For the complete documentation index, see llms.txt. This page is also available as Markdown.

Features Introduced in October 2023

Learn what’s new on Prisma® Cloud in October 2023.

New Features Introduced in October 2023

New Features

FEATURE

DESCRIPTION

Cloud Discovery and Exposure Management

Secure the Infrastructure

23.10.2

Cloud Discovery and Exposure Management is a new subscription that uses machine learning to discover internet-exposed and unmonitored assets within your cloud infrastructure, and enables you to secure these exposed assets with a single click. The assets are seamlessly onboarded to Prisma Cloud.

When you subscribe, the Discovery and Exposure Management dashboard provides visibility into your attack surface and surfaces the top risks and exposure by country . The findings on Inventory > Unmanaged Assets enable you to investigate further based on the insights about your shadow assets exposed to the internet and enhance your security posture.

Code to Cloud Dashboard

Secure Code to Cloud

23.10.2

Prisma Cloud’s Code to Cloud Dashboard provides you with a comprehensive assessment of the health of your cloud security posture. Highlights include:

  • Latest Events Tracker— Alerts you to potential threat activity across your software development lifecycle.

  • Code & Build, Deploy, Runtime Inventory— Track and view risks and vulnerabilities identified in every phase of the software development lifecycle.

  • Custom Collections— Group asset views to focus on specific teams, business units or applications.

Compute Workloads in Asset Inventory

Secure the Infrastructure

23.10.2

Prisma Cloud Asset Inventory now includes a summarized view of Compute Workloads (containers images and hosts) across your entire workload for discovery, risk assessment, and securing the runtime.

The findings on Inventory > Compute Workloads help you to assess the impact of the vulnerable container images and hosts on your application lifecycle, identify the top impacting vulnerabilities based on critical CVEs, and identify the Cloud providers for the vulnerable hosts along with the other metadata.

Vulnerabilities Dashboard

Secure Code to Cloud

23.10.2

The Vulnerabilities Dashboard gives you a holistic graphical view of all the vulnerabilities across your entire application lifecycle and narrows them down to the most critical and urgent ones, and the ones that are actionable. You get an overview of the top impacting vulnerabilities based on the CVEs, and the vulnerabilities impact by your app lifecycle in a CBDR view.

The CBDR graph findings help you assess the vulnerable assets in your environment and make informed decisions to remediate or mitigate the risks.

Vulnerability Search on Investigate

Secure Code to Cloud

23.10.2

The vulnerable where RQL clause helps you to investigate the vulnerable assets in Prisma Cloud to assess the risk and take actions to remediate and mitigate the vulnerabilities.

For example, with this vulnerable where RQL clause you can find all assets affected by a CVE ID, vulnerabilities with a CVSS score larger than 9, and vulnerabilities that are Exploitable, Patchable, and in Use.

API Endpoints Inventory

Secure the Runtime

23.10.2

Prisma Cloud Inventory now includes continuous discovery of all the API endpoints in your environment. This discovery helps you to prioritize the risks and understand your security posture as well as attack vectors.

The Inventory > API Endpoints gives insights into the discovered endpoints with details on URL Path, the HTTP method, assets relationship, services, Cloud accounts, risk factors, the workload the API endpoints are associated with, and the discovery method.

The API risk profiling gives you insights on policies violated, findings, risk factors indicators, and the associate workload on which the endpoint is hosted.

Prisma Cloud uses existing WAAS runtime rules (agent-based and agentless) to scan traffic and AWS API Gateway configurations within your deployment to list the API endpoints.

Prioritize and Remediate Risks

Secure Code to Cloud

23.10.2

Prisma Cloud Attack Path Analysis identifies and collects a wide range of security signals to assist with risk prioritization. These signals include vulnerabilities in cloud resources, public exposure of resources to the internet, overly permissive credentials, and threat context, such as potentially malicious traffic or IP addresses.

By intelligently analyzing and correlating these signals, along with considering the business context of an application or data at risk, Prisma Cloud can guide your security teams to address the most critical risks first. This level of prioritization ensures that your organization can focus on securing your most valuable assets while minimizing the risk of data breaches or other threats. Prisma Cloud helps you identify the Attack Paths, which are presented in a graph view and offer valuable security context to protect your assets against high-risk threats.

