Previous Release Notes for Cisco XDR in 2026
Release Date: July 22, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Instant Attack Verification and Attack Storyboard |
Instant Attack Verification and Attack Storyboard are now available to all users in Cisco XDR, providing an automated, AI-driven analysis of security incidents. The Attack Storyboard is now the default view when you click View Incident Detail in the incident drawer, if applicable. For any incidents that do not support the new incident view with AI analysis, the classic incident detail view is displayed instead. The incident detail with AI analysis view may take time to load. While the view is loading, you can click Classic view to open the incident detail in the classic view. When the AI analysis view is ready, a message is displayed and you can click Launch AI analysis view to open the incident detail with AI analysis. The incident detail view presents an overview of the AI analysis and evaluation of the incident, indicating whether it is likely a true or false positive threat. The AI in Instant Attack Verification assesses incidents in a manner similar to a human analyst, systematically forming and validating hypotheses. It analyzes individual detections, observables, indicators, and their combination, to identify a threat narrative consistent with the incident data. The final classification, along with reasoning, supporting evidence, and recommended response steps, is displayed in the incident detail view. |
|
|
Number of unavailable incidents added to Detections page |
The number of unavailable incidents that were previously part of a detection has been added to the Related incidents column on the Detections page. This occurs if an incident has been removed after its retention period or deleted by a user. |
|
|
Incident detail with AI analysis updates |
The following updates have been made to the incident detail with AI analysis page:
|
|
|
Incidents from legacy Cisco Talos and Cisco Umbrella integrations |
Cisco XDR no longer generates incidents from the Cisco Umbrella integration or from Cisco Talos Advisory Blog detections received through the Cisco Talos integration. These legacy sources do not align with the Cisco XDR incident creation methodology. |
|
|
AI classification added to Incidents page and drawer |
The new AI classification column has been added to the Incidents page. It displays the incident classification and confidence tags assigned by agentic AI based on its analysis of compromised or suspicious devices, user behavior and activities, and individual detections and their classifications. The confidence tag indicates the overall confidence of the incident classification (High confidence, Medium confidence, or Low confidence). The AI classification tag has also been added to the incident drawer. |
|
|
Incident Analysis filter update in Worklog tab |
The Incident Analysis filter in the Worklog tab now displays a complete log of steps taken by agentic AI that led to the reasoning, under AI Analysis. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Cisco Vulnerability Management (CVM) End-of-Life |
Existing targets that use the Cisco Vulnerability Management (CVM) integration will be shown as deprecated. Workflow runs that use this integration will list the Status as Fail in the workflows list. |
|
|
Updated webhook API key security |
When you create or regenerate a webhook API key, you can view and copy it only before leaving the page. Store the key securely; when you return, the key is masked in the webhook details and request examples. If you did not save the key, regenerate it to obtain a new one. |
|
|
Help updates |
Clarified that Docker deployments have the same requirements as v3 OVA, and removed v2 OVA connectivity details. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Duplicate devices filter |
A Duplicate devices filter has been added to help users find potential duplicate devices. The Devices chart also shows the duplicate device count. |
|
|
Manual device deletion |
Administrators can now delete devices on the Devices page. Click Delete in the bulk action bar to delete selected devices. A maximum of 15 devices can be deleted at one time. |
|
|
Remove device source |
Administrators can now delete a source from a device on the Device Details page. Click Remove source in the source details drawer to remove the data from the device. |
|
|
Cisco Vulnerability Management (CVM) End-of-Life |
Cisco Vulnerability Management (CVM) has been deprecated. Contact Support to retrieve historical vulnerability data during your organization's retention period. For custom integrations, use the Device Assets: Upload Custom Source API to view vulnerability context in the source card. However, this data will not propagate to other Cisco XDR features. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Endpoint Data Loss Prevention module |
The Endpoint Data Loss Prevention module is now supported for macOS arm64 deployments. |
|
|
Help update |
The Deprecated Versions and EOL Schedules topic has been added to the Help to provide information on deprecated Secure Client module versions, end-of-life (EOL) schedules, and recommended upgrade guidance for deployments in Cisco XDR. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
New Cisco Network Visibility Module (NVM) detections |
Cisco XDR now includes the following detections:
These new detections require Cisco NVM and are enabled by default. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Cisco Vulnerability Management integration removed from Integrations page |
The Cisco Vulnerability Management integration has been removed from the Integrations page due to the End-of-Life announcement. For more information, see End-of-Sale and End-of-Life Announcement for the Cisco Vulnerability Management, Vulnerability Intelligence, and Application Security Module (formerly known as Kenna.VM, Kenna.VI, and AppSec). |
Cisco and Third-Party Integrations and Supported Capabilities |
|
Palo Alto Networks Firewall via SLS integration added to Integrations page |
The new Palo Alto Networks Firewall via SLS integration has been added to the Third-party tab on the Integrations page. Palo Alto Networks NGFW via Strata Logging Service provides a cloud-delivered, scalable, and secure solution for log storage and analysis. This integration enables Cisco XDR with detection of various security events. |
Cisco and Third-Party Integrations and Supported Capabilities |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Asset Isolation |
Asset Isolation is now available in XDR Forensics. Asset Isolation enables you to completely isolate an asset from all network communication except its connection to the XDR Forensics Console, Cisco XDR, and Secure Client. This allows your investigation to proceed with full XDR Forensics capabilities while preventing threat actors from accessing the asset or external parties from interfering with the investigation. |
|
|
Expanded macOS artifact coverage |
XDR Forensics now expands KnowledgeC collection coverage with additional macOS activity streams, including application focus, web usage, lock and power state indicators, audio output, media activity, and modern activity streams. Analysts gain broader context when reconstructing user activity during security investigations. |
|
|
Task memory-limit configuration |
