# Table of Contents
- [Home | Cortex Documentation Portal](#home-cortex-documentation-portal)
- [Cortex Xpanse Expander | Cortex Documentation Portal](#cortex-xpanse-expander-cortex-documentation-portal)
- [Cortex Data Security | Cortex Documentation Portal](#cortex-data-security-cortex-documentation-portal)
- [Cortex XDR Agent | Cortex Documentation Portal](#cortex-xdr-agent-cortex-documentation-portal)
- [Cortex XSIAM Documentation | Cortex Documentation Portal](#cortex-xsiam-documentation-cortex-documentation-portal)
- [Cortex XDR Documentation | Cortex Documentation Portal](#cortex-xdr-documentation-cortex-documentation-portal)
- [Cortex XSOAR Documentation | Cortex Documentation Portal](#cortex-xsoar-documentation-cortex-documentation-portal)
- [Cortex Cloud Documentation | Cortex Documentation Portal](#cortex-cloud-documentation-cortex-documentation-portal)
- [Unknown](#unknown)
- [Cortex AgentiX | Cortex Documentation Portal](#cortex-agentix-cortex-documentation-portal)
- [Unknown](#unknown)
- [Unknown](#unknown)
- [Unknown](#unknown)
- [Unknown](#unknown)
- [Unknown](#unknown)
- [Unknown](#unknown)
- [Cortex Gateway Admin Guide | Cortex Documentation Portal](#cortex-gateway-admin-guide-cortex-documentation-portal)
- [What's New | Cortex Documentation Portal](#what-s-new-cortex-documentation-portal)
- [Release Notes | Cortex Documentation Portal](#release-notes-cortex-documentation-portal)
- [Cortex AgentiX Documentation | Cortex Documentation Portal](#cortex-agentix-documentation-cortex-documentation-portal)
- [API Reference Guide | Cortex Documentation Portal](#api-reference-guide-cortex-documentation-portal)
- [Cortex XQL Schema Reference Guide | Cortex Documentation Portal](#cortex-xql-schema-reference-guide-cortex-documentation-portal)
- [Release 2.14 (July 2026) | Cortex Documentation Portal](#release-2-14-july-2026-cortex-documentation-portal)
- [Cortex XSOAR 6 FAQs | Cortex Documentation Portal](#cortex-xsoar-6-faqs-cortex-documentation-portal)
- [Cortex Xpanse Expander Release Information | Cortex Documentation Portal](#cortex-xpanse-expander-release-information-cortex-documentation-portal)
- [FS-ISAC STIX/TAXII Guide for Cortex XSOAR | Cortex Documentation Portal](#fs-isac-stix-taxii-guide-for-cortex-xsoar-cortex-documentation-portal)
- [Cortex XSOAR On-prem OSS listings | Cortex Documentation Portal](#cortex-xsoar-on-prem-oss-listings-cortex-documentation-portal)
- [Cortex XSOAR 8 FAQs | Cortex Documentation Portal](#cortex-xsoar-8-faqs-cortex-documentation-portal)
- [Cortex XDR OSS Listings | Cortex Documentation Portal](#cortex-xdr-oss-listings-cortex-documentation-portal)
- [Hosted Service Overview | Cortex Documentation Portal](#hosted-service-overview-cortex-documentation-portal)
- [About the Cortex Gateway | Cortex Documentation Portal](#about-the-cortex-gateway-cortex-documentation-portal)
- [Introduction to Demisto SDK | Cortex Documentation Portal](#introduction-to-demisto-sdk-cortex-documentation-portal)
- [Cortex XSIAM Release Information | Cortex Documentation Portal](#cortex-xsiam-release-information-cortex-documentation-portal)
- [Tutorials | Cortex Documentation Portal](#tutorials-cortex-documentation-portal)
- [Cortex XSOAR Platform Overview | Cortex Documentation Portal](#cortex-xsoar-platform-overview-cortex-documentation-portal)
- [Cortex XSOAR Release Information | Cortex Documentation Portal](#cortex-xsoar-release-information-cortex-documentation-portal)
- [Cortex XSOAR Installation Guides | Cortex Documentation Portal](#cortex-xsoar-installation-guides-cortex-documentation-portal)
- [How policies and rules work together | Cortex Documentation Portal](#how-policies-and-rules-work-together-cortex-documentation-portal)
- [Kubernetes Resources Inventory | Cortex Documentation Portal](#kubernetes-resources-inventory-cortex-documentation-portal)
- [Cortex XSOAR 6 Threat Intel Management Guides | Cortex Documentation Portal](#cortex-xsoar-6-threat-intel-management-guides-cortex-documentation-portal)
- [Where can I install the Cortex XDR agent? | Cortex Documentation Portal](#where-can-i-install-the-cortex-xdr-agent-cortex-documentation-portal)
- [Cortex XSOAR 8 Feature Changes | Cortex Documentation Portal](#cortex-xsoar-8-feature-changes-cortex-documentation-portal)
- [Cortex XSOAR 6 Multi-Tenant Guides | Cortex Documentation Portal](#cortex-xsoar-6-multi-tenant-guides-cortex-documentation-portal)
- [Security finding categories | Cortex Documentation Portal](#security-finding-categories-cortex-documentation-portal)
- [Agentless Kubernetes security | Cortex Documentation Portal](#agentless-kubernetes-security-cortex-documentation-portal)
- [Cortex XSOAR 6 Administrator Guides | Cortex Documentation Portal](#cortex-xsoar-6-administrator-guides-cortex-documentation-portal)
- [KSPM dashboard | Cortex Documentation Portal](#kspm-dashboard-cortex-documentation-portal)
- [Retention Policy and Enforcement | Cortex Documentation Portal](#retention-policy-and-enforcement-cortex-documentation-portal)
- [KSPM graph | Cortex Documentation Portal](#kspm-graph-cortex-documentation-portal)
- [Manage Kubernetes Connector instances | Cortex Documentation Portal](#manage-kubernetes-connector-instances-cortex-documentation-portal)
- [What's New in Cortex XDR 5 | Cortex Documentation Portal](#what-s-new-in-cortex-xdr-5-cortex-documentation-portal)
- [Kubernetes Security | Cortex Documentation Portal](#kubernetes-security-cortex-documentation-portal)
- [Asset detail card | Cortex Documentation Portal](#asset-detail-card-cortex-documentation-portal)
- [Mirror connector images to a private registry | Cortex Documentation Portal](#mirror-connector-images-to-a-private-registry-cortex-documentation-portal)
- [Release Information | Cortex Documentation Portal](#release-information-cortex-documentation-portal)
- [Learn about Cortex Xpanse | Cortex Documentation Portal](#learn-about-cortex-xpanse-cortex-documentation-portal)
- [Types of cloud workload policies | Cortex Documentation Portal](#types-of-cloud-workload-policies-cortex-documentation-portal)
- [Kubernetes clusters | Cortex Documentation Portal](#kubernetes-clusters-cortex-documentation-portal)
- [Default (pre-defined) rules | Cortex Documentation Portal](#default-pre-defined-rules-cortex-documentation-portal)
- [Playbooks | Cortex Documentation Portal](#playbooks-cortex-documentation-portal)
- [Cloud workload rules | Cortex Documentation Portal](#cloud-workload-rules-cortex-documentation-portal)
- [Edit a custom detection rule | Cortex Documentation Portal](#edit-a-custom-detection-rule-cortex-documentation-portal)
- [Widgets panel | Cortex Documentation Portal](#widgets-panel-cortex-documentation-portal)
- [Change the layout of the policies table | Cortex Documentation Portal](#change-the-layout-of-the-policies-table-cortex-documentation-portal)
- [Use an existing rule to create a new custom detection rule | Cortex Documentation Portal](#use-an-existing-rule-to-create-a-new-custom-detection-rule-cortex-documentation-portal)
- [Delete a custom detection rule | Cortex Documentation Portal](#delete-a-custom-detection-rule-cortex-documentation-portal)
- [Cloud workload policies | Cortex Documentation Portal](#cloud-workload-policies-cortex-documentation-portal)
- [Deploy the Kubernetes Connector via GitOps | Cortex Documentation Portal](#deploy-the-kubernetes-connector-via-gitops-cortex-documentation-portal)
- [Cortex XSOAR 8 On-prem Documentation | Cortex Documentation Portal](#cortex-xsoar-8-on-prem-documentation-cortex-documentation-portal)
- [Release Information | Cortex Documentation Portal](#release-information-cortex-documentation-portal)
- [Cortex XDR Agent Documentation | Cortex Documentation Portal](#cortex-xdr-agent-documentation-cortex-documentation-portal)
- [Policy details panel | Cortex Documentation Portal](#policy-details-panel-cortex-documentation-portal)
- [Custom (user-defined) rules | Cortex Documentation Portal](#custom-user-defined-rules-cortex-documentation-portal)
- [Cortex XDR Agent iOS Guides | Cortex Documentation Portal](#cortex-xdr-agent-ios-guides-cortex-documentation-portal)
- [Kubernetes pods | Cortex Documentation Portal](#kubernetes-pods-cortex-documentation-portal)
- [Rule details panel | Cortex Documentation Portal](#rule-details-panel-cortex-documentation-portal)
- [Cloud workload policies and rules | Cortex Documentation Portal](#cloud-workload-policies-and-rules-cortex-documentation-portal)
- [Deploy with ArgoCD | Cortex Documentation Portal](#deploy-with-argocd-cortex-documentation-portal)
- [OpenShift container registry | Cortex Documentation Portal](#openshift-container-registry-cortex-documentation-portal)
- [XSIAM Data Model Schema | Cortex Documentation Portal](#xsiam-data-model-schema-cortex-documentation-portal)
- [Get started with Cortex XSOAR 6.x APIs | Cortex Documentation Portal](#get-started-with-cortex-xsoar-6-x-apis-cortex-documentation-portal)
- [Change the layout of the rules table | Cortex Documentation Portal](#change-the-layout-of-the-rules-table-cortex-documentation-portal)
- [Cloud workload preventive action | Cortex Documentation Portal](#cloud-workload-preventive-action-cortex-documentation-portal)
- [Run an on-demand Kubernetes cluster scan | Cortex Documentation Portal](#run-an-on-demand-kubernetes-cluster-scan-cortex-documentation-portal)
- [Deploy with Flux CD | Cortex Documentation Portal](#deploy-with-flux-cd-cortex-documentation-portal)
- [Cortex XDR Agent Releases | Cortex Documentation Portal](#cortex-xdr-agent-releases-cortex-documentation-portal)
- [Cortex XDR Agent Android Guides | Cortex Documentation Portal](#cortex-xdr-agent-android-guides-cortex-documentation-portal)
- [Linux Kernel Versions | Cortex Documentation Portal](#linux-kernel-versions-cortex-documentation-portal)
- [Supported Kubernetes distributions | Cortex Documentation Portal](#supported-kubernetes-distributions-cortex-documentation-portal)
- [Get Started with Xpanse APIs | Cortex Documentation Portal](#get-started-with-xpanse-apis-cortex-documentation-portal)
- [Cloud workload policies page | Cortex Documentation Portal](#cloud-workload-policies-page-cortex-documentation-portal)
- [Filter page results | Cortex Documentation Portal](#filter-page-results-cortex-documentation-portal)
- [Cloud workload rules page | Cortex Documentation Portal](#cloud-workload-rules-page-cortex-documentation-portal)
- [Manage cloud workload policies | Cortex Documentation Portal](#manage-cloud-workload-policies-cortex-documentation-portal)
- [Get started with Cortex XSOAR 8.x APIs | Cortex Documentation Portal](#get-started-with-cortex-xsoar-8-x-apis-cortex-documentation-portal)
- [Onboard the Kubernetes Connector | Cortex Documentation Portal](#onboard-the-kubernetes-connector-cortex-documentation-portal)
- [Getting Started | Cortex Documentation Portal](#getting-started-cortex-documentation-portal)
- [Code to Cloud context and visibility | Cortex Documentation Portal](#code-to-cloud-context-and-visibility-cortex-documentation-portal)
- [Terraform workflow for Compliance assessments | Cortex Documentation Portal](#terraform-workflow-for-compliance-assessments-cortex-documentation-portal)
- [Code to Cloud | Cortex Documentation Portal](#code-to-cloud-cortex-documentation-portal)
- [Operational workflows | Cortex Documentation Portal](#operational-workflows-cortex-documentation-portal)
- [AppSec Objectives with Agentix | Cortex Documentation Portal](#appsec-objectives-with-agentix-cortex-documentation-portal)
- [View and manage applications | Cortex Documentation Portal](#view-and-manage-applications-cortex-documentation-portal)
- [Vulnerability objectives | Cortex Documentation Portal](#vulnerability-objectives-cortex-documentation-portal)
- [Core components and mechanisms | Cortex Documentation Portal](#core-components-and-mechanisms-cortex-documentation-portal)
- [Coverage in the tenant (UI) | Cortex Documentation Portal](#coverage-in-the-tenant-ui-cortex-documentation-portal)
- [Configure and monitor Cortex Cloud Application Security SLAs | Cortex Documentation Portal](#configure-and-monitor-cortex-cloud-application-security-slas-cortex-documentation-portal)
- [Issue/Finding classification by scanner | Cortex Documentation Portal](#issue-finding-classification-by-scanner-cortex-documentation-portal)
---
# Home | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/readme.md)
.
How can I help you today?[](https://cortex-docs.paloaltonetworks.com/#how-can-i-help-you-today)
------------------------------------------------------------------------------------------------
arrow-right
### **What's New**[](https://cortex-docs.paloaltonetworks.com/#whats-new)

What's new
**Cortex XDR**
#### Dedicated Idira IdP threat detection[](https://cortex-docs.paloaltonetworks.com/#dedicated-idira-idp-threat-detection)
Introduces 17 new, out-of-the-box detectors built specifically to monitor your Idira identity provider environment, instantly flagging credential manipulation and identity provider compromise.
[**Read guide →**](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/investigate-user-risk)

What's new
**Cortex XSIAM**
#### Extended Threat Intel (XTI)[](https://cortex-docs.paloaltonetworks.com/#extended-threat-intel-xti)
Introducing XTI, a comprehensive threat intelligence offering that embeds adversary insights directly into SOC workflows through enriched case investigations and AI-driven behavioral analysis.
[**Read guide →**](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence#extended-threat-intelligence-overview)

What's new
**Cortex Data Security**
#### Data Security Command Center[](https://cortex-docs.paloaltonetworks.com/#data-security-command-center)
A central hub for understanding your organization's data security posture at a glance. It brings together data discovery, classification, posture, detection, and access governance into a single interactive view, helping you quickly see where your sensitive data lives, how it is protected, and what needs your attention next.
[**Read guide →**](https://cortex-docs.paloaltonetworks.com/data-security-documentation)
### **Explore products**[](https://cortex-docs.paloaltonetworks.com/#explore-products)
Product
#### Cortex XSIAM[](https://cortex-docs.paloaltonetworks.com/#cortex-xsiam)
Highlights
→ Unified security operations → AI-driven threat prioritization → Automated response
Guide
[**Read more →**](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs/)
Product
#### Cortex XDR[](https://cortex-docs.paloaltonetworks.com/#cortex-xdr)
Highlights
→ Correlated detection data → Incident investigations → Unified response
Guide
[**Read more →**](https://cortex-docs.paloaltonetworks.com/cortex-xdr-docs/)
Product
#### Cortex XDR Agent[](https://cortex-docs.paloaltonetworks.com/#cortex-xdr-agent)
Highlights
→ Endpoint protection → Threat prevention → Endpoint telemetry
Guide
[**Read more →**](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-docs/)
Product
#### Cortex AgentiX[](https://cortex-docs.paloaltonetworks.com/#cortex-agentix)
Highlights
→ AI security workflows → Analyst automation → Guided actions
Guide
[**Read more →**](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/)
Product
#### Cortex Cloud[](https://cortex-docs.paloaltonetworks.com/#cortex-cloud)
Highlights
→ Runtime protection → Threat detection → Workload context → Configuration risk discovery → Exposure prioritization → Remediation tracking
Guide
[**Read more →**](https://cortex-docs.paloaltonetworks.com/cortex-cloud-docs/)
Product
#### Cortex Data Security[](https://cortex-docs.paloaltonetworks.com/#cortex-data-security)
Highlights
→ Sensitive data discovery → Data classification → Risk prioritization
Guide
[**Read more →**](https://cortex-docs.paloaltonetworks.com/data-security-documentation/)
Product
#### Cortex Application Security[](https://cortex-docs.paloaltonetworks.com/#cortex-application-security)
Highlights
→ Code-to-cloud visibility → Exploitability prioritization → Delivery workflow security
Guide
[**Read more →**](https://cortex-docs.paloaltonetworks.com/application-security/)
Product
#### Cortex XSOAR[](https://cortex-docs.paloaltonetworks.com/#cortex-xsoar)
Highlights
→ Response playbooks → Tool orchestration → Incident management
Guide
[**Read more →**](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs/)
Product
#### Cortex Xpanse[](https://cortex-docs.paloaltonetworks.com/#cortex-xpanse)
Highlights
→ Asset discovery → Exposure identification → Attack-surface remediation
Guide
[**Read more →**](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs/)
Last updated 8 days ago
Was this helpful?
---
# Cortex Xpanse Expander | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs/readme.md)
.
How can we help?[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs#how-can-we-help)
------------------------------------------------------------------------------------------------
Find product documentation, API references, and the latest release information.
arrow-right
Use the tiles below to browse Cortex Xpanse Expander documentation.
[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs#cortex-xpanse-expander)
**Cortex Xpanse Expander**
Product documentation for setup, configuration, investigation, and remediation.
[Cortex Xpanse Expander](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs#cortex-xpanse-expander)
[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs#apis-and-sdk)
**APIs and SDK**
Explore the Cortex Xpanse API and Python SDK.
[APIs and SDK](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs#apis-and-sdk)
[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs#support-and-releases)
**Support and releases**
Review releases and access administrator guidance.
[Support and releases](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs#support-and-releases)
* * *
### Cortex Xpanse Expander[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs#cortex-xpanse-expander)
Explore Cortex Xpanse Expander guides and release information.
[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases/july-2026)
**Release Notes**
Review the latest Cortex Xpanse Expander features and known issues.
[Release 2.14 (July 2026)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases/july-2026)
[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse)
**User Guide**
Learn setup, configuration, investigation, and remediation workflows.
[Learn about Cortex Xpanse](https://cortex-docs.paloaltonetworks.com/cortex-xpanse)
* * *
### APIs and SDK[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs#apis-and-sdk)
Use these resources to integrate with Cortex Xpanse Expander.
[](https://cortex-docs.paloaltonetworks.com/xpanse-api/)
**API Reference**
Explore Cortex Xpanse APIs and generate an API key.
[Xpanse APIs](https://cortex-docs.paloaltonetworks.com/xpanse-api/)
[](https://cortex-xpanse-python-sdk.readthedocs.io/en/latest/)
**Python SDK**
Learn to use the Python interface for the Cortex Xpanse API.
[https://cortex-xpanse-python-sdk.readthedocs.io/en/latest/](https://cortex-xpanse-python-sdk.readthedocs.io/en/latest/)
* * *
### Support and releases[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs#support-and-releases)
Keep informed about product changes and manage user access.
[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn)
**What’s New**
Review Cortex Xpanse 2.x release notes.
[Cortex Xpanse Expander Release Information](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn)
[](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-gateway-admin-guide)
**Cortex Gateway Administrator Guide**
Manage permissions, RBAC, and user groups across Cortex products.
[Cortex Gateway Admin Guide](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-gateway-admin-guide)
This site uses cookies to deliver its service and to analyze traffic. By browsing this site, you accept the [privacy policy](https://www.paloaltonetworks.com/legal-notices/privacy)
.
AcceptReject
---
# Cortex Data Security | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-data-security-docs/cortex-data-security.md)
.
How can we help?[](https://cortex-docs.paloaltonetworks.com/cortex-data-security-docs#how-can-we-help)
-------------------------------------------------------------------------------------------------------
Find product guides, references, and resources.
arrow-right
Use the tiles below to browse each documentation area.
[](https://cortex-docs.paloaltonetworks.com/data-security-documentation)
**Get Started**
Get started with Cortex Data Security
[Get started with Cortex Data Security](https://cortex-docs.paloaltonetworks.com/data-security-documentation)
[](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/cortex-data-security-terminology)
**Core Functionality**
Guides, references, and resources for the core functionality of Data Security
[Data Security](https://cortex-docs.paloaltonetworks.com/data-security-documentation/data-security/cortex-data-security-terminology)
[](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/plan-and-prepare)
**Onboard and Configure**
Plan, prepare, and onboard your data sources
[Onboard and configure](https://cortex-docs.paloaltonetworks.com/data-security-documentation/onboard-and-configure/plan-and-prepare)
[](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/asset-management)
**Inventory and Monitoring**
Asset management, dashboards and reports
[Inventory & Monitoring](https://cortex-docs.paloaltonetworks.com/data-security-documentation/inventory-and-monitoring/asset-management)
[](https://cortex-docs.paloaltonetworks.com/data-security-documentation/issue-management/cases-and-issues)
**Issue Management**
Managing cases and issues, and handling investigation and response
[Issue Management](https://cortex-docs.paloaltonetworks.com/data-security-documentation/issue-management/cases-and-issues)
This site uses cookies to deliver its service and to analyze traffic. By browsing this site, you accept the [privacy policy](https://www.paloaltonetworks.com/legal-notices/privacy)
.
AcceptReject
---
# Cortex XDR Agent | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-docs/readme.md)
.
How can we help?[](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-docs#how-can-we-help)
---------------------------------------------------------------------------------------------------
Find Cortex XDR Agent documentation, compatibility details, and the latest release information.
arrow-right
Use the tiles below to browse each Cortex XDR Agent documentation area.
* * *
### Cortex XDR Agent[](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-docs#cortex-xdr-agent)
Explore installation, configuration, and troubleshooting guidance for Cortex XDR agents.
**Agent Release Notes**
Review the newest features and known issues for Cortex XDR Agent.
[Guide](https://cortex-docs.paloaltonetworks.com/agent-release-notes/)
**Agent Administrator Guide**
Learn the requirements for installing and using Cortex XDR Agent.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/)
**Cortex XDR Agent Releases**
Review supported Cortex XDR Agent releases.
[Guide](https://cortex-docs.paloaltonetworks.com/agent-release-notes)
**Compatibility Matrix**
Find Cortex XDR Agent compatibility information.
[Guide](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/)
**Agent iOS Guide**
Learn how the iOS app detects and blocks malicious URLs.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide)
**Agent Android Guide**
Learn how the Android app prevents malware on endpoints.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/)
**Agent OSS Listings**
Review open-source software licenses for Cortex XDR Agent.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings)
**Linux Kernel Versions**
Latest kernel module version support
[Guide](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/)
This site uses cookies to deliver its service and to analyze traffic. By browsing this site, you accept the [privacy policy](https://www.paloaltonetworks.com/legal-notices/privacy)
.
AcceptReject
---
# Cortex XSIAM Documentation | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs/cortex-xsiam-documentation.md)
.
How can we help?[](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs#how-can-we-help)
-----------------------------------------------------------------------------------------------
Find product documentation, compatibility details, and the latest release information.
arrow-right
Use the tiles below to browse each documentation area.
* * *
### Cortex XSIAM[](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs#cortex-xsiam)
Explore Cortex XSIAM platform documentation and technical references.
**Release Notes**
Review the latest Cortex XSIAM features and known issues.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn)
**Cortex XSIAM Documentation**
Learn daily tasks, configuration, and product workflows.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsiam)
**XQL Query Language Reference**
Use XQL functions and stages to transform and analyze data.
[Guide](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/)
**Cortex XSIAM API Reference**
Explore Cortex XSIAM APIs and integration endpoints.
[Guide](https://cortex-docs.paloaltonetworks.com/xsiam-api/)
**XQL Schema Reference**
Review available datasets, fields, and presets.
[Guide](https://cortex-docs.paloaltonetworks.com/xql-schema-reference)
**Analytics Alerts Reference Guide**
Review Cortex XSIAM analytics alerts and detection details.
[Guide](https://cortex-docs.paloaltonetworks.com/analytics-alerts/)
[Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases)
**Data Model Schema Reference**
Browse the XSIAM data model and field definitions.
[Guide](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/)
**Cortex Gateway Guide**
Manage permissions, RBAC, and user groups.
[Guide](https://cortex-docs.paloaltonetworks.com/gateway-guide/)
**Cortex XSIAM Developer Guide**
Develop integrations and custom content for Cortex XSIAM.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/)
**Broker VM Image Migration**
Migrate to the latest Broker VM image installed with Debian 13.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/migrating-to-a-new-broker-vm-image/migrating-to-a-new-broker-vm-image)
* * *
### Cortex XDR Agent[](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs#cortex-xdr-agent)
Explore installation, configuration, and troubleshooting guidance for Cortex XDR agents.
**Agent Release Notes**
Review the newest features and known issues for Cortex XDR Agent.
[Guide](https://cortex-docs.paloaltonetworks.com/agent-release-notes/)
**Agent Administrator Guide**
Learn the requirements for installing and using Cortex XDR Agent.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/)
**Cortex XDR Agent Releases**
Review supported Cortex XDR Agent releases.
[Guide](https://cortex-docs.paloaltonetworks.com/agent-release-notes)
**Compatibility Matrix**
Find Cortex XDR Agent compatibility information.
[Guide](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/)
**Agent iOS Guide**
Learn how the iOS app detects and blocks malicious URLs.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide)
**Agent Android Guide**
Learn how the Android app prevents malware on endpoints.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/)
**Agent OSS Listings**
Review open-source software licenses for Cortex XDR Agent.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings)
**Linux Kernel Versions**
Latest kernel module version support
[Guide](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/)
Last updated 1 day ago
Was this helpful?
---
# Cortex XDR Documentation | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-docs/readme.md)
.
How can we help?[](https://cortex-docs.paloaltonetworks.com/cortex-xdr-docs#how-can-we-help)
---------------------------------------------------------------------------------------------
Find product documentation, compatibility details, and the latest release information.
arrow-right
Use the tiles below to browse each documentation area.
* * *
### Cortex XDR 5.x[](https://cortex-docs.paloaltonetworks.com/cortex-xdr-docs#cortex-xdr-5.x)
Explore Cortex XDR 5.x guides, APIs, and release notes.
**Cortex XDR 5.x Documentation**
Learn daily tasks, configuration, and product workflows.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/)
**Cortex XDR 5.x API Reference**
Explore Cortex XDR 5.x APIs and integration endpoints.
[Guide](https://cortex-docs.paloaltonetworks.com/xdr-5-api/)
**Cortex XDR 5.x Release Notes**
Review the latest Cortex XDR 5.x features and known issues.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/)
* * *
### Cortex XDR 3.x[](https://cortex-docs.paloaltonetworks.com/cortex-xdr-docs#cortex-xdr-3.x)
Explore Cortex XDR 3.x guides, APIs, and release notes.
**Cortex XDR 3.x Documentation**
Learn daily tasks, configuration, and product workflows.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/)
**Cortex XDR 3.x API Reference**
Explore Cortex XDR 3.x APIs and integration endpoints.
[Guide](https://cortex-docs.paloaltonetworks.com/xdr-3-api/)
**Cortex XDR 3.x Release Notes**
Review the latest Cortex XDR 3.x features and known issues.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/)
* * *
### Shared Cortex XDR documentation[](https://cortex-docs.paloaltonetworks.com/cortex-xdr-docs#shared-cortex-xdr-documentation)
Explore references that apply across Cortex XDR versions.
**XQL Query Language Reference**
Use XQL functions and stages to transform and analyze data.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql)
**XQL Schema Reference**
Review available datasets, fields, and presets.
