> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-cspm-release-information/features-introduced-in-september-2023.md).

# Features Introduced in September 2023

Learn what’s new on Prisma® Cloud in September 2023.

* [New Features Introduced in 23.9.2](#new-features-sep-2)
* [New Features Introduced in 23.9.1](#new-features-sep-1)

## New Features Introduced in 23.9.2

* [New Features](#new-features2)
* [API Ingestions](#api-ingestions2)
* [New Policies](#new-policies2)
* [Policy Updates](#policy-updates2)
* [IAM Policy Updates](#iam-policy-update2)
* [Changes in Existing Behavior](#changes-in-existing-behavior2)
* [REST API Updates](#rest-api-updates2)

## New Features

| FEATURE                              | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Credit Consumption Visualization** | <p>On Aug 1, 2023, Prisma Cloud Enterprise Edition introduced reductions to the credit required for several modules. When this change was rolled out, the data pertaining to historical credit usage (prior to Aug 1st, 2023) was normalized to the new model and the visualization was updated on the licensing page of the Prisma Cloud console. As a result , you could not see a decrease in credit consumption for resources that are no longer billed.</p><p>Now, in the 23.9.2 release, we no longer normalize credit data consumed prior to Aug 1st, 2023. This update enables you to accurately track your credit consumption trend using historical data before Aug 1, 2023 and the new usage after Aug 1, 2023.</p><p><img src="/files/zsGKzsObLolp4YiTJvZ5" alt="" data-size="original"></p> |

