Platform Changes
Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.
Covering August 03, 2026, 00:00–24:00 UTC · published August 03, 2026 15:04 UTC.
Still waiting on Documentation and Analytics rules. That sync has not landed for this day, so this is a partial picture rather than the whole one.
Last checked about 16 hours ago. Summaries are written by claude-code/claude-opus-5; the changes themselves are recorded automatically.
Documentation
Not synced yet — nothing has been recorded for this source on this day.
Analytics rules
Not synced yet — nothing has been recorded for this source on this day.
Content packs
10 packs changed +4989 −151Cyberint 1.5.0 adds four Check Point Exposure Management playbooks and two intelligence commands
- Cyberint 1.5.0 added four Check Point Exposure Management playbooks — IOC enrichment and triage, credential leak validation and response, vulnerability exploitation monitoring, and phishing takedown — all available from Cortex XSOAR 6.10.0.
- Two new feed commands:
cyberint-cve-enrichreturns EPSS, CVSS, CWE, the Cyberint CVE score and active-exploitation evidence, andcyberint-credential-leak-lookupfinds leaked credentials for a company domain. - Check Point EM Premium Feed was renamed Check Point EM ThreatCloud Intelligence Feed; the integration ID and the TIM
servicevalue stayCyberint Premium Feed, so existing instances and indicator filters keep working. - Cyberint alerts now extract indicators through two new incident fields — Cyberint Alert URL and CyberInt CVEs — wired into the incoming mapper, incident type and layout.
- Vega 1.0.1 added a Recommended Actions field, layout section and mapper support; Tenable Vulnerability Management exposed its assets fetch interval in the Exposure Management module.
- Base
- CommonPlaybooks
- CommonScripts
- Core
- Cyberint
- DemistoRESTAPI
- and 4 more
BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.