[Guide](https://cortex-docs.paloaltonetworks.com/xql-schema-reference)
**Analytics Alerts**
Explore Analytics Alert references and content release notes.
[Guide](https://cortex-docs.paloaltonetworks.com/analytics-alerts)
[Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/)
**Cortex Gateway Guide**
Manage permissions, RBAC, and user groups.
[Guide](https://cortex-docs.paloaltonetworks.com/gateway-guide/)
**Broker VM Image Migration**
Migrate to the latest Broker VM image installed with Debian 13.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/migrate-to-a-new-broker-vm-image/migrating-to-a-new-broker-vm-image)
**Linux Kernel Versions**
Latest kernel module version support
[Guide](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/)
**Upgrade to Cortex XDR 5.x**
Essential release information
[Guide](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/)
**Content Release Updates**
Review release notes for each major content release version.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-content-update-releases)
* * *
### Cortex XDR Agent[](https://cortex-docs.paloaltonetworks.com/cortex-xdr-docs#cortex-xdr-agent)
Explore installation, configuration, and troubleshooting guidance for Cortex XDR agents.
**Agent Administrator Guide**
Learn the requirements for installing and using Cortex XDR Agent.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/)
**Cortex XDR Agent Releases**
Review supported Cortex XDR Agent releases.
[Guide](https://cortex-docs.paloaltonetworks.com/agent-release-notes)
**Compatibility Matrix**
Find Cortex XDR Agent compatibility information.
[Guide](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/)
**Agent iOS Guide**
Learn how the iOS app detects and blocks malicious URLs.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide)
**Agent Android Guide**
Learn how the Android app prevents malware on endpoints.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/)
**Agent OSS Listings**
Review open-source software licenses for Cortex XDR Agent.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings)
**Linux Kernel Versions**
Latest kernel module version support
[Guide](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/)
This site uses cookies to deliver its service and to analyze traffic. By browsing this site, you accept the [privacy policy](https://www.paloaltonetworks.com/legal-notices/privacy)
.
AcceptReject
---
# Cortex XSOAR Documentation | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs/readme.md)
.
How can we help?
Find Cortex XSOAR documentation, deployment guides, and the latest release information.
arrow-right
Use the tiles below to browse Cortex XSOAR documentation areas.
* * *
### Cortex XSOAR 8 SaaS[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs#cortex-xsoar-8-saas)
Use these areas to deploy, manage, and maintain Cortex XSOAR 8.
**Cortex XSOAR 8 Documentation**
Configure systems, orchestration, incidents, and playbooks for Cortex XSOAR 8 SaaS
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/)
**Release Notes**
Review the newest Cortex XSOAR 8 SaaS features and known issues.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/)
**Cortex XSOAR 8 Retention Policy**
View retention and enforcement policies for SaaS.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy)
**API Reference Guide**
View APIs and generate Cortex XSOAR API keys.
[Guide](https://cortex-docs.paloaltonetworks.com/xsoar-8-api)
**Cortex XSOAR 8 SaaS Releases**
Review the latest Cortex XSOAR 8 SaaS release dates
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-releases)
* * *
### Cortex XSOAR 8 On-prem[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs#cortex-xsoar-8-on-prem)
**Cortex XSOAR 8 Documentation**
Configure systems, orchestration, incidents, and playbooks for Cortex XSOAR 8 On-prem
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem)
**Release Notes**
Review the newest Cortex XSOAR 8 SaaS features and known issues.
[Guide](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes)
**API Reference Guide**
View APIs and generate Cortex XSOAR API keys.
[Guide](https://cortex-docs.paloaltonetworks.com/xsoar-8-api)
**Cortex XSOAR On-prem OSS Listings**
View the Open-Source Software licenses.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem-oss-listings/)
* * *
### Cortex XSOAR 6[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs#cortex-xsoar-6)
Explore Cortex XSOAR 6 documentation and technical references.
**Administrator Guides**
Configure systems, playbooks, incidents, and monitoring.
[Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/)
**Release Notes**
Review the newest features and known issues.
[Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/)
**Installation Guides**
Learn how to install Cortex XSOAR.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/)
**Multi-Tenant Guide**
Manage multi-tenant deployments and MSP workflows.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/)
**Threat Intel Management Guides**
Unify threat intelligence aggregation, scoring, and sharing.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/)
**Playbook Design Guide**
Learn how to design Cortex XSOAR playbooks.
[Guide](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/)
**Tutorials**
Find detailed tutorials for SOC engineers and architects.
[Guide](https://cortex-docs.paloaltonetworks.com/tutorials/)
**API Reference Guide**
View Cortex XSOAR APIs.
[Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-api)
**Python Development Quick Start Guide**
Learn how to develop Python scripts for Cortex XSOAR
[Guide](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/)
**Cortex XSOAR 6 FAQs**
View Cortex XSOAR 6 frequently asked questions
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs)
**Hosted Services Guides**
Learn how to use Cortex XSOAR Hosted Services. This is EOL
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/hosted-service-overview)
* * *
### Shared Cortex XSOAR documentation[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs#shared-cortex-xsoar-documentation)
**Cortex XSOAR 8 FAQs**
View frequently asked questions for SaaS and On-prem.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/)
**Cortex Gateway Administrator Guide**
Manage permissions, tenants, RBAC, and user groups.
[Guide](https://cortex-docs.paloaltonetworks.com/gateway-guide/)
**Demisto SDK Development Guide**
Learn how to use the Demisto SDK for content development.
[Guide](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/)
**FS-ISAC STIX/TAXII Guide for Cortex XSOAR**
Assist FS-ISAC member firms in connecting and configuring Cortex XSOAR through a STIX/TAXII feed integration with the FS-ISAC Threat Intelligence Exchange Repository (IntelX Repo)
[Guide](https://cortex-docs.paloaltonetworks.com/fs-isac-stix-taxii-guide-for-cortex-xsoar/)
**Cortex XSOAR 8 Feature Changes**
View the feature changes in Cortex XSOAR 8 Cloud and On-prem.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes/)
This site uses cookies to deliver its service and to analyze traffic. By browsing this site, you accept the [privacy policy](https://www.paloaltonetworks.com/legal-notices/privacy)
.
AcceptReject
---
# Cortex Cloud Documentation | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-docs/readme.md)
.
How can we help?[](https://cortex-docs.paloaltonetworks.com/cortex-cloud-docs#how-can-we-help)
-----------------------------------------------------------------------------------------------
Find product guides, technical references, and the latest release information.
arrow-right
Use the tiles below to browse each documentation area.
* * *
### Cortex Cloud[](https://cortex-docs.paloaltonetworks.com/cortex-cloud-docs#cortex-cloud)
Choose a documentation area or reference for your task.
#### Cortex Cloud Runtime Security[](https://cortex-docs.paloaltonetworks.com/cortex-cloud-docs#cortex-cloud-runtime-security)
**Cortex Cloud Runtime Security release notes**
Review the newest features and known issues for Cortex Cloud Runtime Security.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security-rn/)
**Cortex Cloud Runtime Security documentation**
Get started, configure the system, and complete daily tasks.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/)
**Broker VM Image Migration**
Migrate to the latest Broker VM image installed with Debian 13.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/migration-process-for-new-broker-vm-image/migrating-to-a-new-broker-vm-image)
#### Cortex Cloud Posture Management[](https://cortex-docs.paloaltonetworks.com/cortex-cloud-docs#cortex-cloud-posture-management)
**Cortex Cloud Posture Management release notes**
Review the newest features and known issues for Cortex Cloud Posture Management.
[Guide](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/)
**Cortex Cloud Posture Management documentation**
Get started, configure the system, and complete daily tasks.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/)
**Broker VM Image Migration**
Migrate to the latest Broker VM image installed with Debian 13.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/migrate-to-a-new-broker-vm-image/migrating-to-a-new-broker-vm-image)
#### Shared Guides[](https://cortex-docs.paloaltonetworks.com/cortex-cloud-docs#shared-guides)
**Cortex Cloud API documentation**
Review the latest API documentation for Cortex Cloud.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-cloud-api/)
**Kubernetes Security documentation**
Monitor and manage Kubernetes resources, clusters, and workloads.
[Guide](https://cortex-docs.paloaltonetworks.com/kubernetes-security/)
**Analytics Alert Reference**
View Cortex Cloud Runtime Security analytics alerts.
[Guide](https://cortex-docs.paloaltonetworks.com/analytics-alerts/)
[Release Notes](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases)
* * *
### Cortex Application Security[](https://cortex-docs.paloaltonetworks.com/cortex-cloud-docs#cortex-application-security)
Explore application security products, posture management, and rule references.
**Cortex Cloud Application Security**
Review the latest Cortex Cloud Application Security documentation.
[Guide](https://cortex-docs.paloaltonetworks.com/application-security/)
**Code-to-Cloud**
Maps your code-to-production path with deterministic, bidirectional SDLC lineage.
[Guide](https://cortex-docs.paloaltonetworks.com/application-security/code-to-cloud/code-to-cloud)
**Application Security Posture Management (ASPM)**
Understand application risks and vulnerabilities across your environment.
[Guide](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/application-security-posture-management-aspm)
**Software Supply Chain Security**
Secure the components, tools, systems, and identities that create software.
[Guide](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/software-supply-chain-security)
**AppSec Rule Reference**
Browse rules for infrastructure as code, secrets, and CI/CD pipelines.
[Guide](https://cortex-docs.paloaltonetworks.com/appsec-rules/)
This site uses cookies to deliver its service and to analyze traffic. By browsing this site, you accept the [privacy policy](https://www.paloaltonetworks.com/legal-notices/privacy)
.
AcceptReject
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs/readme.md). # Cortex Xpanse Expander ## How can we help? Find product documentation, API references, and the latest release information. Ask a question {% hint style="info" %} Use the tiles below to browse Cortex Xpanse Expander documentation. {% endhint %}
| | | |
| --- | --- | --- |
| _:shield:_ **Cortex Xpanse Expander** | Product documentation for setup, configuration, investigation, and remediation. | [#cortex-xpanse-expander](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs/readme.md#cortex-xpanse-expander) |
| _:code:_ **APIs and SDK** | Explore the Cortex Xpanse API and Python SDK. | [#apis-and-sdk](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs/readme.md#apis-and-sdk) |
| _:life-ring:_ **Support and releases** | Review releases and access administrator guidance. | [#support-and-releases](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs/readme.md#support-and-releases) |
\*\*\* ### Cortex Xpanse Expander Explore Cortex Xpanse Expander guides and release information.
| | | |
| --- | --- | --- |
| _:star:_ **Release Notes** | Review the latest Cortex Xpanse Expander features and known issues. | [/spaces/c1KOsU9bD1SUrXmJU2Wv/pages/LoXwPOXfRuPhxIcrRHVB](https://cortex-docs.paloaltonetworks.com/spaces/c1KOsU9bD1SUrXmJU2Wv/pages/LoXwPOXfRuPhxIcrRHVB) |
| _:book:_ **User Guide** | Learn setup, configuration, investigation, and remediation workflows. | [/spaces/02CCMTnqc4fWJkdEuCs8/pages/yKkvKyeQDRFzjAIwO6Zk](https://cortex-docs.paloaltonetworks.com/spaces/02CCMTnqc4fWJkdEuCs8/pages/yKkvKyeQDRFzjAIwO6Zk) |
\*\*\* ### APIs and SDK Use these resources to integrate with Cortex Xpanse Expander.
| | | |
| --- | --- | --- |
| _:code:_ **API Reference** | Explore Cortex Xpanse APIs and generate an API key. | [/spaces/F7NvUytdKiwfTl1NbkVR](https://cortex-docs.paloaltonetworks.com/spaces/F7NvUytdKiwfTl1NbkVR) |
| _:python:_ **Python SDK** | Learn to use the Python interface for the Cortex Xpanse API. | [https://cortex-xpanse-python-sdk.readthedocs.io/en/latest/](https://cortex-xpanse-python-sdk.readthedocs.io/en/latest/) |
\*\*\* ### Support and releases Keep informed about product changes and manage user access.
| | | |
| --- | --- | --- |
| _:star:_ **What’s New** | Review Cortex Xpanse 2.x release notes. | [/spaces/c1KOsU9bD1SUrXmJU2Wv/pages/HCumZqbQIX47ZQ2Yr3ml](https://cortex-docs.paloaltonetworks.com/spaces/c1KOsU9bD1SUrXmJU2Wv/pages/HCumZqbQIX47ZQ2Yr3ml) |
| _:user-shield:_ **Cortex Gateway Administrator Guide** | Manage permissions, RBAC, and user groups across Cortex products. | [/spaces/nG6FTSH3MviWTK9yhAIg/pages/lFkZEctYqLTMZRc24sM7](https://cortex-docs.paloaltonetworks.com/spaces/nG6FTSH3MviWTK9yhAIg/pages/lFkZEctYqLTMZRc24sM7) |
\--- # Agent Instructions This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com. ## Querying This Documentation If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question. Perform an HTTP GET request on the current page URL with the \`ask\` query parameter, and the optional \`goal\` query parameter: \`\`\` GET https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs/readme.md?ask=&goal= \`\`\` \`ask\` is the immediate question: it should be specific, self-contained, and written in natural language. \`goal\` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal. The response will contain a direct answer to the question and relevant excerpts and sources from the documentation. Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
---
# Cortex AgentiX | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-agentix.md)
.
How can we help?[](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs#how-can-we-help)
-------------------------------------------------------------------------------------------------
Find Cortex AgentiX documentation, administration guidance, and current release information.
arrow-right
Use the tiles below to browse each documentation area.
### Cortex AgentiX[](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs#cortex-agentix)
Explore product guides, technical references, and release information.
**Release Notes**
Review the newest Cortex AgentiX features and known issues.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-agentix-rn/)
**Cortex AgentiX Documentation**
Learn daily tasks, configuration, security orchestration, playbooks, and incident management.
[Guide](https://cortex-docs.paloaltonetworks.com/cortex-agentix)
**API Reference Guide**
View all Cortex AgentiX APIs.
[Guide](https://cortex-docs.paloaltonetworks.com/agentix-api)
**Cortex Gateway Guide**
Manage permissions, RBAC, and user groups.
[Guide](https://cortex-docs.paloaltonetworks.com/gateway-guide/)
[NextWhat's New](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/whats-new)
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://cortex-docs.paloaltonetworks.com/cortex-data-security-docs/cortex-data-security.md). # Cortex Data Security ## How can we help? Find product guides, references, and resources. Ask a question {% hint style="info" %} Use the tiles below to browse each documentation area. {% endhint %}
| | | |
| --- | --- | --- |
| _:laptop:_ **Get Started** | Get started with Cortex Data Security | [/spaces/HfNuZNmWlqy9Bl7fETmL/pages/798I11YPT3o4iH4LO3AG](https://cortex-docs.paloaltonetworks.com/spaces/HfNuZNmWlqy9Bl7fETmL/pages/798I11YPT3o4iH4LO3AG) |
| _:shield:_ **Core Functionality** | Guides, references, and resources for the core functionality of Data Security | [/spaces/HfNuZNmWlqy9Bl7fETmL/pages/RKUXRHUU2joJUqGUXxbo](https://cortex-docs.paloaltonetworks.com/spaces/HfNuZNmWlqy9Bl7fETmL/pages/RKUXRHUU2joJUqGUXxbo) |
| _:gears:_ **Onboard and Configure** | Plan, prepare, and onboard your data sources | [/spaces/HfNuZNmWlqy9Bl7fETmL/pages/KuZp4A0nfNthLHKWL8Ct](https://cortex-docs.paloaltonetworks.com/spaces/HfNuZNmWlqy9Bl7fETmL/pages/KuZp4A0nfNthLHKWL8Ct) |
| _:chart-gantt:_ **Inventory and Monitoring** | Asset management, dashboards and reports | [/spaces/HfNuZNmWlqy9Bl7fETmL/pages/wYeca5m7w99rF7DB173z](https://cortex-docs.paloaltonetworks.com/spaces/HfNuZNmWlqy9Bl7fETmL/pages/wYeca5m7w99rF7DB173z) |
| _:box-circle-check:_ **Issue Management** | Managing cases and issues, and handling investigation and response | [/spaces/HfNuZNmWlqy9Bl7fETmL/pages/HRfbPbTmntB9GGU2b1MA](https://cortex-docs.paloaltonetworks.com/spaces/HfNuZNmWlqy9Bl7fETmL/pages/HRfbPbTmntB9GGU2b1MA) |
\--- # Agent Instructions This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com. ## Querying This Documentation If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question. Perform an HTTP GET request on the current page URL with the \`ask\` query parameter, and the optional \`goal\` query parameter: \`\`\` GET https://cortex-docs.paloaltonetworks.com/cortex-data-security-docs/cortex-data-security.md?ask=&goal= \`\`\` \`ask\` is the immediate question: it should be specific, self-contained, and written in natural language. \`goal\` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal. The response will contain a direct answer to the question and relevant excerpts and sources from the documentation. Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-docs/readme.md). # Cortex XDR Agent ## How can we help? Find Cortex XDR Agent documentation, compatibility details, and the latest release information. Ask a question {% hint style="info" %} Use the tiles below to browse each Cortex XDR Agent documentation area. {% endhint %} \*\*\* ### Cortex XDR Agent Explore installation, configuration, and troubleshooting guidance for Cortex XDR agents.
| | | |
| --- | --- | --- |
| _:bullhorn:_ **Agent Release Notes** | Review the newest features and known issues for Cortex XDR Agent. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/RwAoI4lZv8Q7OzaOg2cK) |
| _:book-open:_ **Agent Administrator Guide** | Learn the requirements for installing and using Cortex XDR Agent. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/5UJguKA09UlnsSwXqQSr) |
| _:list:_ **Cortex XDR Agent Releases** | Review supported Cortex XDR Agent releases. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/RwAoI4lZv8Q7OzaOg2cK/pages/G1oOaedpqKSGfgg5sjZj) |
| _:table-columns:_ **Compatibility Matrix** | Find Cortex XDR Agent compatibility information. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/fZ8QSMnkjnXpuOeuRcam) |
| _:apple:_ **Agent iOS Guide** | Learn how the iOS app detects and blocks malicious URLs. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/8AQY2hSDDP8XenSfAtjj/pages/8MEMPMTozIxe6Kp08pdJ) |
| _:android:_ **Agent Android Guide** | Learn how the Android app prevents malware on endpoints. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/QYFpeEghdkGqvW2PdVmn) |
| _:scale-balanced:_ **Agent OSS Listings** | Review open-source software licenses for Cortex XDR Agent. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/TBvbxZu9tJn714mkiz7P/pages/x6PxiO2Z89EBzWBucl6M) |
| _:linux:_ **Linux Kernel Versions** | Latest kernel module version support | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/y29o8lwSBpbfPbvztsyt) |
\--- # Agent Instructions This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com. ## Querying This Documentation If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question. Perform an HTTP GET request on the current page URL with the \`ask\` query parameter, and the optional \`goal\` query parameter: \`\`\` GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-docs/readme.md?ask=&goal= \`\`\` \`ask\` is the immediate question: it should be specific, self-contained, and written in natural language. \`goal\` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal. The response will contain a direct answer to the question and relevant excerpts and sources from the documentation. Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://cortex-docs.paloaltonetworks.com/readme.md). # Home
How can I help you today?
-------------------------
Search our docs the easy way...
\### \*\*What's New\*\*
| | | | | | Cover image |
| --- | --- | --- | --- | --- | --- |
| What's new | **Cortex XDR**
#### Dedicated Idira IdP threat detection | Introduces 17 new, out-of-the-box detectors built specifically to monitor your Idira identity provider environment, instantly flagging credential manipulation and identity provider compromise. | [**Read guide →**](https://cortex-docs.paloaltonetworks.com/spaces/cyIgISZgANJYkmLlnwdK/pages/jItyZ3CGoGXW48zsOMTJ) | / | [/files/PGJejYpIoftzISmWHXsE](https://cortex-docs.paloaltonetworks.com/files/PGJejYpIoftzISmWHXsE) |
| What's new | **Cortex XSIAM**
#### Extended Threat Intel (XTI) | Introducing XTI, a comprehensive threat intelligence offering that embeds adversary insights directly into SOC workflows through enriched case investigations and AI-driven behavioral analysis. | [**Read guide →**](https://cortex-docs.paloaltonetworks.com/spaces/AEIjuYE3RXcIfmuQnBbm/pages/RcpwiBUk7ndGnHWaFFSa#extended-threat-intelligence-overview) | | [/files/ZtHRf95rhQM2q6q4wBBx](https://cortex-docs.paloaltonetworks.com/files/ZtHRf95rhQM2q6q4wBBx) |
| What's new | **Cortex Data Security**
#### Data Security Command Center | A central hub for understanding your organization's data security posture at a glance. It brings together data discovery, classification, posture, detection, and access governance into a single interactive view, helping you quickly see where your sensitive data lives, how it is protected, and what needs your attention next. | [**Read guide →**](https://cortex-docs.paloaltonetworks.com/spaces/HfNuZNmWlqy9Bl7fETmL/pages/798I11YPT3o4iH4LO3AG) | | [/files/Pk5Xz4AolV8Iy7aO7RR4](https://cortex-docs.paloaltonetworks.com/files/Pk5Xz4AolV8Iy7aO7RR4) |
\### \*\*Explore products\*\*
| Product | Highlights | Guide |
| --- | --- | --- |
| #### _:shield:_ Cortex XSIAM | → Unified security operations
→ AI-driven threat prioritization
→ Automated response | [**Read more →**](https://cortex-docs.paloaltonetworks.com/spaces/XO7Budkunf9O78igMwUM) |
| #### _:shield-halved:_ Cortex XDR | → Correlated detection data
→ Incident investigations
→ Unified response | [**Read more →**](https://cortex-docs.paloaltonetworks.com/spaces/RATlGrcoSzIkoMIySpFR) |
| #### _:laptop:_ Cortex XDR Agent | → Endpoint protection
→ Threat prevention
→ Endpoint telemetry | [**Read more →**](https://cortex-docs.paloaltonetworks.com/spaces/YhAQu4OiCd3X2NZv62G3) |
| #### _:robot:_ Cortex AgentiX | → AI security workflows
→ Analyst automation
→ Guided actions | [**Read more →**](https://cortex-docs.paloaltonetworks.com/spaces/nG6FTSH3MviWTK9yhAIg) |
| #### _:cloud:_ Cortex Cloud | → Runtime protection
→ Threat detection
→ Workload context
→ Configuration risk discovery
→ Exposure prioritization
→ Remediation tracking | [**Read more →**](https://cortex-docs.paloaltonetworks.com/spaces/3KStLIk7bIVZ1wH8UXES) |
| #### _:database:_ Cortex Data Security | → Sensitive data discovery
→ Data classification
→ Risk prioritization | [**Read more →**](https://cortex-docs.paloaltonetworks.com/spaces/HfNuZNmWlqy9Bl7fETmL) |
| #### _:code:_ Cortex Application Security | → Code-to-cloud visibility
→ Exploitability prioritization
→ Delivery workflow security | [**Read more →**](https://cortex-docs.paloaltonetworks.com/spaces/8Z0RLJ1BFF5TQL8VtUeK) |
| #### _:gears:_ Cortex XSOAR | → Response playbooks
→ Tool orchestration
→ Incident management | [**Read more →**](https://cortex-docs.paloaltonetworks.com/spaces/62ZHoHZBxxG2zr3LS78a) |
| #### _:globe:_ Cortex Xpanse | → Asset discovery
→ Exposure identification
→ Attack-surface remediation | [**Read more →**](https://cortex-docs.paloaltonetworks.com/spaces/1CKsHC5AGGixlT1wFfTW) |
\--- # Agent Instructions This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com. ## Querying This Documentation If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question. Perform an HTTP GET request on the current page URL with the \`ask\` query parameter, and the optional \`goal\` query parameter: \`\`\` GET https://cortex-docs.paloaltonetworks.com/readme.md?ask=&goal= \`\`\` \`ask\` is the immediate question: it should be specific, self-contained, and written in natural language. \`goal\` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal. The response will contain a direct answer to the question and relevant excerpts and sources from the documentation. Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://cortex-docs.paloaltonetworks.com/cortex-xdr-docs/readme.md). # Cortex XDR Documentation ## How can we help? Find product documentation, compatibility details, and the latest release information. Ask a question {% hint style="info" %} Use the tiles below to browse each documentation area. {% endhint %} \*\*\* ### Cortex XDR 5.x Explore Cortex XDR 5.x guides, APIs, and release notes.
| | | | |
| --- | --- | --- | --- |
| _:book-open:_ **Cortex XDR 5.x Documentation** | Learn daily tasks, configuration, and product workflows. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/cyIgISZgANJYkmLlnwdK) | |
| _:plug:_ **Cortex XDR 5.x API Reference** | Explore Cortex XDR 5.x APIs and integration endpoints. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/FK89utN7l3ilSek2DmU5) | |
| _:bullhorn:_ **Cortex XDR 5.x Release Notes** | Review the latest Cortex XDR 5.x features and known issues. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/d6B1RLHUyhHSdajBpqem) | |
\*\*\* ### Cortex XDR 3.x Explore Cortex XDR 3.x guides, APIs, and release notes.
| | | | |
| --- | --- | --- | --- |
| _:book-open:_ **Cortex XDR 3.x Documentation** | Learn daily tasks, configuration, and product workflows. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/FOhYBYLdbwpnbJgr6uaX) | |
| _:plug:_ **Cortex XDR 3.x API Reference** | Explore Cortex XDR 3.x APIs and integration endpoints. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/bcaz3nnErYwzhJKuv5Ls) | |
| _:bullhorn:_ **Cortex XDR 3.x Release Notes** | Review the latest Cortex XDR 3.x features and known issues. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/YAZ9UcMoSKwRIsX27EyG) | |
\*\*\* ### Shared Cortex XDR documentation Explore references that apply across Cortex XDR versions.
| | | | | |
| --- | --- | --- | --- | --- |
| _:code:_ **XQL Query Language Reference** | Use XQL functions and stages to transform and analyze data. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/cyIgISZgANJYkmLlnwdK/pages/U5yQBCAEmPizAmFAArVV) | | |
| _:database:_ **XQL Schema Reference** | Review available datasets, fields, and presets. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/6UN9P7f8B5L9QmLYI9Te/pages/0tbMO07opuvWRaO0m8ev) | | |
| _:bell:_ **Analytics Alerts** | Explore Analytics Alert references and content release notes. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/5O67gr80iLneA56jiuO2/pages/QjdZQ5MsklwDaDcVInMC)
[Release Notes](https://cortex-docs.paloaltonetworks.com/spaces/hJnzmcGQsreNQBWx4YG9) | | |
| _:user-shield:_ **Cortex Gateway Guide** | Manage permissions, RBAC, and user groups. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/SqEFcjERpi4JSgB9LjVw) | | |
| _:server:_ **Broker VM Image Migration** | Migrate to the latest Broker VM image installed with Debian 13. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/cyIgISZgANJYkmLlnwdK/pages/S02UyUZ0WE133IQ0hLIq) | | |
| _:linux:_ **Linux Kernel Versions** | Latest kernel module version support | | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/y29o8lwSBpbfPbvztsyt) | |
| _:arrow-up:_ **Upgrade to Cortex XDR 5.x** | Essential release information | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/CLlcXfXjtSjJlneqhjgm) | | |
| _:file-lines:_ **Content Release Updates** | Review release notes for each major content release version. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/JZVikp6ohjY6qBMfKrfn/pages/POBG9K5Fn0b0iBt8cOHh) | | |
\*\*\* ### Cortex XDR Agent Explore installation, configuration, and troubleshooting guidance for Cortex XDR agents.
