Platform Changes
Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.
Covering August 09, 2026, 00:00–24:00 UTC · published August 09, 2026 15:23 UTC.
Last checked about 12 hours ago. Summaries are written by claude-code/claude-opus-5 and claude-code/claude-sonnet-5; the changes themselves are recorded automatically.
Documentation
8 pages changed +197 −140Cribl gains a generic-UUID onboarding workflow; dev tenant now syncs case fields and layouts
Cortex XSIAM data-source docs got one substantial new workflow and one small feature note; the rest of the day’s docs changes were formatting cleanup with no content change.
- Cribl generic UUID ingestion: a new step-by-step section explains how to onboard a data source that isn’t in Cribl’s dedicated UUID catalog — create a pipeline, set
__sourceIdentifier/__vendor/__productfields, and route the data to the XSIAM destination. - Dev tenant sync: “Case fields and layouts” joins the list of content types Cortex XSIAM can push/pull with a remote repository.
- Syslog Collector applet: its content-pack/integration links table now scopes itself to integrations “onboarded prior to July 26, 2026”.
- Three broker VM applet pages (DSPM Fileshare, Local Agent Settings, Network Mapper) were reformatted into call-out boxes with bolded UI labels — the instructions themselves did not change.
- The Cribl UUID reference table’s cross-links were rewritten from opaque short links to descriptive relative paths pointing at the actual vendor pages.
- Activate DSPM Fileshare
- Activate Local Agent Settings
- Activate Network Mapper
- Syslog Collector applet
- Ingest logs from a Syslog receiver
- Ingest data from Cribl
- and 2 more
Analytics rules
1293 rules changed +53061 −0Analytics rule catalog exported for the first time: 1,293 detectors
This is the analytics mirror’s first export, not a day of change to an existing catalog. All 1,293 files under analytics/ are additions — nothing was modified or removed, so there is no prior baseline to diff against.
Each file is one exported detection rule. Given the size and all-additions shape of this commit, individual rules were not read; see the mirror for the full list.
- A Backup vault policy was modified
- A browser extension was installed or loaded in an uncommon way
- A browser was opened in private mode
- A Cloud DB instance was exported to an unknown destination
- A cloud function was created with an unusual runtime
- A cloud identity created or modified a security group
- and 1287 more
Content packs
12 packs changed +12410 −873AWS Security Hub v2 and Intel471 Credentials land; 663 CommonTypes definitions gain module gating
- AWS - Security Hub v2 is a new integration: OCSF-format findings, four
aws-securityhub-v2-*commands, and bidirectional incident mirroring with incoming/outgoing mappers and its own incident type. - Intel471 Credentials is a new integration fetching leaked credentials as one indicator per credential, alongside twelve new Intel471 Info Stealer indicator fields.
- CommonTypes added a
supportedModuleslist to 663 field, classifier and indicator-type definitions —xsiamandagentixthroughout, plusxtion the five core reputation types. - Cyware Intel Exchange (CTIX) 2.5.0 shipped a flagged-indicator deletion job, five new flag fields, and deprecated the older Cyware Threat Intelligence eXchange integration.
- Three authentication and severity-mapping fixes: Defender for Endpoint on GCC High/DoD, Graph Security severity, and CTIX revoked indicators.
- AWS-SecurityHub
- CTIX
- Cisco-umbrella-cloud-security
- CommonTypes
- EDL
- FeedDomainTools
- and 6 more
BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.