Memory-limit settings are now available across acquisition, Hunt/Triage, and Full Text Search workflows through task advanced options and policy configuration. This helps administrators control task impact on production assets while maintaining scalable evidence collection and analysis. |
Release Date: July 8, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
| Help update |
Added the Understanding Cisco XDR Incidents, Detections, and Activities section to the About Cisco XDR topic to provide definitions of incidents, detections, and activities, how they relate to each other, and where they appear in the Cisco XDR UI. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
View worklog link added to Reasoning panel in incident detail with AI analysis |
Click the new View worklog link in the upper right corner of the Reasoning panel on the incident detail with AI analysis page to open the Worklog tab in the right pane, where the complete log of steps taken by agentic AI that led to the reasoning is available under AI Analysis. |
|
|
Lifecycle added to Incidents page |
The new Lifecycle column has been added to the incidents list on the Incidents page. It indicates whether the incident is currently active and still receiving new detections and detection updates, or inactive and the reason it is no longer active, such as size limit reached or no recent activity. Any changes to the lifecycle state are also displayed in the Worklog tab. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
CSV downloads for Devices and Users pages |
CSV downloads now continue in the background for the Devices and Users pages. Cisco XDR sends a notification when the file is ready, so downloads are not interrupted if the UI session expires or the page refreshes. |
|
|
Cisco Vulnerability Manager (CVM) end of life |
Due to the Cisco Vulnerability Manager (CVM) end of life, device vulnerability information and the respective Cisco Vulnerability Risk Score has been removed from the Devices and Device Details pages. The vulnerability data will be available for the duration of each tenant's retention period. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
CSV downloads for Clients page |
CSV downloads now continue in the background for the Clients page. Cisco XDR sends a notification when the file is ready, so downloads are not interrupted if the UI session expires or the page refreshes. |
|
|
Duo Desktop module for deployments |
The Duo Desktop module is now available for Client Management deployments. Duo Desktop enables device health and security posture checks at authentication, device-bound authentication without a secondary device, proximity verification with Duo Mobile, and reduced MFA prompts throughout the day with Duo Passport. |
|
|
Endpoint Visibility Module version update |
Endpoint Visibility Module version 1.7.2.15 has been released for Windows amd64 deployments. This release resolves an issue that caused incomplete file information to be provided when reporting kernel driver registration. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Asset CSV Export Ready notification added to Notifications |
The Asset CSV Export Ready notification is now available on the Notifications page. It is triggered when the CSV file is ready for download for the Devices and Users pages. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Secure Email Threat Defense integration update |
Added a note to clarify that detections from the Secure Email Threat Defense (India) and Secure Email Threat Defense (UAE) integrations are not supported in Cisco XDR to the following topics: Cisco Secure Email Threat Defense Integration, Cisco and Third-Party Integrations and Supported Capabilities, and Detections. |
Cisco and Third-Party Integrations and Supported Capabilities |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Asset CSV Export Ready notification added to Notifications |
The Asset CSV Export Ready notification has been added to the Notifications page in Cisco XDR ribbon. It is triggered when the CSV file is ready for download for the Devices and Users pages. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Expanded Windows event collection coverage |
Updated acquisition profiles to collect additional relevant Windows Event IDs. This gives you more visibility into activity that can support security investigations and retrospective analysis. |
|
|
Improved interACT file download experience |
InterACT command result downloads now include file size information. This enables progress indicators for larger downloads and improves the experience. |
|
|
Investigation Hub usability improvements |
Added a Toolbox button to the Investigation Hub header so you can access related investigation actions during active case review. |
Release Date: June 24, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Incident detail with AI analysis updates |
The following updates have been made to the incident detail with AI analysis page:
|
|
|
Date range filter update on Incidents page |
The date range drop-down list at the top of the Incidents page now filters the incidents list based on the last activity date, instead of the created date. The Date range drop-down list in the Filters drawer also has been updated to Last activity. |
|
|
Evidence tab renamed to Forensics |
The Evidence tab in incident detail and incident detail with AI analysis has been renamed to Forensics for better alignment with XDR Forensics UI. |
Incident Detail with AI Analysis |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Activities filter updates |
A banner is now displayed at the top of the Actvities page with a query timestamp, indicating that the results reflect the data available when the query ran. Search results expire one hour after the timestamp. When results expire, click Refresh in the expiration message to rerun the search with the current filters. The refreshed results may include newly observed activities. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Workflow execution controls for production-ready workflows |
Updated the workflow execution controls so non-administrator users can only run production-ready workflows. Run actions for non-production-ready workflows are disabled or hidden for non-administrator users in the Workflows tab on the Workspace page, Workflow Editor, and run details. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Devices and Users page selection controls |
The header row check box now selects all devices or users on the table page. Click Select all on the bulk action bar to select all the devices or users in the entire table. |
|
|
OS version information tooltip |
Added an information tooltip to the Operating system field in the Device Details drawer on the Devices page and the Device Details page. The tooltip explains that Windows 10, Windows 11, and Windows Server share the same base NT version (10.0.x), so a Windows 11 host may report a version beginning with 10. |
|
|
Daily sync for Secure Client sources |
You can now configure Secure Client sources to sync daily. On the Sources page, click the |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
OS version information tooltip |
Added an information tooltip to the Operating system field in the Device Details drawer on the Clients page and the Device Details page. The tooltip explains that Windows 10, Windows 11, and Windows Server share the same base NT version (10.0.x), so a Windows 11 host may report a version beginning with 10. |
