file detection                         | Stop cross-platform threats from entering your network. You can now detect malicious mach-o files and non-native macOS binaries (such as Windows PEs and Linux ELFs) the moment they are saved to your system. We updated the Cortex XDR agent to provide comprehensive on-write detection for these binary types. | Cortex XSIAM Premium and Enterprise licenses |
| Advanced Java malware protection                          | Prevent cyberattacks from compromising your applications. You can now automatically detect and block malicious Java-based threats the moment they appear or are saved to your system. We added real-time on-write protection for all Java files.                                                                   | Cortex XSIAM Premium and Enterprise licenses |

## Exposure Management

| FEATURE                                             | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                             | LICENSE/ADD-ON             |
| --------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------- |
| Vulnerability & Exposure Management: unified module | <p>Streamline risk assessment and remediation with a consolidated workspace designed to minimize time-to-action.<br>We combined these tools into one navigation structure to eliminate context switching and speed up remediation. You can now use quick links for high-priority triage and pivot instantly between Findings and Issues to resolve threats faster.</p>                  | Exposure Management add-on |
| `Refine your risk accuracy`                         | Focus your resources on real threats by eliminating inaccurate and inflated risk scores. You can now recalibrate calculations to reflect your true security posture by accounting for custom or third-party security controls—such as Network or Web Application Firewalls. We added features to define control effectiveness and automate risk labeling across your cloud environment. | Exposure Management add-on |
| Vulnerability ingest API                            | You can now bring your own scanner to the table. Ingest vulnerabilities and related assets from third-party tools directly into your asset inventory and vulnerability management workflows.                                                                                                                                                                                            | Exposure Management add-on |
| Tenable.sc vulnerability ingest                     | Streamline your workflow and reduce the need to switch between tools by ingesting assets and vulnerabilities from Tenable.sc directly into Cortex Exposure Management.                                                                                                                                                                                                                  | Exposure Management add-on |

## Exposure Management: Network Scanner

| FEATURE                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                            | LICENSE/ADD-ON             |
| ---------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------- |
| Streamline network scans           | Optimize your security workflows by reusing existing organizational data. You can now select previously saved Asset Groups as targets when creating new scans, eliminating the need to redefine external groups manually.                                                                                                                                                                                                              | Exposure Management add-on |
| Automate cloud compliance auditing | Secure your cloud environment by automatically verifying that your assets meet industry standards like CIS Benchmarks for Windows 11 and Windows Server 2022. You can now run **Compliance Policy Audit** scans to instantly identify misconfigurations or weak security controls across your Asset Groups. We added this dedicated scan type to help you maintain continuous governance and simplify your routine audit preparations. | Exposure Management add-on |
| Deepen device scan visibility      | Cortex Network Scanner now supports authenticated scans over Simple Network Management Protocol (SNMP). You can now use SNMP credentials to authenticate various services on a target device. Add SNMP v2 or v3 credentials to authenticate configured services.                                                                                                                                                                       | Exposure Management add-on |
| Easily access Network Scanner      | Cortex UI enhancements allow you to easily access the Network Scanner functionality as part of the unified Vulnerability and Exposure Management module. Scanner functionality has migrated from and Settings->Configurations to Modules->Vulnerability & Exposure Management.                                                                                                                                                         | Exposure Management add-on |

## External Data Ingestion and Management

| FEATURE                                    | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                              | LICENSE/ADD-ON |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------- |
| Simplify ingestion tier configuration      | Optimize your ingestion costs with less effort. We simplified how you configure datasets to use the Cortex Data Lake tier. You can now easily route your data to the appropriate ingestion tier by right-clicking a Parsing Rule and selecting **Change Tier to Data lake**.                                                                                                                                             | All licenses   |
| Enhanced Cribl integration performance     | Support high-volume data streams with enterprise-grade stability and simplified setup. You can now use Cribl’s own operational pack to automate configuration, replacing the need for manual technical identifiers. We also added support for compressed data to improve efficiency and enabled seamless streaming of Windows event logs from Cribl Edge or WEC directly into XSIAM analytics.                           | All licenses   |
| New Cloud NGFW data source                 | Gain complete visibility into your cloud-native network security with the new **CNGFW** (Cloud NGFW) data source. You can now stream traffic and application logs directly to Cortex XSIAM with support to cross-region and cross-account connections. We introduced this distinct connector to handle unique cloud-native identifiers, ensuring seamless log ingestion and analysis for your managed security services. | All licenses   |
| Near-real-time Salesforce event collection | Improve threat detection accuracy and eliminate duplicate alerts. You can now collect Salesforce events in near-real-time rather than relying on hourly or daily log files. We added support for near-real-time event streaming to the Salesforce data source integration to ensure you capture critical multi-event alerts without delay.                                                                               | All licenses   |

