Platform Changes
Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.
Covering July 26, 2026, 00:00–24:00 UTC · published July 26, 2026 14:34 UTC.
Still waiting on Documentation and Analytics rules. That sync has not landed for this day, so this is a partial picture rather than the whole one.
Last checked about 22 hours ago. Summaries are written by claude-code/claude-sonnet-5; the changes themselves are recorded automatically.
Documentation
Not synced yet — nothing has been recorded for this source on this day.
Analytics rules
Not synced yet — nothing has been recorded for this source on this day.
Content packs
10 packs changed +7740 −692ThreatMon adds a Threat Feed pack and CVE commands; Sysdig ships a breaking v2.0.0 rewrite
A mix of real integration work landed alongside a large [AUD Isolation] PaloAltoNetworks_IoT bookkeeping commit that re-added ~82,000 files across virtually every pack in the catalog — that commit is a repository snapshot from an internal isolation/build process, not a day of content change, and is excluded from the detail below.
- ThreatMon shipped a new ThreatMon Threat Feed pack, and the base ThreatMon integration gained
threatmon_list_cvesandthreatmon_list_subscribed_cvescommands. - Sysdig cut a breaking v2.0.0: the incoming mapper was rewritten for the real Secure V2 webhook payload (the old mapper targeted fields that didn’t exist), 34 new incident fields were added, and
execute-response-actionnow supports all 24 response action types with per-action validation. Agent ID/Customer ID are no longer supplied by the webhook and must be resolved via a newsysdig-agent-info-getcommand. - GravityZone’s
gz-endpoint-listcommand gained recursive listing across managed companies plus new filters and output fields. - Anthropic Claude integration added
claude-chat-file-deleteandclaude-project-document-deletecommands. - Doppel fixed duplicate incident creation in
fetch-incidents(now paginated and de-duplicated by alert ID) and switched to the API’s max page size. - Cybersixgill Actionable Alerts moved case-details/alert-info URL construction into integration code and appended the organization ID as a query parameter.
- Microsoft Entra ID parsing rule added a
timefield fallback for events missingTimeGenerated. - Base pack bumped Docker images for
GetMLModelEvaluation,DBotPredictPhishingWords, andGetIndicatorsByQuery.
- AnthropicClaude
- Base
- Cybersixgill-ActionableAlerts
- Doppel
- GravityZone
- MicrosoftEntraID
- and 4 more
BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.