## API Ingestions

| SERVICE                                                                           | API DETAILS                                                                                                                                                                                                                                                                                                                                                                                                                   |
| --------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **AWS Backup**                                                                    | <p><strong>aws-backup-backup-plan</strong></p><p>Additional permissions required:</p><ul><li><code>backup:ListBackupPlans</code></li><li><code>backup:GetBackupPlan</code></li><li><code>backup:ListTags</code></li></ul><p>You must manually add or update the CFT template to enable the permissions.</p>                                                                                                                   |
| **AWS Glue**                                                                      | <p><strong>aws-glue-crawler</strong></p><p>Additional permissions required:</p><ul><li><code>glue:GetCrawler</code></li><li><code>glue:ListCrawlers</code></li></ul><p>The Security Audit role only includes <code>glue:GetCrawler</code>.</p><p>You must manually add or update the CFT template to enable <code>glue:ListCrawlers</code> permission.</p>                                                                    |
| **AWS Trusted Advisor**                                                           | <p><strong>aws-trusted-advisor-check-result</strong></p><p>Additional permissions required:</p><ul><li><code>support:DescribeTrustedAdvisorChecks</code></li><li><code>support:DescribeTrustedAdvisorCheckResult</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                     |
| <mark style="background-color:orange;">Update</mark> **Azure Container Registry** | <p><strong>azure-container-registry</strong></p><p>The resource JSON for this API has been updated to include the <code>properties.policies.exportPolicy.status</code> field. The field identifies the export policy for a container registry.</p>                                                                                                                                                                            |
| <mark style="background-color:orange;">Update</mark> **Azure SQL Database**       | <p><strong>azure-sql-managed-instance</strong></p><p>The resource JSON for this API has been updated to include the <code>properties.azureADOnlyAuthentication</code> field. The field identifies if Azure Active Directory only authentication is enabled.</p>                                                                                                                                                               |
| <mark style="background-color:orange;">Update</mark> **Azure Storage**            | <p><strong>azure-storage-account-list</strong></p><p>Prisma Cloud now supports soft delete setting for <strong>azure-storage-account-list</strong>. The resource JSON for this API has been updated to include the following fields.</p><ul><li><code>shareDeleteRetentionPolicy.file</code></li><li><code>shareDeleteRetentionPolicy.file.days</code></li><li><code>shareDeleteRetentionPolicy.file.enabled</code></li></ul> |
| <mark style="background-color:orange;">Update</mark> **Azure Security Center**    | <p><strong>azure-security-center-settings</strong></p><p>The resource JSON for this API has been updated to include <code>pricings\[].properties.subPlan</code> field. The field enables a set of security features for a given resource.</p>                                                                                                                                                                                 |
| **Google Cloud DNS**                                                              | <p><strong>gcloud-dns-response-policy-rule</strong></p><p>Additional permissions required:</p><ul><li><code>dns.responsePolicies.list</code></li><li><code>dns.responsePolicyRules.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                      |
| **Google Cloud Filestore**                                                        | <p><strong>gcloud-filestore-instance-snapshot</strong></p><p>Additional permissions required:</p><ul><li><code>file.instances.list</code></li><li><code>file.snapshots.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                  |
| **Google Cloud Filestore**                                                        | <p><strong>gcloud-filestore-instance-backup</strong></p><p>Additional permission required:</p><ul><li><code>file.backups.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                 |
