Platform Changes
Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.
Covering August 17, 2026, 00:00–24:00 UTC · published August 18, 2026 09:14 UTC.
Last checked about 5 hours ago. Summaries are written by claude-code/claude-opus-5; the changes themselves are recorded automatically.
Documentation
4 pages changed +14 −13Cortex CLI and MCP server docs restructured; EDL root certificate switches to DigiCert
- The Cortex CLI section moved to
about-cortex-cliand the Cortex MCP server overview collapsed into its parent, renaming 19 pages between them — bookmarks break. - Twelve pages are new, ten of them net: CLI installation and post-install management,
parse_cef()andparse_json()for parsing rules, a Data Ingestion dashboard reference, and three XDR Collector profile pages. - Acting on today: EDL setup needs the DigiCert root certificate, scheduled correlations are capped at 1,200, and data ingestion health monitoring is now labelled BETA.
- Quieter churn: ~25 Cloud Security pages changed only their front-matter
description, and 30 Linux kernel tables gained newly supported kernel versions.
- Task 2: Create the app registration for the Azure BYOA outpost
- Evidence
- Cortex XSIAM product licenses
- Navigate the Cortex XSIAM docs
Analytics rules
0 rules changed +0 −0Synced, and nothing changed upstream.
Content packs
48 packs changed +7742 −15092CyberArk EPM adds Idira OAuth; rasterize's 8.15 fork removed; 21 more packs get identity modeling rules
- 13 commits, 269 files across 48 packs — the bulk of it CRTX-271523/271526 PRs 2, 4, 5 and 7 of 7, which added a second
_2_11modeling rule to 21 more log sources. - CyberArk EPM 1.3.0 gains a third authentication method: CyberArk Identity (Idira ISPSS) OAuth 2.0
client_credentials. - The version-forked rasterize_8_15 integration was deleted and folded into the single Rasterize integration, which loses its
toversion: 8.14.0cap. - XSUP-74186 restricted the three summary-report scripts to the Cortex XSOAR marketplace and updated 16 playbooks across the compliance and IR packs to skip that task gracefully.
- Fixes to the Slack and Oracle Cloud Infrastructure event collectors,
DBotFindSimilarIncidentsandGetDockerImageLatestTag, plus a round of Docker base-image bumps.
- AnthropicClaude
- ApacheTomcat
- Auditd
- Base
- BreachNotification-US
- BruteForce
- and 42 more
BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.