## Graph Search

| FEATURE                          | DESCRIPTION                                                                                                                                                                                                                                                                                                          | LICENSE/ADD-ON                                                                  |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| SBAC enforcement in Graph Search | Safely explore your environment in Graph Search with precise permission management. We introduced Scope-Based Access Control (SBAC) to give you granular control over user scope. You can now assign users to **User Groups** and **Asset Groups**, ensuring they only see authorized graph nodes and relationships. | Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license |

## Investigation and Response

| FEATURE                                              | DESCRIPTION                                                                                                                                                                                                                                                              | LICENSE/ADD-ON |
| ---------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------- |
| Centralized issue resolution                         | Simplified issue-level remediation by centralizing all remediation actions in one place. From the Resolution tab, you can access recommended and pending actions, run playbooks, and complete manual playbook tasks, with seamless sync to the case's Resolution Center. | All licenses   |
| Service Level Agreements (SLAs) for issue resolution | Reduce security risk and ensure accountability with SLAs for issue resolution. These SLAs ensure teams resolve critical issues within a consistent, predictable timeframe.                                                                                               | All licenses   |
| MSSP support for new cases experience                | Multi-tenant users can now leverage the new cases experience in parent and child tenants for improved efficiency and consistency.                                                                                                                                        | All licenses   |
| Issue exceptions                                     | Formalize risk deferrals and align security alerts with operational constraints using issue exceptions. This feature allows you to "snooze" or exempt specific issues while maintaining oversight through documented justifications and an approval workflow.            | All licenses   |
| Integrated asset context for investigations          | Provides richer investigation context by connecting asset data directly to cases and issues.                                                                                                                                                                             | All licenses   |

## Vulnerability Management

| FEATURE                                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                          | LICENSE/ADD-ON                                                                  |
| ----------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| Trace vulnerabilities with Contextual Asset IDs | <p>Streamline triage and remediation across complex environments, with the Contextual Asset ID column available in the Vulnerabilities and Packages table views.<br>Eliminate ambiguity when inspecting top-level assets (such as VMs or Kubernetes nodes) by explicitly identifying the origin of a finding—whether it resides in the host OS or a nested workload like a specific Container Image or Instance.</p> | Cloud Posture Security, Cloud Runtine Security, or Cortex XSIAM Premium license |
| Support for CVSS V4                             | Cortex Vulnerability Management now offers support for Common Vulnerability Scoring System (CVSS) Version 4 framework. This update enhances vulnerability assessment by introducing higher granularity, reducing ambiguity between systems.                                                                                                                                                                          | Cloud Posture Security, Cloud Runtine Security, or Cortex XSIAM Premium license |
| SBOM-Based vulnerability evaluation for CaaS    | We have extended our vulnerability management capabilities to include Container as a Service (Service) assets. Cortex XSIAM now performs automated vulnerability evaluations by analyzing Software Bill of Materials (SBOMs) associated with your CaaS workloads. This update provides a unified view of your risk posture, by rigorously scanning your ensures serverless container environments.                   | Cloud Posture Security, Cloud Runtine Security, or Cortex XSIAM Premium license |

## XDR Collectors

**XDR Collectors 1.5.2:** Windows 1.5.2.2326 and Linux 1.5.2.2173

**XDR Collectors 1.4.3:** Windows 1.4.3.1686

| FEATURE                        | DESCRIPTION                                                   | LICENSE/ADD-ON |
| ------------------------------ | ------------------------------------------------------------- | -------------- |
| XDR Collectors 1.5.2 and 1.4.3 | This release includes performance improvements and bug fixes. | All licenses   |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam/may-2026/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
