Cortex XSOAR Releases - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR Releases

Product
Cortex XSOAR
Creation date
2022-11-23
Last date published
2025-04-07

Cortex XSOAR has introduced the following releases.

Date

Version

Details

February 2, 2025

8.9 Cloud

GA

  • A new look and feel for playbooks: The latest enhancements in user experience improve playbook readability and clarity through an updated look and feel.

  • Collapsible playbook sections: The updated collapsible playbook sections enable users to stay focused on the relevant playbook details without distractions, allowing for easier navigation through complex playbooks and increased productivity.

  • Unlimited user license for development tenants: With no license limit for users on development tenants, you can build, test, and refine automations at scale. This drives faster innovation, more reliable workflows, and scalable solutions as your organization grows.

  • Notifications for deprecated content: New automated user notifications about deprecated playbooks, sub-playbooks, and scripts ensure updated, effective, and accurate security workflows.

September 22, 2024

8.8 Cloud

GA

  • Canvas -Multilayer indicator/incident relationship graph: SOC analysts can now create and share dynamic attack diagrams or static snapshots with incident response, forensics, and threat-hunting teams.

  • The Guard Rails page: Cortex XSOAR 8 now includes the Guard Rails page, which shows performance-related errors and warnings that can be used as a guide to detect and prevent actions that may cause a decline in performance or instability.

  • Exclude enrichment of indicators: Indicators can now be marked as Enrichment Excluded in Cortex XSOAR, ensuring they will not be enriched. This gives you better control over your Indicators and the ability to optimize system performance by managing the indicator enrichment process.

  • Audit logs: Audit log coverage is expanded to capture detailed records of incident edits, including the modified fields. This improvement ensures a comprehensive record of all changes, significantly enhancing the ability to trace the incident's history and evolution.

June 30, 2024

8.7 Cloud

GA

  • Seamlessly migrate all your data, configurations, and settings, including indicators and incidents from Cortex XSOAR 6.13 On-prem to Cortex XSOAR 8 Cloud using a built-in wizard streamlining the migration process.

  • To effectively investigate an incident and analyze associated indicators, the SOC analyst must have access to up-to-date data and a clear view of the most recent changes made to the relevant indicators, as well as the initial entries of indicator changes.

  • When generating a report, you can choose the timezone to ensure accurate and localized reporting for users working in multiple geographical locations.

  • Admin users can manage notification distribution by adding or removing tenant’s stakeholders' email addresses on the Server Settings page without the need to add them first on the tenant. This feature streamlines communication and simplifies administration.

April 14, 2024

8.6 Cloud

GA

  • You can create API keys with multiple roles to improve operational efficiency and allow dynamic RBAC management of API keys.

  • The Administrator can restrict designated users' access to specific dashboards through role assignment.

  • Cortex XSOAR has an API endpoint for GET, CREATE, UPDATE, and DELETE for API keys.

  • You can change the color of the favicon for each tenant, which allows you to identify which tenant is being used in each tab at a glance.

February 11, 2024

8.5 Cloud

GA

  • Enable communication between SOC analysts (MT/MSSP)

  • Keep Retained Incidents

  • Assign retention licenses for MT deployments

  • Content repository improvements

  • Customize system emails

  • Use an authenticated docker image

October 29, 2023

8.4 Cloud

GA

  • In-app documentation

  • Private repository support in a dev/prod environment

  • Export incidents to Excel

  • Authenticated communication tasks

  • Define credentials for long-running integrations

  • SSO improvements

July 9, 2023

8.3 Cloud

GAJuly 2023

  • Improved Auditing

  • Manage User Groups in the Cortex Gateway

  • Manage RBAC settings in the Cortex Gateway

  • Improved Navigation

  • Improved Indicator Verdict Calculation

April 23, 2023

8.2 Cloud

GAApril 2023

  • XSOAR 8 now offers Cortex XSOAR multi-tenant, designed for managed security service providers and enterprises requiring strict data segregation with the flexibility to share and manage critical security practices across tenant accounts.

  • Role permissions have been updated to separate some administration permissions.

  • You can now subscribe to content pack updates in Marketplace.

  • Improved UI for Data Collection and Ask tasks in Playbooks and a simplified search for playbooks with free text search.

  • Improvements to the Default Playbook.