| **Google Cloud Run**                                                              | <p><strong>gcloud-cloud-run-job</strong></p><p>Additional permissions required:</p><ul><li><code>run.jobs.list</code></li><li><code>run.services.list</code></li><li><code>run.jobs.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                             |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>NEW POLICIES</td><td>DESCRIPTION</td></tr><tr><td><strong>Azure Policies</strong></td><td><p>Prisma Cloud has included the following new policies:</p><ul><li>Azure Cache for Redis not configured with data in transit encryption</li><li>Azure Database for MariaDB not configured with private endpoint</li><li>Azure Database for MySQL server not configured with private endpoint</li><li>Azure PostgreSQL servers not configured with private endpoint</li><li>Azure SQL Database server not configured with private endpoint</li></ul><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p></td></tr><tr><td><strong>GCP backend bucket having dangling GCP Storage bucket</strong></td><td><p>Identifies the GCP backend buckets having dangling GCP Storage bucket.</p><p>A GCP backend bucket is usually used by GCP Load Balancers for serving static content. Such setups can also have DNS pointing to the load balancer’s IP for easy human access. A GCP backend bucket pointing to a GCP storage bucket that doesn’t exist in the same project is a potential risk of bucket takeover as well as at risk of subdomain takeover. An attacker can exploit such a setup by creating a GCP Storage bucket with the same name in their own GCP project, thus receiving all requests redirected to this backend bucket from the load balancer to an attacker-controlled GCP Storage bucket. This attacker-controlled bucket can be used to serve malicious content to perform phishing attacks, spread malware, or engage in other illegal activities.</p><p>As a best practice, it is recommended to review and protect GCP storage buckets bound to a GCP backend bucket from accidental deletion. Delete the GCP backend bucket if it points to a non-existent GCP storage bucket.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-backend-bucket' as X; config from cloud.resource where api.name = 'gcloud-storage-buckets-list' as Y; filter ' not (Y.name intersects X.bucketName) '; show X;
</code></pre></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>POLICY UPDATES</td><td>DESCRIPTION</td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>AWS S3 bucket accessible to unmonitored cloud accounts</strong></td><td><p><strong>Changes—</strong> The policy RQL has been updated to exclude reporting for the awslogsdelivery account which is used by CloudFront to save logs to the S3 bucket.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-s3api-get-bucket-acl' AND json.rule = "acl.grants[?(@.grantee.typeIdentifier=='id')].grantee.identifier size > 0 and _AWSCloudAccount.isRedLockMonitored(acl.grants[?(@.grantee.typeIdentifier=='id')].grantee.identifier) is false"
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-s3api-get-bucket-acl' AND json.rule = "acl.grants[?(@.grantee.typeIdentifier=='id')].grantee.identifier size > 0 and acl.grants[?(@.grantee.typeIdentifier=='id')].grantee.identifier does not contain c4c1ede66af53448b93c283ce9448c4ba468c9432aa01d700d3878632f77d2d0 and _AWSCloudAccount.isRedLockMonitored(acl.grants[?(@.grantee.typeIdentifier=='id')].grantee.identifier) is false"
</code></pre><p><strong>Impact—</strong> Low. Existing alerts will be resolved.</p></td></tr><tr><td><strong>GCP VPC Network subnets have Private Google access disabled</strong></td><td><p><strong>Changes—</strong> The policy RQL has been updated to exclude proxy-only subnet as private google access cannot be configured on proxy-only subnets.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-networks-subnets-list' AND json.rule = 'privateIpGoogleAccess does not exist or privateIpGoogleAccess is false'
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-networks-subnets-list' AND json.rule = purpose is not member of (REGIONAL_MANAGED_PROXY, PRIVATE_SERVICE_CONNECT) and (privateIpGoogleAccess does not exist or privateIpGoogleAccess is false)
</code></pre><p><strong>Impact—</strong> Low. Any alert triggered for Proxy-only subnet will be resolved.</p></td></tr><tr><td><strong>Policy Updates—Metadata</strong></td><td></td></tr><tr><td><strong>Azure App Services Remote debugging is enabled</strong></td><td><p><strong>Changes—</strong> The policy now supports remediation. You can resolve the alerts by running the remediation.</p><p><strong>Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> No impact since support for remediation is introduced.</p></td></tr><tr><td><strong>Azure Cosmos DB key based authentication is enabled</strong></td><td><p><strong>Changes—</strong> The policy now supports remediation. You can resolve the alerts by running the remediation.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> No impact since support for remediation is introduced.</p></td></tr><tr><td><strong>Policy Deletions</strong></td><td></td></tr><tr><td><strong>Azure Policies</strong></td><td><p>The following Azure policies were enabled by default and have been deleted from Prisma Cloud. However, these policies are added again in the disabled state by default with a new policy name. See <a href="#new-policies2">New Policies</a> for more details.</p><ul><li>Azure Cache for Redis not configured with data in-transit encryption</li><li>Azure Database for MariaDB not configured private endpoint</li><li>Azure Database for MySQL server not configured private endpoint</li><li>Azure PostgreSQL servers not configured private endpoint</li><li>Azure SQL Database server not configured private endpoint</li></ul><p><strong>Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> Low. Previously generated alerts will be resolved as <strong>Policy_Deleted</strong>.</p></td></tr><tr><td><strong>Attack Path Policies</strong></td><td><p>The following policies have been deleted from Prisma Cloud:</p><ul><li>Potentially unauthorized port scanning activity detected on a publicly exposed AWS EC2 instance</li><li>Potentially unauthorized port scanning activity detected on a publicly exposed and vulnerable Azure Virtual Machine</li><li>Potentially unauthorized port scanning activity detected on a publicly exposed and vulnerable GCP VM instance</li></ul><p><strong>Policy Type—</strong> Attack Path</p><p><strong>Impact—</strong> High. Previously generated alerts will be resolved as <strong>Policy_Deleted</strong>.</p></td></tr></tbody></table>

