Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.

Covering August 09, 2026, 00:00–24:00 UTC · published August 09, 2026 15:23 UTC.

Last checked about 12 hours ago. Summaries are written by claude-code/claude-opus-5 and claude-code/claude-sonnet-5; the changes themselves are recorded automatically.

Documentation

8 pages changed +197 −140

Cribl gains a generic-UUID onboarding workflow; dev tenant now syncs case fields and layouts

Cortex XSIAM data-source docs got one substantial new workflow and one small feature note; the rest of the day’s docs changes were formatting cleanup with no content change.

  • Cribl generic UUID ingestion: a new step-by-step section explains how to onboard a data source that isn’t in Cribl’s dedicated UUID catalog — create a pipeline, set __sourceIdentifier/__vendor/__product fields, and route the data to the XSIAM destination.
  • Dev tenant sync: “Case fields and layouts” joins the list of content types Cortex XSIAM can push/pull with a remote repository.
  • Syslog Collector applet: its content-pack/integration links table now scopes itself to integrations “onboarded prior to July 26, 2026”.
  • Three broker VM applet pages (DSPM Fileshare, Local Agent Settings, Network Mapper) were reformatted into call-out boxes with bolded UI labels — the instructions themselves did not change.
  • The Cribl UUID reference table’s cross-links were rewritten from opaque short links to descriptive relative paths pointing at the actual vendor pages.
  • Activate DSPM Fileshare
  • Activate Local Agent Settings
  • Activate Network Mapper
  • Syslog Collector applet
  • Ingest logs from a Syslog receiver
  • Ingest data from Cribl
  • and 2 more

See what changed →

Analytics rules

1293 rules changed +53061 −0

Analytics rule catalog exported for the first time: 1,293 detectors

This is the analytics mirror’s first export, not a day of change to an existing catalog. All 1,293 files under analytics/ are additions — nothing was modified or removed, so there is no prior baseline to diff against.

Each file is one exported detection rule. Given the size and all-additions shape of this commit, individual rules were not read; see the mirror for the full list.

  • A Backup vault policy was modified
  • A browser extension was installed or loaded in an uncommon way
  • A browser was opened in private mode
  • A Cloud DB instance was exported to an unknown destination
  • A cloud function was created with an unusual runtime
  • A cloud identity created or modified a security group
  • and 1287 more

See what changed →

Content packs

12 packs changed +12410 −873

AWS Security Hub v2 and Intel471 Credentials land; 663 CommonTypes definitions gain module gating

  • AWS - Security Hub v2 is a new integration: OCSF-format findings, four aws-securityhub-v2-* commands, and bidirectional incident mirroring with incoming/outgoing mappers and its own incident type.
  • Intel471 Credentials is a new integration fetching leaked credentials as one indicator per credential, alongside twelve new Intel471 Info Stealer indicator fields.
  • CommonTypes added a supportedModules list to 663 field, classifier and indicator-type definitions — xsiam and agentix throughout, plus xti on the five core reputation types.
  • Cyware Intel Exchange (CTIX) 2.5.0 shipped a flagged-indicator deletion job, five new flag fields, and deprecated the older Cyware Threat Intelligence eXchange integration.
  • Three authentication and severity-mapping fixes: Defender for Endpoint on GCC High/DoD, Graph Security severity, and CTIX revoked indicators.
  • AWS-SecurityHub
  • CTIX
  • Cisco-umbrella-cloud-security
  • CommonTypes
  • EDL
  • FeedDomainTools
  • and 6 more

See what changed →

BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.