# Cortex Toolbox Cortex Toolbox browses Palo Alto Cortex security content: content packs from the public demisto/content repository, the Cortex product documentation, and analytics alerts. This is an independent community project, not affiliated with Palo Alto Networks. ## Available Pages - /packs — Browse content packs (1352 packs) - /integrations — Browse integrations (1342 integrations) - /playbooks — Browse playbooks (1992 playbooks) - /scripts — Browse scripts (1448 scripts) - /incident-types — Incident types (597) - /incident-fields — Incident fields (5503) - /classifiers — Classifiers and mappers (489) - /layouts — Layouts (526) - /parsing-rules — Parsing rules (151) - /correlation-rules — Correlation rules (10) - /modeling-rules — Modeling rules (446) - /xsiam-dashboards — XSIAM dashboards (24) - /xsiam-reports — XSIAM reports (7) - /jobs — Scheduled jobs (7) - /generic-definitions — Generic object definitions (1) - /generic-modules — Generic modules (1) - /generic-types — Generic types (5) - /generic-fields — Generic fields (34) - /docs — Cortex documentation browser (2581 topics) - /platform-changes — Day-by-day changes across Cortex (docs, analytics rules, content packs) - /detectors — Every detection rule in one filterable set: analytics alerts, BIOCs and correlation rules (1677 detectors). /detectors/stats for the statistics, /detectors/attack for the ATT&CK matrix. - /analytics-alerts — Analytics alert definitions (1300 alerts) - /biocs — BIOC (behavioral indicator of compromise) detection rules (367 rules) - /xdm — Cross Data Model (XDM) schema field explorer - /versions — What a content pack's fromversion (e.g. 8.15.0) is called in each Cortex product: XSOAR, XSIAM, XDR, Cortex Cloud, AgentiX - /reputation-commands — Reputation command coverage matrix across integrations - /feeds — Threat feed integrations - /search?q={query} — Search across all content ## Lite mode (semantic HTML, no CSS, no JS) Prefix any read-only path with /lite for a clean, dependency-free rendering, ideal for scraping and LLM ingestion. Every page listed above also exists at /lite/. Entry points: - /lite — home - /lite/docs — documentation - /lite/packs, /lite/integrations, /lite/playbooks, /lite/scripts - /lite/analytics-alerts, /lite/biocs - /lite/search?q={query} See /sitemap.xml for the full list of canonical URLs. ## API Endpoints (JSON) - GET /api/status — Version and per-source load state - GET /api/stats — Content statistics - GET /api/search?q={query} — Search results - GET /api/packs — All packs with counts - GET /api/packs/:name — Pack details - GET /api/integrations/:id — Integration details with commands - GET /api/analytics-alerts — Analytics alert definitions - GET /api/biocs — BIOC detection rule definitions - GET /api/docs — Documentation manifest (tree) ## Full Content For a comprehensive machine-readable index, see /llms-full.txt