> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/readme.md).

# Home

<h2 align="center">How can I help you today?</h2>

<p align="center"><button type="button" class="button secondary" data-action="ask" data-icon="gitbook-assistant">Search our docs the easy way...</button></p>

### **What's New**

<table data-view="cards"><thead><tr><th><select><option value="YRl6zdwrgKsI" label="What&#x27;s new" color="blue"></option><option value="1q6MW3lariYd" label="Release" color="blue"></option><option value="HWisrY2nLFnM" label="Tutorials" color="blue"></option></select></th><th></th><th></th><th></th><th data-hidden></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><span data-option="YRl6zdwrgKsI">What's new</span></td><td><p><strong>Cortex XDR</strong></p><h4>Dedicated Idira IdP threat detection</h4></td><td>Introduces 17 new, out-of-the-box detectors built specifically to monitor your Idira identity provider environment, instantly flagging credential manipulation and identity provider compromise. </td><td><a href="/spaces/cyIgISZgANJYkmLlnwdK/pages/jItyZ3CGoGXW48zsOMTJ"><strong>Read guide →</strong></a></td><td>/</td><td><a href="/files/PGJejYpIoftzISmWHXsE">/files/PGJejYpIoftzISmWHXsE</a></td></tr><tr><td><span data-option="YRl6zdwrgKsI">What's new</span></td><td><p><strong>Cortex XSIAM</strong></p><h4>Extended Threat Intel (XTI)</h4><p></p></td><td>Introducing XTI, a comprehensive threat intelligence offering that embeds adversary insights directly into SOC workflows through enriched case investigations and AI-driven behavioral analysis. </td><td><a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/RcpwiBUk7ndGnHWaFFSa#extended-threat-intelligence-overview"><strong>Read guide →</strong></a></td><td></td><td><a href="/files/ZtHRf95rhQM2q6q4wBBx">/files/ZtHRf95rhQM2q6q4wBBx</a></td></tr><tr><td><span data-option="YRl6zdwrgKsI">What's new</span></td><td><p><strong>Cortex Data Security</strong></p><h4>Data Security Command Center</h4></td><td>A central hub for understanding your organization's data security posture at a glance. It brings together data discovery, classification, posture, detection, and access governance into a single interactive view, helping you quickly see where your sensitive data lives, how it is protected, and what needs your attention next.</td><td><a href="/spaces/HfNuZNmWlqy9Bl7fETmL/pages/798I11YPT3o4iH4LO3AG"><strong>Read guide →</strong></a></td><td></td><td><a href="/files/Pk5Xz4AolV8Iy7aO7RR4">/files/Pk5Xz4AolV8Iy7aO7RR4</a></td></tr></tbody></table>

### **Explore products**

<table data-view="cards"><thead><tr><th>Product</th><th>Highlights</th><th>Guide</th></tr></thead><tbody><tr><td><h4><i class="fa-shield">:shield:</i> Cortex XSIAM</h4></td><td>→ Unified security operations<br>→ AI-driven threat prioritization<br>→ Automated response</td><td><a href="/spaces/XO7Budkunf9O78igMwUM"><strong>Read more →</strong></a></td></tr><tr><td><h4><i class="fa-shield-halved">:shield-halved:</i> Cortex XDR</h4></td><td>→ Correlated detection data<br>→ Incident investigations<br>→ Unified response</td><td><a href="/spaces/RATlGrcoSzIkoMIySpFR"><strong>Read more →</strong></a></td></tr><tr><td><h4><i class="fa-laptop">:laptop:</i> Cortex XDR Agent</h4></td><td>→ Endpoint protection<br>→ Threat prevention<br>→ Endpoint telemetry</td><td><a href="/spaces/YhAQu4OiCd3X2NZv62G3"><strong>Read more →</strong></a></td></tr><tr><td><h4><i class="fa-robot">:robot:</i> Cortex AgentiX</h4></td><td>→ AI security workflows<br>→ Analyst automation<br>→ Guided actions</td><td><a href="/spaces/nG6FTSH3MviWTK9yhAIg"><strong>Read more →</strong></a></td></tr><tr><td><h4><i class="fa-cloud">:cloud:</i> Cortex Cloud </h4></td><td>→ Runtime protection<br>→ Threat detection<br>→ Workload context<br>→ Configuration risk discovery<br>→ Exposure prioritization<br>→ Remediation tracking</td><td><a href="/spaces/3KStLIk7bIVZ1wH8UXES"><strong>Read more →</strong></a></td></tr><tr><td><h4><i class="fa-database">:database:</i> Cortex Data Security</h4></td><td>→ Sensitive data discovery<br>→ Data classification<br>→ Risk prioritization</td><td><a href="/spaces/HfNuZNmWlqy9Bl7fETmL"><strong>Read more →</strong></a></td></tr><tr><td><h4><i class="fa-code">:code:</i> Cortex Application Security</h4></td><td>→ Code-to-cloud visibility<br>→ Exploitability prioritization<br>→ Delivery workflow security</td><td><a href="/spaces/8Z0RLJ1BFF5TQL8VtUeK"><strong>Read more →</strong></a></td></tr><tr><td><h4><i class="fa-gears">:gears:</i> Cortex XSOAR</h4></td><td>→ Response playbooks<br>→ Tool orchestration<br>→ Incident management</td><td><a href="/spaces/62ZHoHZBxxG2zr3LS78a"><strong>Read more →</strong></a></td></tr><tr><td><h4><i class="fa-globe">:globe:</i> Cortex Xpanse</h4></td><td>→ Asset discovery<br>→ Exposure identification<br>→ Attack-surface remediation</td><td><a href="/spaces/1CKsHC5AGGixlT1wFfTW"><strong>Read more →</strong></a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/readme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
