Asset Inventory - Cortex XSIAM

Cortex XSIAM 3.x Release Notes

Product
Cortex XSIAM
Last date published
2026-06-09
FEATURE DESCRIPTION LICENSE/ADD-ON

Drift detection highlight in Container Instances

Container Instances asset cards in Asset Inventory now include a Security Drift Detected highlight and a dedicated Security Drift tab, making it easy to identify containers that have deviated from their base image. These drifts expose vulnerabilities, misconfigurations, compliance violations, and other security risks introduced at runtime that were not part of the base image.

Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license

Base Image Visibility for Container Images

You can now identify the base image for any Build, Registry, or Runtime container image directly from its asset details page. With the new has base reference and is base reference for relationships in Security Graph, you can trace image lineage and assess vulnerability impact in a single query. Define custom Base Image Rules to mark foundational Registry Images, create targeted asset groups and policies, and quickly determine whether vulnerabilities originate from a base image layer. This streamlines your security investigations and accelerates incident response.

Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license

Consolidated CaaS resource visibility

Improve security oversight and simplify asset management by viewing CaaS (Containers as a Service) resources within a dedicated section of the Asset Inventory. This update organizes resources from Amazon ECS, Google Cloud Run, and Azure Container Instances into a single, purpose-built view under Compute assets, making it easier to locate, monitor, and assess the security posture of your cross-cloud CaaS deployments.

Cloud Posture Security, Cloud Runtine Security, or Cortex XSIAM Premium license