|
|
Help updates |
Updated Endpoint Visibility Module version 1.7.1.11 release information to clarify the release was for Windows amd64 only. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Notification updates |
The new XDR System Event notification type has been added to the Notifications page and the Notifications popup. It is triggered when there are system status updates that may impact service, or when a system task requires your attention or has been completed. |
|
|
New Cisco Network Visibility Module (NVM) detections |
Cisco XDR now includes the following detections:
These new detections require Cisco NVM and are enabled by default. Go to the Detection settings page to review each detection and configure its settings. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Windows Clipboard History artifacts |
Added Windows Clipboard History and Clipboard Activity evidence sources to Investigation Hub. Analysts can review copied text activity and correlate clipboard-related evidence with other case data during Windows asset investigations. |
|
|
Evidence repository options |
Added support for S3-compatible evidence repositories and custom Azure Blob Storage domains. Administrators can use improved filtering, sorting, and last-used details to manage evidence storage across restricted, hybrid, or multi-organization environments. |
|
|
Export controls |
Updated export workflows with configurable CSV delimiters, UTF-8 BOM support, timezone options for Investigation Hub flag exports, and column-selection-aware exports. Analysts can generate cleaner files for reporting, correlation, and downstream analysis. |
|
|
Investigator Toolbox from evidence details |
Added Investigator Toolbox entry points to evidence detail views. Analysts can open selected field values directly from the evidence context without copying values into external tools. |
|
|
Configurable audit logging |
Administrators can now control which audit events are written to the Audit Log. This helps reduce noise, focus on high-value security events, and support compliance-driven monitoring requirements. |
|
|
Auto Asset Tagging rules |
Updated Auto Asset Tagging so administrators can manage tagging at the rule level and apply automation more precisely across customer or organizational environments. |
Release Date: June 10, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help update |
Updated the What's Next section in the Getting Started topic to include the Detections and Activities features. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Incident ID added to the Incidents page |
The new ID column on the Incidents page now displays the unique short identification number, with an INC prefix, to reference the incident. The number is only unique within the current organization. You can search or sort by ID number. The ID is also displayed in the incident drawer and the incident detail header. Note: The ID is not available for incidents that were created prior to March 4th, 2026. |
|
|
Last Activity column added to Incidents page |
The new Last Activity column has been added to the Incidents page. It displays the date and time the current incident was updated by the system based on new or updated detections. The Last Activity is also displayed in the incident drawer. |
|
|
Modified column renamed to Last Updated on Incidents page |
The Modified column has been renamed to Last updated on the Incidents page. The column is optional and can be selected in the Table Settings drawer. |
|
|
Investigated events in Detection tab |
Investigated events are no longer generated for incidents and will not appear for new incidents in the Detection tab on the Incident Detail page. |
Detection Incident Detail with AI Analysis |
|
Incident detail with AI analysis updates |
The following updates have been made to the incident detail with AI analysis page:
|
|
| Help update |
Updated the Detections topic with a note indicating that if Cisco Secure Endpoint does not provide network interfaces, these Secure Endpoint detections may not be part of an incident. |
Detections |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Filters drawer update on Activities page |
You must now enter the full and exact IP address (IPv4 or IPv6) in the Source IP and Destination IP fields in the Filters drawer on the Activities page. To filter for multiple IPs, separate each address with a comma. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
AI Run Summary |
You can now generate an AI summary for completed workflow runs, helping you quickly understand workflow results without reviewing every action in detail. The run summary is available from the run drawer and supports workflow runs that include sub-workflows or atomic workflows. In the run view drawer, click Generate Run Summary, when completed the summary is available within the drawer. |
|
|
Improved Exchange workflow installation errors |
Updated Exchange workflow installation errors to provide clearer, actionable details when installation fails because of configuration issues. The error details now appear on the Exchange page and the run's view details page when the workflow installation status is Import Failed. Links to additional information are provided when available. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Seen in sources card added to User Details page |
The Seen is sources card has been added to the User Details page. This card displays the Cisco Identity Intelligence sources that provided the user data. Click the source name to open a drawer that contains all the user data provided by that source. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Endpoint Visibility Module version update |
Endpoint Visibility Module version 1.7.1.11 has been released for Windows amd64 deployments. This release includes fixes for an issue in the reporting of HTTP requests that use uncommon HTTP methods, and fixed an incompatibility with a forthcoming version of the Cloud Management module. |
|
Feature |
Description |
Help Topic |
|---|---|---|
| Help update |
Updated the Secure Endpoint Integration topic with a note indicating that if Cisco Secure Endpoint does not provide network interfaces, these Secure Endpoint detections may not be part of an incident. |
Release Date: May 27, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Recommended panel update in incident detail with AI analysis |
When you execute a workflow for specific incident observables, the observables drawer now displays a notification confirming that AI-recommended observables are automatically selected. Expand View task notes to display up to the two most recent task notes, which consists of manually added notes and results of any automated workflows that have been executed for the task. Click the View task drawer link to view all the task notes in the task drawer. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Filters drawer update |
You can now click Apply in the Filters drawer on the Activities page to save your filter options and the activities list will refresh and only display activities that match the filter criteria. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Linux deployments |