January 1, 2023

8.1 Cloud

GAJanuary 2023

  • Integration into the Cortex platform:

    • Unified look and feel

    • Uses the platform's storage engines

    • Simplified deployment and onboarding

    • Consistent user management

  • Improved performance and reliability

  • High scalability based on a revamped architecture that utilizes cloud features

  • Built-in Git Repository for sharing data between development and production instances

Date

Version

Details

April 7, 2025

8.9 On-prem

GA

  • A new look and feel for playbooks: The latest enhancements in user experience improve playbook readability and clarity through an updated look and feel.

  • Collapsible playbook sections: The updated collapsible playbook sections enable users to stay focused on the relevant playbook details without distractions, allowing for easier navigation through complex playbooks and increased productivity.

  • Unlimited user license for development tenants: With no license limit for users on development tenants, you can build, test, and refine automations at scale. This drives faster innovation, more reliable workflows, and scalable solutions as your organization grows.

  • Notifications for deprecated content: New automated user notifications about deprecated playbooks, sub-playbooks, and scripts ensure updated, effective, and accurate security workflows.

  • Export and delete incidents: Enhance incident data management by enabling administrators to export and delete incidents for regulatory and storage requirements. This helps minimize data exposure, ensures efficient and secure management of incident data retention, and helps free up disk space to optimize system performance.

  • Use an authenticated Docker image repository: Use a custom container registry with your authentication credentials to apply custom images created on a private machine. Using your registry enables you to manage access permissions, ensuring only authorized users can pull and use the custom images. This protects sensitive information and enables more secure and controlled deployment of custom images within the Cortex XSOAR environment.

January 5, 2025

8.8 On-prem

GA

  • Cortex XSOAR multi-tenant: Cortex XSOAR 8 On-prem now offers the following:

    • Multi-tenant for Managed Security Service Providers (MSSP)

    • Multi-tenant for Enterprises

  • Backup and restore of configurations and data: Continuous and efficient operation of your Cortex XSOAR tenant by periodically backing up your tenant, which enables you to recover data, configurations, and settings.

  • Canvas - Multilayer Indicator/Incident Relationship Graph: SOC analysts can now create and share dynamic attack diagrams or static snapshots with IR, forensics, and threat-hunting teams. This enables them to visualize and link key security incidents and IOCs for faster and more streamlined investigation.

September 17, 2024

8.7 On-prem

GA

  • Cortex XSOAR On-prem now supports:

    • Deployment on Oracle Cloud Infrastructure (OCI).

    • Deployment on AWS

    • Log in via SSH to the Cortex XSOAR textual UI for admin users.

  • To effectively investigate an incident and analyze associated indicators, the SOC analyst must have access to up-to-date data and a clear view of the most recent changes made to the relevant indicators, as well as the initial entries of indicator changes.

  • Cortex XSOAR now supports teams working in different locations, enabling the user to select the timezone of the report.

  • Cortex XSOAR can now run more playbooks per hour for medium and large-scale deployments

July 14, 2024

8.6 On-prem

GA

  • Cortex XSOAR Cluster High Availability: Cortex XSOAR On-prem cluster, with three or more nodes, includes high availability capabilities to improve reliability for critical security operations.

  • Enhanced role-based access control for dashboards: The Administrator can now restrict access to specific dashboards for designated users through role assignment.

  • Multi-role API keys: You can now create API keys with multiple roles to improve operational efficiency and allow dynamic RBAC management of API keys.

  • New endpoint for managing API keys using the API: Cortex XSOAR now has an API endpoint for GET, CREATE, UPDATE, and DELETE for API keys.

  • Customize the favicon color: You can now change the color of the favicon for each tenant. This allows you to identify which tenant is being used in each tab at a glance.

March 31, 2024

8.5 On-prem

GA

Cortex XSOAR 8.5 On-prem is now released and includes the following features:

  • Integration into the Cortex platform:

    • Unified look and feel

    • Simplified deployment and onboarding

  • Improved performance and reliability

  • High scalability based on a revamped architecture

  • User-friendly installation with an easy-to-follow step-by-step TUI to install and configure Cortex XSOAR:

    • Tenant network and IP settings

    • Proxy settings

    • Cluster settings

    • Scale size

Date

Version

Details

April 6, 2025

Cortex XSOAR 6.14.0 (B3036535)

Maintenance Release: Cortex XSOAR is now compliant with FIPS 140-3.

February 9, 2025

Cortex XSOAR 6.14 (B2436668)

GA

  • Migration from Cortex XSOAR 6 MSSP/multi-tenant to Cortex XSOAR 8 cloud MSSP/multi-tenant. To start the migration, users need to upgrade to this version. For more information about the migration process, see the Cortex XSOAR Migration Guide.