| | | |
| --- | --- | --- |
| _:book-open:_ **Agent Administrator Guide** | Learn the requirements for installing and using Cortex XDR Agent. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/5UJguKA09UlnsSwXqQSr) |
| _:bullhorn:_ **Cortex XDR Agent Releases** | Review supported Cortex XDR Agent releases. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/RwAoI4lZv8Q7OzaOg2cK/pages/G1oOaedpqKSGfgg5sjZj) |
| _:table-columns:_ **Compatibility Matrix** | Find Cortex XDR Agent compatibility information. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/fZ8QSMnkjnXpuOeuRcam) |
| _:apple:_ **Agent iOS Guide** | Learn how the iOS app detects and blocks malicious URLs. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/8AQY2hSDDP8XenSfAtjj/pages/8MEMPMTozIxe6Kp08pdJ) |
| _:android:_ **Agent Android Guide** | Learn how the Android app prevents malware on endpoints. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/QYFpeEghdkGqvW2PdVmn) |
| _:scale-balanced:_ **Agent OSS Listings** | Review open-source software licenses for Cortex XDR Agent. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/TBvbxZu9tJn714mkiz7P/pages/x6PxiO2Z89EBzWBucl6M) |
| _:linux:_ **Linux Kernel Versions** | Latest kernel module version support | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/y29o8lwSBpbfPbvztsyt) |
\--- # Agent Instructions This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com. ## Querying This Documentation If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question. Perform an HTTP GET request on the current page URL with the \`ask\` query parameter, and the optional \`goal\` query parameter: \`\`\` GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-docs/readme.md?ask=&goal= \`\`\` \`ask\` is the immediate question: it should be specific, self-contained, and written in natural language. \`goal\` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal. The response will contain a direct answer to the question and relevant excerpts and sources from the documentation. Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs/readme.md). # Cortex XSOAR Documentation How can we help? Find Cortex XSOAR documentation, deployment guides, and the latest release information. Ask a question {% hint style="info" %} Use the tiles below to browse Cortex XSOAR documentation areas. {% endhint %} \*\*\* ### Cortex XSOAR 8 SaaS Use these areas to deploy, manage, and maintain Cortex XSOAR 8.
| | | |
| --- | --- | --- |
| _:book:_ **Cortex XSOAR 8 Documentation** | Configure systems, orchestration, incidents, and playbooks for Cortex XSOAR 8 SaaS | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/gHZkkpS9tCAU2tRJlYSx) |
| _:bullhorn:_ **Release Notes** | Review the newest Cortex XSOAR 8 SaaS features and known issues. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/aUKGnsF9X4Dz3YLa8G0L) |
| _:clock:_ **Cortex XSOAR 8 Retention Policy** | View retention and enforcement policies for SaaS. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/B9wj8hV3yPF9Sj7EWql1/pages/9jVfmxiMjCgL4O8gXwh3) |
| _:plug:_ **API Reference Guide** | View APIs and generate Cortex XSOAR API keys. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/dXXxClt1YkGQlGTYJWdB/pages/pnQMYB7ijRMTYAkAd1yK) |
| _:star:_ **Cortex XSOAR 8 SaaS Releases** | Review the latest Cortex XSOAR 8 SaaS release dates | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/kZc9JtAfs83sv2XtLjgc/pages/bp7Iqo0aF8UJR5XreQmt) |
\*\*\* ### Cortex XSOAR 8 On-prem
| | | |
| --- | --- | --- |
| _:book:_ **Cortex XSOAR 8 Documentation** | Configure systems, orchestration, incidents, and playbooks for Cortex XSOAR 8 On-prem | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/DDln2YM6gCMkmEv8gdCD/pages/CbPc2Ku3Ma6qmu4c903P) |
| _:bullhorn:_ **Release Notes** | Review the newest Cortex XSOAR 8 SaaS features and known issues. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/B5iqkOGwhpMKNIlAHCrO/pages/xDOLGBANbPXOR0PcnRiw) |
| _:plug:_ **API Reference Guide** | View APIs and generate Cortex XSOAR API keys. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/dXXxClt1YkGQlGTYJWdB/pages/pnQMYB7ijRMTYAkAd1yK) |
| _:scale-balanced:_ **Cortex XSOAR On-prem OSS Listings** | View the Open-Source Software licenses. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/ilVCYDvSfVsGkKGJ3uJa) |
\*\*\* ### Cortex XSOAR 6 Explore Cortex XSOAR 6 documentation and technical references.
| | | |
| --- | --- | --- |
| _:book:_ **Administrator Guides** | Configure systems, playbooks, incidents, and monitoring. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/d64qhC8spkDTR7uJU4Ew) |
| _:bullhorn:_ **Release Notes** | Review the newest features and known issues. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/623zUS8jl0uZx8p8sETZ) |
| _:download:_ **Installation Guides** | Learn how to install Cortex XSOAR. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/QZ8JZb2ptpWFbOY3VQ8c) |
| _:users:_ **Multi-Tenant Guide** | Manage multi-tenant deployments and MSP workflows. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/OBWCsa4fxAvzkyke19UJ) |
| _:database:_ **Threat Intel Management Guides** | Unify threat intelligence aggregation, scoring, and sharing. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/MSCUI8m5OQ8actuEpHBp) |
| _:diagram-project:_ **Playbook Design Guide** | Learn how to design Cortex XSOAR playbooks. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/gaMaDyA7IyU5W44zuyhm) |
| _:graduation-cap:_ **Tutorials** | Find detailed tutorials for SOC engineers and architects. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/diKXnbzsot9ObrD3kCBJ) |
| _:plug:_ **API Reference Guide** | View Cortex XSOAR APIs. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/bWXCK6Ok7gHeWX1hZloJ/pages/XHHgqNUiAdKwkeUP1Au4) |
| _:code:_ **Python Development Quick Start Guide** | Learn how to develop Python scripts for Cortex XSOAR | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/1gnp6guN8K5qqalY6vhQ) |
| _:life-ring:_ **Cortex XSOAR 6 FAQs** | View Cortex XSOAR 6 frequently asked questions | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/txlQXTJVEbT6VvUnmq1N/pages/nZbnWVXD67jEmDRmymBh) |
| _:book:_ **Hosted Services Guides** | Learn how to use Cortex XSOAR Hosted Services. This is EOL | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/flismJO0G3HCx24oN3sy/pages/Gy0dMBnFOiVP7T7uIx5O) |
\*\*\* ### Shared Cortex XSOAR documentation
| | | |
| --- | --- | --- |
| _:life-ring:_ **Cortex XSOAR 8 FAQs** | View frequently asked questions for SaaS and On-prem. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/CJ6Glfma1g0Ve1V1GHrW) |
| _:user-gear:_ **Cortex Gateway Administrator Guide** | Manage permissions, tenants, RBAC, and user groups. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/SqEFcjERpi4JSgB9LjVw) |
| _:code:_ **Demisto SDK Development Guide** | Learn how to use the Demisto SDK for content development. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/nozw5MT5S8KZD2eF8roV) |
| _:share-nodes:_ **FS-ISAC STIX/TAXII Guide for Cortex XSOAR** | Assist FS-ISAC member firms in connecting and configuring Cortex XSOAR through a STIX/TAXII feed integration with the FS-ISAC Threat Intelligence Exchange Repository (IntelX Repo) | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/RjnOsUL6Mcxnrd8qinos) |
| **Cortex XSOAR 8 Feature Changes** | View the feature changes in Cortex XSOAR 8 Cloud and On-prem. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/yznYnWCbczlUTPPYfjsP) |
| | | |
| | | |
\--- # Agent Instructions This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com. ## Querying This Documentation If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question. Perform an HTTP GET request on the current page URL with the \`ask\` query parameter, and the optional \`goal\` query parameter: \`\`\` GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs/readme.md?ask=&goal= \`\`\` \`ask\` is the immediate question: it should be specific, self-contained, and written in natural language. \`goal\` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal. The response will contain a direct answer to the question and relevant excerpts and sources from the documentation. Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs/cortex-xsiam-documentation.md). # Cortex XSIAM Documentation ## How can we help? Find product documentation, compatibility details, and the latest release information. Ask a question {% hint style="info" %} Use the tiles below to browse each documentation area. {% endhint %} \*\*\* ### Cortex XSIAM Explore Cortex XSIAM platform documentation and technical references.
| | | | |
| --- | --- | --- | --- |
| _:bullhorn:_ **Release Notes** | Review the latest Cortex XSIAM features and known issues. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/URJI4U6i9UDwotNccb7R/pages/kZlvobjlgo6Prn8MFcoi) | |
| _:book-open:_ **Cortex XSIAM Documentation** | Learn daily tasks, configuration, and product workflows. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/AEIjuYE3RXcIfmuQnBbm/pages/QODQbh65sM5UR93gfxSJ) | |
| _:code:_ **XQL Query Language Reference** | Use XQL functions and stages to transform and analyze data. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/fUtoMSNyY2P8jbK3cQsM) | |
| _:plug:_ **Cortex XSIAM API Reference** | Explore Cortex XSIAM APIs and integration endpoints. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/1ZrobAtcwfCDWAJAWeuj) | |
| _:database:_ **XQL Schema Reference** | Review available datasets, fields, and presets. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/6UN9P7f8B5L9QmLYI9Te/pages/0tbMO07opuvWRaO0m8ev) | |
| _:chart-line:_ **Analytics Alerts Reference Guide** | Review Cortex XSIAM analytics alerts and detection details. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/5O67gr80iLneA56jiuO2) | [Release Notes](https://cortex-docs.paloaltonetworks.com/spaces/hJnzmcGQsreNQBWx4YG9/pages/qndTuB407KX5tHt1Ad30) |
| _:table-columns:_ **Data Model Schema Reference** | Browse the XSIAM data model and field definitions. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/HVBaxKOW1b6qcIQ6iMBh) | |
| _:user-shield:_ **Cortex Gateway Guide** | Manage permissions, RBAC, and user groups. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/SqEFcjERpi4JSgB9LjVw) | |
| _:code-branch:_ **Cortex XSIAM Developer Guide** | Develop integrations and custom content for Cortex XSIAM. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/urXrv6qkJRLbdhMdvPIU) | |
| _:server:_ **Broker VM Image Migration** | Migrate to the latest Broker VM image installed with Debian 13. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/AEIjuYE3RXcIfmuQnBbm/pages/fhfTWtIP4TJKPWJ85FMh) | |
\*\*\* ### Cortex XDR Agent Explore installation, configuration, and troubleshooting guidance for Cortex XDR agents.
| | | |
| --- | --- | --- |
| _:bullhorn:_ **Agent Release Notes** | Review the newest features and known issues for Cortex XDR Agent. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/RwAoI4lZv8Q7OzaOg2cK) |
| _:book-open:_ **Agent Administrator Guide** | Learn the requirements for installing and using Cortex XDR Agent. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/5UJguKA09UlnsSwXqQSr) |
| _:list:_ **Cortex XDR Agent Releases** | Review supported Cortex XDR Agent releases. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/RwAoI4lZv8Q7OzaOg2cK/pages/G1oOaedpqKSGfgg5sjZj) |
| _:table-columns:_ **Compatibility Matrix** | Find Cortex XDR Agent compatibility information. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/fZ8QSMnkjnXpuOeuRcam) |
| _:apple:_ **Agent iOS Guide** | Learn how the iOS app detects and blocks malicious URLs. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/8AQY2hSDDP8XenSfAtjj/pages/8MEMPMTozIxe6Kp08pdJ) |
| _:android:_ **Agent Android Guide** | Learn how the Android app prevents malware on endpoints. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/QYFpeEghdkGqvW2PdVmn) |
| _:scale-balanced:_ **Agent OSS Listings** | Review open-source software licenses for Cortex XDR Agent. | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/TBvbxZu9tJn714mkiz7P/pages/x6PxiO2Z89EBzWBucl6M) |
| _:linux:_ **Linux Kernel Versions** | Latest kernel module version support | [Guide](https://cortex-docs.paloaltonetworks.com/spaces/y29o8lwSBpbfPbvztsyt) |
\--- # Agent Instructions This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com. ## Querying This Documentation If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question. Perform an HTTP GET request on the current page URL with the \`ask\` query parameter, and the optional \`goal\` query parameter: \`\`\` GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs/cortex-xsiam-documentation.md?ask=&goal= \`\`\` \`ask\` is the immediate question: it should be specific, self-contained, and written in natural language. \`goal\` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal. The response will contain a direct answer to the question and relevant excerpts and sources from the documentation. Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
---
# Cortex Gateway Admin Guide | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-gateway-admin-guide.md)
.
Cortex Gateway Admin Guide[](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-gateway-admin-guide#cortex-gateway-admin-guide)
-------------------------------------------------------------------------------------------------------------------------------------------------
Learn how to view and manage permissions, role-based access control (RBAC), and user-group settings across all Cortex products.
[PreviousWhat's New](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/whats-new)
[NextRelease Notes](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/release-notes)
Last updated 29 days ago
Was this helpful?
Was this helpful?
---
# What's New | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/whats-new.md)
.
What's New[](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/whats-new#whats-new)
-----------------------------------------------------------------------------------------------
Review the latest Cortex AgentiX release notes.
[PreviousCortex AgentiX](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs)
[NextCortex Gateway Admin Guide](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-gateway-admin-guide)
Last updated 29 days ago
Was this helpful?
Was this helpful?
---
# Release Notes | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/release-notes.md)
.
Release Notes[](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/release-notes#release-notes)
----------------------------------------------------------------------------------------------------------
Review the newest features and known issues for Cortex AgentiX.
[PreviousCortex Gateway Admin Guide](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-gateway-admin-guide)
[NextCortex AgentiX Documentation](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-agentix-documentation)
Last updated 29 days ago
Was this helpful?
Was this helpful?
---
# Cortex AgentiX Documentation | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-agentix-documentation.md)
.
Cortex AgentiX Documentation[](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-agentix-documentation#cortex-agentix-documentation)
-------------------------------------------------------------------------------------------------------------------------------------------------------
Learn how to use Cortex AgentiX from getting started through daily tasks.
Explore configuration, security orchestration, playbooks, incident management, monitoring, and more.
[PreviousRelease Notes](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/release-notes)
[NextAPI Reference Guide](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/api-reference-guide)
Last updated 29 days ago
Was this helpful?
Was this helpful?
---
# API Reference Guide | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/api-reference-guide.md)
.
API Reference Guide[](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/api-reference-guide#api-reference-guide)
----------------------------------------------------------------------------------------------------------------------------
View all Cortex AgentiX APIs.
[PreviousCortex AgentiX Documentation](https://cortex-docs.paloaltonetworks.com/cortex-agentix-docs/cortex-agentix-documentation)
Last updated 29 days ago
Was this helpful?
Was this helpful?
---
# Cortex XQL Schema Reference Guide | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/readme.md)
.
This guide describes the fields available in the xdr\_data dataset. This dataset contains all data collected from all Cortex product agents, including EDR data, and PAN NGFW data.
[NextXDR\_DATA Fields by Actor](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields-by-actor)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Release 2.14 (July 2026) | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases/july-2026.md)
.
The table below describes the features and enhancements introduced in the Cortex Xpanse Expander 2.14 (July 2026) release.
Cortex Xpanse typically upgrades customers over a three-week time frame. Contact customer success to find out your specific upgrade date.
Attack Surface Management[](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases/july-2026#attack-surface-management)
--------------------------------------------------------------------------------------------------------------------------------------------------
FEATURE
DESCRIPTION
On-demand attack surface rescan
Confirm remediation faster by triggering a new Attack Surface Testing (AST) scan directly from an AST alert. Validate findings and keep alert status current without waiting for the next scheduled scan.
Business unit asset mapping
Organize your attack surface more efficiently with bulk business unit assignment for IP addresses and domains. Map assets to the right teams faster and maintain clearer ownership across the enterprise.
Frontier AI-informed detection coverage
Expand protection with new detections shaped by frontier AI attack research. Built from testing with models like Mythos, these detections help identify exploitable weaknesses and exposures across external attack surfaces.
[PreviousFeatures introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases)
[NextRelease 2.13 (May 2026)](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases/may-2026)
Last updated 26 days ago
Was this helpful?
Was this helpful?
---
# Cortex XSOAR 6 FAQs | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs.md)
.
[Content Feature Requests](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/content-feature-requests)
[Customer Support Portal FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/customer-support-portal-faqs)
[Licensing](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/licensing)
[Resources](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/resources)
[Upgrade from Cortex XSOAR 6](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/upgrade-from-cortex-xsoar-6)
[NextContent Feature Requests](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.x-faqs/cortex-xsoar-6-faqs/content-feature-requests)
Was this helpful?
Was this helpful?
---
# Cortex Xpanse Expander Release Information | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/expander-release-information.md)
.
Cortex Xpanse Expander is a cloud-based attack surface management solution that helps organizations find and fix their known and unknown internet-connected risks. Expander performs automated, continuous scans to index the entire internet and discover all connected assets, misconfigurations, and exposed services. Expander's supervised machine-learning model accurately attributes assets to your organization, identifies exposures, and prioritizes these exposures for remediation. With the Cortex Xpanse Active Response add-on module, AI-powered playbooks automatically identify service owners and remediate exposures.
The topics in this release note describe the new features and enhancements introduced in Cortex Xpanse Expander.
[NextFeatures introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-expander-rn/2026-releases)
Last updated 2 months ago
Was this helpful?
Was this helpful?
---
# FS-ISAC STIX/TAXII Guide for Cortex XSOAR | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/fs-isac-stix-taxii-guide-for-cortex-xsoar/fs-isac-stix-taxii-guide-for-cortex-xsoar.md)
.
Assist FS-ISAC member firms in connecting and configuring Cortex XSOAR through a STIX/TAXII feed integration with the FS-ISAC Threat Intelligence Exchange Repository (IntelX Repo).
Use this guide to:
* Install the TAXII Feed integration
* Set up the FS-ISCA instance in Cortex XSOAR
[NextConnect to the FS-ISAC IntelX Exchange in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/fs-isac-stix-taxii-guide-for-cortex-xsoar/fs-isac-stix-taxii-guide-for-cortex-xsoar/connect-to-the-fs-isac-intelx-exchange-in-cortex-xsoar)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Cortex XSOAR On-prem OSS listings | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem-oss-listings/cortex-xdr-oss-listings.md)
.
The following sections list Open-Source Software (OSS) licenses specific to Cortex XSOAR On-prem.
### Note[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem-oss-listings#note)
These listings capture the component versions found in the most recent maintenance release of each Cortex XSOAR software version. Whenever possible, Palo Alto Networks recommends that you upgrade to the latest maintenance release for the version you are running on your appliances because each maintenance release contains additional enhancements and bug fixes as well updates that address security vulnerabilities. If you are not able to upgrade to the latest version, you should consult the Cortex XSOAR release notes for the version you are running to determine whether there are component updates in later versions.
[NextCortex XSOAR on-prem 8.14 OSS listings](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem-oss-listings/cortex-xdr-oss-listings/cortex-xdr-agent-9.2-oss-listing)
Last updated 23 days ago
Was this helpful?
Was this helpful?
---
# Cortex XSOAR 8 FAQs | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs.md)
.
[General information](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/general-information)
[Content Feature Requests](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/content-feature-requests)
[Cortex XSOAR 8 SaaS FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-saas-faqs)
[Cortex XSOAR 8 On-Prem FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/cortex-xsoar-8-on-prem-faqs)
[NextGeneral information](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-faqs/cortex-xsoar-8-faqs/general-information)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Cortex XDR OSS Listings | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-oss-listings.md)
.
The following section displays Open-Source Software (OSS) licenses specific to the Cortex XDR agent.
### Note[](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings#note)
These listings capture the component versions found in the most recent maintenance release of each Cortex XDR agent software version. Whenever possible Palo Alto Networks, recommends that you upgrade to the latest maintenance release for the version you are running on your appliances because each maintenance release contains additional enhancements and bug fixes as well updates that address security vulnerabilities. If you are not able to upgrade to the latest version, you should consult the Cortex XDR release notes for the version you are running to determine whether there are component updates in later versions.
[NextCortex XDR Agent 9.3 OSS Listing](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-oss-listings/cortex-xdr-agent-9.2-oss-listing)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Hosted Service Overview | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/hosted-service-overview.md)
.
Cortex XSOAR hosted service is EOL.
The Cortex XSOAR hosted service enables you to use Cortex XSOAR for security orchestration, incident management, and investigation, without the infrastructure required for an on-premise deployment. Palo Alto Networks provides the service infrastructure layer, and you manage only the Cortex XSOAR application.
[PreviousHosted Service](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide)
[NextService Limits](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6.12-hosted-service-guide/hosted-service/service-limits)
Last updated 7 days ago
Was this helpful?
Was this helpful?
---
# About the Cortex Gateway | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/gateway-guide/cortex-gateway.md)
.
Cortex Gateway is a centralized portal for managing roles, user groups, and users for all tenants. Any roles and user groups created in Cortex Gateway are available for all tenants.
Only users with the Account Admin role can manage roles, tenants, and user groups in Cortex Gateway.
[NextActivate a tenant](https://cortex-docs.paloaltonetworks.com/gateway-guide/activate-a-tenant)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Introduction to Demisto SDK | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/readme.md)
.
The Demisto SDK is a Python library designed to aid the development process, both to validate entities being developed and to assist in the interaction between your development setup and Cortex XSOAR or Cortex XSIAM. This guide provides information about installation and setup, as well as a detailed description of Demisto SDK commands.
[NextInstall Demisto SDK](https://cortex-docs.paloaltonetworks.com/demisto-sdk-development-guide/demisto-sdk-guide/install-demisto-sdk)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Cortex XSIAM Release Information | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information.md)
.
Cortex Extended Security Intelligence and Automation Management (XSIAM) is an AI-driven SOC platform that aims to learn how to outpace threats and accelerate your response.
To view the current operational status of Palo Alto Networks cloud services including Cortex XSIAM and maintenance releases, see [https://status.paloaltonetworks.com/](https://status.paloaltonetworks.com/)
. We recommend that you subscribe to the status page for service-related announcements.
[NextFeatures introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-rn/cortex-xsiam-release-information/features-introduced-in-2026-xsiam)
Last updated 6 days ago
Was this helpful?
Was this helpful?
---
# Tutorials | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme.md)
.
[Ingest Incidents from a SIEM Using QRadar](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme/ingest-incidents-from-a-siem-using-qradar)
[Ingest Incidents from a SIEM Using Splunk](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme/ingest-incidents-from-a-siem-using-splunk)
[Set up a Phishing Incident in Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme/set-up-a-phishing-incident-in-cortex-xsoar)
[Set up a Malware Incident Using the Deployment Wizard](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme/set-up-a-malware-incident-using-the-deployment-wizard)
[NextIngest Incidents from a SIEM Using QRadar](https://cortex-docs.paloaltonetworks.com/tutorials/cortex-xsoar-tutorials/readme/ingest-incidents-from-a-siem-using-qradar)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Cortex XSOAR Platform Overview | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/readme.md)
.
Cortex XSOAR uses Python scripts to automate, integrate, and extend functionality. It is implemented as a single Linux service (demisto) and provides:
* The Cortex XSOAR UI
* Control and execution of integrations for collecting threat and incident data
* Incident response orchestration and automation through playbooks
Over 700 Marketplace content packs provide out-of-th- box (OOTB) integrations and playbooks supported by a common base of 300+ commands and automation scripts. While automations do support JavaScript and PowerShell, the most comprehensive support is for Python-based development.
The Cortex XSOAR service uses two mechanisms for communication: the REST API and standard input/ouput/error streams provided by Linux. The Cortex XSOAR browser-based UI uses the REST API. Scripts may also use the REST API for additonal functionality. The standard input/output/error streams are internal to the Cortex XSOAR server for communicating with automation scripts executed within Docker and Podman containers and are not directly accessed by user developed scripts.

cortex-xsoar-high-level-architecture.png
[NextWhere Cortex XSOAR Uses Python Scripts](https://cortex-docs.paloaltonetworks.com/python-development-quick-start-guide/cortex-xsoar-python-development-quick-start-guide/readme/where-cortex-xsoar-uses-python-scripts)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Cortex XSOAR Release Information | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/cortex-xsoar-release-information.md)
.
Cortex XSOAR combines security orchestration, incident management, and interactive investigation into a seamless experience. The orchestration engine is designed to automate security product tasks and weave in human analyst tasks and workflows.
To view the current operational status of Palo Alto Networks cloud services, including Cortex XSOAR 8 and maintenance releases, see [https://status.paloaltonetworks.com](https://status.paloaltonetworks.com/#about-this-site)
. This status page is updated two weeks before any deployment.
We recommend that you subscribe to the status page for service-related announcements.
These Release Notes are relevant for Cortex XSOAR SaaS. To view the Cortex XSOAR On-prem release notes, go to [Cortex XSOAR Release Information](https://cortex-docs.paloaltonetworks.com/xsoar-8-opp-release-notes)
.
[NextFeatures Introduced in This Release](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-this-release)
Last updated 5 days ago
Was this helpful?
Was this helpful?
---
# Cortex XSOAR Installation Guides | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/cortex-xsoar-installation-guides.md)
.
Choose the correct Cortex XSOAR 6 Installation documentation set. Use the latest supported version for new deployments.
Version
Status
Documentation
6.14
Latest supported version
[6.14 Installation Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.14)
6.13
Supported earlier version
[6.13 Installation Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.13/)
6.12
End-of-life
[6.12 Installation Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-installation-guides/6.12/)
Versions 5.5 to 6.11 are end-of-life and not supported.
Last updated 9 days ago
Was this helpful?
Was this helpful?
---
# How policies and rules work together | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/how-policies-and-rules-work-together.md)
.
Cloud Workload Policies\_serve as enforcement mechanisms that govern the responses to the identified findings, whereas _Cloud Workload Rules_ establish the criteria for evaluation but do not initiate any actions unless incorporated within a policy.
In the absence of an associated policy, rules exist solely as evaluative criteria and do not generate alerts or trigger any response actions. Policies determine how findings from rules are escalated to issues or preventive measures.
[PreviousCloud workload policies and rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules)
[NextCloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Kubernetes Resources Inventory | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory.md)
.
The Kubernetes Resources page provides a detailed microview of the individual components deployed inside your connected Kubernetes clusters. The Kubernetes resources are tracked and managed within the broader Unified Asset Inventory (UAI). You can access the Kubernetes Resources page by navigating to Modules → Kubernetes Security → Kubernetes Assets Inventory → Kubernetes Resources or from Inventory → Assets → Kubernetes Resources.
The Kubernetes Resource page is a very granular inventory of Kubernetes objects discovered by the Kubernetes Connector:
* Workloads: Deployments, ReplicaSets, StatefulSets, DaemonSets, Jobs, and CronJobs
* Identity: ServiceAccounts, ClusterRoles, Roles, RoleBindings, and ClusterRoleBindings
* Network/Configuration: Services, Endpoints, Ingresses, NetworkPolicies, ConfigMaps, and Secrets
Use the filter at the top of the page to customize precisely which resources you want to view. Selecting any resource in the inventory opens the detailed asset card. The asset card provides a detailed overview, including asset properties, such as its ID, provider, region, and the cluster it belongs to. It also includes a clickable relationship graph to visualize and understand the full context and dependencies of the resource within the cluster. The asset card also includes the resource's code and vulnerability findings.
[PreviousAgentless Kubernetes security](https://cortex-docs.paloaltonetworks.com/kubernetes-security/agentless-kubernetes-security)
[NextKubernetes pods](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory/kubernetes-pods)
Last updated 24 days ago
Was this helpful?
Was this helpful?
---
# Cortex XSOAR 6 Threat Intel Management Guides | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/cortex-xsoar-6-threat-intel-management-guides.md)
.
Choose the correct Cortex XSOAR 6 Threat Intel Management documentation set. Use the latest supported version for new deployments.