You can now create Linux amd64 and arm64 deployments. To get started, click Create New on the Deployments page. We currently support RHEL, SUSE Linux Enterprise, and Ubuntu Linux distributions, and when downloading a Linux deployment installer, you will select the distribution endpoint version to download, such as RHEL 8. For a list of the supported modules for Linux deployments, see Operating System and Architecture Support. |
|
|
Endpoint Visibility Module version update |
Endpoint Visibility Module version 1.7 has been released. This release enhances threat visibility with OCSF 1.8 support, HTTP activity monitoring, API import reporting, and MITRE ATT&CK annotations for persistence. Performance improvements include optimized CPU and file IO, expanded DNS record collection, intelligent event aggregation, and restored Windows script execution visibility. |
|
|
Help updates |
Updated the Create Deployment and Deployment Management topics for Linux support. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Controlled MITRE ATT&CK Analyzer database update management |
XDR Forensics now supports versioned MITRE ATT&CK database delivery, release notes, manual version selection per asset, automatic update settings, and responder-side update tasks for more consistent Hunt/Triage activity. |
|
|
Investigation toolbox |
Investigation Hub now includes a floating, draggable, resizable toolbox with purpose-built analysis tools. It auto-detects common input types and routes analysts to the most relevant action. |
|
|
Bulk notes in Investigation Hub |
You can now select multiple flagged findings or evidence items and apply the same note in a single action. This improves reporting workflows and reduces repetitive updates during investigations. |
Release Date: May 13, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help update |
Updated the Theme section in the Navigate Cisco XDR topic to include the Auto setting. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Incident detail with AI analysis updates |
The following updates have been made to the incident detail with AI analysis page:
|
|
| Cisco Managed Incident Playbook updates |
The following updates have been made to the Cisco Managed Incident Playbook:
|
|
| Detections page added to Incidents |
The Detections page has been added to the Incidents left navigation menu. It was moved from the previous Detection Findings tab on the Investigate page has been moved to Incidents as a page and it has been renamed to Detections. |
Detections |
|
Detection Details page added to Detections page |
You can now click View details in the detection drawer on the Detections page to open the detection details page. It displays detection details, such as description, MITRE ATT&CK tactics and techniques used by the detection, and activities as supporting evidence for the detection. |
Detections |
|
Detections table update |
The previous Finding count column has been renamed to Detection count. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
New Activities page added to Investigate |
The new Activities page has been added to Investigate in the left navigation menu. The Activities page displays network activities from your environment. The current release supports only network activities from your Cisco Secure Client Network Visibility Module (NVM) if the XDR Default Deployment is installed on your endpoints. The normalized activity data are analyzed by Cisco XDR to generate Cisco XDR detections; these detections are then analyzed by the detection engine and may be correlated into incidents. |
|
|
Detection findings tab moved to Incidents |
The previous Detection findings tab has been moved to Incidents in the left navigation menu as a page and it has been renamed to Detections. |
— |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Adds best practice suggestions during workflow validation |
Workflow validation now prompts for missing workflow and variable descriptions. These updates improve workflow quality and AI compatibility, ensuring your workflows are fully documented and ready for production. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help updates |
Updated the Default Deployments section of the Deployments topic for the migration of NVM data from Secure Cloud Analytics to Cisco XDR. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Detection settings page |
The new Detection Settings page allows you to enable or disable specific detections to manage which events are included in Cisco XDR incident correlation. Additionally, you can view detailed descriptions and associated MITRE ATT&CK tactics and techniques for each detection. You can now view and configure detections for Cisco Network Visibility Module (NVM) telemetry on the new Detection Settings page in Administration, with support for more telemetry sources planned for future releases. NVM alerts from Secure Cloud Analytics are being migrated to the Detection Settings page and require the XDR Default Deployment to be installed on your endpoints. As part of the transition from Secure Cloud Analytics, some NVM detections have been renamed or deprecated. For more information, see the Network Visibility Module Detection Migration Guide. Note: As the NVM detections are migrated from Secure Cloud Analytics to Cisco XDR, the Detection Settings page may appear empty. |
|
|
Help updates |
Added View activities and View and configure detection settings to the Roles topic. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help updates |
Added the Network Visibility Module Detection Migration Guide topic which provides information on the updated NVM detection names, deprecated NVM alerts, and how to view NVM data in Cisco XDR. |
Network Visibility Module Detection Migration Guide |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Data retention alignment |
XDR Forensics Case data retention is now aligned with your Cisco XDR entitlement. |
_ |
|
Structured Data Viewer for JSON, XML, and YAML |
The Investigation Hub now includes a read-only structured data viewer supporting JSON, XML, and YAML, improving readability and forensic-level clarity on parsed artifact sources without external extraction. Enhancements in user visibility provide sortable "Created" and "Last Active" fields to help track authentication and active use for audit and compliance purposes. Syslog forwarding configuration applies dynamically, ensuring uninterrupted log integration during active investigations. |
|
|
Policy Cloning and Bulk Import Allow-Lists |
Users can now duplicate existing isolation or acquisition policies, which reduces setup time and configuration errors when standardizing response templates across organizations. Isolation policies also now support bulk allow-list import, with automated validation, and now include process and domain-based entries, improving cross-platform containment precision. |
Release Date: April 29, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help update |
Updated the Default Cards topic to remove the Detection Ingest Status card from the Secure Cloud Analytics section. The card has been deprecated in the Customize Dashboards dialog box. You can view the last created time and the last verified time for each integrated detection source in the Detection findings tab on the Investigate page. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Incident detail with AI analysis updates |
The following updates have been made to the incident detail with AI analysis page:
|
|
|
Requested by updates in Evidence tab |
