Platform Changes
Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.
Covering August 10, 2026, 00:00–24:00 UTC · published August 10, 2026 22:11 UTC.
Last checked about 11 hours ago. Summaries are written by claude-code/claude-opus-5; the changes themselves are recorded automatically.
Documentation
33 pages changed +128 −275Mobile compatibility pages folded into one; AWS Control Tower BYOB onboarding corrected
- Cortex XDR Compatibility Matrix lost two pages: the Android and iOS/iPadOS tables now live on their parent page, taking the book from 15 pages to 13.
- Most compatibility tables were re-emitted as raw HTML with a single Cortex XDR agent header row over the version columns.
- AWS Control Tower (BYOB) audit log collection gained a CloudFormation parameter, a corrected IAM role name, and a post-deployment page retitled to cover it.
- Microsoft Azure automated collection now documents one management-group diagnostic setting instead of per-subscription ones.
- Nine pages lost their front-matter
descriptionblocks, and several XSOAR/XSIAM naming slips were fixed.
- README
- Navigation manifest (compatibility)
- Navigation manifest (xsiam)
- Cloud platforms supported with Cortex XDR agent
- Linux
- Mac
- and 27 more
Analytics rules
18 rules changed +60 −22Run-together required_data entries split into separate sources on 18 rules
- 18 analytics rules were modified; nothing was added or withdrawn.
- Every edit is inside
required_data: sources that had been stored as one run-together string are now separate list items. - Four identity and cloud rules went from two merged strings to eight named sources each.
- No severity, test period, description or investigative action changed on any rule.
- A compromised process accessed a rare cloud resource
- A compromised process accessed a rare external host
- A user accessed an uncommon AppID
- A user accessed multiple time-consuming websites
- Azure Privilege Escalation Using an Application
- Cloud IMDS access followed by remote token usage
- and 12 more
Content packs
101 packs changed +5883 −551Eight new AWS Network Firewall commands; SOC Framework Pack Manager 1.1.0 reworks pack installation
- Amazon Web Services 2.5.0 added eight
aws-network-firewall-*commands covering resource policies, resource tagging and logging configuration. - SOC Framework Pack Manager 1.1.0 now upgrades packs in place instead of installing each release as a separate pack, adds a
diagnoseaction, and no longer needs the XSIAMContentPackInstaller automation. - Three ingestion and mirroring fixes: CrowdStrike Falcon event fetch past 10,000 records, SplunkPy v2 mirror-out to Splunk Enterprise Security 8.2.x, and Microsoft Defender for Cloud Apps dropping low-volume event types.
- Cloud Posture remediation content moved off the deprecated
azure-nsg-*andazure-disk-*commands onto the newazure-vn-*andazure-compute-*names. - An automated Docker bump touched 85 packs, and eight core packs were re-released as dependency locks with no functional change.
- AWS
- Active_Directory_Query
- AnsibleTower
- ArcherRSA
- Attlasian
- AwakeSecurity
- and 95 more
BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.