Application Asset

Secure the Source

23.10.2

Application Asset queries are added to the Search and Investigate page, providing a graphical representation (graph) of your software development life cycle (SDLC) and enabling you to conduct a comprehensive analysis of security issues throughout your engineering environment. You will gain valuable insights into the assets in your environment and understand the relationships between them.

Repository Application Graph

Secure the Source

23.10.2

  • Added the option to access the Repository Application Graph through a dedicated sidecar. You can access this sidecar by selecting a repository in the repository inventory table of the Repositories page.

  • Removed query functionality from the Repository Application Graph.

Inventory - IaC Resources

Secure the Source

23.10.2

Prisma Cloud introduces inventory management for IaC Resources on the console (Inventory > IaC Resources). The inventory gives you a comprehensive list of interconnected frameworks across diverse cloud accounts and repositories, delivering enhanced visibility into cloud resource management through the console.

GCP Drift Detection and Drift Alerts

Secure the Source

23.10.2

Prisma Cloud provides support for Terraform to GCP Drift Detection, enabling you to identify instances when configurations for resources on the Google Cloud Platform deviate from the Terraform specifications in your version control system (VCS). Additionally, you will receive alerts for any divergence of your resources from your Terraform configurations, enabling you to uphold consistency and security, ensuring that your infrastructure aligns with your desired configuration.

Selective Scan for Organization Member Accounts

Secure the Infrastructure

23.10.2

Prisma Cloud introduces selective Agentless scanning for workloads and serverless functions for the member accounts within an organization for AWS, GCP and Azure. You can selectively enable or disable agentless or serverless scanning for individual member accounts or choose to scan the entire organization. By being selective you can incrementally add accounts for scanning and choose whether to scan all accounts in the organization or just some accounts.

Enable Organization Scan to scan all the accounts in the organization

Support for New Region on AWS

Secure the Infrastructure

23.10.2

Prisma Cloud now ingests data for resources deployed in the Israel region on AWS.

To review a list of supported regions, select Inventory > Assets, and choose Cloud Region from the filter drop-down.

Security Fix

HTTP/2 Rapid Reset Attack Vulnerability (CVE-2023-44487)

Secure the Runtime

30.02.137

This security update in v31.02.137 for Runtime Security addresses the HTTP/2 Rapid Reset Attack Vulnerability (CVE-2023-44487).

  1. Go updated from 1.20.8 to 1.20.10 (https://go.dev/doc/devel/release#go1.20.10).

  2. Go package "golang.org/x/net" was updated to version 0.17.0 (https://github.com/advisories/GHSA-4374-p667-p6c8).

  3. The "nghttp2" package (installed in the Defender/Console images) updated by Red Hat (https://access.redhat.com/errata/RHSA-2023:5837).

Action - You do not need to make any updates to Compute console or the deployed Defenders.

API Ingestions

SERVICE

API DETAILS

AWS DataSync

23.10.2

aws-datasync-task-execution

Additional permissions required:

  • datasync:ListTaskExecutions

  • datasync:DescribeTaskExecution

  • datasync:ListTagsForResource

The Security Audit role includes the permissions.

AWS Transfer Family

23.10.2

aws-transfer-family-security-policy

Additional permissions required:

  • transfer:DescribeSecurityPolicy

  • transfer:DescribeServer

  • transfer:ListServers

The Security Audit role includes the permissions.

AWS WAF

23.10.2

aws-waf-v2-rule-group

Additional permissions required:

  • wafv2:GetRuleGroup

You must manually add or update the CFT template to enable the permission.

Azure AD B2C

23.10.2

azure-active-directory-b2c-tenants

Additional permission required:

  • Microsoft.AzureActiveDirectory/b2cDirectories/read

The Reader role includes the permission.

Update Azure Application Gateway

23.10.2

azure-application-gateway

The resource JSON for this API has been updated to include the defaultPredefinedSslPolicy field. The field defines the default TLS policy to use.

Google Vertex AI AIPlatform

23.10.2

gcloud-vertex-ai-aiplatform-feature-store

Additional permissions required:

  • aiplatform.featurestores.list

  • aiplatform.featurestores.getIamPolicy

The Viewer role includes the permissions.

