Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.

Covering August 17, 2026, 00:00–24:00 UTC · published August 18, 2026 09:14 UTC.

Last checked about 5 hours ago. Summaries are written by claude-code/claude-opus-5; the changes themselves are recorded automatically.

Documentation

4 pages changed +14 −13

Cortex CLI and MCP server docs restructured; EDL root certificate switches to DigiCert

  • The Cortex CLI section moved to about-cortex-cli and the Cortex MCP server overview collapsed into its parent, renaming 19 pages between them — bookmarks break.
  • Twelve pages are new, ten of them net: CLI installation and post-install management, parse_cef() and parse_json() for parsing rules, a Data Ingestion dashboard reference, and three XDR Collector profile pages.
  • Acting on today: EDL setup needs the DigiCert root certificate, scheduled correlations are capped at 1,200, and data ingestion health monitoring is now labelled BETA.
  • Quieter churn: ~25 Cloud Security pages changed only their front-matter description, and 30 Linux kernel tables gained newly supported kernel versions.
  • Task 2: Create the app registration for the Azure BYOA outpost
  • Evidence
  • Cortex XSIAM product licenses
  • Navigate the Cortex XSIAM docs

See what changed →

Analytics rules

0 rules changed +0 −0

Synced, and nothing changed upstream.

Content packs

48 packs changed +7742 −15092

CyberArk EPM adds Idira OAuth; rasterize's 8.15 fork removed; 21 more packs get identity modeling rules

  • 13 commits, 269 files across 48 packs — the bulk of it CRTX-271523/271526 PRs 2, 4, 5 and 7 of 7, which added a second _2_11 modeling rule to 21 more log sources.
  • CyberArk EPM 1.3.0 gains a third authentication method: CyberArk Identity (Idira ISPSS) OAuth 2.0 client_credentials.
  • The version-forked rasterize_8_15 integration was deleted and folded into the single Rasterize integration, which loses its toversion: 8.14.0 cap.
  • XSUP-74186 restricted the three summary-report scripts to the Cortex XSOAR marketplace and updated 16 playbooks across the compliance and IR packs to skip that task gracefully.
  • Fixes to the Slack and Oracle Cloud Infrastructure event collectors, DBotFindSimilarIncidents and GetDockerImageLatestTag, plus a round of Docker base-image bumps.
  • AnthropicClaude
  • ApacheTomcat
  • Auditd
  • Base
  • BreachNotification-US
  • BruteForce
  • and 42 more

See what changed →

BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.