## IAM Policy Updates

The following IAM out-of-the-box (OOTB) policies have been updated in Prisma Cloud:

<table data-header-hidden><thead><tr><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td>POLICY NAME</td><td>DESCRIPTION</td><td>RQL</td><td>CLOUD TYPE</td><td>SEVERITY</td></tr><tr><td><strong>EC2 with IAM role attached has iam:PassRole and ec2:Run Instances permissions</strong></td><td>This IAM policy enforces controlled access by permitting only the specified actions (iam:PassRole, ec2:RunInstances) within AWS, specifically for 'instance' resources. By limiting the scope of permissions to this focused context, potential risks and unauthorized activity are mitigated.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name IN ('iam:PassRole','ec2:RunInstances') AND source.cloud.service.name = 'ec2' AND source.cloud.resource.type = 'instance' AND source.cloud.type = 'AWS'
</code></pre></td><td>AWS</td><td>Low</td></tr><tr><td><strong>AWS role having iam:PassRole and lambda:InvokeFunction permissions attached to EC2 instance</strong></td><td>This IAM policy is meticulously designed to address potential vulnerabilities arising from an AWS EC2 instance with specific permissions. The 'iam:PassRole' action, coupled with 'lambda:CreateFunction' and 'lambda:InvokeFunction', holds the potential for adversaries to exploit and escalate privileges. By strategically controlling access to these actions within the 'ec2' service, this policy effectively mitigates the risk of unauthorized creation and manipulation of Lambda functions, safeguarding against potential escalation of privileges and maintaining the integrity of your system.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name IN ('iam:PassRole','lambda:CreateFunction', 'lambda:InvokeFunction') AND source.cloud.service.name = 'ec2' AND source.cloud.resource.type = 'instance' AND source.cloud.type = 'AWS'
</code></pre></td><td>AWS</td><td>Low</td></tr><tr><td><strong>AWS IAM policy allows access and decrypt Secrets Manager Secrets permissions</strong></td><td>This IAM policy tackles potential vulnerabilities linked to an AWS EC2 instance equipped with an IAM role that confers access to the 'secretsmanager:GetSecretValue' and 'kms:Decrypt' actions. By closely managing permissions within the 'ec2' service, this policy guards against unauthorized retrieval of sensitive secrets from Secrets Manager and unauthorized decryption of encrypted data through AWS Key Management Service (KMS). This strategic control ensures the safeguarding of system confidentiality and integrity, mitigating risks associated with potential unauthorized access or compromise.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name IN ( 'secretsmanager:GetSecretValue', 'kms:Decrypt' ) AND source.cloud.service.name = 'ec2' AND source.cloud.resource.type = 'instance'
</code></pre></td><td>AWS</td><td>Low</td></tr><tr><td><strong>AWS EC2 with IAM role with destruction permissions for Amazon RDS databases</strong></td><td>This IAM policy addresses the potential risks associated with an AWS EC2 instance having an IAM role enabling the execution of SQL statements directly on Amazon RDS databases. By meticulously controlling access to the 'rds-data:ExecuteStatement' and 'rds-data:BatchExecuteStatement' actions within the 'ec2' service, this policy mitigates the possibility of data breaches, unauthorized modifications, and access to sensitive information stored in the databases, ensuring a robust security posture for your cloud environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name IN ('rds-data:ExecuteStatement', 'rds-data:BatchExecuteStatement') AND source.cloud.service.name = 'ec2' AND source.cloud.resource.type = 'instance'
</code></pre></td><td>AWS</td><td>Low</td></tr><tr><td><strong>AWS EC2 machine with write access permission to resource-based policies</strong></td><td>This IAM policy identifies ec2 instance with permissions contol resource based policies for different AWS services. They enable setting policies and permissions for repositories, applications, backup vaults, file systems, data stores, and more. While these permissions offer operational flexibility, it is crucial to use them responsibly. Mishandling these permissions may result in unauthorized access, misconfigurations, or data exposure. It is recommended to assign and manage these permissions to trusted individuals to maintain security posture for AWS resources.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name IN ("ecr:SetRepositoryPolicy","serverlessrepo:PutApplicationPolicy","backup:PutBackupVaultAccessPolicy","efs:PutFileSystemPolicy","glacier:SetVaultAccessPolicy","secretsmanager:PutResourcePolicy","events:PutPermission","mediastore:PutContainerPolicy","glue:PutResourcePolicy","ses:PutIdentityPolicy","lambda:AddPermission","lambdaAddLayerVersionPermission","s3:PutBucketPolicy","s3:PutBucketAcl","s3:PutObject","s3:PutObjctAcl","kms:CreateGrant","kms:PutKeyPolicy","es:UpdateElasticsearchDomainConfig","sns:AddPermission","sqs:AddPermission") AND source.cloud.service.name = 'ec2' AND source.cloud.resource.type = 'instance'
</code></pre></td><td>AWS</td><td>Medium</td></tr><tr><td><strong>AWS EC2 IAM role with Elastic IP Hijacking permissions</strong></td><td>This precision-crafted IAM policy provides vigilant control over essential actions within AWS, specifically targeting 'instance' resources. By meticulously governing access to actions like 'ec2:DisassociateAddress' and 'ec2:EnableAddressTransfer', this policy serves as a bulwark against unauthorized endeavors to transfer Elastic IPs to unauthorized accounts, bolstering the security of your cloud environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name IN ('ec2:DisassociateAddress', 'ec2:EnableAddressTransfer') AND source.cloud.service.name = 'ec2' AND source.cloud.resource.type = 'instance'
</code></pre></td><td>AWS</td><td>Medium</td></tr><tr><td><strong>AWS EC2 with IAM role attached has credentials exposure permissions</strong></td><td>This meticulously tailored IAM policy enforces precise control over vital actions within AWS, specifically honing in on EC2 'instance' resources. By meticulously governing access to a comprehensive range of actions, this policy provides a robust defense mechanism against unauthorized activities, thereby enhancing the overall security posture of your AWS environment</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name IN ('chime:createapikey', 'codepipeline:pollforjobs', 'cognito-identity:getopenidtoken', 'cognito-identity:getopenidtokenfordeveloperidentity', 'cognito-identity:getcredentialsforidentity', 'connect:getfederationtoken', 'connect:getfederationtokens', 'ec2:getpassworddata', 'ecr:getauthorizationtoken', 'gamelift:requestuploadcredentials', 'iam:createaccesskey', 'iam:createloginprofile', 'iam:createservicespecificcredential', 'iam:resetservicespecificcredential', 'iam:updateaccesskey', 'lightsail:getinstanceaccessdetails', 'lightsail:getrelationaldatabasemasteruserpassword', 'rds-db:connect', 'redshift:getclustercredentials', 'sso:getrolecredentials', 'mediapackage:rotatechannelcredentials', 'mediapackage:rotateingestendpointcredentials', 'sts:assumerole', 'sts:assumerolewithsaml', 'sts:assumerolewithwebidentity', 'sts:getfederationtoken', 'sts:getsessiontoken') AND source.cloud.service.name = 'ec2' AND source.cloud.resource.type = 'instance'