Google Vertex AI AIPlatform

23.10.2

gcloud-vertex-ai-aiplatform-metadata-store

Additional permission required:

  • aiplatform.metadataStores.list

The Viewer role includes the permission.

Google Vertex AI AIPlatform

23.10.2

gcloud-vertex-ai-aiplatform-tensor-board

Additional permission required:

  • aiplatform.tensorboards.list

The Viewer role includes the permission.

Google Vertex AI AIPlatform

23.10.2

gcloud-vertex-ai-aiplatform-index-endpoint

Additional permission required:

  • aiplatform.indexEndpoints.list

The Viewer role includes the permission.

OCI Cloud Guard

23.10.2

oci-cloudguard-target

Additional permissions required:

  • CG_TARGET_INSPECT

  • CG_TARGET_READ

You must update the Terraform template to enable the permissions.

New Policies

New Attack Path policies are available. Log in to the Prisma Cloud console and filter for the list of available policies.

Policy Updates

POLICY UPDATES

DESCRIPTION

Policy Updates—RQL

GCP Kubernetes Engine Clusters have Network policy disabled

23.10.2

Changes— The RQL has been updated as per the current network policy settings for GCP Kubernetes Engine Clusters.

Current RQL—

Updated RQL—

Severity— Low

Policy Type— Config

Impact— Low. Existing alerts where the cluster is configured with ADVANCED_DATAPATH will be resolved as Policy_Updated. New alerts will be generated where it checks for Calico Kubernetes Network policy not being configured.

Changes in Existing Behavior

FEATURE

DESCRIPTION

Enhancement to Code Security Dashboards

Secure the Source

23.10.2

From this release Code Security Dashboard (Dashboard > Code Security) will support the Latest Code Review Scans widget to provide insights into real-time monitoring of coding errors, and security vulnerabilities.

REST API Updates

CHANGE

DESCRIPTION

Code to Cloud APIs

The following new endpoints are added to get data that is used for plotting the deploy and runtime trends on the Code to Cloud dashboard:

Command Center APIs

The following new endpoints are available for the Command Center API:

Cloud Discovery and Exposure Management APIs

New endpoints are available in the Cloud Discovery and Exposure Management category to onboard cloud accounts and get details about the exposed or unmanaged assets.

Collection APIs

The following new endpoints are added to manage collections which is a logical group of assets:

Updates to Cloud Account APIs

A new parameter, defaultMemberState, is added to the following endpoints:

Deprecation Notice

Feature

Description

Date Filter Support

Secure the Infrastructure

This deprecation was first announced in the Look Ahead that was published with the 23.10.1 release.

The Date filter is being deprecated on Inventory > Assets, Asset Explorer, and Compliance > Overview.

With the 23.10.2 release, the date filter will no longer be supported. With this change, links in Compliance reports that were generated before 23.10.2 will be removed.

Data Dashboard

Secure the Infrastructure

This deprecation was first announced in the Look Ahead that was published with the 23.10.1 release.

The Data Dashboard is being deprecated on Dashboards > Data.

With the 23.10.2 release, the widgets in the Data dashboard will be available in a custom dashboard. To view the Data Security information, you will be able to create a custom dashboard and add the data security widgets.

Removal of deprecated AWS, GCP, and Azure Cloud Types in CSPM Cloud Accounts API

Secure the Infrastructure

This deprecation was first announced in the Look Ahead that was published with the 23.6.1 release.

The following endpoints no longer support the AWS, GCP, and Azure cloud types:

The following APIs released previously, provide the same functionality separately for each cloud type.

Supply Chain Graph

Secure the Code

From this release, the Application Security > Supply Chain page is no longer available as a standalone page. The package dependency tree will be added to the Application Graph on Investigate in a future release.

Use Application Security > Projects for insights into vulnerabilities within open-source packages

Development Pipelines

Secure the Code

From this release Application Security > Development Pipelines is no longer available as a standalone page. For Code Reviews details, use the Latest Code Review Scans widget on Dashboard > Code Security.

Last updated

Was this helpful?