Version
Status
Documentation
6.14
Latest supported version
[6.14 Threat Intel Management Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14)
6.13
Supported earlier version
[6.13 Threat Intel Management Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.13)
6.12
End-of-life
[6.12 EoL Threat Intel Management Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.12)
#### End-of-life versions[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides#end-of-life-versions)
Versions 5.5 to 6.11 are end-of-life and not supported.
Last updated 26 days ago
Was this helpful?
Was this helpful?
---
# Where can I install the Cortex XDR agent? | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent.md)
.
The Cortex XDR agent is installed on supported physical and virtual endpoints.
Cortex XDR agent is a software component of the larger Cortex products. It provides both cloud workload and endpoint protection, depending on your license and deployment environment. Cortex XDR agent is installed on supported physical and virtual endpoints. As a comprehensive security solution, it secures a wide range of assets, from cloud environments (like containers and Kubernetes clusters) to traditional endpoints, and mobile devices. To ensure maximum protection of your endpoints, Palo Alto Networks recommends that you always deploy the latest maintenance version for each agent release.
Palo Alto Networks strives to support the latest major operating systems. When a new operating system is available, there may be a short delay in our support as we test interoperability.
Until a Cortex XDR agent release reaches its end-of-life status, the following support is provided:
* Microsoft operating systems are supported for three years beyond the end of Microsoft support.
* In general, other operating systems are supported until they reach end-of-life, or their extended life, as relevant.
* For Android, we support the latest Cortex XDR agent app that is available on the Google Play Store regardless of the app release date. An agent version that is no longer on Google Play will be supported for one year after the date of its release.
### Note[](https://cortex-docs.paloaltonetworks.com/compatibility-matrix#note)
The Cortex XDR agents for iOS, Android, 32-bit Windows, and version 7.5-CE agents, are not FedRamp compliant.
#### Agent releases[](https://cortex-docs.paloaltonetworks.com/compatibility-matrix#agent-releases)
To ensure maximum protection of your endpoints, Palo Alto Networks recommends that you always deploy the latest maintenance version for each agent release.
Critical Environment (CE) versions must be enabled in your Cortex system before use. CE versions are designed for sensitive and highly regulated environments. These versions receive full content update coverage and contain the same feature set as the standard line it is based on. Please note, that some bug fixes, introducing higher stability risk, may not be incorporated into the maintenance releases of these lines. Support is provided for CE versions for 24 months, while support for standard versions is provided for 9 months.
See [Cortex XDR Agent Releases](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Agent-Releases/Cortex-XDR-Agent-Releases)
for details and the release notes of the current agent versions. EOL versions may be shown in this document for information purposes only.
[NextEndpoint operating systems supported](https://cortex-docs.paloaltonetworks.com/compatibility-matrix/where-can-i-install-the-cortex-xdr-agent/endpoint-operating-systems-supported)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Cortex XSOAR 8 Feature Changes | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes/cortex-xsoar-8-feature-changes/cortex-xsoar-8-feature-changes.md)
.
Cortex XSOAR 8 comes in the following formats:
* Cortex XSOAR SaaS
* Cortex XSOAR On-prem
### Cortex XSOAR SaaS[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes#cortex-xsoar-saas)
Cortex XSOAR 8 SaaS is built on the Cortex Platform, which offers:
* Improved performance, scalability, and reliability
* Centralized user management
* An enhanced user experience unified with the broader Cortex portfolio
* Simplified deployment and onboarding across the Cortex portfolio
* Auto-scalability and built-in high availability
* Automatic software updates are free of compatibility issues
### Cortex XSOAR On-prem[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes#cortex-xsoar-on-prem)
Cortex XSOAR 8 On-prem offers the following:
* Unified look and feel
* Simplified deployment and onboarding
* Improved performance and reliability
* User-friendly installation with an easy-to-follow step-by-step TUI to install and configure Cortex XSOAR.
[NextComparison between Cortex XSOAR 6 and Cortex XSOAR 8](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes/cortex-xsoar-8-feature-changes/comparison-between-cortex-xsoar-6-and-cortex-xsoar-8)
Last updated 1 month ago
Was this helpful?
* [Cortex XSOAR SaaS](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes#cortex-xsoar-saas)
* [Cortex XSOAR On-prem](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-feature-changes#cortex-xsoar-on-prem)
Was this helpful?
---
# Cortex XSOAR 6 Multi-Tenant Guides | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/cortex-xsoar-6-multi-tenant-guides.md)
.
Choose the correct Cortex XSOAR 6 Threat Intel Management documentation set. Use the latest supported version for new deployments.
Version
Status
Documentation
6.14
Latest supported version
[6.14 Multi-Tenant Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.14/)
6.13
Supported earlier version
[6.13 Multi-Tenant Guide](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides/6.13/)
6.12
End-of-life
[6.12 EoL Multi-Tenant Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/)
#### End-of-life versions[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-multi-tenant-guides#end-of-life-versions)
Versions 5.5 to 6.11 are end-of-life and not supported.
Last updated 26 days ago
Was this helpful?
Was this helpful?
---
# Security finding categories | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph/security-finding-categories.md)
.
KSPM Graph displays security finding categories on every node in the graph. Each category can be enabled or disabled independently.
Category
Description
Vulnerabilities
Displays a severity histogram showing the distribution of Critical, High, Medium, and Low vulnerabilities detected in your container images and workload configurations.
Issues
Highlights misconfigurations and policy violations detected by CIS Kubernetes Benchmark assessments and custom security policies.
Malware
Shows a count of malware detections identified through runtime analysis of container images and workload file systems.
Secrets
Highlights exposed secrets, such as API keys, credentials, and certificates, detected in container images or workload environment variables.
Internet exposure
Provides a Boolean indicator identifying workloads and container images that are reachable from the public internet.
[PreviousAsset detail card](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph/asset-detail-card)
[NextKubernetes clusters](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-clusters)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Agentless Kubernetes security | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/agentless-kubernetes-security.md)
.
Agentless Kubernetes security is a KSPM collection method that discovers your Kubernetes clusters and collects their inventory and compliance posture without deploying any component inside the cluster. Instead of running the in-cluster Kubernetes Connector, Cortex uses the cloud provider APIs and the cluster's own managed control plane access model to read cluster state with read-only permissions.
You enable agentless collection at the cloud account level. When you onboard or edit a supported cloud account, select the Kubernetes Security capability to grant Cortex the scoped, read-only access it needs. Cortex then automatically discovers every supported cluster in that account and begins collecting Kubernetes inventory. There are no per-cluster installers to run and nothing to deploy in the cluster. Newly created clusters are discovered and collected automatically, and a scheduled refresh keeps agentless inventory current.
Use agentless collection when you need fast, broad visibility across many clusters, or for clusters where you cannot install in-cluster software. You can combine both methods: use agentless collection for broad coverage and deploy the Kubernetes Connector on the clusters that need deep in-cluster scanning, admission control prevention, and runtime protection. When a cluster is covered by both methods, the Kubernetes Connector takes precedence for collection, and agentless collection stops for that cluster, so you do not get duplicate inventory. Each cluster's collection method is shown by the scan method value on the Kubernetes Clusters page.
Agentless KSPM continuously scans existing and newly discovered Kubernetes clusters for deep Kubernetes inventory context, compliance insights, and misconfiguration findings. Vulnerabilities, secrets, malware, untrusted images, and other image-assurance insights are available when the relevant container images are scanned by supported image scanning sources, such as Agentless Disk Scanner, Registry Scanner, CLI scans, or other supported image assurance capabilities, and are correlated back to the Kubernetes workloads using those images.
Collected inventory and findings are surfaced in the Unified Asset Inventory (UAI), on the Kubernetes Clusters page, and in the KSPM Graph, alongside your Connector-collected clusters.
#### Capabilities not available with agentless collection (these require the Kubernetes Connector)[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/agentless-kubernetes-security#capabilities-not-available-with-agentless-collection-these-require-the-kubernetes-connector)
* **Admission control prevention**: Blocking non-compliant resources at kube-apiserver admission time. Prevention requires a webhook in the admission request path inside the cluster.
* **Real-time runtime protection**: Detecting and blocking malicious activity as the activity happens. Detection requires a component observing process, network, and file system activity on the Node.
* **Node-level (host) CIS Kubernetes Benchmark checks and deep in-cluster scanning**: Evaluating file permissions, mount options, and process arguments on the Node. The evidence for these checks exists only on the Node file system and is not exposed through the Kubernetes API, so no external scanner can collect it.
#### Requirements and supported platforms:[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/agentless-kubernetes-security#requirements-and-supported-platforms)
* Agentless Kubernetes security supports Amazon EKS, Google Cloud GKE, and Microsoft Azure AKS clusters. Clusters on other platforms (self-managed vanilla Kubernetes, OpenShift, and Rancher) require the Kubernetes Connector for KSPM coverage.
* A supported cloud account (AWS, Google Cloud, or Azure) onboarded with the Kubernetes Security capability enabled, which grants Cortex read-only access to discover and read your clusters.
* EKS clusters must use EKS access entries for authentication. Clusters that use a different authentication mode are not collected.
* GKE clusters must run Kubernetes version 1.28 or later and must have the DNS-based control plane endpoint enabled with access from external networks allowed, because Cortex connects to the GKE control plane through that endpoint. GKE clusters that expose only an IP-based control plane endpoint, or whose DNS-based endpoint does not allow external traffic, cannot be reached agentlessly. Use the Kubernetes Connector for those clusters.
* AKS clusters must have AKS-managed Microsoft Entra ID integration enabled, because Cortex authenticates to the AKS API server with a Microsoft Entra ID token. Clusters that use legacy Entra ID integration, or that use local accounts only, are not collected.
* AKS clusters must expose a publicly reachable API server. Private AKS clusters and clusters restricted by an Azure network security perimeter cannot be reached agentlessly. Use the Kubernetes Connector for those clusters.
[PreviousKubernetes clusters](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-clusters)
[NextKubernetes Resources Inventory](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory)
Last updated 8 days ago
Was this helpful?
Was this helpful?
---
# Cortex XSOAR 6 Administrator Guides | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/cortex-xsoar-6-administrator-guides.md)
.
Choose the correct Cortex XSOAR 6 documentation set. Use the latest supported version for new deployments.
Version
Status
Documentation
6.14
Latest supported version
[6.14 XSOAR Administrator Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/overview)
6.13
Supported earlier version
[6.13 XSOAR Administrator Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/readme)
6.12
End-of-life
[6.12 XSOAR Administrator Guide](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/learn-about-cortex-xsoar/overview)
Versions 5.5 to 6.11 are end-of-life and not supported.
Last updated 26 days ago
Was this helpful?
Was this helpful?
---
# KSPM dashboard | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-dashboard.md)
.
### Important[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-dashboard#important)
Users can access all information on the dashboard when their user access is scoped to view **All assets** or assigned to the Instance Administrator role. Otherwise, users with granular scoping set to **No assets** or **Select asset groups** will have limited access to the dashboard. For more information on Scope-Based Access Control (SBAC), see [Manage user scope](https://app.gitbook.com/s/mxWuY3s7AUvWfzCV9p1A/post-deployment-steps/manage-user-roles-and-access-management/manage-user-scope)
in the Cortex Cloud Runtime Security Documentation or [Manage user scope](https://app.gitbook.com/s/Hpcayc1yGiwVhvGJ7DK1/post-deployment-steps/manage-user-roles-and-access-management/manage-user-scope)
in the Cortex Cloud Posture Management Documentation.
The KSPM dashboard provides a centralized overview of your entire Kubernetes environment, enabling you to quickly identify risks and prioritize remediation actions. The KSPM dashboard is included in the predefined dashboards.
To access the KSPM dashboard, select **Dashboards & Reports** → **Dashboard** or **Modules** → **Kubernetes Security** → **KSPM Dashboard** . From the dashboard header, a drop-down menu lists all available predefined and custom dashboards. Select **KSPM**. You can use the filtering options at the top of the dashboard to focus on specific cloud accounts and clusters.
The dashboard consolidates critical security and operational data into the following widgets, allowing you to assess your security posture at a glance:
* **Kubernetes Assets Overview**: Obtain a high-level inventory of your Kubernetes environment, displaying the total count of clusters, namespaces, nodes, and workloads. Click on the drop-down icon for each asset to see a detailed breakdown of the Kubernetes platform type or workload. Click on an asset type to go to the **Kubernetes Resources** page, filtered according to that asset type.
* **Cluster Protection Coverage**: This widget shows the percentage of clusters that are fully protected for real time protection and posture management are installed on this cluster. protected with posture management, protected with real-time management, or unprotected. Identify your protection coverage gaps so that you can prioritize the riskiest clusters and onboarding of unprotected clusters. Click on the **more options** icon to see all clusters in the **Kubernetes Connectivity Management** page. Clicking on each state takes you to the Kubernetes Cluster page filtered by the state.
* **Malware Detected**: A list of cluster names and the total count of malware detected within them to allow for quick identification and response to active threats. Click a cluster row to open that cluster's asset side pane and investigate its findings. Click on the **more options** icon to go to the **Policy Management** page.
* **Cases and Issues**: Displays the total number of cases and issues currently opened across your Kubernetes environment. Click on the **more options** icon to go to the **Cases** or **Issues** pages.
* **Top Clusters by Vulnerabilities**: Kubernetes clusters are ranked based on the number of high-severity vulnerabilities, ranked by CVSS score. Click a cluster row to open that cluster's asset side pane and investigate its findings. Click on the **more options** icon to see all clusters in the **Kubernetes Connectivity Management** page or to go to the **Vulnerability Policies Management** page.
* **Secrets Detected in Clusters**: Shows the number of unsecured secrets found within your clusters. Click on the **more options** icon to go to the **Policy Management** page.
[PreviousUse kcli to mirror connector images](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry/use-kcli-to-mirror-connector-images)
[NextKSPM graph](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph)
Last updated 24 days ago
Was this helpful?
Was this helpful?
---
# Retention Policy and Enforcement | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy/cortex-xsoar-8-retention-policy-faqs/readme.md)
.
Cortex XSOAR SaaS operates a retention policy for the following data:
* Incidents
Incidents are retained for 6 months, by default, after the incident was created in Cortex XSOAR. For more information, see [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#incidents)
.
If using an MSSP/Multi-tenant environment, each child tenant has 6 months of incident retention by default. For more information, see [MSSP and Multi-Tenant Environments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#mssp-and-multi-tenant-environments)
.
* Indicators (not yet enforced)
Indicators will be limited according to your license. For more information, see [Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#indicators)
.
### Incidents[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#incidents)
Cortex XSOAR SaaS includes an incident storage limit and a nominal retention charge for extended incident storage, which enables us to ensure the seamless availability of data and provide you with a reliable and efficient platform.
The incident retention policy is now being enforced for customers. Incident retention license add-ons can be purchased to extend the retention period.
Users can permanently retain up to 1000 specific incidents depending on their needs. The incident retention policy does not delete retained incidents, even after the 6-month retention period and any extension license period. Retaining an incident can be done for compliance or incident management reasons to ensure that the most valuable incidents are kept on the tenant and not deleted by retention enforcement or accidental removal.
### Note[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#note)
The retention policy does not apply to users who migrated from Cortex XSOAR 6 or purchased Cortex XSOAR 8 before January 2024 until their license renewal. After which, the retention policy applies.
#### What is the default retention period for my Cortex XSOAR tenant?[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#what-is-the-default-retention-period-for-my-cortex-xsoar-tenant)
The default retention period for Cortex XSOAR incidents is 6 months.
#### How is the retention period calculated?[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#how-is-the-retention-period-calculated)
The incident retention period is calculated from when the incident was created in Cortex XSOAR.
#### Can I extend the retention period?[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#can-i-extend-the-retention-period)
You can easily extend the retention period according to your needs by purchasing a retention extension add-on.
#### Where can I find the tenant’s retention entitlement?[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#where-can-i-find-the-tenants-retention-entitlement)
The retention entitlement will be visible on the Cortex XSOAR license page **Settings & Info** → **Cortex XSOAR License**.

xsoar-license.png
### MSSP and Multi-Tenant Environments[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#mssp-and-multi-tenant-environments)
By default, each child tenant retains incidents for 6 months. The retention period is calculated from when the incident was created in Cortex XSOAR.
You can purchase incident retention licenses to extend the incident retention of one or more child tenants. These licenses, once purchased, are available in the Cortex Gateway for allocation to child tenants. For more information, see [Allocate incident retention licenses](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-3.-allocate-incident-retention-licenses)
.
### Note[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#note-1)
Once an incident retention license has been assigned to a child tenant, the license cannot be removed from the child tenant or assigned to another child tenant via the Cortex Gateway. If you need to remove or reassign an incident retention license, contact Customer Support.
If you delete a child tenant, any incident retention licenses assigned to that tenant are returned to the main account and can be reallocated.
#### How do I assign retention licenses to a new child tenant?[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#how-do-i-assign-retention-licenses-to-a-new-child-tenant)
You can assign retention licenses when creating a new child tenant.

child-retention.png
#### How do I assign retention licenses to an existing child tenant?[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#how-do-i-assign-retention-licenses-to-an-existing-child-tenant)
Users can manage child tenant retention licenses from Cortex Gateway.

license-activation-mt.png
When clicking Manage Incident Retention Licenses:

manage-retention.png
### Indicators[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#indicators)
Unlike incidents, indicators in Cortex XSOAR will not have a time limit. We will limit the number of indicators per tenant as follows:
License
Indicators
XSOAR + TIM
Up to 100 million indicators
XSOAR (No TIM license)
Up to 3 million indicators
#### When will Palo Alto Networks start to enforce indicators retention?[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#when-will-palo-alto-networks-start-to-enforce-indicators-retention)
Indicators retention enforcement is planned for 2025.
#### Can the number of indicators on my tenant be expanded?[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#can-the-number-of-indicators-on-my-tenant-be-expanded)
Customers with no TIM license can buy a TIM license and have up to 100 million indicators on their tenant. The number of indicators can’t exceed 100 million per tenant.
#### How will indicators be deleted when the limit has been exceeded?[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#how-will-indicators-be-deleted-when-the-limit-has-been-exceeded)
The indicators will be deleted from older to newer (FIFO). Indicators that are linked to open incidents will not be deleted.
Last updated 17 days ago
Was this helpful?
* [Incidents](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#incidents)
* [MSSP and Multi-Tenant Environments](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#mssp-and-multi-tenant-environments)
* [Indicators](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy#indicators)
Was this helpful?
---
# KSPM graph | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph.md)
.
The KSPM Graph provides a functional map of your infrastructure, moving away from static lists to an interactive visual interface. This allows for a direct drill-down workflow: navigate from global clusters down to specific workloads, nodes, and container images.
By mapping the actual visual map of your environment, the platform integrates security intelligence, such as vulnerabilities and misconfigurations, directly onto the relevant assets. This provides immediate context on how a specific security risk sits within your network.
**Key capabilities**:
* **Risk prioritization**: By presenting security posture as a hierarchical graph, security teams can easily identify which clusters, namespaces, and workloads carry the highest aggregated risk. Cortex then prioritizes aggregated risk based on all the findings, vulnerabilities, and internet exposure.
* **Granular filtering**: Apply client-side filtering with AND/OR logic to isolate specific resources that you want to focus on. namespaces, clusters, or labels. You can filter dimensions that include cloud provider, cluster name, cloud account, severity levels, and specific finding types. Filters persist seamlessly across your drill-down navigation.
* **Managing limited visibility**: A yellow status indicator on a cluster signifies limited visibility. This state occurs when the cluster connector is either non-functional or non-existent, typically due to a missing or incorrectly configured Kubernetes Posture Management (KSPM) connector. Without an active connector, the system cannot facilitate necessary data transmission.
In the Asset card, from the More Options menu, you can select to Deploy Connector.
* **Instant insights**: The popovers on any node instantly display a detailed security breakdown. From there, navigate to the full asset detail view for investigation.
#### Evaluate your security posture[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph#uuid-9c1c2d32-61df-f3de-b399-985980f0ebcc_bridgehead-id235388654629787)
KSPM Graph organizes your Kubernetes infrastructure into three navigable levels, each providing progressively deeper visibility. Access is integrated directly from the Kubernetes Assets.
Level
Description
Cluster level
Displays all Kubernetes clusters across cloud providers in a grid layout. Each cluster node shows aggregated security metadata, including the total count of vulnerabilities, issues, malware findings, secrets, and internet-facing assets.
Namespace level
When you expand a cluster, the graph shows the namespaces and VM instances. To identify risk levels and compliance status, drill down into individual namespaces and workloads for detailed risk assessment and compliance information.
Workload and container image level
When you expand a namespace, the graph shows individual workloads, such as deployments and jobs, and runtime container images. This view shows security findings, vulnerability severity histograms, risk scores, and internet exposure status to help you investigate them directly.
[PreviousKSPM dashboard](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-dashboard)
[NextAsset detail card](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph/asset-detail-card)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Manage Kubernetes Connector instances | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances.md)
.
1. Navigate to Settings → Data Sources & Integrations.
2. Find the Kubernetes instance by clicking on the Kubernetes name or using the **Search** field.
3. In the row for the Kubernetes instance, click **View Details**. The **Kubernetes Connectors** page is displayed with all deployed Kubernetes Connectors. To view all Kubernetes clusters, including ones that are not yet deployed, go to the **Kubernetes Connectivity Management** page.
4. In the **Kubernetes Connectors** page, click on a cluster name to open the details pane for that instance.
5. You can perform the following actions on each Kubernetes Connector instance:
Action
Instructions
Open Cluster Details
In the details pane, click the more options icon and select **Open Cluster Details**. The Asset Card for that Kubernetes cluster is displayed.
Edit Connector
In the row for the Kubernetes instance, right-click and select **Edit**. Alternatively, in the details pane, click the more options icon and select **Edit Connector**. In **Edit Kubernetes Connector**, edit the configurations and click **Apply Changes**.You must execute the updated template in the Kubernetes environment for the configuration changes to be applied.
Delete Connector
In the row for the Kubernetes instance, right-click and select **Delete**. Alternatively, in the details pane, click the more options icon and select **Delete Connector**. To remove the connector, you must manually run Kubernetes commands to delete the resources in the Kubernetes environment. The commands are listed [here](https://kubernetes.io/docs/reference/generated/kubectl/kubectl-commands#delete)
.
### Kubernetes Connectivity Management[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances#kubernetes-connectivity-management)
Navigate to **Settings** → **Data Sources & Integrations** and find the Kubernetes instances by clicking on the Kubernetes name or using the **Search** field. In the **Kubernetes Connectors** page, click **Kubernetes Connectivity Management** to view all detected Kubernetes clusters. Here, you can check if a cluster is connected, view the status, and see the connector version. When a new version of the Kubernetes Connector is available, you can update it here.
### Note[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances#note)
After uninstalling the Kubernetes connector, the connector status updates to Not connected 48 hours after the uninstall process is initiated.
[PreviousKubernetes pods](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory/kubernetes-pods)
[NextRun an on-demand Kubernetes cluster scan](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# What's New in Cortex XDR 5 | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/whats-new-in-cortex-xdr-5.md)
.
Introducing Cortex XDR 5, our latest major release, which brings powerful advancements to your AI-driven security operations. This version features significant enhancements, a more intuitive user experience, and updated terminology for a smoother, more effective workflow. Take time to review these release notes to understand the pivotal differences and improvements in this version.
These release notes cover the following key changes:
1. [Integrated Cloud Posture capabilities](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/integrated-cloud-posture-capabilities)
2. [Improved incident management workflow with cases and issues](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/improved-incident-management-workflow-with-cases-and-issues)
3. [Navigation bar and menu enhancements](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/navigation-bar-and-menu-enhancements)
4. [New unified Asset Inventory and cloud data sources](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/new-unified-asset-inventory-and-cloud-data-sources)
5. [Built-in automations](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/built-in-automations)
6. [Scope-Based Access Control (SBAC) changes and enhancements](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/scope-based-access-control-sbac-changes-and-enhancements)
7. [Additional features and enhancements](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/additional-features-and-enhancements)
8. [Early upgrade with flexible scheduling](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/early-upgrade-with-flexible-scheduling)
[NextIntegrated Cloud Posture capabilities](https://cortex-docs.paloaltonetworks.com/upgrade-to-cortex-xdr-5/integrated-cloud-posture-capabilities)
Last updated 24 days ago
Was this helpful?
Was this helpful?
---
# Kubernetes Security | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-security.md)
.
The Kubernetes Security Posture Management (KSPM) capability, driven by the Kubernetes Connector component, is positioned as a core security module within Cortex Cloud. KSPM is a lightweight cloud-native solution for Kubernetes security, both posture management and real-time protection that automatically discovers assets, enforces policies, and scans for vulnerabilities, malware, secrets, and misconfigurations across the environment.
The Cortex Cloud KSPM offering focuses on deep security posture and compliance checks:
* Inventory and visibility: KSPM provides full visibility into your Kubernetes cluster and resources, including namespaces, nodes, and workloads. The KSPM dashboard provides a visual overview including inventory insights and cluster protection coverage to show which cluster have no protection solution deployed.
* Compliance and misconfiguration detection: KSPM leverages hundreds of out-of-the-box KSPM rules. It detects compliance violations and misconfigurations using built-in and custom rules mapped to compliance controls. Compliance checks include CIS Benchmarks for both managed and unmanaged Kubernetes distributions. Custom rules are supported using Rego for the Kubernetes Connector, and Python for XDR Agent endpoints.
* Vulnerability, malware, and secret scanning: KSPM receives critical security information related to vulnerabilities, malware, secrets, and other available scanners. The KSPM dashboard includes metrics for malware detected and secrets detected in clusters
* Policy enforcement and control: By enabling an admission controller, you can ensure that all resources created within the cluster adhere to the desired security and governance standards, enhancing the overall security posture of your environment. The admission controller intercepts requests to the Kubernetes API server before they are persisted, allowing enforcement of access control, [image assurance](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies/trusted-image-cloud-workload-policies)
, and security configurations.
* Centralized policy management: The offering provides centralized [Cloud Workload Policy management](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies)
and enforcement at runtime when the admission controller is utilized.
* Real-time threat detection and response (XDR): Beyond static posture, the solution provides active XDR capabilities to detect and intercept threats as they happen. It monitors live cluster activity to identify malicious behavior, zero-day attacks, and unauthorized runtime changes. This ensures that instead of just finding vulnerabilities, you are actively defending your environment against ongoing attacks with immediate visibility and automated response.
[NextWhat's new in Kubernetes Connector?](https://cortex-docs.paloaltonetworks.com/kubernetes-security/whats-new-in-kubernetes-connector)
Last updated 14 days ago
Was this helpful?
Was this helpful?
---
# Asset detail card | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph/asset-detail-card.md)
.
To analyze a resource in more detail, select View Asset to open the asset card. The card includes these tabs:
Tab
Description
Overview
Provides a high-level summary of the resource's identity, security posture, and critical threats such as vulnerabilities or malware. It includes a health status of security scans and an interactive graph to visualize dependencies.
Resource Explorer
Provides a breakdown of associated assets, featuring visual graphs for Assets per Namespace and Assets per K8S Category, along with a detailed table listing resource specifics such as asset name, type, category, and tags.
Identity
Maps the permissions and access controls associated with the resource, illustrating relationships between its identity and associated roles or services.
Configurations
Displays cloud configuration issues associated with the asset, tracking details such as severity and category. It also provides the raw Asset Configuration JSON for deep inspection of the asset's properties and metadata.
Vulnerabilities
Provides a detailed breakdown of all detected security findings associated with the resource. It offers a centralized view to help assess and prioritize the remediation of known security issues.
SBOM
Provides a comprehensive inventory of all software components and dependencies detected within the resource, tracking identification metadata and scan timing.