</code></pre></td><td>AWS</td><td>Low</td></tr><tr><td><strong>AWS EC2 with IAM role with alter critical configuration for s3 permissions</strong></td><td>This IAM policy instates precise oversight over essential operations within AWS, with a specific focus on 'instance' resources. By thoughtfully managing the capability to influence s3 bucket attributes, such as configuring retention, lifecycle, policy, and versioning settings, this policy plays a crucial role in averting potential hazards. It ensures that unauthorized modifications, which could lead to public exposure or data loss, are effectively mitigated, contributing to the overall resilience of your cloud environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name IN ('s3:PutObjectRetention','s3:PutLifecycleConfiguration','s3:PutBucketPolicy','s3:PutBucketVersioning') AND source.cloud.service.name = 'ec2' AND source.cloud.resource.type = 'instance'
</code></pre></td><td>AWS</td><td>Low</td></tr><tr><td><strong>AWS Lambda with IAM role attached has credentials exposure permissions</strong></td><td>This IAM policy serves as an impenetrable shield for your AWS Lambda resources. It empowers your Lambda functions to wield powerful capabilities, seamlessly orchestrating tasks such as secure communication, user authentication, and data protection. This policy acts as a sentinel, guarding against potential attempts to acquire sensitive login tokens, thus ensuring the sanctity of your critical services. With its astute vigilance, your Lambda environment remains impervious to unauthorized access and unwarranted data exposure, bolstering the robustness and integrity of your cloud ecosystem</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name IN ('chime:createapikey', 'codepipeline:pollforjobs', 'cognito-identity:getopenidtoken', 'cognito-identity:getopenidtokenfordeveloperidentity', 'cognito-identity:getcredentialsforidentity', 'connect:getfederationtoken', 'connect:getfederationtokens', 'ec2:getpassworddata', 'ecr:getauthorizationtoken', 'gamelift:requestuploadcredentials', 'iam:createaccesskey', 'iam:createloginprofile', 'iam:createservicespecificcredential', 'iam:resetservicespecificcredential', 'iam:updateaccesskey', 'lightsail:getinstanceaccessdetails', 'lightsail:getrelationaldatabasemasteruserpassword', 'rds-db:connect', 'redshift:getclustercredentials', 'sso:getrolecredentials', 'mediapackage:rotatechannelcredentials', 'mediapackage:rotateingestendpointcredentials', 'sts:assumerole', 'sts:assumerolewithsaml', 'sts:assumerolewithwebidentity', 'sts:getfederationtoken', 'sts:getsessiontoken') AND source.cloud.service.name = 'lambda'
</code></pre></td><td>AWS</td><td>Medium</td></tr><tr><td><strong>Azure VM instance with risky Storage account permissions</strong></td><td>This IAM policy bolsters protection for Azure VM instances by meticulously controlling access to critical actions related to storage accounts, including management of keys, regeneration, and deletion. By imposing stringent access controls within the 'Microsoft.Compute' service, potential risks associated with risky storage account permissions are effectively mitigated.</td><td><pre><code>config from iam where dest.cloud.type = 'AZURE' and source.cloud.service.name = 'Microsoft.Compute' and action.name IN ( 'Microsoft.Storage/storageAccounts/write', 'Microsoft.Storage/storageAccounts/listKeys/action', 'Microsoft.Storage/storageAccounts/regeneratekey/action', 'Microsoft.Storage/storageAccounts/delete' , 'Microsoft.Storage/storageAccounts/ListAccountSas/action')
</code></pre></td><td>Azure</td><td>Low</td></tr><tr><td><strong>GCP VM instance with permissions to disrupt logging</strong></td><td>This IAM policy exerts meticulous control over crucial actions associated with Google Cloud’s 'compute' service, focusing on 'Instances' resources. By thoughtfully overseeing capabilities such as managing logging metrics, buckets, logs, and sinks, this policy effectively bolsters the integrity of your cloud environment. By mitigating the potential for unauthorized alterations, this policy thwarts attempts to evade proper event logging during lateral movement, reinforcing the overall security of your GCP infrastructure</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'compute' and source.cloud.resource.type = 'Instances' AND action.name IN ('logging.logMetrics.delete', 'logging.logMetrics.update', 'logging.buckets.delete', 'logging.buckets.update', 'logging.logs.delete', 'logging.sinks.delete', 'logging.sinks.update')
</code></pre></td><td>GCP</td><td>Medium</td></tr><tr><td><strong>GCP Cloud Function with permissions to disrupt logging</strong></td><td>This IAM policy maintains vigilant control over pivotal operations within Google Cloud’s 'cloudfunctions' service, with a specific focus on ensuring the integrity of event logging. By thoughtfully governing the management of logging metrics, buckets, logs, and sinks within the 'logging' service, this policy serves as a robust safeguard against unauthorized alterations. This fortified control mitigates the potential for unauthorized manipulations, thereby thwarting any attempts to evade proper event logging during lateral movement. The policy contributes to a resilient and secure GCP environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'cloudfunctions' AND action.name IN ('logging.logMetrics.delete', 'logging.logMetrics.update', 'logging.buckets.delete', 'logging.buckets.update', 'logging.logs.delete', 'logging.sinks.delete', 'logging.sinks.update') AND dest.cloud.service.name = 'logging'
</code></pre></td><td>GCP</td><td>Medium</td></tr><tr><td><strong>GCP VM instance with permissions over Deployments Manager</strong></td><td>This IAM policy empowers stringent oversight over pivotal functions within Google Cloud’s 'compute' service, exclusively targeting 'Instances' resources. It effectively governs the critical actions involved in managing deployments through Deployment Manager, ensuring a robust defense against unauthorized alterations. By orchestrating deploymentmanager.deployments.create and deploymentmanager.deployments.update capabilities, this policy enforces meticulous control over resource creation and updates, guarding against potential internet exposure, privilege escalation, or lateral movements. This heightened control fortifies the security of your GCP VM instances with heightened vigilance over Deployment Manager functionalities.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'compute' and source.cloud.resource.type = 'Instances' AND action.name IN ('deploymentmanager.deployments.create', 'deploymentmanager.deployments.update')
</code></pre></td><td>GCP</td><td>Medium</td></tr><tr><td><strong>GCP Cloud Function with permissions over Deployments Manager</strong></td><td>This IAM policy for GCP’s 'cloudfunctions' service orchestrates vigilant control over the potent capabilities tied to Deployment Manager. With a keen focus on deploying and updating resources, this policy reinforces a robust defense against unauthorized resource creation and modifications. By weaving together the intricacies of deploymentmanager.deployments.create and deploymentmanager.deployments.update actions, this policy establishes a formidable barrier against potential security risks. Through these measures, the policy ensures heightened protection for your GCP Cloud Function, guarding against the perils of internet exposure, privilege escalation, and lateral movements. This strategic fortification bolsters your cloud infrastructure’s resilience and security</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'cloudfunctions' AND action.name IN ('deploymentmanager.deployments.create', 'deploymentmanager.deployments.update')
</code></pre></td><td>GCP</td><td>Medium</td></tr></tbody></table>