The Requested by column in the Evidence tab now displays the name of the user who requested the acquisition or remote shell session. It previously displayed the email of the user. You can also filter the evidence list by the name of the user who requested the acquisition or remote shell session using the Requested by drop-down list at the top of the Evidence tab. |
|
|
Incident correlation |
Incident analysis and correlation now includes Cisco Meraki AMP and IDS engine events. To view incidents with Meraki data, go to Incidents, select an incident with Cisco Meraki as a source, and open the Incident Detail page. On the Detection tab, you will see events from Cisco Meraki. |
|
|
Help updates |
Updated the links to the XDR Forensics Knowledge Base in the Evidence topic. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help updates |
The following updates have been made to the Help:
|
Detection Findings |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Workflow Editor |
The following updates have been made to the Workflow Editor:
|
|
|
Targets Page |
You can now filter by integration target type when searching targets. |
|
|
Remotes |
You can now add Remotes via Docker packages. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
User trust level |
The Level of trust field on the Users and User Details page has been renamed to Trust level. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help updates |
The Create Deployment topic has been updated to include connectivity requirements for the Endpoint Visibility Module (EVM). |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Cisco Meraki integration |
The Cisco Meraki integration now ingests AMP engine events, and malware and indicator-compromise IDS engine events for incident correlation. Support for additional event types is planned for future releases. |
|
|
Help updates |
The following updates have been made to the Help:
|
Cisco Secure Endpoint Integration Cisco Secure Network Analytics Integration Cisco Secure Email Threat Defense Integration Cisco Secure Access Integration CrowdStrike Falcon Integration Microsoft Defender for Endpoint Integration Microsoft Defender for Office 365 Integration SentinelOne Singularity Integration |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
XDR Forensics Knowledge Base |
The XDR Forensics Knowledge Base has been migrated out of the PDF-based knowledge base to the web-based HTML Cisco XDR Help Center to improve the discoverability of technical resources and provide a more intuitive navigation experience. |
|
|
AIR File Explorer XFS Partition Support |
Added support for recognizing and parsing XFS partitions in disk images. Analysts can now browse and analyze evidence from XFS-based assets directly within AIR File Explorer. |
|
|
Expanded Windows evidence coverage in Baseline Comparison |
Comparison supports over 40 new Windows artifact sources, including file system, registry, system, network, and SRUM data, enabling deeper and broader comparative analysis. |
|
|
Enhanced RelayPro |
Upgraded RelayPro with a new toolchain and improved dependencies, enhancing responder–console communication security and reliability for uninterrupted evidence transfers during complex investigations. |
Release Date: April 15, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Response tab update in incident detail |
The Cisco Managed tasks that are automatically generated by AI based on the observables for the incident have been removed from the list of tasks in the Identification phase in the Response tab. You can view AI-generated recommended tasks in the Recommendations panel on the incident detail with AI analysis page, if applicable. |
|
|
Incident detail with AI analysis updates |
The following updates have been made to the incident detail with AI analysis page:
|
|
|
Action count badge added to Actions Taken in node drawer |
If there are more than 50 actions taken, all identical actions will now be aggregated into one action with the action count displayed as a badge to the left of the source in the Actions Taken area of the node drawer. |
Overview |
|
Help updates |
The following updates have been made to the Help:
|
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Account Keys |
For security reasons, HTTP targets with remote no longer support Cisco XDR Token as an account key. Pass an authentication header instead. |
|
|
Automation Remote |
Virtual appliances based on v2.x OVAs are deprecated. The state of connected v2.x Remotes are not impacted, but users should replace their virtual appliances with v3.0 or newer OVAs for continued support. |
|
|
|
You can now set the validity period of certificates up to 2 years on remotes based on v3.0 or newer OVAs. |
|
| Help updates | Added new OVA information to the Configure and Deploy the Virtual Appliance section in the Remote Setup and Deployment topic. | Remote Setup and Deployment |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Unified device status fields |
Fields on the Devices page have been updated to improve filtering and provide an easier way to view the different properties for devices. We've merged the data from previous fields and the following fields have been added:
Rules that included the deprecated fields will be disabled until you update the Rule Criteria. Click Rules on the Devices page to view which rules need to be updated. Saved filters containing deprecated fields have been automatically updated to remove those fields. To include the updated status fields, you will need to create and save new filters. |
|
|
Security and Compliance card |
The Security Products card on the Device Details page has been expanded into the new Security and Compliance card. This card provides the previous fields for Firewall status and Disk encryption, while providing new fields for Device health, Antivirus details, and Compliance status if available. |
Device Overview |
|
Secure Endpoint source card |
The Cisco Secure Endpoint (AMP) card on the Device Details page has been merged into the Secure Endpoint card in the Seen in Sources section. To see the AV definitions status, Device isolation status, Orbital enablement, and other device data provided by Secure Endpoint, click View full details on the source card. |
Device Overview |
|
New user fields |
The following fields have been added to the Users page to enable you to evaluate user behavior, risk levels, and take more effective action during incident investigations:
|
|
|
User details |
The User Details page has been reorganized to display the Security and User Details sections. The Security section includes the user's trust level and additional information that was used to determine the user's Trust Level, and the user's multi-factor authentication status and a list of all the identity events from Identity Intelligence. The User Details section includes the identity details, used devices, activity details, and organization details for the user. |
|
|
Help updates |
The following has been updated in the Help:
|
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Endpoint Visibility Module version update |
Endpoint Visibility Module version 1.6.1.9 for Windows has been released. It resolves a performance issue in Endpoint Visibility Module version 1.6 that caused high CPU usage by optimizing file information retrieval. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Filtered results have been added to the Integrations page |