Network
Summarizes the resource's connectivity and exposure by displaying networking metadata and security controls. It allows users to analyze traffic boundaries, firewall policies, and network rules governing the assets across the cloud or cluster network.
Compliance
Evaluates the resource's adherence to regulatory requirements and industry benchmarks by presenting an overall security score. It provides a breakdown of audit results, highlighting which controls are met and which require immediate attention to mitigate risk.
**Workloads context**: The workloads section specifically identifies managed workloads, including Deployments, DaemonSets, StatefulSets, CronJobs, and ReplicaSets not managed by deployments, and jobs not managed by a CronJob.
[PreviousKSPM graph](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph)
[NextSecurity finding categories](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph/security-finding-categories)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Mirror connector images to a private registry | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry.md)
.
Mirror container images from the Cortex Cloud source registry to your private registry, enabling secure, air-gapped Kubernetes cluster deployments.
**Notice**
Licensed under the Apache License, Version 2.0.
### What is image mirroring?[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry#what-is-image-mirroring)
Image mirroring is the process of copying container images from a source registry to a private registry under your control. This capability is essential for organizations operating in air-gapped environments, restricted networks, or those requiring centralized image governance.
The Cortex Cloud Konnector Image Mirroring CLI (kcli) automates this process by pulling multi-architecture konnector images from the Cortex source registry, pushing them to your private registry, and rewriting your Helm values file to reference the mirrored images. This eliminates the need for cluster nodes to access external registries during deployment, reducing attack surface and enabling compliance with network isolation policies.
### Why image mirroring matters[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry#why-image-mirroring-matters)
* **Network isolation**: Clusters pull images from internal registries only, not from external sources
* **Compliance**: Meets requirements for air-gapped deployments and restricted egress policies
* **Supply chain control**: Centralize image governance and scanning before deployment
* **Deployment reliability**: Eliminates external registry dependencies during cluster operations
### Scope and limitations[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry#scope-and-limitations)
#### What kcli does[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry#what-kcli-does)
* Pulls multi-architecture konnector images from the Cortex source registry
* Pushes images to your private registry
* Rewrites your Helm values file to reference the mirrored images
#### What kcli does not do[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry#what-kcli-does-not-do)
* Execute `helm install` or `helm upgrade` commands (the portal's installation wizard is the source of truth)
* Create Kubernetes Secret resources in your cluster
* Manage Namespaces, RBAC, or cluster prerequisites
* Commit or push the rewritten values file to Git (GitOps workflows must handle this)
* Commit or push the rewritten values file to Git (GitOps workflows must handle this)
[PreviousDeploy with ArgoCD](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops/deploy-with-argocd)
[NextUse kcli to mirror connector images](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry/use-kcli-to-mirror-connector-images)
Last updated 25 days ago
Was this helpful?
* [What is image mirroring?](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry#what-is-image-mirroring)
* [Why image mirroring matters](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry#why-image-mirroring-matters)
* [Scope and limitations](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry#scope-and-limitations)
Was this helpful?
---
# Release Information | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information.md)
.
Cortex XDR 5.x sets a new standard in Extended Detection and Response (XDR) solutions, offering comprehensive protection, detection, and response capabilities. By analyzing data from the Cortex endpoint and various third-party sources, it effectively counters evolving threats in the cybersecurity landscape. Cortex XDR 5.x goes beyond traditional endpoint security, providing full visibility across network, endpoint, cloud, third-party, and identity sources.
To view the current operational status of Palo Alto Networks cloud services including Cortex XDR 5.x apps, see [https://status.paloaltonetworks.com/](https://status.paloaltonetworks.com/)
. We recommend that you subscribe to the status page for service-related announcements.
If you are upgrading from XDR 3 to XDR 5, review the essential release information outlining the key changes between these major versions. XDR 5 introduces significant updates to the user experience, including updated terminology designed to support a smoother and more effective investigation workflow.
[NextFeatures introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x-rn/release-information/features-introduced-in-2026-xdr-5x)
Last updated 26 days ago
Was this helpful?
Was this helpful?
---
# Learn about Cortex Xpanse | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse.md)
.
Before you get started with Cortex Xpanse, review the topics in this section to better understand what attack surface management is, what the key use cases are, and how it works.
[NextWhat is Cortex Xpanse?](https://cortex-docs.paloaltonetworks.com/cortex-xpanse/learn-about-cortex-xpanse/what-is-cortex-xpanse)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Types of cloud workload policies | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies.md)
.
* **Misconfiguration policies:** Enables you to assess various workloads for misconfigurations against relevant security standards and your organization’s security guidelines. You can include both predefined and custom rules in these policies to either prevent violations or create issues for violations.
* **Malware policies:** Enable you to detect and manage malicious files within cloud workloads. These policies analyze files based on predefined parameters such as file name, path, size, and detection method.
* **Secret policies:** Enable you to identify and protect sensitive information—such as API keys and credentials—within workloads.
* **Trusted Image policies:** Enable you to ensure the authenticity, integrity, and security of container images and VMs deployed into your Kubernetes environments. This includes actions such as limiting allowed image sources, mitigating possible image tampering, and more.
[PreviousCloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies)
[NextTrusted image cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies/trusted-image-cloud-workload-policies)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Kubernetes clusters | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-clusters.md)
.
The Kubernetes Clusters page provides a macro view of the entire cluster environment discovered by Cortex Cloud. The inventory view displays details about each cluster, including the cluster name, Kubernetes platform, Kubernetes version, cloud account, the scan method used to collect its data (Agentless or Connector), and its connectivity status. You can access the Kubernetes Clusters page by navigating to Modules > Kubernetes Security > Kubernetes Assets Inventory or from Inventory > Assets > All Assets > Compute.
The Kubernetes Clusters page provides a high-level overview of the containerized infrastructure through three primary data widgets:
* Kubernetes Clusters Distribution: Displays the total count of managed clusters segmented by their respective hosting platforms (e.g., EKS, GKE, OpenShift, AKS).
* Kubernetes Version Distribution: Provides a breakdown of the specific Kubernetes software versions currently running across the active environment.
* Protection Coverage: Offers a security status view that highlights the proportion of clusters where the security connector is either deployed or remains undeployed, indicating overall security visibility.
* Scan Method Distribution: Shows how clusters are distributed across collection methods (Agentless, Connector, or not collected). This widget is available from the widget dropdown above the clusters table and is not displayed by default.
The Kubernetes Clusters table serves as the central location for granular cluster management. It offers a comprehensive, detailed view of each cluster, enabling administrators to assess the specific status and metadata of individual assets within the environment.
You can access the Kubernetes Connectivity Management page from the Kubernetes Clusters page to view cluster connectors and all related information.
Key functional aspects include:
* **Asset visibility**: Provides a centralized list of all clusters, including hosting platforms, versions, account identifiers, and custom tagging for easy categorization.
* **Operational status**: Allows you to track Last Seen and Last Scan timestamps to ensure real-time visibility and audit readiness across the environment.
* **Scan method and connectivity**: Each cluster shows the method used to collect its data, Agentless or Connector, and its connectivity status (Healthy, Error, or Warning). When a cluster is not Healthy, open the cluster's side panel to view the connectivity status reason.
* **Connectivity & Remediation**: Displays the current deployment state of security connectors. Click the Deploy button at the top of the page to launch the Kubernetes Connector and manage the deployment of security connectors for your clusters.
* **Customization & Filtering**: Supports flexible data manipulation through filter controls and configurable display settings to tailor the view based on specific investigation or reporting needs.
Data for the Resource Explorer and Vulnerabilities tabs are populated with data once the posture management solution is deployed.
Selecting a cluster in the table opens its detailed asset card. The tabs displayed depend on the cluster's connection status and may include:
* **Overview**: Summarizes the high-level identifying details and security posture of the cluster. Cluster details, including asset ID, provider, cloud region, and asset groups. The Overview tab also shows the cluster's scan method and connectivity status, and it displays connector details for Connector-managed clusters. A clickable relationship graph allows you to visualize and understand the full context and dependencies of the cluster.
* **Resource Explorer**: Provides granular visibility into the specific assets deployed within the cluster. It includes a detailed list of discovered resources, including the namespace (when applicable), asset name, asset type, and category type.
* **Identity**: Displays the list of identities that can access this Kubernetes cluster.
* **Configurations**: Lists security configuration issues detected within the Kubernetes cluster. For each issue, you can view the severity, name, category, and creation date. You can also view the asset configuration JSON.
* **Vulnerabilities**: Details all discovered vulnerabilities found within the container images running in the cluster, as well as for the host operating systems of your Kubernetes nodes.
[PreviousSecurity finding categories](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-graph/security-finding-categories)
[NextAgentless Kubernetes security](https://cortex-docs.paloaltonetworks.com/kubernetes-security/agentless-kubernetes-security)
Last updated 23 days ago
Was this helpful?
Was this helpful?
---
# Default (pre-defined) rules | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/default-pre-defined-rules.md)
.
Cortex Cloud includes a number of pre-defined rules to secure your cloud runtimes. These rules are used by default policies to prevent security violations and create issues.
[PreviousCloud workload rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules)
[NextCustom (user-defined) rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/custom-user-defined-rules)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Playbooks | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/readme.md)
.
[What Are Playbooks?](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/readme/what-are-playbooks)
[Playbook Development](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/readme/playbook-development)
[Configure IoT Security Playbooks](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/readme/configure-iot-security-playbooks)
[NextWhat Are Playbooks?](https://cortex-docs.paloaltonetworks.com/playbook-design-guide/playbook-design-guide/readme/what-are-playbooks)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Cloud workload rules | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules.md)
.
**Rules**: Cloud Workload Rules define the criteria for identifying security violations. This criteria can be applied to assets in your cloud environment and to findings generated by Cortex Cloud.
Rules only enable the detection of security violations. They must be included in a policy to trigger a preventive response or generate an alert in the form of an issue.
[PreviousCloud workload preventive action](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action)
[NextDefault (pre-defined) rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/default-pre-defined-rules)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Edit a custom detection rule | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/edit-a-custom-detection-rule.md)
.
1. Navigate to **Posture Management** → **Rules & Policies** → **Rules** → **Cloud Workload**.
2. In the **Cloud Workload Rules** page, click the rule you want to edit.
3. In the **Details** page, click the **More Options** icon (**⋮**) and then click **Edit**.
4. Make the necessary changes.
5. Click **Update** to save the changes.
[PreviousUse an existing rule to create a new custom detection rule](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/use-an-existing-rule-to-create-a-new-custom-detection-rule)
[NextDelete a custom detection rule](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/delete-a-custom-detection-rule)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Widgets panel | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/widgets-panel.md)
.
The widget panel provides a visual summary of cloud workload policies.
Use the panel to view policy information by policy type or evaluation stage. You can show or hide the panel as needed.
### Show or hide the widget panel[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/widgets-panel#show-or-hide-the-widget-panel)
To hide the widget panel, do the following:
1. Navigate to **Posture Management** → **Rules & Policies** → **Policies** → **Cloud Workload**.
2. On the Cloud Workload Policies page, click the Widget Panel icon at the top of the page.
3. The panel toggles between visible and hidden states.
[PreviousCloud workload policies page](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page)
[NextChange the layout of the policies table](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/change-the-layout-of-the-policies-table)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Change the layout of the policies table | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/change-the-layout-of-the-policies-table.md)
.
1. Navigate to **Posture Management** → **Rules & Policies** → **Policies** → **Cloud Workload**.
2. In the Cloud Workload Policies page, click the More Options icon (**⋮**).
3. In the Layout tab, do the following:
* To remove columns, go to the **In View** section and search for a specific column. Click **\-** next to the column to remove it from the table.
* To reorder columns, go to the **In View** section. Click and drag columns up or down to rearrange the columns.
* To add new columns, go to the **Add Columns** section. Click **+** next to the columns to include them in the table.
4. The table layout updates automatically based on your selections.
[PreviousWidgets panel](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/widgets-panel)
[NextPolicy details panel](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/policy-details-panel)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Use an existing rule to create a new custom detection rule | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/use-an-existing-rule-to-create-a-new-custom-detection-rule.md)
.
1. Navigate to **Posture Management** → **Rules & Policies** → **Rules** → **Cloud Workload**.
2. In the **Cloud Workload Rules** page, click the policy you want to enable or disable.
3. In the **Details** page, click the **More Options** icon (**⋮**) and then select **Save as new**.
4. Modify the fields as required.
5. Click **Create** to create the new custom detection rule.
[PreviousCreate a new custom detection rule](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/create-a-new-custom-detection-rule)
[NextEdit a custom detection rule](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/edit-a-custom-detection-rule)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Delete a custom detection rule | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/delete-a-custom-detection-rule.md)
.
1. Navigate to **Posture Management** → **Rules & Policies** → **Rules** → **Cloud Workload**.
2. In the **Cloud Workload Rules** page, click the rule you want to delete.
3. In the **Details** page, click the **More Options** icon (**⋮**) and then select **Delete**.
4. In the confirmation message, click **Delete**.
[PreviousEdit a custom detection rule](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/edit-a-custom-detection-rule)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Cloud workload policies | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies.md)
.
Cloud Workload Policies help you prevent and manage security violations in your cloud runtime instances. They enable you to apply detection logic to specific asset groups at the desired SDLC stage, and define what action needs to be taken if the conditions are met.
### Depending on the nature of the security violation, a Cloud Workload Policy allows you to[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies#depending-on-the-nature-of-the-security-violation-a-cloud-workload-policy-allows-you-to)
* **Prevent the violation.** Enable proactive prevention of the violation. For example: Block an S3 bucket deployment that is open to the public.
* **Create an issue.** Create an issue when violation is seen. For example: Create an issue when an AWS credential file is found on a Linux server.
#### Note[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies#note)
Issues are automatically resolved when the finding is no longer applicable to the asset or when the affected asset is removed from the inventory.
For more details on Prevent and create issues, see [Cloud Workload Preventive Action](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action)
.
### A Cortex Cloud Workload Policy has the following elements:[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies#a-cortex-cloud-workload-policy-has-the-following-elements)
* **SDLC Evaluation Stage:** The SDLC stage at which the policy is applied and evaluated. Depending on the policy type, one or more of the following stages may be available:
* **CI:** The stage during which a pipeline builds the artifact. After building the artifact, the pipeline pushes it to a registry.
* **Deploy:** The stage when the artifact is pushed to a cloud instance for running.
* **Runtime:** The stage when the artifact is running on a cloud instance.
* **Rule (Conditions):** The logical conditions that will trigger the evaluation of this policy.
* **Scope:** A filter specifying which assets the rule applies to.
* **Action:** The response triggered when the rule evaluates successfully (only when part of a policy). Based on the rules included in the policy, it can create an issue or prevent the security violation.
[PreviousHow policies and rules work together](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/how-policies-and-rules-work-together)
[NextTypes of cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies)
Last updated 14 days ago
Was this helpful?
* [Depending on the nature of the security violation, a Cloud Workload Policy allows you to](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies#depending-on-the-nature-of-the-security-violation-a-cloud-workload-policy-allows-you-to)
* [A Cortex Cloud Workload Policy has the following elements:](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies#a-cortex-cloud-workload-policy-has-the-following-elements)
Was this helpful?
---
# Deploy the Kubernetes Connector via GitOps | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops.md)
.
Deploy and manage the Kubernetes Connector (konnector-bundle Helm chart) across multiple Kubernetes clusters using a complete GitOps setup. Implement this repository structure to use either ArgoCD or Flux CD as your primary controller.
**GitOps controller comparison**
* ArgoCD: Recommended if you want a visual UI for managing deployments, need real-time drift detection, require built-in rollback with history, and prefer a GUI-based workflow.
* Flux CD: Recommended if you want native Helm release management (`helm install`), need Helm hooks support, and prefer a pure CLI/GitOps workflow.
**Prerequisites**
Before you begin, ensure you have the following:
* A Kubernetes cluster with `kubectl` configured.
* The `helm` CLI installed for pulling charts from OCI registries
* The `flux` CLI and/or `argocd` CLI installed.
* A Git repository accessible from within the cluster.
* Access to the `konnector-bundle` OCI registry.
[PreviousOpenShift container registry](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/openshift-container-registry)
[NextRepository architecture and tenant management](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops/repository-architecture-and-tenant-management)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Cortex XSOAR 8 On-prem Documentation | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/cortex-xsoar-8-on-prem-documentation.md)
.
Choose the correct Cortex XSOAR 8 on-prem documentation set. Use the latest supported version for new deployments.
**Looking for Cortex XSOAR 8 SaaS documentation?** Go to [Cortex XSOAR 8 SaaS documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas)
.
Version
Status
Documentation
8.14
Supported earlier version
[Cortex XSOAR 8.14 On-prem Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14)
8.13
Supported earlier version
[Cortex XSOAR 8.13 On-prem Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13)
8.12
Supported earlier version
[Cortex XSOAR 8.12 On-prem Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12)
8.11
Supported earlier version
[Cortex XSOAR 8.11 On-prem Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.11)
8.10
Supported earlier version
[Cortex XSOAR 8.10 On-prem Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10)
#### End-of-life versions[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem#end-of-life-versions)
Use these versions only if you maintain an existing deployment.
View older versions[](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem#view-older-versions)
* [Cortex XSOAR 8.9 EoL Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9)
* [Cortex XSOAR 8.8 EoL Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8)
* [Cortex XSOAR 8.7 EoL Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.7)
* [Cortex XSOAR 8.6 EoL Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6)
* [Cortex XSOAR 8.5 EoL Documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5)
Last updated 8 days ago
Was this helpful?
Was this helpful?
---
# Release Information | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information.md)
.
Cortex XDR consumes and correlates data from the Cortex Native Data Lake to reveal threat causalities and timelines—it's your mission control for complete visibility into all your endpoint and network traffic. The Cortex XDR app triggers alerts based on indicators of compromise (including behavioral anomalies). Cortex XDR is a single interface from which you can investigate and triage alerts, take remediation actions, and define policies to prevent future attacks.
To view the current operational status of Palo Alto Networks cloud services including Cortex XDR apps and maintenance releases, see [https://status.paloaltonetworks.com/](https://status.paloaltonetworks.com/)
. We recommend that you subscribe to the status page for service-related announcements.
[NextFeatures introduced in 2026](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2026-xdr)
Last updated 2 months ago
Was this helpful?
Was this helpful?
---
# Cortex XDR Agent Documentation | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/cortex-xdr-agent-documentation.md)
.
Choose the correct Cortex XDR Agent documentation set. Use the latest supported version for new deployments.
Version
Status
Documentation
9.3
Latest supported version
[Cortex XDR Agent 9.3 documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.3)
9.2
Supported earlier version
[Cortex XDR Agent 9.2 documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.2)
9.1
Supported earlier version
[Cortex XDR Agent 9.1 documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1)
9.0
Supported earlier version
[Cortex XDR Agent 9.0 documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.0)
8.7-CE
Supported earlier version
[Cortex XDR Agent 8.7 documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.7)
#### End-of-life versions[](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent#end-of-life-versions)
Use end-of-life documentation only for existing deployments.
View older versions[](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent#view-older-versions)
* [Cortex XDR Agent 8.9 documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.9)
* [Cortex XDR Agent 8.8 documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.8-eol)
* [Cortex XDR Agent 8.6 documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol)
Last updated 8 days ago
Was this helpful?
---
# Policy details panel | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/policy-details-panel.md)
.
The policy details panel is displayed when you click a policy in the policy table. To view details of a cloud workload policy:
1. Navigate to **Posture Management** → **Rules & Policies** → **Policies** → **Cloud Workload**.
2. In the **Cloud Workload Policies** page, select the policy you want to check.
The policy panel displays the following details related to the selected policy:
* Policy details.
* Related rule settings.
* The number of issues opened as part of the policy. You can click on the link to navigate to the Issues and Casessection to check the issue details.
From the policy detail panel, you can:
* Enable or disable the policy
* Edit the policy
* Save as new
* Delete the policy
[PreviousChange the layout of the policies table](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/change-the-layout-of-the-policies-table)
[NextManage cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Custom (user-defined) rules | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/custom-user-defined-rules.md)
.
Custom Rules or Custom Detection Rules allow you to define and implement tailored security and compliance checks within cloud workloads. These rules enable organizations to detect specific conditions, vulnerabilities, or misconfigurations that might not be covered by built-in system rules.
A custom rule consists of the following components:
* **Scanner:** Defines the mechanism by which the rule inspects the cloud assets. You need to select the scanner type that will implement the rule. Every time the selected scanner runs, all the rules associated with that scanner are also executed. The available scanner types are:
* Agentless Disk Scan: Rules that use Agentless Disk Scanner to inspect the container images on which the Agentless scanner runs. You can specify different rules for containers running different OSes. For example, you can create a rule that checks for incorrect or malicious entries in the etc\\hosts file on Windows images.
* [Kubernetes Connector:](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Cloud-Documentation/What-s-new-in-Kubernetes-Connector)
Rules that use the Kubernetes Connector scanner to inspect Kubernetes environment variables and resources such as Namespaces, ReplicaSets, Deployments and more.
* [XDR Agent:](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Cloud-Documentation/Install-Cortex-XDR-agents)
Rules that use XDR Agent Scanner to perform custom compliance checks by executing user-defined Python scripts, offering a tailored approach to compliance validation.
* Rule (Condition): Defines the detection criteria. This is specified as Rego or Python statements that evaluate assets, findings, and their associated attributes to identify security violations based on the selected scanner.
* Severity: The selected value is included in issues that are created as a result of rule violation.
* Compliance Controls: Associates the custom rule with a custom compliance control. If the rule detects the security violation, it will invoke the corresponding compliance control, thereby including the violation in relevant compliance reports.
[PreviousDefault (pre-defined) rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/default-pre-defined-rules)
[NextCloud workload rules page](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Cortex XDR Agent iOS Guides | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/cortex-xdr-agent-ios-guides.md)
.
Choose the correct Cortex XDR Agent iOS documentation set.
Version
Documentation
9.3
[9.3 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.3/get-started/release-notes-for-cortex-xdr-agent-app-for-ios)
9.2
[9.2 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2)
9.1
[9.1 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1)
9.0
[9.0 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.0)
8.9
[8.9 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.9-agent-ios-guide)
8.8
[8.8 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.8)
8.7
[8.7 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7)
8.6
[8.6 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.6)
8.5
[8.5 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.5)
8.4
[8.4 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.4)
8.3
[8.3 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.3)
8.2
[8.2 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.2)
8.1
[8.1 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.1-agent-ios-guide)
8.0
[8.0 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.0)
7.9
[7.9 Agent iOS Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/7.9)
Last updated 1 day ago
Was this helpful?
Was this helpful?
---
# Kubernetes pods | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory/kubernetes-pods.md)
.
Kubernetes security provides comprehensive support for pods, including inventory tracking, detailed asset visibility, compliance scanning, and container inspection. This enhances protection across your workloads, whether they are managed by a controller (such as a deployment or job), deployed directly as standalone pods, or modified during admission before they run. Kubernetes security models the actual running pod, showing you the workload exactly as it operates in the cluster, including any changes applied after its definition.
Support for pods is available through the Posture Management solution of the Kubernetes Security offering. To collect pods, install either the agent-based Kubernetes Connector or Agentless KSPM.
Pods are where your workloads actually run. By modeling both directly, Kubernetes security gives you a complete, instance-level view of your clusters:
* See the real running state of every workload, not only its desired state as defined by the controller.
* Extend security coverage to workloads deployed directly as pods, for example, with `kubectl apply -f pod.yaml`, so standalone workloads are fully represented alongside managed ones.
* Assess and prioritize risk at the container-instance level, providing your teams with precise context for investigation and remediation.
Key benefits include:
* **Complete visibility**: A dedicated **Kubernetes Pod Group** in the inventory includes a relationship graph that shows how a pod connects to related Kubernetes resources. **Kubernetes Pod Groups** are also available in **Search Graph** for discovery and investigation.
* **Container inspection:** A **Containers** tab on each **Kubernetes Pod Group** asset provides complete visibility into pod composition and container details, including each container's name, image, exposed ports, command, arguments, and **Container type**: **Main** (your application's primary container), **Init** (runs to completion before the main container starts), or **Sidecar** (a helper container that runs alongside the main container). You can filter the **Containers** tab to focus on specific containers and export the container data for reporting or offline analysis. Use the **Kubernetes Pod Group** to investigate the security posture of individual pods and their containers.
* **Compliance and rules**: Run compliance checks on pods alongside workload controllers, including system-rule validation for pod-scoped Rego rules. Custom compliance rules also support pods.
* **Scalable by design**: Identical replicas are automatically aggregated into a single **Kubernetes Pod Group** asset, so you gain full visibility without inventory clutter in large clusters. **Kubernetes Pod Group** aggregation is available for both the Kubernetes connector (agent) and Kubernetes agentless deployments. Standalone pods and pods owned by unsupported kinds (for example, Node-owned static pods) each produce their own single-replica **Kubernetes Pod Group** with **Is Standalone** = true. Agentless deployments collect pods that are linked to a controlling workload.
### Kubernetes Pod Group[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory/kubernetes-pods#kubernetes-pod-group)
Kubernetes clusters can run thousands of pods, most of which are identical replicas of the same workload. To keep your inventory clear and eliminate clutter, Kubernetes security automatically aggregates identical pods into a single **Kubernetes Pod Group** asset. When you access **Kubernetes Resources** in the **Kubernetes Resources** page, you can filter by the **Kubernetes Pod Group** type to view these assets.
Each **Kubernetes Pod Group** reports the following properties:
* **Replicas**: The number of identical pods aggregated into the group.
* **Is Standalone**: Indicates whether the pod was created directly (with no controlling owner) or is managed by a controller.
* **Containers**: Details on the containers running in the pod, including name, image, exposed ports, commands, arguments, and container type (**Main**, **Init**, or **Sidecar**).
With the Kubernetes connector, standalone pods and pods owned by unsupported resource types are represented individually so nothing is hidden from the inventory.
A **Kubernetes Pod Group** asset represents all identical Pod replicas of a workload as a single, unique inventory asset based on the workload owner's unique identifier.
### Relationships graph for Kubernetes Pod Groups in Search Graph[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory/kubernetes-pods#relationships-graph-for-kubernetes-pod-groups-in-search-graph)
**Kubernetes Pod Groups** participate in the **Search Graph** asset relationship graph like other workloads. In addition to standard workload relationships, they include the following:
* **Owned by**: Links a **Kubernetes Pod Group** to its controlling workload (ReplicaSet, StatefulSet, DaemonSet, or Job).
* **Runs**: Links the **Kubernetes Pod Group** to the container images it runs.
* **Routes traffic to/selected by**: Services and NetworkPolicies that target the workload also resolve to the corresponding **Kubernetes Pod Group**.
**Note**:
These relationships are available in **Search Graph** only.
Selecting a **Kubernetes Pod Group** in the **Kubernetes Resources** inventory opens its asset card, where you can review its overview, configuration, containers, security findings, and relationships within the cluster.
[PreviousKubernetes Resources Inventory](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory)
[NextManage Kubernetes Connector instances](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances)
Last updated 9 days ago
Was this helpful?
* [Kubernetes Pod Group](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory/kubernetes-pods#kubernetes-pod-group)
* [Relationships graph for Kubernetes Pod Groups in Search Graph](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-resources-inventory/kubernetes-pods#relationships-graph-for-kubernetes-pod-groups-in-search-graph)
Was this helpful?
---
# Rule details panel | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/rule-details-panel.md)
.
The rule panel displays the following details related to the selected rule:
* Details of the rule like scanner details, remediation details and more.
* Compliance Controls for the rule.