## Changes in Existing Behavior

No changes in existing behavior for 23.9.2.

## REST API Updates

No REST API Updates for 23.9.2.

## New Features Introduced in 23.9.1

* [New Features](#new-features1)
* [API Ingestions](#api-ingestions1)
* [New Policies](#new-policies1)
* [Policy Updates](#policy-updates1)
* [IAM Policy Updates](#iam-policy-update)
* [Changes in Existing Behavior](#changes-in-existing-behavior1)
* [REST API Updates](#rest-api-updates1)

## New Features

No new features in 23.9.1.

## API Ingestions

| SERVICE                           | API DETAILS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| --------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **AWS Application Auto Scaling**  | <p><strong>aws-application-autoscaling-scaling-policy</strong></p><p>Additional permission required:</p><ul><li><code>application-autoscaling:DescribeScalingPolicies</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                    |
| **AWS DataSync**                  | <p><strong>aws-datasync-task</strong></p><p>Additional permissions required:</p><ul><li><code>datasync:ListTasks</code></li><li><code>datasync:DescribeTask</code></li><li><code>datasync:ListTagsForResource</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                           |
| **Amazon EFS**                    | <p><strong>aws-efs-access-point</strong></p><p>Additional permission required:</p><ul><li><code>elasticfilesystem:DescribeAccessPoints</code></li></ul><p>You must manually add or update the CFT template to enable the above permission.</p>                                                                                                                                                                                                                                                                   |
| **Amazon Inspector**              | <p><strong>aws-inspector-v2-account-status</strong></p><p>Additional permission required:</p><ul><li><code>inspector2:BatchGetAccountStatus</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                              |
| **Amazon Route53**                | <p><strong>aws-route53-health-check</strong></p><p>Additional permissions required:</p><ul><li><code>route53:ListHealthChecks</code></li><li><code>route53:GetHealthCheck</code></li><li><code>route53:ListTagsForResource</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                              |
| **AWS Systems Manager**           | <p><strong>aws-ssm-custom-inventory-entry</strong></p><p>Additional permissions required:</p><ul><li><code>ssm:GetInventory</code></li><li><code>ssm:GetInventorySchema</code></li><li><code>ssm:ListInventoryEntries</code></li></ul><p>The Security Audit role only includes <code>ssm:ListInventoryEntries</code>.</p><p>You must manually add or update the CFT template to enable the following permissions:</p><ul><li><code>ssm:GetInventory</code></li><li><code>ssm:GetInventorySchema</code></li></ul> |
| **Google Binary Authorization**   | <p><strong>gcloud-binary-authorization-attestor</strong></p><p>Additional permissions required:</p><ul><li><code>binaryauthorization.attestors.list</code></li><li><code>binaryauthorization.attestors.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                             |
| **Google Cloud Build**            | <p><strong>gcloud-cloud-build-github-enterprise-config-v1</strong></p><p>Additional permission required:</p><ul><li><code>cloudbuild.integrations.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                           |
| **Google Cloud Build**            | <p><strong>gcloud-cloud-build-private-worker-pool</strong></p><p>Additional permission required:</p><ul><li><code>cloudbuild.workerpools.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                    |
| **Google Stackdriver Monitoring** | <p><strong>gcloud-monitoring-uptime-check-config</strong></p><p>Additional permission required:</p><ul><li><code>monitoring.uptimeCheckConfigs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                              |
| **OCI IAM**                       | <p><strong>oci-iam-compartment</strong></p><p>Additional permission required:</p><ul><li><code>COMPARTMENT\_INSPECT</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permission.</p>                                                                                                                                                                                                                                                                       |
| **OCI Integration**               | <p><strong>oci-integration-instance</strong></p><p>Additional permissions required:</p><ul><li><code>INTEGRATION\_INSTANCE\_INSPECT</code></li><li><code>INTEGRATION\_INSTANCE\_READ</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permissions.</p>                                                                                                                                                                                                     |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>NEW POLICIES</td><td>DESCRIPTION</td></tr><tr><td><strong>AWS Transit Gateway auto accept vpc attachment is enabled</strong></td><td><p>Identifies if Transit Gateways are automatically accepting shared VPC attachments. When this feature is enabled, the Transit Gateway automatically accepts any VPC attachment requests from other AWS accounts without requiring explicit authorization or verification. This can be a security risk, as it may allow unauthorized VPC attachments to connect to the Transit Gateway. As per the best practices for authorization and authentication, it is recommended to turn off the AutoAcceptSharedAttachments feature.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-vpc-transit-gateway' AND json.rule = isShared is false and options.autoAcceptSharedAttachments exists and options.autoAcceptSharedAttachments equal ignore case "enable"
</code></pre></td></tr><tr><td><strong>AWS CodeBuild project environment privileged mode is enabled</strong></td><td><p>Identifies the CodeBuild projects where the privileged mode is enabled. Privileged mode grants unrestricted access to all devices and runs the Docker daemon inside the container. It is recommended to enable this mode only for building Docker images. It recommended disabling the privileged mode to prevent unintended access to Docker APIs and container hardware, reducing the risk of potential tampering or critical resource deletion.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-code-build-project' AND json.rule = environment.privilegedMode exists and environment.privilegedMode is true
</code></pre></td></tr><tr><td><strong>AWS ECS services have automatic public IP address assignment enabled</strong></td><td><p>Identifies whether Amazon ECS services are configured to assign public IP addresses automatically. Assigning public IP addresses to ECS services may expose them to the internet. If the services are not adequately secured or have vulnerabilities, they could be susceptible to unauthorized access, DDoS attacks, or other malicious activities. It is recommended that the Amazon ECS environment not have an associated public IP address except for limited edge cases.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-ecs-service' AND json.rule = networkConfiguration.awsvpcConfiguration.assignPublicIp exists and networkConfiguration.awsvpcConfiguration.assignPublicIp equal ignore case "ENABLED"