The total number of integrations is now displayed next to the Detection sources check box on the Integrations page. The results counts are also displayed as badges in the Cisco and Third-party tabs, updating automatically when you search or apply filters. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Enhanced remote shell session visibility |
When reviewing historical remote shell (interACT) sessions, the session header now shows the specific task name, enabling analysts to quickly identify and navigate between concurrent live-response sessions. This improves investigation context and analyst efficiency. |
_ |
|
MITRE ATT&CK Analyzer version 13.0.1 update |
Added Microsoft 365 detection enhancements to identify unauthorized administrative configuration changes and correlating suspicious activity such as brute-force logins and permission changes. Sigma rule integrations have also been updated with the latest rules for comprehensive endpoint and cloud analysis. Additionally, YARA-based detection signatures for Covenant C2 activities strengthen early adversary infrastructure identification. |
MITRE ATT&CK Analyzer changelog |
Release Date: April 1, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Top Seen Techniques card added to Private Intelligence on Dashboards page |
The Top Seen Techniques card has been added to Private Intelligence in the Customize Dashboards dialog box. It displays the top ten MITRE ATT&CK® techniques seen in incidents within the selected timeframe. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Filter by evidence type added to Evidence tab in incident detail |
You can now filter the evidence list by evidence type using the new Evidence type drop-down list in the Evidence tab. |
|
| Help updates |
The following updates have been made to the Help:
|
Incident Detail in Classic View Detection |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Getting Started Page |
View a Getting Started page the first time you navigate to Automate > Workspace. |
|
|
Custom security event type |
Added a new Identity security event type to Custom Security Event Workflow. |
|
|
Help updates |
Updated Automate documentation with current procedure to create workflows. |
|
| Integration targets | Added a new Commvault Cloud target. This target does not need to be configured and is not editable. | Targets Created From Integrations |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Commvault Cloud integration added to Integrations page |
The new Commvault Cloud integration has been added to the Third-Party tab on the Integrations page. Integrating Commvault Cloud with Cisco XDR enhances network and data security and inter-operability. Organizations can initiate Commvault protection for VM workloads directly from the Cisco XDR platform, through the Automate functionality, preserving the VM’s current state early in incident response. SOC teams can also create Cleanroom Recovery Groups within Commvault, enabling impacted VMs to be restored into an isolated environment for investigation and, when appropriate, recovered back to production after the incident. |
Cisco and Third-Party Integrations and Supported Capabilities |
|
Microsoft Graph Security API integration update |
The Microsoft Graph Security API integration in the Third-Party tab on the Integrations page has been updated to use the advanced hunting API in Microsoft Graph. This replaces the legacy alerts API that will be deprecated in April 2026. The description and Step 12 in the Integration Guide area on the Microsoft Graph Security API integration page has been updated to reflect the new API change. To ensure continued functionality, you must update your application in Microsoft Azure to use the Threat Hunting.Read.All permission. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
User role updates |
XDR Forensics Org Admins have been promoted to the Global Admin user role. This will enable admins to have full control over managing 118 specific privileges, allowing the creation of highly customized user roles. This granular access control ensures that each user or group has permissions tailored to their specific needs, such as handling evidence acquisition, interACT sessions, or audit log management. |
User Roles |
|
Auto update |
The XDR Forensics console now automatically updates to ensure that customers have access to the latest features. You can schedule a specific time frame for the Responder to update to ensure that updates do not delay or disrupt ongoing investigations. Go to Settings > Assets in XDR Forensics to schedule a specific time frame for the auto updates. |
Updating Responders |
Release Date: March 18, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help icons added to drawers |
The |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
New incident detail view with AI analysis |
You can now click Launch New Incident View in the upper right corner of the incident detail to display the new AI-powered incident detail view. This view presents an overview of the AI analysis and evaluation of the incident, indicating whether it is likely a true or false positive threat. The AI assesses incidents in a manner similar to a human analyst, systematically forming and validating hypotheses. It analyzes individual detections, observables, indicators, and their combination, to identify a threat narrative consistent with the incident data. The final classification, along with reasoning, supporting evidence, and recommended response steps, is displayed in the incident detail view. Note: The new incident detail view is currently in Beta and subject to change. |
|
|
Help update |
Updated the Add AI-Generated Note section in the Response topic to clarify the AI-generated note feature. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Detection findings tab updates |
The following updates have been made to the Detection Findings tab on the Investigate page:
|
Detection Findings |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Activities |
Added toggle to fill empty fields with default values in the Parse JSON activity. |
|
| Help updates | Added new OVA information to the Configure and Deploy the Virtual Appliance section in the Remote Setup and Deployment topic. | Remote Setup and Deployment |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Endpoint Visibility Module |
The Endpoint Visibility Module is available for Windows amd64 and macOS deployments. The Endpoint Visibility Module is a critical component for organizations striving for seamless endpoint visibility and advanced threat detection within Cisco XDR. Its comprehensive endpoint telemetry complements Cisco and third-party EDR deployments, adding essential context to threat detections. |
|
|
Endpoint Data Loss Prevention |
The Endpoint Data Loss Prevention module is now available for Windows amd64 deployments. Cisco Endpoint Data Loss Prevention (Endpoint DLP) enables you to protect sensitive data on endpoints by controlling what data is transferred to external devices. It extends your organization’s data protection policies to the endpoint. You can also upload a new Endpoint Data Loss Prevention profile to the Profiles page and select a Endpoint Data Loss Prevention profile when creating new deployments. |
|
|
Help updates |
The following updates have been made to the Help:
|
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Detection sources filter added to Integrations page |
You can now check the new Detection sources check box on the Integrations page to quickly filter the page to only display the source products that continuously provide detections to Cisco XDR. These detections are analyzed by the detection engine and may be correlated into incidents. The new Detection sources check box has also been added to the Capabilities drop-down list on the Integrations page. |
Cisco and Third-Party Integrations and Supported Capabilities |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help update |
Updated the previous Detection Analytics and Correlation column by splitting it into the following two columns in the Cisco and Third-Party Integrations and Supported Capabilities topic: Detections and Telemetry. |
Cisco and Third-Party Integrations and Supported Capabilities |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help update |
Added the Endpoint Visibility Module in Cisco XDR topic to provide more information on the capabilities and supported operating systems for the Endpoint Visibility Module. |
Endpoint Visibility Module in Cisco XDR |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Advanced Time Display and Copy Options |
The DateTime component within XDR Forensics now includes a contextual popover to view and copy timestamps in multiple formats including UTC, ISO, local, and relative time. This enhancement streamlines correlation activities across multiple evidence sources and logs during complex investigations. |
|
|
Improved Kerberos Event Collection for KDC Event ID 42 |
Added support for critical Kerberos Key Distribution Center events (Event ID 42) within default Windows event collection profiles. This expands detection visibility for authentication downgrade and anomaly scenarios often relevant in enterprise breaches. |
Release Date: March 4, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Filter by data type added to Observables drawer |
You can now filter the list of observables by data type using the new Type drop-down list at the top of the Observables drawer in the incident detail. The total number of searched or filtered results is now displayed to the right of the Type drop-down list. |
Overview |
|
Evidence tab update |
When you click the evidence name in the Evidence tab, it opens the evidence details directly in the XDR Forensics UI. You no longer need to click the View Investigation Hub icon on the XDR Forensics page before it opens the evidence details in the XDR Forensics UI. |
— |
|
Search Results added to assign incident popup |
When you assign users to an incident, a list of all the users are listed in the new Search Results area. You can narrow the list by entering a user in the Search field. The current user is now displayed as a suggested assignee under the Search field if the incident is assigned to other users. |
|
Feature |
Description |
Help Topic |
|---|---|---|
| AI run summary | You can now view an AI-generated summary of workflow runs. | View, Filter, and Search for Runs |
| Help updates | Updated documentation for reorganized Automation pages and navigation. | About Automation |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help updates |
Added a note that Cisco Identity Intelligence provides a maximum of 10 groups for a user to the Users topic. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help updates |
Updated the steps in the Configure a GCP Subnet to Generate VPC Flow Logs section of the Google Cloud Platform Integration topic. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Improved Endpoint Name Change Handling to Enhance System Performance |
In certain environments, endpoint name change events could previously be triggered due to misconfigured deployments, particularly in cases involving golden image deployments that did not follow the provided deployment guidelines. This scenario could result in a high volume of asset name changes, generating excessive audit logs and triggering updates on investigations. The combination of frequent asset name updates, audit log generation, and related notifications created significant system load, leading to performance degradation. In addition, audit log generation and event-based notifications related to endpoint name changes have been disabled, as their operational impact outweighed their functional value. To improve overall system performance and protect core AIR functionality, endpoint name change handling on investigations and the related audit log generation have been removed, as their operational impact outweighed their functional value. Additionally, the warning status indicating a high number of endpoint name changes has been removed, as it relied on audit log data. |
— |
|
Improved Auto-Scaling and Recovery Stability for SaaS Tenants |
Some SaaS tenants previously experienced extended auto-scaling and recovery durations due to a potential issue related to database connection handling during application startup. Enhancements have been implemented to improve database connection management during startup, resulting in more stable auto-scaling behavior and reduced recovery times. |
— |
|
Enhanced Export Service Performance for Large Data Sets |
The export service used across multiple features (including Audit Log exports and Investigation Hub Evidence/Finding exports) has been enhanced to better handle large data sets. These improvements increase reliability, stability, and performance when exporting high-volume data. |
— |
Release Date: February 18, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Record screen added to Help menu |
The new Record screen option is now available from a drop-down list access by clicking the |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
New statuses added to the Evidence tab |
The following new statuses have been added to the Evidence tab in the incident detail:
|
|
|
Resize table column width on the Incidents page |
You can now resize the column width in the incident table on the Incidents page. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Related incidents update on Detection Findings page |
The Not available status is now displayed in the Related incidents column on the Detection Findings page if the related incidents cannot be determined due to the security event being generated prior to the related incidents feature support (September 25th, 2025). The previous em dash (—) status now displays None in the Related incidents column. |
Detection Findings |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Copy and Download buttons added to Intelligence page |
The new Copy and Download buttons have been added to the JSON panel in the Judgments, Indicators, Events, and Feeds tabs on the Intelligence page. |
|
|
Help update |
Updated screenshots in the Judgments topic to align with the UI. |
|
Feature |
Description |
Help Topic |
|---|---|---|
| Run monitoring | You can view the duration of runs in the new Run time column. You can toggle the display of sub-workflows and atomics by filling a checkbox on the Runs page. The Owner column has been removed. Runs can no longer be deleted from the Runs page. | |
| Help updates | Added new OVA information to the Configure and Deploy the Virtual Appliance section in the Remote Setup and Deployment topic. | Remote Setup and Deployment |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help update |