This panel enables you to:
* Edit the rule
* Save as new
* Delete the rule
[PreviousChange the layout of the rules table](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/change-the-layout-of-the-rules-table)
[NextCreate a new custom detection rule](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/create-a-new-custom-detection-rule)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Cloud workload policies and rules | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules.md)
.
Cloud workload policies and rules help you identify, manage, and prevent security violations in cloud workloads.
Rules define the criteria that identify a violation. Policies apply rules to a scope and define the response.
### Get started[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules#get-started)
1. Learn [how policies and rules work together](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/how-policies-and-rules-work-together)
.
2. Review [cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies)
.
3. Review [cloud workload rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules)
.
### Manage policies[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules#manage-policies)
Use policies to define the scope, evaluation stage, and action for security violations.
* Explore the available [types of cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies)
.
* Learn how to [create a cloud workload policy](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies)
.
* Manage policies from the [Cloud workload policies page](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page)
.
### Manage rules[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules#manage-rules)
Use rules to define the conditions that detect security violations.
* Review [default (pre-defined) rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/default-pre-defined-rules)
.
* Learn about [custom (user-defined) rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/custom-user-defined-rules)
.
* Manage rules from the [Cloud workload rules page](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page)
.
[PreviousRun an on-demand Kubernetes cluster scan](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan)
[NextHow policies and rules work together](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/how-policies-and-rules-work-together)
Last updated 14 days ago
Was this helpful?
* [Get started](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules#get-started)
* [Manage policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules#manage-policies)
* [Manage rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules#manage-rules)
Was this helpful?
---
# Deploy with ArgoCD | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops/deploy-with-argocd.md)
.
Deploy the Cortex KSPM agent to on-premises Kubernetes clusters using ArgoCD. ArgoCD is a declarative GitOps continuous delivery tool that automates agent deployment and configuration synchronization from a Git repository.
1. Install ArgoCD.
AskCopy
kubectl create namespace argocd
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
2. Connect ArgoCD to a git repository.
AskCopy
# HTTPS based authentication
cat <
password:
EOF
AskCopy
# SSH based authentication
cat <
-----END OPENSSH PRIVATE KEY-----
EOF
3. Apply the ArgoCD Application manifest.
AskCopy
kubectl apply -f charts/overlays/application.yaml
[PreviousDeploy with Flux CD](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops/deploy-with-flux-cd)
[NextMirror connector images to a private registry](https://cortex-docs.paloaltonetworks.com/kubernetes-security/mirror-connector-images-to-a-private-registry)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# OpenShift container registry | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/openshift-container-registry.md)
.
The OpenShift Container Registry provides visibility into the container images stored within your OpenShift environment. When you deploy the Kubernetes Connector on an OpenShift platform, the system automatically discovers and creates registry instances for monitoring.
When adding an instance of Kubernetes from **Data Sources & Integrations**, the setting **Registry Scanning (OpenShift Only)** must be configured to enable automatic scanning of an OpenShift container registry. By default, scanning operates in a concurrency-limited mode (10 images at a time) to minimize resource impact on the cluster while maintaining thorough security coverage.
Manage OpenShift registry instances[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/openshift-container-registry#manage-openshift-registry-instances)
You can view and manage the registry instances automatically created by your OpenShift Kubernetes deployment.
* Data source page: Displays a list of all discovered OpenShift registry instances.
* Key details: For each instance, you can quickly see the status, instance name, and associated cluster name.
View instance details[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/openshift-container-registry#view-instance-details)
To gain deeper insights into a specific registry, click on one of the instances from the table of the **OpenShift Container Registry**. This opens a page that includes detailed information about the particular instance.
The detailed dashboard provides the following information:
* **Status**: The current operational state of the registry instance.
* **Kubernetes Connector Status**: Indicates the health and connectivity of the connector managing the registry.
* **Repositories**: The total count of image repositories discovered within the registry.
* **Scan Mode**: Displays the current scanning configuration.
* **Registry Scanning**: Shows the real-time status of the cluster. Click on the **Status**, which navigates you to a dashboard that shows the total number of assets and their current status, and the **Health Audits** of the specific cluster.
Repository inventory[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/openshift-container-registry#repository-inventory)
The instance details page includes a granular list of all repositories found within the OpenShift registry. This list includes:
* **Name**: The identifier for the specific image repository.
* **Repository Type**: Categorization of the repository within the OpenShift environment.
Actions[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/openshift-container-registry#actions)
From the top left side of the page, click the More Options () to:
* **Exclude/Include images**: You can configure scoping rules to include or exclude specific images and repositories from scans based on their names or tags. While updates apply to all future scans, previously excluded images will only be processed during a subsequent system-wide rescan.
* **Discover Now**: Triggers the discovery and then scanning of newly discovered assets.
Access OpenShift from Kubernetes[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/openshift-container-registry#access-openshift-from-kubernetes)
You can also view important details about your OpenShift registry from the Kubernetes data source. From the list of clusters in the Kubernetes table, select the OpenShift registry to view:
* **Connector Details**: Shows last scan, connector status and connector version of the OpenShift platform.
* **Cluster Details**: Click the link to view the asset card of the [OpenShift cluster](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kubernetes-clusters)
.
* **Deployment Details**: Shows deployment method used and the deployment date.
[PreviousOnboard the Kubernetes Connector](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector)
[NextDeploy the Kubernetes Connector via GitOps](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# XSIAM Data Model Schema | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/readme.md)
.
Cortex XSIAM enables you to map your logs into a single, unified data model. This data model provides a consolidated schema, and a simpler way to interact with your data, regardless of its source or dataset. This includes information about the Cortex Data Model (XDM) fields, consts, fieldsets, and aliases.
How this reference is organized[](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema#how-this-reference-is-organized)
------------------------------------------------------------------------------------------------------------------------------------
This reference documents the Cortex Data Model (XDM). It is arranged into the following sections:
* [**Aliases**](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases)
— Named groups of XDM fields you can reference in the Cortex Query Language (XQL) using a filter stage. Each alias resolves to a set of member fields.
* [**Consts**](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts)
— Enumerated constant sets (`XDM_CONST.*`). Each const page lists the original source values and the normalized XDM values they map to.
* [**Fieldsets**](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fieldsets)
— Curated collections of XDM fields grouped for a common purpose, such as a pre-defined set of the most relevant fields.
* [**Fields**](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/fields)
— The XDM field tree (`xdm.*`). Container nodes group related fields; leaf nodes describe a single field with its datatype, dataclass, and examples.
* [**System Fields**](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/system-fields)
— The reserved system fields that Cortex XSIAM populates automatically for every event, such as `_time` and `_product`.
Each field describes its datatype and dataclass. When a field's datatype is an enumerated const, it links to the corresponding const page. Aliases and fieldsets link to the pages of the fields they reference wherever those fields can be resolved.
[NextXDM Aliases](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/aliases)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Get started with Cortex XSOAR 6.x APIs | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/get-started-with-cortex-xsoar-6-apis.md)
.
[Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs/)
is a comprehensive security orchestration, automation and response (SOAR) platform that unifies case management, automation, real-time collaboration and threat intel management to serve security teams across the incident lifecycle. Using the Cortex XSOAR APIs, you can integrate Cortex XSOAR with third-party apps or services. The APIs allow you to create and search for incidents, search for indicators, and retrieve a widget's statistics.
Before you can begin using Cortex XSOAR APIs, you must generate the following items from Cortex XSOAR:
Value
Description
**API Key**
The API Key is your unique identifier used as the `Authorization:{key}` header required for authenticating API calls.
**FQDN**
The FQDN is a unique host and domain name associated with each tenant.
Cortex XSOAR API URIs are made up of your tenant's FQDN, the API name, and endpoint path. For example, `https://{fqdn}/{endpoint_path}/.`
> #### Note[](https://cortex-docs.paloaltonetworks.com/xsoar-6-api#note)
>
> In Cortex XSOAR OPP, you must add a DNS record that points the Cortex XSOAR DNS name that is mapped to the API IP address. For example, `api-xsoar.mycompany.com`.
The following steps describe how to generate the necessary key values and run your first API call:
1. [Create a new API key](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/create-a-new-api-key)
.
2. [Make your first API call](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/make-your-first-api-call)
.
[NextCreate a new API key](https://cortex-docs.paloaltonetworks.com/xsoar-6-api/create-a-new-api-key)
Last updated 27 days ago
Was this helpful?
Was this helpful?
---
# Change the layout of the rules table | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/change-the-layout-of-the-rules-table.md)
.
1. Navigate to **Posture Management > Rules > Cloud Workload**.
2. In the **Cloud Workload Rules** page, click the **More Options** icon (**⋮**).
3. In the **Layout** tab, do the following:
* To add or remove columns, search for a specific column and:
* Click **+** to add it to the table.
* Click **\-** to remove it from the table.
* To reorder columns, go to the **In View** section and **click and drag** columns up or down.
* To add new columns, go to the **Add Columns** section and click **+** to include them in the table.
1. The table layout updates automatically based on your selections.
[PreviousFilter page results](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/filter-page-results)
[NextRule details panel](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/rule-details-panel)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Cloud workload preventive action | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action.md)
.
Some Cloud Workload policies provide a Prevent and Create an Issue action that enforces compliance during deployments.
### Prevention action for Runtime stage Policies[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action#prevention-action-for-runtime-stage-policies)
The Prevent action at Runtime applies only to Kubernetes Workload Images assets.
When a Kubernetes Workload image violates a policy, the Kubernetes Admission Controller (on clusters where the KSPM Connector is deployed and Admission Control is enabled) can block it from being admitted to the cluster.
For all other asset types within the policy scope, no runtime prevention will occur. Instead, the violation will result in an Issue being created.
### Prerequisites[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action#prerequisites)
Deploy your cluster via the **Kubernetes connect** wizard. After your clusters are connected, you can manage and monitor your Kubernetes clusters for posture management and real-time protection.
To access the **Kubernetes connect** page, navigate to the following URL in your tenant environment: `https://[TENANT-ADDRESS]/cwp/k8s-management.`
### Admission controller[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action#admission-controller)
This option is enabled via the **Kubernetes connect** wizard in the **Posture management** solution option. **Policy enforcement by the admission controller** must be enabled for the admission controller to evaluate requests that help you set the right policy scope and avoid unexpected blocks.
The admission controller manages the following:
* Kubernetes object-level enforcement based on workload specs, including Deployments, StatefulSets, DaemonSets, ReplicaSets, Jobs, and CronJobs.
* Create and update operations, re-evaluating the entire object for policy violations on every change, including simple scaling or replica updates.
* Visibility for already-running workloads, surfacing existing policy violations as issues without disrupting or deleting the active resources.
* Image-based blocking, relying on pre-existing scan results in the backend (such as CI, registry, or Agentless Disk Scanner results) to enforce policies without adding latency at admission time.
* Trusted Images validation, blocking a workload that lacks a valid, up-to-date scan result in the backend when the policy uses the **Prevent** action on a cluster where the admission controller is enabled.
### Important considerations[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action#important-considerations)
* **Recommended Approach**: Begin with the **Create an Issue** action to validate results before selecting **Prevent and Create an Issue**. This helps prevent potential disruptions to your applications or development workflows.
* **Impact on New Deployments**: The **Prevent and Create an Issue** action affects only new or future deployments that meet the prevention criteria. It does not impact cloud workload assets that are already deployed.
### Prevention action for CI stage Policies[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action#prevention-action-for-ci-stage-policies)
Prevention actions in the CI stage triggers a pipeline failure by returning an exit code of 2 in the CI tool.
[PreviousManage cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies)
[NextCloud workload rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules)
Last updated 24 days ago
Was this helpful?
* [Prevention action for Runtime stage Policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action#prevention-action-for-runtime-stage-policies)
* [Prerequisites](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action#prerequisites)
* [Admission controller](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action#admission-controller)
* [Important considerations](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action#important-considerations)
* [Prevention action for CI stage Policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action#prevention-action-for-ci-stage-policies)
Was this helpful?
---
# Run an on-demand Kubernetes cluster scan | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan.md)
.
On-demand scanning applies to individual Kubernetes clusters managed by an active Cortex Cloud KSPM connector. On-demand scanning does not replace scheduled scan cycles and does not support bulk operations across multiple clusters simultaneously.
**Prerequisites**
Before requesting an on-demand scan, verify the following:
* A KSPM connector is deployed on the target cluster. If no connector is deployed, the context menu displays a **Deploy connector** option instead of **Request scan**.
* Ensure the Kubernetes connector for the target cluster is active and sends heartbeats to Cortex Cloud every 15 minutes.
* The KSPM connector is running version 2.0 or later. This version includes redefined cluster-level RBAC permissions that enhance security by restricting access to specific namespaces where possible.
If the Kubernetes connector for the target cluster sent a heartbeat more than 15 minutes ago, the Kubernetes Cluster Scan Now dialog displays the message: Action temporarily unavailable. The connector connectivity cannot currently be verified.
The Request scan option is available to all Cortex Cloud users with access to the Kubernetes Clusters inventory. No additional role-based permissions are required to request a scan.
### Scan types[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan#scan-types)
The Request scan dialog provides the following scan types:
Scan type
Description
Cooldown period
Inventory
Collects and updates the full inventory of Kubernetes resources in the cluster.
1 hour
Nodes and containers
Scans all nodes in the cluster, including container images, for vulnerabilities and misconfigurations.
6 hours
The nodes and containers scan is both CPU and memory-intensive. Run the scan no more than once every six hours to avoid performance degradation on the target cluster.
Each scan type enforces a cooldown period after a successful request. When a scan type is in cooldown, the corresponding checkbox is disabled, and a countdown badge indicates when the next scan request becomes available.
### Request an on-demand scan[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan#request-an-on-demand-scan)
The Request scan option is available from two locations in the Cortex Cloud console:
1
#### Open the Request scan dialog[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan#open-the-request-scan-dialog)
1. Go to **Kubernetes Asset Inventory** → **Kubernetes Clusters**.
2. Right-click the target Kubernetes cluster row and select **Request scan**. Alternatively, open the asset detail panel and select **Request scan** from the actions menu.
2
#### Select scan types[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan#select-scan-types)
1. In the **Request scan** dialog, review the cluster details: cluster name, cluster distribution (EKS, AKS, GKE, OpenShift, or Kubernetes), cloud account name, and cloud provider.
2. Under **Select scan type**, select one or both scan types: **Inventory scan** and **Nodes & containers scan**.
3. Select **Request**.
If the connector version is earlier than 2.0, the Request scan option appears as Request scan (Update required) and is disabled. Upgrade the Kubernetes connector to version 2.0 or later to enable on-demand scanning.
### Results[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan#results)
After a successful request, Cortex Cloud displays the Scan Requested confirmation, followed by one of the following messages:
* An Inventory scan was successfully requested
* A Nodes and Containers scan was successfully requested
* The connector is inactive (no heartbeat received in the last 15 minutes).
### Known limitations[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan#known-limitations)
* The scan executes after the next connector heartbeat (approximately 30 seconds), not immediately upon request.
* Bulk scan requests across multiple clusters simultaneously are not supported.
* Customization of cooldown periods is not available through the Cortex Cloud console.
* A historical audit log of on-demand scan requests is not available.
[PreviousManage Kubernetes Connector instances](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances)
[NextCloud workload policies and rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules)
Last updated 24 days ago
Was this helpful?
* [Scan types](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan#scan-types)
* [Request an on-demand scan](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan#request-an-on-demand-scan)
* [Results](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan#results)
* [Known limitations](https://cortex-docs.paloaltonetworks.com/kubernetes-security/manage-kubernetes-connector-instances/run-an-on-demand-kubernetes-cluster-scan#known-limitations)
Was this helpful?
---
# Deploy with Flux CD | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops/deploy-with-flux-cd.md)
.
Deploy the Cortex KSPM agent to on-premises Kubernetes clusters using Flux CD. Flux CD is a declarative GitOps continuous delivery tool that automates agent deployment and configuration synchronization from a Git repository.
1. Install the following Flux controllers:
* Source Controller
* Kustomize Controller
* Helm Controller
* Notification Controller
AskCopy
flux install
2. Verify that all controllers are running.
AskCopy
flux check
AskCopy
#Expected output:
✔ helm-controller: deployment ready
✔ kustomize-controller: deployment ready
✔ notification-controller: deployment ready
✔ source-controller: deployment ready
3. Create the authentication secret.
AskCopy
# For username/password or token (HTTP)
kubectl create secret generic gitlab-auth \
--namespace=flux-system \
--from-literal=username=\ \
--from-literal=password=\
#For SSH-based authentication
flux create secret git gitlab-auth \
--namespace=flux-system \
--url=ssh://git@gitlab.example.com/kspm/kspm-gitops.git \
--private-key-file=
4. Create a GitRepository source.
AskCopy
flux create source git kspm-gitops \
--url=https://gitlab.example.com/kspm/kspm-gitops.git \
--branch=main \
--interval=1m \
--secret-ref=gitlab-auth \
--namespace=flux-system
5. Verify the source is connected.
AskCopy
flux get source git kspm-gitops
AskCopy
#Expected output:
NAME REVISION SUSPENDED READY MESSAGE
kspm-gitops main@sha1:abc123 False True stored artifact for revision 'main@sha1:abc123'
6. Deploy the connector.
AskCopy
flux create kustomization kspm-agent \
--source=GitRepository/kspm-gitops \
--path="./charts/overlays" \
--prune=true \
--interval=5m
[PreviousRepository architecture and tenant management](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops/repository-architecture-and-tenant-management)
[NextDeploy with ArgoCD](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/deploy-the-kubernetes-connector-via-gitops/deploy-with-argocd)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Cortex XDR Agent Releases | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/agent-release-notes/cortex-xdr-agent-releases/readme.md)
.
Click the link to view the new features and addressed issues per release. Agent releases are divided into deployments, the release date shown here is the first date that the agent is made available.
**Major release**
**Release Notes**
**Release Date**
9.3
[Cortex XDR agent 9.3](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes)
July 26, 2026
9.2
[Cortex XDR agent 9.2](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.2)
May 3, 2026
9.1-CE
[Cortex XDR agent 9.1-CE](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1-ce)
June 15, 2026
9.1
[Cortex XDR agent 9.1.1](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1/cortex-xdr-agent-release-information/addressed-issues/addressed-issues-911)
[Cortex XDR agent 9.1](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.1)
June 10, 2026 January 25,2026
9.0
[Cortex XDR agent 9.0.1](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.0/agent-9.0-release-information/addressed-issues-in-agent-9.0/addressed-issues-in-cortex-xdr-agent-9.0.1)
[Cortex XDR agent 9.0](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.0)
March 16, 2026 November 9, 2025
8.9
[Cortex XDR agent 8.9.1](https://cortex-docs.paloaltonetworks.com/8.x/cortex-xdr-agent-8.9-release-information/addressed-issues-in-cortex-xdr-agent-8.9/addressed-issues-in-cortex-xdr-agent-8.9.1)
[Cortex XDR agent 8.9](https://cortex-docs.paloaltonetworks.com/8.x)
January 5, 2026 July 20, 2025
8.7-CE
[Cortex XDR agent 8.7.101-CE](https://cortex-docs.paloaltonetworks.com/8.x/8.7ce/cortex-xdr-agent-8.7-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.7-ce/addressed-issues-in-cortex-xdr-agent-8.7.101-ce)
[Cortex XDR agent 8.7-CE](https://cortex-docs.paloaltonetworks.com/8.x/8.7ce)
February 18, 2026 June 25, 2025
8.3-CE
[Cortex XDR agent 8.3.102-CE](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.3-ce/cortex-xdr-agent-8.3.102-ce-addressed-issues)
[Cortex XDR agent 8.3.101-CE Linux](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.3-ce/cortex-xdr-agent-8.3.101-ce-addressed-issues)
[Cortex XDR agent 8.3.101-CE Windows](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce/cortex-xdr-agent-8.3-ce-release-information/addressed-issues-in-cortex-xdr-agent-8.3-ce/cortex-xdr-agent-8.3.101-ce-addressed-issues)
[Cortex XDR agent 8.3-CE](https://cortex-docs.paloaltonetworks.com/8.x/8.3ce)
November 24, 2025 January 13, 2025 December 3, 2024 May 21, 2024
7.9-CE
[Cortex XDR agent 7.9.103-CE](https://cortex-docs.paloaltonetworks.com/7.x)
November 11, 2024
[NextCortex XDR Hotfix Releases](https://cortex-docs.paloaltonetworks.com/agent-release-notes/cortex-xdr-agent-releases/cortex-xdr-hotfix-releases)
Last updated 22 days ago
Was this helpful?
Was this helpful?
---
# Cortex XDR Agent Android Guides | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/cortex-xdr-agent-android-guides.md)
.
Choose the correct Cortex XDR Agent Android documentation set.
Version
Documentation
9.3
[9.3 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.3/release-notes-for-cortex-xdr-app-for-android)
9.2
[9.2 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2)
9.1
[9.1 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.1)
9.0
[9.0 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.0)
8.9
[8.9 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.9)
8.8
[8.8 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.8)
8.7
[8.7 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/8.7)
8.6
[8.6 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.6)
8.5
[8.5 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.5)
8.4
[8.4 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.4)
8.3
[8.3 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.3)
8.2
[8.2 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.2)
8.1
[8.1 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.1)
8.0
[8.0 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/8.0)
7.1.3
[7.1.3 Agent Android Guide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/7.1.3)
Last updated 1 day ago
Was this helpful?
Was this helpful?
---
# Linux Kernel Versions | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/readme.md)
.
This reference documents the Linux kernel module versions supported by the Cortex XDR agent. It lists, for each supported Linux distribution, the kernel versions the agent can protect, along with the minimal agent version and minimal content version required for that support.
This reference is for administrators and security engineers who deploy the Cortex XDR agent on Linux hosts and need to confirm whether a given kernel is supported before rolling out or upgrading the agent.
How this reference is organized[](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions#how-this-reference-is-organized)
----------------------------------------------------------------------------------------------------------------------------------
Support information is arranged in a three-level hierarchy:
* **Distribution** — A Linux distribution, such as Ubuntu or Red Hat Enterprise Linux (RHEL).
* **Architecture** — The CPU architecture, either x86\_64 or aarch64.
* **OS version** — A major version of the distribution, such as Ubuntu 22 or RHEL 9.
Each OS-version page lists a table of the supported kernel versions. For every kernel version, the table shows the minimal Cortex XDR agent version and the minimal content version required to support it.
Covered distributions[](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions#covered-distributions)
--------------------------------------------------------------------------------------------------------------
This reference covers the following distributions:
* AlmaLinux
* Amazon Linux
* Amazon Linux 2
* Amazon Linux 2023
* CentOS
* CentOS Stream
* Debian
* OpenSUSE
* Oracle Linux
* Photon OS
* Red Hat Enterprise Linux (RHEL)
* Rocky Linux
* SUSE Linux Enterprise Server
* Ubuntu
Find a supported kernel[](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions#find-a-supported-kernel)
------------------------------------------------------------------------------------------------------------------
To check whether a kernel is supported, navigate the table of contents in the left navigation:
1. Select your distribution to open its landing page.
2. Select the architecture that matches your host (x86\_64 or aarch64).
3. Open the page for your OS version and locate your kernel version in the table.
The minimal agent version and minimal content version shown next to a kernel version indicate the earliest Cortex XDR agent and content releases that support it.
[NextAlmaLinux](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions/almalinux)
Last updated 1 month ago
Was this helpful?
* [How this reference is organized](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions#how-this-reference-is-organized)
* [Covered distributions](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions#covered-distributions)
* [Find a supported kernel](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions#find-a-supported-kernel)
Was this helpful?
---
# Supported Kubernetes distributions | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/supported-kubernetes-distributions.md)
.
The following are the supported Kubernetes platform versions for the Kubernetes connector (Posture Management). The table shows the latest version that is supported. We support n-3 versions of each supported Kubernetes environment.
Kubernetes environment
Notes
Managed clusters
* Amazon Elastic Kubernetes Service (EKS)
* Microsoft Azure Kubernetes Service (AKS)
* Google Kubernetes Engine (GKE)
**Note**
Does not include Autopilot.
Managed OpenShift
Managed Openshift clusters, including ROSA (Red Hat OpenShift on AWS), are supported.
Self-Managed
We support every CNCF-certified Kubernetes solution. We've tested our solution on:
* Self-managed vanilla/on-premise Kubernetes clusters.
* Self-managed OpenShift Kubernetes clusters.
* Rancher Distributions (RKE and RKE2).
The following are the Kubernetes platforms that are supported with Cortex XDR agents (Real-time protection).
This table shows the Kubernetes platform versions that have been compatibility tested. The table shows the latest version that has been tested. All versions that are not EOL, up to the latest version are supported.
Linux Kubernetes Platform
Version
Unmanaged Kubernetes (k8s)
1.30
Amazon Elastic Kubernetes Service (EKS)
1.33
BottleRocket OS x86\_64
User mode agent only
BottleRocket OS aarch64
User mode agent only
Microsoft Azure Kubernetes Service (AKS)
1.33
CBL-mariner 2 x86\_64
Google Kubernetes Engine (GKE)
1.33
Google Container-Optimized OS (COS)^(\*) x86\_64
User mode agent only
Google Kubernetes Engine (GKE) Autopilot
Oracle Kubernetes Engine (OKE)
1.33
Red Hat Openshift Container Platform (OCP)
4.16
RHCOS^(\*) x86\_64
User mode agent only
SUSE Rancher Kubernetes Engine 2 (RKE2)
1.28
Talos
1.8.3
### Note[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/supported-kubernetes-distributions#note)
In Google Container-Optimized OS release 100 and earlier, where the FANOTIFY EXEC flag is not supported, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.
In RHCOS version 4.12 and earlier, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.
[PreviousKSPM limitations and system components](https://cortex-docs.paloaltonetworks.com/kubernetes-security/kspm-limitations-and-system-components)
[NextOnboard the Kubernetes Connector](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Get Started with Xpanse APIs | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/xpanse-api/get-started-with-cortex-xpanse-apis.md)
.
Using the Cortex Xpanse APIs, you can integrate [Cortex Xpanse](https://cortex-docs.paloaltonetworks.com/cortex-xpanse-docs/)
with third-party apps or services to ingest alerts, services, assets, and IP ranges and leverage investigation capabilities. The APIs allow you to manage incidents in a ticketing or automation system of your choice by reviewing and editing the incident's details, status, and assignee.
Before you can begin using Cortex Xpanse APIs, you must generate the following items from the Cortex Xpanse console:
Value
Description
**API Key**
The API Key is your unique identifier used as the `Authorization:{key}` header required for authenticating API calls. Depending on your desired security level, you can generate two types of API keys, Advanced or Standard, from your Cortex Xpanse app.
**API Key ID**
The API Key ID is your unique token used to authenticate the API Key. The header used when running an API call is `x-xdr-auth-id:{key_id}`.
**FQDN**
The FQDN is a unique host and domain name associated with each tenant. When you generate the API Key and Key ID, you are assigned an individual FQDN.
Cortex XPanse API URIs are made up of your unique FQDN, the API name, and name of call. For example, `https://api-{fqdn}/public_api/v1/{name of api}/{name of call}/.`
The following steps describe how to generate the necessary key values:
1. Get your Cortex Xpanse API Key.
1. In Cortex Xpanse, navigate to **Settings** > **Configurations** > **Integrations** > **API Keys**.
2. Select **\+ New Key**.
3. Choose the type of API Key you want to generate based on your desired security level: **Advanced** or **Standard**. The Advanced API key hashes the key using a nonce, a random string, and a timestamp to prevent replay attacks. cURL does not support this but is suitable with scripts. Use the provided script to create the advanced API authentication token.
