Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.

Covering August 05, 2026, 00:00–24:00 UTC · published August 05, 2026 16:56 UTC.

Still waiting on Documentation and Analytics rules. That sync has not landed for this day, so this is a partial picture rather than the whole one.

Last checked about 15 hours ago. Summaries are written by claude-code/claude-opus-5; the changes themselves are recorded automatically.

Documentation

Not synced yet — nothing has been recorded for this source on this day.

Analytics rules

Not synced yet — nothing has been recorded for this source on this day.

Content packs

9 packs changed +1754 −64

Cisco Email Threat Defense connector added; AWS CloudWatchLogs marked for deprecation

  • Cisco Email Threat Defense (ETD) Cortex XSOAR Connector is a new pack that fetches ETD message events as incidents and ships a reclassification and remediation playbook.
  • AWS - CloudWatchLogs carries a deprecation notice for November 2026, pointing users at the unified AWS integration.
  • Deprecations landed on two Microsoft commands: the display_name argument of azure-sentinel-threat-indicator-update, and the filter, select and expand arguments of azure-sc-list-alert.
  • Microsoft Sentinel also gained two incident fetch filters, and Amazon Web Services a tags argument on EKS access entry creation.
  • AWS
  • AWS-CloudWatchLogs
  • ApiModules
  • AzureSecurityCenter
  • AzureSentinel
  • CommunityElasticSearch
  • and 3 more

See what changed →

BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.