Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.

Covering August 10, 2026, 00:00–24:00 UTC · published August 10, 2026 22:11 UTC.

Last checked about 11 hours ago. Summaries are written by claude-code/claude-opus-5; the changes themselves are recorded automatically.

Documentation

33 pages changed +128 −275

Mobile compatibility pages folded into one; AWS Control Tower BYOB onboarding corrected

  • Cortex XDR Compatibility Matrix lost two pages: the Android and iOS/iPadOS tables now live on their parent page, taking the book from 15 pages to 13.
  • Most compatibility tables were re-emitted as raw HTML with a single Cortex XDR agent header row over the version columns.
  • AWS Control Tower (BYOB) audit log collection gained a CloudFormation parameter, a corrected IAM role name, and a post-deployment page retitled to cover it.
  • Microsoft Azure automated collection now documents one management-group diagnostic setting instead of per-subscription ones.
  • Nine pages lost their front-matter description blocks, and several XSOAR/XSIAM naming slips were fixed.
  • README
  • Navigation manifest (compatibility)
  • Navigation manifest (xsiam)
  • Cloud platforms supported with Cortex XDR agent
  • Linux
  • Mac
  • and 27 more

See what changed →

Analytics rules

18 rules changed +60 −22

Run-together required_data entries split into separate sources on 18 rules

  • 18 analytics rules were modified; nothing was added or withdrawn.
  • Every edit is inside required_data: sources that had been stored as one run-together string are now separate list items.
  • Four identity and cloud rules went from two merged strings to eight named sources each.
  • No severity, test period, description or investigative action changed on any rule.
  • A compromised process accessed a rare cloud resource
  • A compromised process accessed a rare external host
  • A user accessed an uncommon AppID
  • A user accessed multiple time-consuming websites
  • Azure Privilege Escalation Using an Application
  • Cloud IMDS access followed by remote token usage
  • and 12 more

See what changed →

Content packs

101 packs changed +5883 −551

Eight new AWS Network Firewall commands; SOC Framework Pack Manager 1.1.0 reworks pack installation

  • Amazon Web Services 2.5.0 added eight aws-network-firewall-* commands covering resource policies, resource tagging and logging configuration.
  • SOC Framework Pack Manager 1.1.0 now upgrades packs in place instead of installing each release as a separate pack, adds a diagnose action, and no longer needs the XSIAMContentPackInstaller automation.
  • Three ingestion and mirroring fixes: CrowdStrike Falcon event fetch past 10,000 records, SplunkPy v2 mirror-out to Splunk Enterprise Security 8.2.x, and Microsoft Defender for Cloud Apps dropping low-volume event types.
  • Cloud Posture remediation content moved off the deprecated azure-nsg-* and azure-disk-* commands onto the new azure-vn-* and azure-compute-* names.
  • An automated Docker bump touched 85 packs, and eight core packs were re-released as dependency locks with no functional change.
  • AWS
  • Active_Directory_Query
  • AnsibleTower
  • ArcherRSA
  • Attlasian
  • AwakeSecurity
  • and 95 more

See what changed →

BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.