> #### Note[](https://cortex-docs.paloaltonetworks.com/xpanse-api#note)
>
> To integrate with Cortex XSOAR you must generate a Standard Key.
1. If you want to define a time limit on the API key authentication, mark **Enable Expiration Date** and select the expiration date and time. Navigate to **Settings** > **Configurations** > **Integrations** > **API Keys** to track the **Expiration Time** field for each API key. In addition, Cortex Xpanse displays a API Key Expiration notification in the Notification Center one week and one day prior to the defined expiration date.
2. Provide a comment that describes the purpose for the API key, if desired.
3. Select the desired level of access for this key. You can select existing **Roles**, or you can select **Custom** to set the permissions on a more granular level.
> #### Note[](https://cortex-docs.paloaltonetworks.com/xpanse-api#note-1)
>
> Be sure to select a role with **View/Edit** access for the Public API. Use the predefined Instance Administrator role or a create a custom role with Public API permission. Roles are described in the Manage Roles section of the Cortex Xpanse User Guide.
1. **Generate** the API Key.
2. Copy the API key, and then click **Done**. This value represents your unique `Authorization:{key}`.
> You will not be able to view the API Key again after you complete this step. Ensure that you copy it before closing the notification.
2. Get your Cortex Xpanse API Key ID.
1. In the API Keys table, locate the **ID** field.
2. Note your corresponding **ID** number. This value represents the `x-xdr-auth-id:{key_id}` token.
3. Get your FQDN.
1. Right-click your API key and select **View Examples**.
2. Copy the **CURL Example** URL. The example contains your unique FQDN: `https://api-{fqdn}/public_api/v1/{name of api}/{name of call}/`
You can use the **CURL Example** URL to run the APIs.
4. Make your first API call. The following examples vary depending on the type of key you select. You can test authentication with Advanced API keys using the provided Python 3 example. With Standard API keys, use either the cURL example or the Python 3 example. Don’t forget to replace the example variables with your unique API key, API key ID, and FQDN tenant ID. After you verify authentication, you can begin making API calls.
[NextWhat's new in this release](https://cortex-docs.paloaltonetworks.com/xpanse-api/changes-to-the-api-in-this-release)
Last updated 27 days ago
Was this helpful?
Was this helpful?
AskCopy
curl -X POST https://api-{fqdn}/public_api/v1/{name of api}/{name of call}/
-H "x-xdr-auth-id:{key_id}"
-H "Authorization:{key}"
-H "Content-Type:application/json"
-d '{}'
AskCopy
import requests
def test_standard_authentication(api_key_id, api_key):
headers = {
"x-xdr-auth-id": str(api_key_id),
"Authorization": api_key
}
parameters = {}
res = requests.post(url="https://api-{fqdn}/public_api/v1/{name of api}/{name of call}",
headers=headers,
json=parameters)
return res
AskCopy
import requests
from datetime import datetime, timezone
import secrets
import string
import hashlib
import requests
def test_advanced_authentication(api_key_id, api_key):
# Generate a 64 bytes random string
nonce = "".join([secrets.choice(string.ascii_letters + string.digits) for _ in range(64)])
# Get the current timestamp as milliseconds.
timestamp = int(datetime.now(timezone.utc).timestamp()) * 1000
# Generate the auth key:
auth_key = "%s%s%s" % (api_key, nonce, timestamp)
# Convert to bytes object
auth_key = auth_key.encode("utf-8")
# Calculate sha256:
api_key_hash = hashlib.sha256(auth_key).hexdigest()
# Generate HTTP call headers
headers = {
"x-xdr-timestamp": str(timestamp),
"x-xdr-nonce": nonce,
"x-xdr-auth-id": str(api_key_id),
"Authorization": api_key_hash
}
parameters = {}
res = requests.post(url="https://api-{fqdn}/public_api/v1/{name of api}/{name of call}",
headers=headers,
json=parameters)
return res
---
# Cloud workload policies page | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page.md)
.
The **Cloud Workload Policies** page allows users to manage policies that define security and compliance actions for cloud workloads. Users can create, edit, filter, and manage policies through a structured table and widget panel.
#### Note[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page#note)
Keep the following caveats in my mind when working with Policies:
* Instance Administrators are able to view all facets of policies without restrictions, even if Scope Based Access Control (SBAC) roles are in effect. Learn more about [SBAC](file:///document/preview/1410276#UUID-c3eebdf1-af6e-6820-c11d-457e6aabae48)
.Manage user scope
* If you’ve been assigned a custom role with View/Edit permissions limited by SBAC, you may not be able to view certain policies.
* You can further narrow your search on the Inventory page by using SBAC to limit the scope of the finding, issue, and case counts.
The Cloud Workload Policies page displays all the configured policies with the following fields.
**Policy table columns**
**Field**
**Description**
**Policy Type**
Defines the policy category: **Misconfigurations, Secrets, Malware, Trusted Images**.
**Policy Name**
The user-defined name of the policy.
**Action**
Defines the action taken when conditions match: **Create an Issue** (logs an issue) or **Prevent and Create an Issue** (prevents the action and logs an issue).
**Severity**
The severity level of the issue created: **Critical, High, Medium, Low, or Informational**.
**Asset Groups**
Predefined groups of assets to which the policy applies.
**Open Issues**
The number of unresolved issues associated with the policy.
**Conditions**
Define the detection rule by specifying the criteria that match relevant malware, secret, or trusted image findings.
**Exceptions**
Defines the exclusion criteria to omit malware, secret, or trusted image findings that meet specific conditions you want to exclude from the policy.
**Evaluation Stage**
Indicates at which stage in the **SDLC** the policy is evaluated.
**Description**
Additional details about the policy.
**Created By**
The user who created the policy.
**Last Modified**
The timestamp of the last modification.
[PreviousTrusted image cloud workload policies](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/types-of-cloud-workload-policies/trusted-image-cloud-workload-policies)
[NextWidgets panel](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/widgets-panel)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Filter page results | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/filter-page-results.md)
.
You can use Show filter Panel button in the upper-right corner of the Rules page to filter the existing rules based on different filter criteria, as described below:
Table 1. Rule Filter table
Filter
Allowed Values
Rule Name
Rule names and empty values
Description
Rule description and empty values
Policies
No. of policies
Controls
No. of controls
Platform
_Linux, Windows and Kubernetes_
Scanner
_Agentless Disk Scan, Host Scanner, Kubernetes Connector, Kubernetes File System Scanner_ and _Inventory Scanner_
Data type
_Hosts, Kubernetes Resources_
Severity
_Informational, Low, Medium, High_ and _Critical_
Created by
System or specific username
Last modified
Selected date and time
Rule type
_Built-in_ and _Custom_
Remediation
Remediation values
Applicable assets
Supported applicable asset types
Available actions
_Prevent and Create an Issue_ and _Create an Issue_
Standards
Associated compliance standards or controls
Open Issues
No. of open issue
Rule ID
Unique Id of a rule
[PreviousCloud workload rules page](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page)
[NextChange the layout of the rules table](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/change-the-layout-of-the-rules-table)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Cloud workload rules page | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page.md)
.
The **Cloud Workload Rules** page allows users to manage rules. Users can create, edit, filter, and manage rules.
#### Note[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page#note)
Keep the following caveats in my mind when working with Rules:
* Instance Administrators are able to view all facets of Rules without restrictions, even if Scope Based Access Control (SBAC) roles are in effect. Learn more about [SBAC](file:///document/preview/1410276#UUID-c3eebdf1-af6e-6820-c11d-457e6aabae48)
.Manage user scope
* If you’ve been assigned a custom role with View/Edit permissions limited by SBAC, you may not be able to view specific Rules.
* You can further narrow your search in a Rules table by using SBAC to limit the scope of the finding, issues, and case counts.
The Widget section enables the users to get 'at-a-glance' based on Platform, Rule type and Scanner type.
The Cloud Workload Rules page displays both the default rules and user-configured rules, with the following fields.
**Rule table columns**
Column Name
Description
**Rule ID**
A unique identifier assigned to each rule.
**Rule Name**
The name of the rule, typically defined by the user or system.
**Description**
A brief summary of the rule's purpose and functionality.
**Policies**
Lists the policies in which the rule is included.
**Controls**
Compliance controls associated with the rule for regulatory adherence.
**Platform**
Specifies the platform or environment the rule applies to. For example: **Linux, Windows**or **Kubernetes**.
**Scanner**
The tool or method used to evaluate findings, such as _Inventory Scanner_, _Agentless Disk Scan, Host Scanner, Kubernetes Connector or Kubernetes File System Scanner_ .
Severity
Defines the severity of the rule.
**Data Type**
The type of data the rule evaluates. For example: **Hosts** or **Kubernetes Resources**
**Created By**
The user who created the rule.
**Last Modified**
The date and time the rule was last updated.
**Rule Type**
Indicates whether the rule is a **Built-in** or Custom rule.
Remediation
Defines the remediation steps to address the detected misconfiguration.
**Applicable assets**
Supported applicable asset types.
**Available actions**
Indicates whether the available action is **Prevent and Create an Issue** or **Create an Issue**
**Standards**
Associated compliance standards or controls
**Open issue**
No. of open issue related to this rule.
[PreviousCustom (user-defined) rules](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/custom-user-defined-rules)
[NextFilter page results](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-rules/cloud-workload-rules-page/filter-page-results)
Last updated 25 days ago
Was this helpful?
Was this helpful?
---
# Manage cloud workload policies | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies.md)
.
Use Cloud Workload policies to detect risks and enforce actions across your workloads.
Open **Posture Management** → **Rules & Policies** → **Policies** → **Cloud Workload**.
### Create a policy[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#create-a-policy)
Select **Create Policy**, then select the policy type.
#### Misconfiguration policy[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#misconfiguration-policy)
1. Enter a unique name and description.
2. The evaluation stage is **Runtime**.
3. Select **Next**, then add the rules to evaluate.
4. Set rule severity, policy action, and remediation guidance as needed.
5. Select **Asset Groups** or **Default Asset Scopes** for the policy scope.
6. Select **Done**.
The policy summary updates as you configure its general settings, rules, and scope.
Misconfiguration policies work only at Runtime. The Kubernetes Admission Controller enforces them for clusters onboarded through the Posture Management connector.
Asset groups contain relevant compute assets only. A filter creates a dynamic group. Manually selected assets create a static group.
For Kubernetes Prevent policies, dynamic asset groups support these attributes:
* Kubernetes Resource Cluster, Namespace, Labels, Category, and Creation Time.
* Kubernetes Resource Name.
#### Malware policy[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#malware-policy)
1. Enter a unique name and description.
2. Select **CI**, **Runtime**, or **Deploy**.
3. Define detection criteria and optional exclusions.
4. Configure the scope for the selected stage.
5. Select an action, severity, and optional remediation guidance.
6. Select **Done**.
At **CI**, the policy covers all Cloud Workload Build Container Images. A Prevent action fails the pipeline with exit code `2`.
At **Runtime**, select asset groups or default asset scopes. Default scopes include all Cloud Workload assets, hosts, container images, container instances, Kubernetes workloads, and serverless functions.
At **Deploy**, select registry-image asset groups or all Cloud Workload registry images. Deploy policies create an issue by default.
#### Secret policy[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#secret-policy)
1. Enter a unique name and description.
2. Select **CI**, **Runtime**, or **Deploy**.
3. Define detection criteria and optional exclusions.
4. Configure the stage-specific scope and action.
5. Select **Done**.
The available scopes and actions match those for Malware policies. At CI, the policy applies to all Cloud Workload Build Container Images. At Runtime, choose asset groups or default asset scopes. At Deploy, choose registry-image asset groups or all registry images.
#### Trusted Images policy[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#trusted-images-policy)
1. Enter a unique name and description.
2. The evaluation stage is **Runtime**.
3. Define image trust criteria and any exclusions.
4. Choose **Asset Groups** or **Default Asset Scopes**.
5. Select an action, severity, and optional remediation guidance.
6. Select **Done**.
Use stable image identifiers, such as registries, signatures, or digests. Avoid mutable tags. Pre-ingest images when trust criteria depend on image metadata.
Exclude system-critical namespaces, such as `kube-system`, from the scope. A namespace-scoped asset group applies only to that namespace.
Select **Create an issue** to log a violation. Select **Prevent and create an issue** to block it and log an issue. Trusted Images policies also provide an action for unavailable trust verdicts.
### Enable or disable a policy[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#enable-or-disable-a-policy)
1. Select the policy.
2. On the **Details** page, use the toggle at the top.
### Copy a policy[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#copy-a-policy)
1. Select the policy.
2. On the **Details** page, select **More Options** (**⋮**) → **Save as new**.
3. Update the policy name, conditions, scope, or actions.
4. Select **Done**.
### Edit a policy[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#edit-a-policy)
1. Select the policy.
2. On the **Details** page, select **Edit**.
3. Make the required changes.
4. Select **Done**.
### Delete a policy[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#delete-a-policy)
1. Select the policy.
2. On the **Details** page, select **More Options** (**⋮**) → **Delete policy**.
3. Select **Delete** to confirm.
[PreviousPolicy details panel](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-policies-page/policy-details-panel)
[NextCloud workload preventive action](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/cloud-workload-preventive-action)
Last updated 25 days ago
Was this helpful?
* [Create a policy](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#create-a-policy)
* [Enable or disable a policy](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#enable-or-disable-a-policy)
* [Copy a policy](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#copy-a-policy)
* [Edit a policy](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#edit-a-policy)
* [Delete a policy](https://cortex-docs.paloaltonetworks.com/kubernetes-security/cloud-workload-policies-and-rules/cloud-workload-policies/manage-cloud-workload-policies#delete-a-policy)
Was this helpful?
---
# Get started with Cortex XSOAR 8.x APIs | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/get-started-with-cortex-xsoar-8-apis.md)
.
[Cortex XSOAR](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-docs/)
is a comprehensive security orchestration, automation and response (SOAR) platform that unifies case management, automation, real-time collaboration and threat intel management to serve security teams across the incident lifecycle. Using the Cortex XSOAR APIs, you can integrate Cortex XSOAR with third-party apps or services. The APIs allow you to create and search for incidents, search for indicators, and retrieve a widget's statistics.
Before you can begin using Cortex XSOAR APIs, you must generate the following items from Cortex XSOAR:
Value
Description
**API Key**
The API Key is your unique identifier used as the `Authorization:{key}` header required for authenticating API calls. Depending on your desired security level, you can generate two types of API keys, Advanced or Standard, from Cortex XSOAR.
**API Key ID**
The API Key ID is your unique token used to authenticate the API Key. The header used when running an API call is `x-xdr-auth-id:{key_id}`.
**FQDN**
The FQDN is a unique host and domain name associated with each tenant.
Cortex XSOAR API URIs are made up of your tenant's FQDN, the API name, and endpoint path. For example, `https://api-{fqdn}/xsoar/public/v1/{endpoint_path}/.`
> #### Note[](https://cortex-docs.paloaltonetworks.com/xsoar-8-api#note)
>
> In Cortex XSOAR OPP, you must add a DNS record that points the Cortex XSOAR DNS name that is mapped to the API IP address. For example, `api-xsoar.mycompany.com`.
The following steps describe how to generate the necessary key values and run your first API call:
1. [Create a new API key](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/create-a-new-api-key)
.
2. [Get your Cortex XSOAR API key ID](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/get-your-cortex-xsoar-api-key-id)
.
3. [Get your FQDN](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/get-your-fqdn)
.
4. [Make your first API call](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/make-your-first-api-call)
.
[NextChanges in this release](https://cortex-docs.paloaltonetworks.com/xsoar-8-api/changes-in-this-release)
Last updated 27 days ago
Was this helpful?
Was this helpful?
---
# Onboard the Kubernetes Connector | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector.md)
.
Follow this wizard to deploy your Kubernetes Connector. The Kubernetes onboarding wizard is designed to facilitate the seamless setup of Kubernetes data into Cortex Cloud. The guided experience requires minimal user input; simply select the capabilities that fit your needs and download the custom installer file. For full control of the setup, you can use the advanced settings. Based on the onboarding settings, Cortex Cloud then creates a custom installer file for running in your Kubernetes environment. This file, once executed in your Kubernetes environment, grants Cortex Cloud the necessary permissions to collect the data. The installer file must be executed in your Kubernetes environment to complete the onboarding process. The connector then appears in **Kubernetes Connectors**.
1. Navigate to **Settings** → **Data Sources & Integrations**.
2. On the **Add Data Sources & Integrations** page, click **Create Integration**, search for **Kubernetes**, then hover over it and click **Add Another Instance**.
3. In the **Kubernetes Connect** onboarding wizard, enable the solutions that fit your needs:
* **Posture Management:** (Enabled by default) A lightweight posture management solution for continuous discovery, policy enforcement, and proactive scanning of vulnerabilities, secrets, malware, compliance, and misconfigurations.
* **Realtime Protection:** A solution that monitors workloads in real time to detect and block malicious activity, instantly preventing attacks as they happen.
4. (Optional) Click **Edit** to configure advanced settings and then click **Apply Changes**:
### **Posture management**[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector#posture-management)
Setting
Notes
**Scan Cadence (Hours)**
Define how often to scan (from every one to 24 hours). Default is 12 hours.
**Policy Enforcement by the Admission Controller**
Select to allow enforcement policies to be configured, ensuring that only compliant resources are admitted into the cluster.
**Registry Scanning (OpenShift Only)**
Select this option to scan OpenShift Platform Registry images for vulnerabilities, malware, and exposed secrets.
Select the scanning configuration option to enable security checks for your images:
* **All** (Default) Scans all container images, including all versions (tags), in all discovered repositories.
* **Latest tag**: Scans only images tagged 'latest' in all discovered repositories.
* **Day modified**: Scans container images created or modified in the last few days. You can select a range of up to 90 days for the scan. The default is set to 7.
Refer to [OpenShift container registry](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/openshift-container-registry)
for information on the instances that were automatically created by the Kubernetes deployment.
### Realtime protection[](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector#realtime-protection)
**Notes**:
* On clusters running a Kubernetes Connector version earlier than 2.0, the Realtime protection settings are disabled and cannot be edited. To change the settings, remove the existing connector deployment from the cluster and install the latest available Kubernetes connector version.
* This option is not supported for Fargate.
* Enabling Realtime protection installs the agent on your Kubernetes clusters as a DaemonSet.
Setting
Notes
**Agent type**
Determines which Cortex agent the Kubernetes Connector deploys to your cluster Nodes for real-time protection. Select **Cloud optimized agent** for runtime and threat detection with a lower resource footprint on each Node. Select **XDR agent** for full endpoint protection, including active threat prevention and response. Both agent types deploy as a DaemonSet to every Linux Node in the cluster.
**Node Selector**
Enter node labels to run the agent only on nodes that match those labels. Leave empty to run the agent on all eligible nodes. The node's platform type (for example, Standard, Bottlerocket OS, Google Container-Optimized OS, or OpenShift) is detected automatically.
**Endpoint tags**
Select endpoint tags with relevant context to assign to agents during installation. You can reference the full list of tags under **All endpoints**.
1. (Optional) Click **Edit Profile** to customize the Kubernetes Connector's profile:
Setting
Notes
**Profile Name**
A profile name is automatically generated, including the date and time of creation. You can manually change the profile name.
**Version**
Select which version of the Kubernetes Connector to install.
Each entry in that version list now shows the correlated XDR (Linux real-time) agent version next to the bundle version.
**Cluster Resource Identifier**
(Optional) Enter the Kubernetes cluster resource identifier. If you do not specify the resource identifier, the installer will identify the cluster on its own.
**Note**
For Fargate, you must provide the cluster resource identifier.
The format of the identifier is `arn:aws:eks:::cluster/`.
**Namespace**
Enter the name for the Kubernetes namespace. The default is "panw".
To ensure proper data parsing in an AWS Fargate environment, a Fargate Profile must be explicitly configured for the namespace where the connector is installed (typically panw) and for the kube-system namespace if the cluster is fully Fargate-based. Because the system identifies Fargate clusters by scanning for active workloads during deployment, a Fargate profile that contains no running pods will not be recognized as such. Furthermore, since this detection occurs at installation, any transition from EC2 to Fargate requires an agent update to trigger a new scan and ensure the environment is correctly identified and monitored.
**Proxy Gateway**
Enable this option if network traffic between Cortex Cloud and your Kubernetes cluster must route through a proxy gateway. Enter the following details:
* **Proxy IP**: The full IP address and port number for your HTTP proxy server. For example: `192.168.1.1:8080`
* **Authentication**: Select **None** or **Basic**. Enter the username and password for a proxy user account that has permission to pass traffic to the Kubernetes cluster.
**Note**
Basic authentication is only supported in Posture Management. If deploying Realtime Protection, select **None** .
**Auto Upgrade**
Enable **Auto Upgrade** to ensure the Kubernetes Connector and its installed capabilities are automatically updated to a newer version when available. This minimizes manual maintenance and ensures continuous access to the latest features and security patches.
Select the **Upgrade Strategy**:
* **Latest Available Version (GA)**: Automatically upgrade to the newest version as soon as it is released to gain immediate access to all new features.
* **One release before the latest one (N-1)**: Maintain a policy to always remain one version behind the latest available release.
**Note**
If you install the latest version but select the N-1 strategy, this policy will take effect starting from the next upgrade cycle (it will not immediately downgrade your current installation).
If you choose an older version and keep the latest strategy, the latest version will be installed.
Select **Advanced** to customize the upgrade schedule. Define whether to be upgraded immediately or to delay the upgrade by a specified number of days. You can then specify the preferred day and time for the upgrade to be applied.
1. Click **Generate**, then follow the instructions to complete the deployment.
2. Verify the deployment succeeded when you see **Status: Deployed**.
When the Kubernetes Connector is deployed, the initial discovery scan is started, and the connector appears in **Data Sources & Integrations** → **Kubernetes** → **Kubernetes Connectors**.
[PreviousSupported Kubernetes distributions](https://cortex-docs.paloaltonetworks.com/kubernetes-security/supported-kubernetes-distributions)
[NextOpenShift container registry](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector/openshift-container-registry)
Last updated 8 days ago
Was this helpful?
* [Posture management](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector#posture-management)
* [Realtime protection](https://cortex-docs.paloaltonetworks.com/kubernetes-security/onboard-the-kubernetes-connector#realtime-protection)
Was this helpful?
---
# Getting Started | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme.md)
.
This guide helps you create Cortex XSIAM content. You can create content for your own use, or contribute content to Marketplace that either you support or that is community supported.
Playbooks, alert fields/layouts/rules, indicator fields/types/layouts, classifiers, mappers, widgets, and dashboards should be developed within the Cortex XSIAM UI.
For integrations and scripts, when creating content to use within your instance of Cortex XSIAM or for contribution as a community supported content pack, the UI may be sufficient. For more complex development needs, or if you plan on contributing content as a partner supported content pack or a modification to partner supported content, we recommend using Visual Studio Code, with the [Visual Studio Code extension](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments/visual-studio-code-extension)
. If you work locally, we recommend installing [Demisto SDK](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments/demisto-sdk)
to upload, download, and run code on Cortex XSIAM directly from your operating system shell. To develop content for contribution as a partner-supported content pack, or to submit modifications to partner-supported content packs, you must set up a [full development environment](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments)
.
If you have questions or need support, contact us on the `#demisto-developers` channel on our [DFIR Slack community](https://start.paloaltonetworks.com/join-our-slack-community)
.
### Prerequisites and resources[](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide#prerequisites-and-resources)
Cortex XSIAM is a powerful platform with a rich set of features and customizations. We recommend following these steps before creating custom content:
1. Read and understand Cortex XSIAM [Concepts](https://cortex-docs.paloaltonetworks.com/cortex-xsiam)
.
2. Read the [FAQs](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/frequently-asked-questions)
.
3. Review relevant sections of the Cortex XSIAM product [documentation](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs/)
.
4. Understand your use case.
What are you trying to achieve? What is the user story? What is the expected workflow? Are you creating a content pack or creating content for internal use?
5. Development scope
What content items do you need to develop? Content can include integrations, scripts, playbooks, dashboards, fields, layouts, classifiers, mappers, lists, and data modeling and parsing rules. In some cases, you may just need a playbook to achieve your goals. In other cases, you may need multiple content items.
6. Verify you have an [active tenant](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam)
.
7. If you plan to publish your content to Marketplace for other customers to use, read about the [contribution process](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/contributing-content)
and the different tiers and support levels (for example, partner vs community support). Learn about best practices and requirements for content pack contributions.
8. Register to the [Learning Center](https://beacon.paloaltonetworks.com/student/catalog)
and go through the Product Training.
9. Access the Palo Alto Networks [DFIR Slack community](https://start.paloaltonetworks.com/join-our-slack-community)
and join the `**#demisto-developers**` channel.
10. If you are integrating with an external API, verify you have API or SDK access to the product or solution you want to integrate with.
11. (Optional) Install the [Demisto SDK](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/content-development-environments/demisto-sdk)
.
The Demisto SDK is a command line tool that can be used to upload, download, validate and run code on Cortex XSIAM directly from your command line. The Demisto SDK offers a Python library and CLI designed to aid the development process, to validate entities and to assist in the interaction between your development setup and Cortex XSIAM. You can use the Demisto SDK with the built-in IDE or with a full development environment.
12. (Optional) Install the Video Studio Code extension to develop integrations and scripts.
### Development, documentation, and contributions[](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide#development-documentation-and-contributions)
* Development
* Integrations and scripts
Review the structure for integrations and code conventions, as well as features such as data centralization, intelligent stitching, analytics-based detection, alert and incident management, script, generic commands, and reputation score. Write and test your code.
* Playbooks - learn about playbook design, conventions, and the use of generic playbooks.
For more information on playbook design and development, see [Playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam)
.
* Lists - learn how to download a list from Cortex XSIAM and include it in your content pack.
* Alerts - learn how to create alert fields, layouts, rules, classifiers, and mappers.
* Data modeling, parsing, and correlation - learn how to create parsing, data modeling, and correlation rules.
Enable mapping of events and logs into a single, unified data model. This data model provides a consolidated schema, and a simpler way to interact with your data, regardless of its source or dataset. To familiarize yourself with the data model schema, see [Cortex XSIAM Data Model Schema](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema)
.
* **Indicators** - learn how to create indicator fields and layouts. Learn how domains and URLs are extracted, how to create and use relationships, and more.
* Documentation - learn about documentation best practices, as well as documentation requirements for Marketplace contributions.
* Contributions - learn the requirements for contributing content to Marketplace.
[NextDesign](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide/cortex-xsiam-development-guide/readme/design)
Last updated 15 days ago
Was this helpful?
* [Prerequisites and resources](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide#prerequisites-and-resources)
* [Development, documentation, and contributions](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-developer-guide#development-documentation-and-contributions)
Was this helpful?
---
# Code to Cloud context and visibility | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/code-to-cloud/code-to-cloud-context-and-visibility.md)
.
Code to Cloud context is integrated throughout the user interface to help you visualize dependencies and enforce security.
* **Topology graph**: Located in the **Business Applications** side card, this tab visualizes the entire path to production (`Code → Build → Deploy → Run`), allowing you to see how assets are interconnected
* Dedicated Cortex Cloud Application Security asset inventories: **Repository**, **Software Package** and **IaC Resources** side cards include **Code to Cloud** tab. This graph maps the specific asset to its upstream source and downstream runtime deployments
* **Issue investigation**: **Vulnerabilities** and **IaC Misconfiguration** issues include a **Code to Cloud** tab. This view traces the specific defect from the code file to the impacted runtime resource, helping verify if a vulnerability is actively deployed
* **Policy enforcement**: Policies can be configured with runtime conditions. For example, you can block a build only if the detected vulnerability affects an asset that is destined for an internet-facing environment. For more information on creating policies, refer to [Create a policy](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/tenant-ui-workflow/create-a-policy)
.
