Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.

Covering July 26, 2026, 00:00–24:00 UTC · published July 26, 2026 14:34 UTC.

Still waiting on Documentation and Analytics rules. That sync has not landed for this day, so this is a partial picture rather than the whole one.

Last checked about 22 hours ago. Summaries are written by claude-code/claude-sonnet-5; the changes themselves are recorded automatically.

Documentation

Not synced yet — nothing has been recorded for this source on this day.

Analytics rules

Not synced yet — nothing has been recorded for this source on this day.

Content packs

10 packs changed +7740 −692

ThreatMon adds a Threat Feed pack and CVE commands; Sysdig ships a breaking v2.0.0 rewrite

A mix of real integration work landed alongside a large [AUD Isolation] PaloAltoNetworks_IoT bookkeeping commit that re-added ~82,000 files across virtually every pack in the catalog — that commit is a repository snapshot from an internal isolation/build process, not a day of content change, and is excluded from the detail below.

  • ThreatMon shipped a new ThreatMon Threat Feed pack, and the base ThreatMon integration gained threatmon_list_cves and threatmon_list_subscribed_cves commands.
  • Sysdig cut a breaking v2.0.0: the incoming mapper was rewritten for the real Secure V2 webhook payload (the old mapper targeted fields that didn’t exist), 34 new incident fields were added, and execute-response-action now supports all 24 response action types with per-action validation. Agent ID/Customer ID are no longer supplied by the webhook and must be resolved via a new sysdig-agent-info-get command.
  • GravityZone’s gz-endpoint-list command gained recursive listing across managed companies plus new filters and output fields.
  • Anthropic Claude integration added claude-chat-file-delete and claude-project-document-delete commands.
  • Doppel fixed duplicate incident creation in fetch-incidents (now paginated and de-duplicated by alert ID) and switched to the API’s max page size.
  • Cybersixgill Actionable Alerts moved case-details/alert-info URL construction into integration code and appended the organization ID as a query parameter.
  • Microsoft Entra ID parsing rule added a time field fallback for events missing TimeGenerated.
  • Base pack bumped Docker images for GetMLModelEvaluation, DBotPredictPhishingWords, and GetIndicatorsByQuery.
  • AnthropicClaude
  • Base
  • Cybersixgill-ActionableAlerts
  • Doppel
  • GravityZone
  • MicrosoftEntraID
  • and 4 more

See what changed →

BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.