</code></pre></td></tr><tr><td><strong>Azure Log analytics linked storage account is not configured with CMK encryption</strong></td><td><p>Identifies Azure Log analytics linked Storage accounts which are not encrypted with CMK. By default Azure Storage account is encrypted using Microsoft Managed Keys. It is recommended to use Customer Managed Keys to encrypt data in Azure Storage accounts linked Log analytics for better control on the data.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.encryption.keySource does not equal ignore case "Microsoft.Keyvault" as X; config from cloud.resource where api.name = 'azure-log-analytics-linked-storage-accounts' AND json.rule = properties.dataSourceType equal ignore case Query as Y; filter '$.X.id contains $.Y.properties.storageAccountIds'; show X;
</code></pre></td></tr><tr><td><strong>Azure Synapse Workspace vulnerability assessment is disabled</strong></td><td><p>Identifies Azure Synpase workspace which has Vulnerability Assessment setting disabled. Vulnerability Assessment service scans Azure Synapse workspaces for known security vulnerabilities and highlight deviations from best practices, such as misconfigurations, excessive permissions, and unprotected sensitive data. It is recommended to enable Vulnerability assessment.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-synapse-workspace' AND json.rule = properties.provisioningState equal ignore case Succeeded as X; config from cloud.resource where api.name = 'azure-synapse-workspace-managed-sql-server-vulnerability-assessments' AND json.rule = properties.recurringScans.isEnabled is false as Y; filter '$.X.name equals $.Y.workspaceName'; show X;
</code></pre></td></tr><tr><td><strong>GCP Cloud Function has risky basic role assigned</strong></td><td><p>Identifies GCP Cloud Functions configured with the risky basic role. Basic roles are highly permissive roles that existed prior to the introduction of IAM and grant wide access over project to the grantee. To reduce the blast radius and defend against privilege escalations if the Cloud Function is compromised, it is recommended to follow the principle of least privilege and avoid use of basic roles.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-projects-get-iam-user' AND json.rule = roles[*] contains "roles/editor" or roles[*] contains "roles/owner" as X; config from cloud.resource where api.name = 'gcloud-cloud-function' as Y; filter '$.Y.serviceAccountEmail equals $.X.user'; show Y;
</code></pre></td></tr><tr><td><strong>GCP VM instance has risky basic role assigned</strong></td><td><p>Identifies GCP VM instances configured with the risky basic role. Basic roles are highly permissive roles that existed prior to the introduction of IAM and grant wide access over project to the grantee. To reduce the blast radius and defend against privilege escalations if the VM is compromised, it is recommended to follow the principle of least privilege and avoid use of basic roles.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-projects-get-iam-user' AND json.rule = roles[*] contains "roles/editor" or roles[*] contains "roles/owner" as X; config from cloud.resource where api.name = 'gcloud-compute-instances-list' AND json.rule = status equals RUNNING and name does not start with "gke-" as Y; filter '$.Y.serviceAccounts[*].email contains $.X.user'; show Y;
</code></pre></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>POLICY UPDATES</td><td>DESCRIPTION</td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>AWS Elastic Load Balancer v2 (ELBv2) with listener TLS/SSL is not configured</strong></td><td><p><strong>Changes—</strong> The policy RQL has been updated to not trigger an alert when the HTTP listener requests are redirected to HTTPS URL.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = state.code contains active and listeners[?any( protocol equals HTTP or protocol equals TCP or protocol equals UDP or protocol equals TCP_UDP )] exists as X; config from cloud.resource where api.name = 'aws-elbv2-target-group' AND json.rule = targetType does not equal alb and protocol exists and protocol is not member of ('TLS', 'HTTPS') as Y; filter '$.X.listeners[?any( protocol equals HTTP or protocol equals UDP or protocol equals TCP_UDP )] exists or ( $.X.listeners[*].protocol equals TCP and $.X.listeners[*].defaultActions[*].targetGroupArn contains $.Y.targetGroupArn)'; show X;
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = state.code contains active and listeners[?any( protocol is member of (HTTP,TCP,UDP,TCP_UDP) and defaultActions[?any( redirectConfig.protocol contains HTTPS)] does not exist )] exists as X; config from cloud.resource where api.name = 'aws-elbv2-target-group' AND json.rule = targetType does not equal alb and protocol exists and protocol is not member of ('TLS', 'HTTPS') as Y; filter '$.X.listeners[?any( protocol equals HTTP or protocol equals UDP or protocol equals TCP_UDP )] exists or ( $.X.listeners[].protocol equals TCP and $.X.listeners[].defaultActions[*].targetGroupArn contains $.Y.targetGroupArn)'; show X;
</code></pre><p><strong>Impact—</strong> Low. Existing alerts where the Listener requests are redirected to HTTPS URL are resolved.</p></td></tr><tr><td><strong>GCP VM instance configured with default service account</strong></td><td><p><strong>Changes—</strong> The policy RQL has been updated to check for Default Service Accounts with editor role.</p><p><strong>Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-instances-list' AND json.rule = (status equals RUNNING and name does not start with "gke-") and serviceAccounts[?any( email contains "compute@developer.gserviceaccount.com")] exists
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-projects-get-iam-user' AND json.rule = user contains "compute@developer.gserviceaccount.com" and roles[*] contains "roles/editor" as X; config from cloud.resource where api.name = 'gcloud-compute-instances-list' AND json.rule = (status equals RUNNING and name does not start with "gke-") and serviceAccounts[?any( email contains "compute@developer.gserviceaccount.com")] exists as Y; filter '$.Y.serviceAccounts[*].email contains $.X.user'; show Y;
</code></pre><p><strong>Impact—</strong> Low. Existing alerts where they do not have editor role attached to default service account are resolved.</p></td></tr><tr><td><strong>Policy Updates—Metadata</strong></td><td></td></tr><tr><td><strong>AWS EC2 instance not configured with Instance Metadata Service v2 (IMDSv2)</strong></td><td><p><strong>Changes—</strong> The policy now supports remediation. You can resolve the alerts by running the remediation.</p><p><strong>Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> No impact since support for remediation is introduced.</p></td></tr></tbody></table>