Added the int-check-in-ignored event type to the Device Events topic. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
AppOmni SaaS Security integration added to the Integrations page |
The new AppOmni SaaS Security integration has been added to the Third-Party tab on the Integrations page. AppOmni enriches Cisco XDR investigations with SaaS identity, access, and threat context. Search AppOmni directly from Cisco XDR to understand who a user is, what SaaS applications they can access, and their level of access, including elevated or administrative privileges. |
Cisco and Third-Party Integrations and Supported Capabilities |
|
Talos Intelligence integration update |
The Talos Intelligence integration now uses Talos URS API instead of Talos SDS API. |
— |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Historical data update in Pivot menu |
The Historical button at the top of the Pivot menu has been renamed to Incident time or Investigation time, depending on whether the Pivot menu is opened in an incident or an investigation. |
Overview |
|
Help update |
Added a note to the Investigate Observable section in the Pivot Menu topic to clarify that manual investigations may not always align with incident observables. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Smarter evidence analyzer behavior for missing artifacts |
DRONE analyzer logic now skips analysis tasks when expected artifacts are absent from collected data. This prevents confusing error messages and makes error logs clearer and more accurate for investigation teams. |
DRONE |
|
Investigation Hub asset filter crashes with large cases |
The Asset drop-down list in Investigation Hub could become unresponsive in investigations with thousands of assets. The filter now supports virtualized loading for smoother performance in enterprise-scale environments. |
Investigation Hub |
|
Asset registration failure on identical cloud instance IDs |
In environments where multiple assets share the same cloud infrastructure ID, responder registration could fail. XDR Forensics now handles additional identifiers to differentiate assets reliably in these cases. |
— |
|
XDR Forensics MITRE ATT&CK Analyzer |
MITRE ATT&CK Analyzer is now at version 12.2.0, which introduces expanded and enhanced detection capabilities across multiple threat categories, including comprehensive rule coverage for advanced malware families. |
MITRE ATT&CK Analyzer changelog |
Release Date: February 4, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help update |
Updated the Sync and Highlight Data section in the Investigation Results topic to remove events highlight. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Meraki adapter |
Meraki adapter was superseded by Cisco Meraki integration in release 2.29. The current release removes the obsolete adapter. |
|
|
Help updates |
The following updates have been made to the Help:
|
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Rules for users |
You can now create rules that will assign labels and values to users automatically. On the Users page, click Rules to open the drawer to create new rules from search or from scratch. |
|
|
Cisco Meraki Network Devices support |
Meraki Network Devices are now supported on the Devices page, and the Sources page will display a separate cards for Meraki Network Devices. Existing customers do not need to update their Cisco Meraki integration, as the integration module will automatically ingest Meraki Network Devices data. |
|
|
Device type chart |
The device type chart on the Devices page now includes a check box for Other devices, which includes network devices and IoT devices. The Other check box will automatically filter the table for those device types. To filter by a specific type of network device, for example, Firewall devices, use the Type drop-down menu in the Filters drawer. |
|
|
Help updates |
The following updates have been made to the Help:
|
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help updates |
The following updates have been made to the Help:
|
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help updates |
Updated the View Git repositories and Used by information and View remotes list and Used by information rows from Yes to No for the Incident Responder and Security Analyst columns in the Roles topic. |
Release Date: January 21, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
| Help update | Updated the onboarding information in the Sign In to Cisco XDR section. | Getting Started |
|
Feature |
Description |
Help Topic |
|---|---|---|
| Help icon updates |
The new Cisco support options are now available from a drop-down list accessed by clicking the Previously, you accessed the Cisco XDR online help by clicking the |
Navigate Cisco XDR |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Assets without XDR Forensics enabled |
The new Assets without XDR Forensics enabled panel has been added to the Acquire forensic evidence and Launch remote shell drawers in the Evidence tab. Click the |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Maximum number of security events displayed on Detection findings page |
The detection findings table now displays the first 10,000 security events only on the Detection findings page. |
Detection Findings |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help updates |
The following updates have been made to the Help:
|
|
Feature |
Description |
Help Topic |
|---|---|---|
|
User management in Secure Cloud Control |
The ability to invite users, change user status, and manage user permissions will be moved from the Manage Users page in Cisco XDR to the Administrator Access page in Security Cloud Control. For more information on inviting users and managing permissions in Security Cloud Control, see Managing Role-Based Access Control in the Cisco Security Cloud Control Administration Guide. The Manage Users page will become view-only, displaying all users in your organization along with their assigned roles and current statuses. This change goes into effect on January 28, 2026. If you are an existing Cisco XDR user, your account will be automatically migrated to Security Cloud Control on January 28th, 2026. Your tenant will need to be attached to your Security Cloud Control Enterprise to leverage this functionality. No additional action is required by your organization. |
|
|
Help update |
Updated the My Account topic with a new screenshot to align with the UI. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Help update |
Updated the Minimum Cisco XDR Licensing Tier Requirement column for the StealthMole integration in the Cisco and Third-Party Integrations and Supported Capabilities topic from Advantage to Essential. |
Cisco and Third-Party Integrations and Supported Capabilities |
|
Feature |
Description |
Help Topic |
|---|---|---|
| Orbital app updates |
The parameter type and the Get parameters from custom script link have been added to the Custom Script area in the Orbital app. |
Orbital App |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Assets menu |
The Assets menu in XDR Forensics has been separated into Devices, Disk Images, and Cloud Assets. This streamlined layout enables you to locate relevant evidence sources, assess responder status, and initiate investigation workflows with improved clarity. |