  • Cortex XSOAR 6.14 now supports:

    • Oracle Linux version 9.4 (for engine and server installation)

    • RHEL 9.5 (for engine and server installation)

    • Amazon Linux 2023 (for engine and server installation)

    • Elasticsearch versions 8.14 and 8.15

    • OpenSearch versions 2.15 and 2.16

August 18, 2024

Cortex XSOAR 6.13 (B1284375)

GA

  • Migration from Cortex XSOAR 6 On-prem to Cortex XSOAR 8 Cloud is now available. To start the migration, users need to upgrade to this version. For more information about the migration process, see the Cortex XSOAR Migration Guide.

  • Cortex XSOAR 6.13 now supports:

    • Oracle Linux versions 8.9 and 9.3 (for engine and server installation)

    • RHEL versions 8.10 and 9.4 (for engine and server installation)

    • Elasticsearch versions 8.11, 8.12, and 8.13

    • OpenSearch versions 2.10, 2.11, 2.12, and 2.14

August 18, 2024

Cortex XSOAR 6.12.0 (B1271551)

Maintenance Release: bug fixes, including some security issues.Minor Releases

February 29, 2024

Cortex XSOAR 6.12.0 (B857430)

Maintenance Release: bug fixes, including some security issues.Minor Releases

December 3, 2023

Cortex XSOAR 6.12.0 (B661643)

Maintenance Release: bug fixes, including some security issues.Minor Releases

September 20, 2023

Cortex XSOAR 6.12.0 (B493375)

Maintenance Release: bug fixes, including some security issues.Minor Releases

September 3, 2023

Cortex XSOAR 6.12 (B481081)

GANew Features

  • Migration from Cortex XSOAR 6 to 8 is available for Hosted customers

  • Cortex XSOAR supports RHEL v8.8 and v9.0

  • Edit a list installed from a content pack by detaching it

  • The reputationCalcAsync argument is now available for the addEntries command

  • The list.<listName>.separator and list.separator server configurations now support tabs as list separators, using \t

August 7, 2023

Cortex XSOAR 6.11.0 (B443478)

Maintenance Release: bug fixes and enhancements, including some security issues.Minor Releases

April 23, 2023

Cortex XSOAR 6.11 (B300044)

GANew Features

  • Improved Upgrade Process for Multi-Tenant Deployments

  • After deleting a user, you can now clear the user's data from content, such as active incidents and investigations, automations, etc.

  • Substantial improvements of playbook performance, including context operations, indicator extraction, and playbook execution.

  • New Menu Navigation

  • Role Permissions have been updated for more granular control.

March 6, 2023

Cortex XSOAR 6.10.0 (B255865)

Maintenance release: fixes an issue related to hosts connecting to the main server in a multi-tenant deployment.Minor Releases

February 26, 2023

Cortex XSOAR 6.10.0 (B250144)

Maintenance release: bug fixes and enhancements, including some security issues.Minor Releases

December 5, 2022

Cortex XSOAR 6.10 (B187344)

GARelease Information

  • Communication task links in Context Data: When running an Ask or Data Collection task, links are generated to collect the recipients' responses and are now available in the incident's context data.

  • Content Security Policy: You can now enable Content Security Policy (CSP), which adds a layer of security, including detecting and mitigating certain types of attacks.

  • Quiet Mode for Manual Tasks: You can now turn Quiet mode on or off for individual manual tasks in a playbook.

  • Documentation Portal: Documentation for all Cortex products, including Cortex XSOAR, has moved to https://docs-cortex.paloaltonetworks.com/.

November 18, 2022

Cortex XSOAR 6.9.0 (B177754)

Maintenance release: bug fixes and enhancements, including some security issues.Minor Releases

November 16, 2022

Cortex XSOAR 6.8.0 (B176620)

Maintenance release: bug fixes and enhancements, including some security issues.Minor Releases

August 8, 2022

Cortex XSOAR 6.9 (B3387847)

GANew Features

  • Deployment Wizard: When installing or updating content packs, the DEPLOYMENT WIZARD tab guides you step-by-step to adopt your use case (including Phishing and Malware), significantly reducing the setup time.

  • SAML 2.0 Configuration: You can now let administrators manually enter certain user information fields when configuring SAML 2.0, which persists if those fields are not provided by the SAML third-party provider.

  • Zoom level:  When switching between playbooks, the user's zoom level is now preserved (in = more detail, out = larger view).

  • Added a warning message when viewing comments in incidents: (Multi-Tenant) Added a warning message when handling bulk incidents to prevent customer information from being unintentionally shared with other customers.