## IAM Policy Updates

Prisma Cloud has updated the following Azure IAM out-of-the-box (OOTB) policies:

<table data-header-hidden><thead><tr><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td>POLICY NAME</td><td>DESCRIPTION</td><td>CURRENT RQL</td><td>UPDATED RQL</td></tr><tr><td><strong>Azure VM instance associated managed identities with Key Vault management access (data access is not included)</strong></td><td>With access to 'Microsoft.KeyVault' service, an adversary can elevate the access of the VM instance, expanding the surface of the attack and granting access to cloud resources with sensitive information</td><td><pre><code>config from iam where source.cloud.type = 'Azure' AND grantedby.cloud.entity.type IN ( 'System Assigned', 'User Assigned' ) AND dest.cloud.service.name = 'Microsoft.KeyVault' AND source.cloud.service.name = 'Microsoft.Compute'
</code></pre></td><td><pre><code>config from iam where source.cloud.type = 'Azure' AND grantedby.cloud.entity.type IN ( 'System Assigned', 'User Assigned' ) AND dest.cloud.service.name = 'Microsoft.KeyVault' AND source.cloud.service.name = 'Microsoft.Compute' AND action.name DOES NOT END WITH 'read'
</code></pre></td></tr><tr><td><strong>Azure Managed Identity (user assigned or system assigned) with broad Key Vault management access</strong></td><td>Managed identities provide an automatic way for applications to connect to resources that support Azure Active Directory (Azure AD) authentication. Providing Key Vault management access lets non-human identities manage key vaults. The least privilege model should be enforced and unused sensitive permissions should be revoked.</td><td><pre><code>config from iam where source.cloud.type = 'Azure' AND grantedby.cloud.entity.type IN ( 'System Assigned', 'User Assigned' ) AND dest.cloud.service.name = 'Microsoft.KeyVault' AND dest.cloud.resource.name = '*'
</code></pre></td><td><pre><code>config from iam where source.cloud.type = 'Azure' AND grantedby.cloud.entity.type IN ( 'System Assigned', 'User Assigned' ) AND dest.cloud.service.name = 'Microsoft.KeyVault' AND dest.cloud.resource.name = '*' AND action.name DOES NOT END WITH 'read'
</code></pre></td></tr><tr><td><strong>Azure Service Principals with broad Key Vault management access</strong></td><td>Service Principles provide an automatic way for applications to connect to resources that support Azure Active Directory (Azure AD) authentication. Providing Key Vault management access lets non-human identities manage key vaults. The least privilege model should be enforced and unused sensitive permissions should be revoked</td><td><pre><code>config from iam where source.cloud.type = 'Azure' grantedby.cloud.entity.type = 'Service Principal' AND dest.cloud.service.name = 'Microsoft.KeyVault' AND dest.cloud.resource.name = '*'
</code></pre></td><td><pre><code>config from iam where source.cloud.type = 'Azure' grantedby.cloud.entity.type = 'Service Principal' AND dest.cloud.service.name = 'Microsoft.KeyVault' AND dest.cloud.resource.name = '*' AND action.name DOES NOT END WITH 'read'
</code></pre></td></tr><tr><td><strong>Azure AD users with broad Key Vault management access</strong></td><td>Providing Key Vault access lets users manage key vaults. The least privilege model should be enforced and unused sensitive permissions should be revoked</td><td><pre><code>config from iam where source.cloud.type = 'Azure' AND source.cloud.resource.type = 'user' AND dest.cloud.service.name = 'Microsoft.KeyVault' AND dest.cloud.resource.name = '*'
</code></pre></td><td><pre><code>config from iam where source.cloud.type = 'Azure' AND source.cloud.resource.type = 'user' AND dest.cloud.service.name = 'Microsoft.KeyVault' AND dest.cloud.resource.name = '*' AND action.name DOES NOT END WITH 'read'
</code></pre></td></tr></tbody></table>

## Changes in Existing Behavior

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>FEATURE</td><td>DESCRIPTION</td></tr><tr><td><strong>Pending Resolution State for Alerts</strong></td><td><p>A new alert state <strong>Pending Resolution</strong> is available for filtering alerts. If you configured an alert rule with Auto Remediation enabled and it includes config policies that are remediable, the alerts is marked with pending_resolution which is an interim state. As soon as the CLI is executed and the resource misconfguration is addressed, the alert transitions from the <strong>Pending Resolution</strong> state to the <strong>Resolved</strong> state.</p><p><strong>API change—</strong> The <a href="https://pan.dev/prisma-cloud/api/cspm/get-alert-filter-and-options/">https://pan.dev/prisma-cloud/api/cspm/get-alert-filter-and-options/</a> includes the new state in the response.</p><pre><code>"alert.status": {
        "options": [
            "dismissed",
            "snoozed",
            "pending_resolution",
            "open",
            "resolved"
        ],
        "staticFilter": true
    },
</code></pre><p>If you have not explicitly included the alert.status value in the API request, the response will include alerts with all states ("dismissed", "snoozed", "pending_resolution", "open", "resolved").</p></td></tr></tbody></table>

## REST API Updates

| CHANGE              | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **New Search APIs** | <p>The following new endpoints are available as part of the Search APIs:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/search-config-by-query/">POST /search/api/v1/config</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/config-search-async/">POST /search/api/v1/config/async</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/search-config-csv-download/">POST /search/api/v1/config/download</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/search-config-by-search-id/">POST /search/api/v1/config/:id</a></li></ul> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-cspm-release-information/features-introduced-in-september-2023.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