Last updated 15 days ago
Was this helpful?
Was this helpful?
---
# Terraform workflow for Compliance assessments | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/compliance-for-cortex-cloud-application-security/terraform-workflow-for-compliance-assessments.md)
.
Automate recurring compliance audits for your Infrastructure-as-Code (IaC) repositories and CI/CD assets. As new Asset Groups are provisioned, Terraform automatically schedules audits and configures report distribution.
**Prerequisites**: Requires an existing Asset Group ID and the target Compliance Standard ID
**Configuration**: Use the cortexcloud\_compliance\_assessment\_profile resource
**How it works**: You define the target standard, the assets to scan, and the automated reporting schedule using standard Cron syntax.
For more information, refer to [Manage resources](https://cortex-docs.paloaltonetworks.com/application-security/terraform-workflows/manage-resources)
.
[PreviousCI/CD Compliance](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/compliance-for-cortex-cloud-application-security/cicd-compliance)
[NextUnified Application Security policies](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---
# Code to Cloud | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/code-to-cloud.md)
.
Code to Cloud context is the correlation engine that maps and maintains the full lineage of assets across the SDLC. By connecting repositories, pipelines, and infrastructure, it provides end-to-end traceability from source code to runtime resources.
Full Code to Cloud (C2C) coverage is achieved when Cortex Cloud can resolve the following chain: **Repository → Pipeline → Image → (optional Registry) → Runtime resources (including VMs, VM images, and IaC-defined infrastructure)**. This lineage mapping connects repositories, pipelines, images, VMs, VM images, IaC-defined infrastructure, and runtime assets back to their originating code, pipelines, IaC resources, and OSS packages, providing full lifecycle context rather than isolated runtime visibility.
When relationships cannot be resolved, for example, due to missing YOR tags or pipeline integrations, Cortex Cloud detects coverage gaps and provides specific configuration steps to fix them. If any part of this chain is unsupported or disconnected, the tenant provides only a partial view, isolating code-side or cloud-side components without end-to-end links. This limits bidirectional impact analysis: code issues cannot be traced to runtime for prioritization by actual exposure, and vulnerabilities cannot be traced back to their source code or owner.
By establishing deterministic links between code, build artifacts, and runtime infrastructure, Code to Cloud context enables the following:
* **Bidirectional traceability**: Trace runtime issues back to the specific line of code, developer, or pipeline that introduced them
* **Contextual application grouping**: Automatically groups related assets into business applications, allowing you to manage risk based on actual business impact
* **Precision prioritization**: Prioritize remediation based on actual exposure, such as whether a vulnerability is active or internet-facing, and its potential business impact
* **Drift detection**: Compare the intended state defined in Infrastructure-as-Code (IaC) templates against the actual state of runtime resources to identify unmanaged changes
* **For IaC drift detection policies**: To configure the security baselines and specific rule mappings that drive this detection logic, see [Create a policy](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies/tenant-ui-workflow/create-a-policy)
* **For IaC Drift Detection issues**: To investigate, prioritize, and remediate the specific runtime discrepancies identified by these scans, see [IaC Drift Detection scans](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/iac-drift-detection-scans)
#### Core components and mechanisms[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/code-to-cloud#core-components-and-mechanisms)
* **Asset Lineage Graph**: This queryable graph database automatically maps the relationships between upstream assets (code repos, packages, IaC resources) and downstream assets (container images, virtual machines, runtime workloads, and cloud services). It is populated by ingesting metadata from:
* **VCS and CI/CD**: Captures repository metadata, build logs, and pipeline run data
* **Build artifacts**: Extracts deterministic links (such as container image digests and VM image references) from container and VM image builds. To ensure comprehensive coverage when standard static detection patterns do not match, Cortex Cloud utilizes AI-powered analysis of CI/CD build logs to automatically detect these links
* **Runtime scanners**: Maps running workloads back to their build sources via the Cloud or Kubernetes connectors
* **Infrastructure-as-Code (IaC) Traceability (**`**YOR**`**)**: To bridge the gap between static IaC files and dynamic cloud resources, Cortex Cloud leverages `YOR` tags:
* **Automated mapping**: `YOR` applies unique trace tags to IaC resources. Cortex Cloud uses these tags to link a Terraform or CloudFormation template to the specific cloud asset it provisioned (for example, IaC Resource → Cloud Asset)
* **Gap analysis**: If YOR tags are missing, the Asset Lineage Graph cannot complete the link. The system will prompt you to initiate tagging via the [yor website](https://yor.io/)
to unlock full visibility
* **Drift detection logic**: Code to Cloud enables drift detection by treating Git as the single source of truth. The system correlates the declared state (from VCS) with the runtime state (from CSPM integrations). Drift is only flagged when a runtime change violates a security policy that is not violated in the source code, ensuring focus on security-relevant regressions rather than operational noise
Last updated 15 days ago
Was this helpful?
Was this helpful?
---
# Operational workflows | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center/operational-workflows.md)
.
The following workflows define the recommended operating procedures for maintaining and improving your Application Security posture.
Workflow 1: Coverage management and gap resolution[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center/operational-workflows#workflow-1-coverage-management-and-gap-resolution)
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
**Context:** Coverage measures the gap between discovered entities and active security oversight. coverage is tracked across four critical dimensions:
* **Onboarding**: Ensuring all repositories and infrastructure are discovered and integrated
* **Scanner enablement**: Verifying that security tools are actively scanning all onboarded assets
* **Code to cloud**: Maintaining visibility across the entire lifecycle, from source code to runtime environments
* **Application mapping**: Linking technical assets to their specific business applications for context
Incomplete coverage creates blind spots and reduces the accuracy of prioritization.
**Posture review (AppSec manager):** Use the **Coverage** page to identify blind spots. Ensure Providers are at 100% to confirm all repositories are onboarded, and verify that scanners reach 100% to ensure those onboarded assets are being properly monitored.
**Execution (AppSec practitioner):** Select **Increase Coverage** to remediate identified gaps. From here, you can enable missing scanners for existing assets. To integrate unmonitored repositories into the platform, launch the onboarding wizard.
For more information about Coverage refer to [Coverage](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage)
.
Workflow 2: Posture hardening[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center/operational-workflows#workflow-2-posture-hardening)
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
**Strategy (AppSec manager):** Review the **Open After Guardrails** section of the **Prioritization and Aggregation** funnel to identify where issues bypass automated gates. Approve AI guardrails to harden the posture.
**Execution (AppSec practitioner):** Apply recommended guardrails. Each applied recommendation becomes a prevention policy. The policy enforces automatically at the configured triggers (PR scan, CI/CD build scan, and periodic scan), blocking matching findings before they progress through the pipeline.
For more information about Application Security policies, refer to [Unified Application Security policies](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/unified-application-security-policies)
.
Workflow 3: Issue remediation[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center/operational-workflows#workflow-3-issue-remediation)
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
**Prioritization (AppSec manager):** Analyze prioritized issues and SLA violations to determine the highest risk based on business impact, breach impact, and breach probability.
**Execution (AppSec practitioner):** Use the **Issues and Cases** view to assign and track delegated items according to the urgency ranking.
**Validation (AppSec manager):** Verify that no **Urgent** or **Top Urgent** issues have exceeded your organization's defined SLAs.
Workflow 4: SLA and MTTR tracking[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center/operational-workflows#workflow-4-sla-and-mttr-tracking)
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
**Monitoring (AppSec practitioner):** Review SLA and MTTR metrics to ensure remediation aligns with internal SLA targets. Select **SLA Violations** to drill into overdue cases.
**Escalation (AppSec practitioner):** Escalate persistent SLA violations with specific remediation deadlines and priority overrides.
**Validation (AppSec practitioner):** Confirm that SLA violation counts are decreasing over time.
For more information on Application Security SLA, refer to [Service Lead Agreements (SLA)](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/service-lead-agreements-sla)
.
[PreviousASPM Command Center](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center)
[NextApplications](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications)
Last updated 16 days ago
Was this helpful?
* [Workflow 1: Coverage management and gap resolution](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center/operational-workflows#workflow-1-coverage-management-and-gap-resolution)
* [Workflow 2: Posture hardening](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center/operational-workflows#workflow-2-posture-hardening)
* [Workflow 3: Issue remediation](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center/operational-workflows#workflow-3-issue-remediation)
* [Workflow 4: SLA and MTTR tracking](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/aspm-command-center/operational-workflows#workflow-4-sla-and-mttr-tracking)
Was this helpful?
---
# AppSec Objectives with Agentix | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix.md)
.
Drive risk reduction with AppSec objectives (Agentix)[](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix#drive-risk-reduction-with-appsec-objectives-agentix)
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Agentix-driven AppSec Objectives turn high-level security goals into tracked, measurable remediation programs without manual policy configuration. You describe a goal in natural language, for example, **eliminate critical vulnerabilities in deployed repositorie**s, and Cortex Cloud converts it into an objective, automatically creating a dedicated dashboard and adding it to a central tracking table to monitor progress.
The result is a continuous, measurable reduction in risk and a clear shift from reactive detection to proactive prevention across the software development life cycle (SDLC).
What an AppSec objective is[](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix#what-an-appsec-objective-is)
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------
An AppSec objective is a focused, measurable goal that groups related open issues by a scope (which assets the objective covers) and a condition (which issues matter for the objective). Each objective is backed by a dedicated dashboard and a set of calculated metrics that quantify how close the objective is to completion.
An objective tracks issues, the deduplicated, actionable records that Cortex Cloud opens from underlying findings. This distinction matters: a single issue can consolidate many periodic findings for the same vulnerability across scans. By operating on issues, the objective ensures accurate, actionable metrics. Progress to resolution is measured using key indicators such as remediation rate, open cases, detection rate, and prevention rate calculated over these issues, rather than raw finding data.
**Scope**: Currently, only vulnerability objectives, which track vulnerability (CVE) issues on code and artifact assets, are supported.
Create an objective[](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix#create-an-objective)
-------------------------------------------------------------------------------------------------------------------------------------------------------------
Create Application Security objectives through the AppSec Agent (Agentix). You do not fill out a policy-style wizard. Instead, you describe the objective in natural language, either by selecting a predefined starter prompt or by typing your own, and the AppSec Agent translates the request into the asset scope and issue condition that define the objective.
When the AppSec Agent creates an objective, Cortex Cloud performs three actions:
1. Persists the objective and its scope and condition.
2. Builds a dedicated dashboard whose widgets are filtered to the objective scope and condition.
3. Starts a background synchronization that populates the objective metrics (remediation rate, detection rate, prevention rate, and open cases).
**IMPORTANT:** The AppSec Agent creates objectives only for goals that map to a supported objective type and its filters. If you request a goal outside the supported filters, the AppSec Agent notifies you and suggests the available starter prompts instead.
**NOTE**: If you do not specify a name or description for the objective, the AppSec Agent generates a human-readable name and description from your prompt.
Prerequisites[](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix#prerequisites)
-------------------------------------------------------------------------------------------------------------------------------------------------
* A license for Cloud Security and the **Application Security** add-on module
* The AppSec Agent (Agentix) enabled in your tenant
#### Next step: [Track objectives](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/track-objectives)
[](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix#next-step-track-objectives)
[PreviousApplication Security dashboard](https://cortex-docs.paloaltonetworks.com/application-security/application-security/cortex-cloud-application-security-dashboard)
[NextTrack objectives](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/track-objectives)
Last updated 16 days ago
Was this helpful?
* [Drive risk reduction with AppSec objectives (Agentix)](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix#drive-risk-reduction-with-appsec-objectives-agentix)
* [What an AppSec objective is](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix#what-an-appsec-objective-is)
* [Create an objective](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix#create-an-objective)
* [Prerequisites](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix#prerequisites)
Was this helpful?
---
# View and manage applications | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/application-management-and-visibility.md)
.
You can view and manage your applications from the following interfaces:
Business Applications asset inventory[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/application-management-and-visibility#business-applications-asset-inventory)
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
This inventory provides a focused view for analyzing and managing business assets. Trace paths to production and manage issues from an asset's side card.
Navigate to **Inventory** → **All Assets** → **Business Applications (under Application)**.
Refer to [Business application assets](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/business-application-assets)
for more information.
Application tabs[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/application-management-and-visibility#application-tabs)
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Dedicated **Application** tabs are displayed in asset side panels. They list assets associated with applications.
These tabs are supported for **IaC Resources**, **Repositories**, and **Software Packages** assets.
[PreviousManually build an application](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/manually-build-an-application)
[NextManage applications via public APIs](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/manage-applications-via-public-apis)
Last updated 15 days ago
Was this helpful?
* [Business Applications asset inventory](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/application-management-and-visibility#business-applications-asset-inventory)
* [Application tabs](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/applications/application-management-and-visibility#application-tabs)
Was this helpful?
---
# Vulnerability objectives | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/vulnerability-objectives.md)
.
A vulnerability objective tracks open **vulnerability (CVE) issues** on your code and artifact assets — repositories and container images — toward a remediation goal. You define which assets to cover (the scope) and which vulnerabilities matter (the condition), and Cortex Cloud tracks the matching issues to resolution. Vulnerability objectives are the only objective type available in the current release.
Create a vulnerability objective to track vulnerability (CVE) issues on code and artifact assets — repositories and container images. You can start from a predefined starter prompt or compose a custom prompt. For the full set of asset scope and vulnerability condition filters the AppSec Agent supports, refer to see [Reference A: Objective scope filters](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/references/reference-a-objective-scope-filters)
and [Reference B: Objective condition filters](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/references/reference-b-objective-condition-filters)
.
Vulnerability objective prerequisites[](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/vulnerability-objectives#vulnerability-objective-prerequisites)
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Fulfill the prerequisites for the vulnerability sources you intend to track:
* Enable the **Application Security SCA scanner**, unless you intend to track only ingested CVE vulnerabilities
* Fulfill any prerequisites required to ingest third-party CVE vulnerability data — for example, onboarding the vendor. For more information refer to [Ingest third-party data sources](https://cortex-docs.paloaltonetworks.com/application-security/application-security/onboard-data-sources/ingest-third-party-data-sources)
Vulnerability issue sources[](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/vulnerability-objectives#vulnerability-issue-sources)
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Vulnerability objectives evaluate vulnerability (CVE) issues on **repositories** and **container images**, regardless of how the underlying vulnerability was detected. A vulnerability issue counts toward an objective whether the CVE was found by:
* The **native Cortex Cloud SCA scanner**, which inventories open-source dependencies to detect CVE vulnerabilities in code and artifact assets
* **Ingested SCA data from supported third-party vendors**, such as **Snyk** and **Semgrep**, whose vulnerability findings Cortex Cloud normalizes into the unified data model
Vulnerability objectives scope[](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/vulnerability-objectives#vulnerability-objectives-scope)
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
* **Repositories**: Objectives evaluate CVE issues carrying the vulnerability detection method
* **Container images**: Objectives evaluate vulnerability-category issues
* **Exclusions**: License, operational-risk, IaC, secrets, SAST, and CI/CD issues are not counted by vulnerability objectives
NOTE**:**
For the full set of supported filters, see:
* [Reference A: Objective scope filters](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/references/reference-a-objective-scope-filters)
* [Reference B: Objective condition filters](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/references/reference-b-objective-condition-filters)
Predefined vulnerability starter prompts[](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/vulnerability-objectives#predefined-vulnerability-starter-prompts)
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
The vulnerability objective type ships with the following predefined starter prompts. Select one from the **AppSec Objectives** tab to create a vulnerability objective without composing a prompt yourself.
* Create an objective for critical vulnerabilities in deployed repositories
* Create an objective for critical vulnerabilities in registry images
* Create an objective for exploitable vulnerabilities in critical applications
[PreviousTrack objectives](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/track-objectives)
[NextReferences](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/references)
Last updated 26 days ago
Was this helpful?
* [Vulnerability objective prerequisites](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/vulnerability-objectives#vulnerability-objective-prerequisites)
* [Vulnerability issue sources](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/vulnerability-objectives#vulnerability-issue-sources)
* [Vulnerability objectives scope](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/vulnerability-objectives#vulnerability-objectives-scope)
* [Predefined vulnerability starter prompts](https://cortex-docs.paloaltonetworks.com/application-security/application-security/appsec-objectives-with-agentix/vulnerability-objectives#predefined-vulnerability-starter-prompts)
Was this helpful?
---
# Core components and mechanisms | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/code-to-cloud/core-components-and-mechanisms.md)
.
Code to Cloud context is the correlation engine that maps and maintains the full lineage of assets across the SDLC. By connecting repositories, pipelines, and infrastructure, it provides end-to-end traceability from source code to runtime resources.
Full Code to Cloud (C2C) coverage is achieved when Cortex Cloud can resolve the following chain: **Repository → Pipeline → Image → (optional Registry) → Runtime resources (including VMs, VM images, and IaC-defined infrastructure)**. This lineage mapping connects repositories, pipelines, images, VMs, VM images, IaC-defined infrastructure, and runtime assets back to their originating code, pipelines, IaC resources, and OSS packages, providing full lifecycle context rather than isolated runtime visibility.
When relationships cannot be resolved, for example, due to missing YOR tags or pipeline integrations, Cortex Cloud detects coverage gaps and provides specific configuration steps to fix them. If any part of this chain is unsupported or disconnected, the tenant provides only a partial view, isolating code-side or cloud-side components without end-to-end links. This limits bidirectional impact analysis: code issues cannot be traced to runtime for prioritization by actual exposure, and vulnerabilities cannot be traced back to their source code or owner.
By establishing deterministic links between code, build artifacts, and runtime infrastructure, Code to Cloud context enables the following:
* **Bidirectional traceability**: Trace runtime issues back to the specific line of code, developer, or pipeline that introduced them
* **Contextual application grouping**: Automatically groups related assets into business applications, allowing you to manage risk based on actual business impact
* **Precision prioritization**: Prioritize remediation based on actual exposure, such as whether a vulnerability is active or internet-facing, and its potential business impact
* **Drift detection**: Compare the intended state defined in Infrastructure-as-Code (IaC) templates against the actual state of runtime resources to identify unmanaged changes
* **For IaC drift detection policies**: To configure the security baselines and rule mappings that drive detection, see [Unified Application Security Policies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/sites/site_gHT7E/s/8Z0RLJ1BFF5TQL8VtUeK/~/edit/~/changes/80/application-security-posture-management-aspm/unified-application-security-policies)
.
* **For IaC Drift Detection issues**: To investigate, prioritize, and remediate runtime discrepancies, see [IaC Drift Detection scans](https://cortex-docs.paloaltonetworks.com/application-security/code-security/code-security-scanners/iac-drift-detection-scans)
.
#### Core components and mechanisms[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/code-to-cloud/core-components-and-mechanisms#core-components-and-mechanisms)
* **Asset Lineage Graph**: This queryable graph database automatically maps the relationships between upstream assets (code repos, packages, IaC resources) and downstream assets (container images, virtual machines, runtime workloads, and cloud services). It is populated by ingesting metadata from:
* **VCS and CI/CD**: Captures repository metadata, build logs, and pipeline run data
* **Build artifacts**: Extracts deterministic links (such as container image digests and VM image references) from container and VM image builds. To ensure comprehensive coverage when standard static detection patterns do not match, Cortex Cloud utilizes AI-powered analysis of CI/CD build logs to automatically detect these links
* **Runtime scanners**: Maps running workloads back to their build sources via the Cloud or Kubernetes connectors
* **Infrastructure-as-Code (IaC) Traceability (**`**YOR**`**)**: To bridge the gap between static IaC files and dynamic cloud resources, Cortex Cloud leverages `YOR` tags:
* **Automated mapping**: `YOR` applies unique trace tags to IaC resources. Cortex Cloud uses these tags to link a Terraform or CloudFormation template to the specific cloud asset it provisioned (for example, IaC Resource → Cloud Asset)
* **Gap analysis**: If YOR tags are missing, the Asset Lineage Graph cannot complete the link. The system will prompt you to initiate tagging via the [yor website](https://yor.io/)
to unlock full visibility
* **Drift detection logic**: Code to Cloud enables drift detection by treating Git as the single source of truth. The system correlates the declared state (from VCS) with the runtime state (from CSPM integrations). Drift is only flagged when a runtime change violates a security policy that is not violated in the source code, ensuring focus on security-relevant regressions rather than operational noise
Last updated 15 days ago
Was this helpful?
Was this helpful?
---
# Coverage in the tenant (UI) | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface.md)
.
How to access Coverage[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#how-to-access-coverage)
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
To access **Coverage**, navigate to **Modules,** → **Application Security** → **AppSec Coverage**.
This interface offers a comprehensive overview of your application security coverage, presenting key metrics and visualizations related to application data sources, scanners, and guardrails. Interactive widgets provide a summary of your coverage. When you apply a filter through a widget, all data displayed on the dashboard, including the asset inventory, will dynamically reflect the selected filter criteria. The asset inventory provides detailed information about application assets in your SDLC for in-depth analysis of your security posture. You can also see all issues for specific assets by selecting them in the inventory table.
Application-specific coverage[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#application-specific-coverage)
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
You can focus on the security posture of your critical business applications, allowing you to prioritize remediation efforts for your most important assets. To view application-specific data, select **Add Filters** → **Applications** → **enter the unique application name as provided when creating it**.
Coverage by data source[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#coverage-by-data-source)
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
This widget provides metrics based on the coverage of the data source such as version control systems (GitHub and so on), CI tools (Jenkins and so on), Repositories (JFrog) and third party data sources (such as Veracode). In addition, insights are provided, such as the amount of assets added recently or whether a data source is not connected.
Coverage by status[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#coverage-by-status)
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
This widget provides coverage metrics based on the percentage of scanned repositories out of the total amount of repositories. Values: scanned, partially scanned, unscanned.
Coverage by scanner type[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#coverage-by-scanner-type)
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
This widget provides metrics based on the coverage of the scan types, including code scanners (vulnerabilities, code weaknesses, secrets, IaC misconfigurations) and images (malware).
Asset coverage inventory table[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#asset-coverage-inventory-table)
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
The asset coverage inventory table displays a list of assets. Table properties include:
Property
Description
Asset Type
The type of asset scanned, such as repositories or container image repositories
Name
The name of the scanned asset
Applications
The type of applications associated with the asset
Scanners Data
Informations about the scanners that were applied to the asset. Upon hovering on the scanner, additional data the type of scanner and its status; enabled or disabled
Last scan status
Displays the status of the most recent scan: Completed, not scanned yet, in progress and error
* **For VCS repositories and images**, this reflects the periodic scan status
* **For pipelines**, this reflects the CI scan status
[PreviousCoverage](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage)
[NextUrgency](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/urgency)
Last updated 15 days ago
Was this helpful?
* [How to access Coverage](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#how-to-access-coverage)
* [Application-specific coverage](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#application-specific-coverage)
* [Coverage by data source](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#coverage-by-data-source)
* [Coverage by status](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#coverage-by-status)
* [Coverage by scanner type](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#coverage-by-scanner-type)
* [Asset coverage inventory table](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/coverage/coverage-in-the-user-interface#asset-coverage-inventory-table)
Was this helpful?
---
# Configure and monitor Cortex Cloud Application Security SLAs | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/service-lead-agreements-sla/configure-and-monitor-cortex-cloud-application-security-slas.md)
.
These procedures defining remediation timeframes and the methods available for monitoring issue compliance against the defined SLAs.
**Configure SLA Remediation Targets**
Define remediation timeframes to track issue compliance with the configured SLAs. The system automatically calculates and updates each issue’s SLA status during periodic scans based on these timeframes.
1. Navigate to **Settings** → **Configurations** → **Application Configuration (under Application Security)**.
2. Define the target SLA for each severity level: **assigning a value in days** → **Save**.
Default values:
* **Critical**: 7 days
* **High**: 14 days
* **Medium**: 30 days
* **Low**: 90 days
3. Set the approaching SLA threshold: **Specify the number of days** → **Save.**
This threshold enables proactive remediation and minimizes the risk of issues becoming **Overdue**.
**Monitor SLA status**
SLA status provides immediate risk context for prioritization. Status tracking is integrated across the Cortex Cloud Application Security **Command Center** dashboard, the **Issues** tables, and their side panels.
* **Cortex Cloud Application Security Dashboard**:
Displays a widget showing the number of Critical and High severity issues that are Overdue or Approaching SLA. The widget breaks down SLA status by scanner (for example, Secrets or IaC). Selecting a scanner opens the relevant issues page, filtered by scanner, severity, and SLA status.
You can access the Cortex Cloud Application Security dashboard from the the **Application Security** dashboard.
* **Issues table**:
The SLA status is integrated directly into the issues table, to provide context and help you track each issue.
To view SLA under Issues tables, under **Modules** select **Application Security** → **\[type of issue such as Secrets**. If SLA is not displayed by default, select it from the **Table Settings Menu**.\
\
**SLA values**:\
\
* **On Track**: The issue is within its assigned remediation timeframe\
\
* **Approaching**: The issue's SLA will be breached in a configurable number of days (the Approaching threshold). This status alerts you before an issue becomes overdue\
\
* **Overdue**: The issue has breached its SLA\
\
\
Hovering over an issue's SLA status will show a tooltip with additional details.\
\
* **SLA in an issue side panel**:\
\
Clicking on any individual issue opens a side panel. The **Overview** tab displays the current SLA status of the issue (such as **Overdue**). Hovering over this status provides additional details, including the issue severity, the total time allotted for remediation, and a countdown of the time remaining until the SLA is breached or since it was breached.\
\
\
[PreviousService Lead Agreements (SLA)](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/service-lead-agreements-sla)\
[NextCompliance for Cortex Cloud Application Security](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/compliance-for-cortex-cloud-application-security)\
\
Last updated 1 month ago\
\
Was this helpful?\
\
Was this helpful?
---
# Issue/Finding classification by scanner | Cortex Documentation Portal
For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt)
. This page is also available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/backlog-baseline/issuefinding-classification-by-scanner.md)
.
This table details how security issues and findings are classified as either **Backlog** or **New** based on their originating scanner and specific detection scenarios
Scanner
Backlog
New Issue
Comment
IaC
The first time an IaC detection rule ran against the code repository
Issues added through pull requests that are created by a detection rule which previously ran against this repository
If a new AppSec rule runs against the code repository, the detected issue is considered a **Backlog** issue
Secrets
The first time a secret was detected on the code repository with a specific signature (out-of-the-box or customer-created)
A secret that was added in a pull request
If a new signature is added/changed in the secret signature engine (by the vendor or by the user), its first run will be considered a **Backlog** issue
SCA Vulnerabilities
The first time the SCA scanner created an SBOM of the code repository and identified vulnerabilities
A vulnerability found in a pull request on a new or updated package
* If there is a new vulnerability on an existing package version, it is considered a **Backlog** issue
* If you set the global parameter **issues on existing SBOM are considered new**, it will be considered a new issue
SAST
The first time the SAST scanner sends results on this code repository and file
A SAST finding that was found on a pull request
This classification also applies if you import a SARIF file for a repository.
**Note**
* In some cases/vendors, this is not accurate as findings are deleted every time new findings are uploaded. In such cases, the feature may not be accurate or supported
* For SAST, the vendor does not support policy in pull requests
### Note[](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/backlog-baseline/issuefinding-classification-by-scanner#note)
**Scanner updates and new detections**: When a security scanner is updated to support new languages, detection rules, or capabilities, any issues discovered by these new features for existing code are classified as part of the backlog.
[PreviousBacklog use cases](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/backlog-baseline/backlog-use-cases)
[NextUsing Backlog](https://cortex-docs.paloaltonetworks.com/application-security/application-security-posture-management-aspm/backlog-baseline/using-backlog)
Last updated 1 month ago
Was this helpful?
Was this helpful?
---