Platform Changes
Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.
Covering August 23, 2026, 00:00–24:00 UTC · published August 24, 2026 03:54 UTC.
Last checked about 24 hours ago. Summaries are written by claude-code/claude-opus-5; the changes themselves are recorded automatically.
Documentation
433 pages changed +2127 −434A 431-page metadata and structure pass across Cortex XSIAM; UPN becomes a mandatory XDM authentication field
- 366 of the 434 changed files touch nothing but their
description:frontmatter — a metadata pass over almost the whole Cortex XSIAM book. - The XDM authentication mapping reference carries the day’s only substantive change:
xdm.source.user.upnis promoted from optional to mandatory, and a newOPERATION_TYPE_AUDITconstant is added. - Structural cleanup elsewhere: bold pseudo-headings promoted to real
###headings in 22 files, and “Note”/”Notice” sub-headings stripped from 14 callouts. - Five pages moved their numbered procedures into GitBook
{% stepper %}blocks. - Six pages were retitled. No page was added, removed, or moved — every one of the 434 entries is a modification.
- Navigation manifest (xsiam)
- Cortex XDR Agent Releases
- Automations
- Agentic Response (Preview)
- AI Prompts
- AI prompts role-based access control
- and 427 more
Analytics rules
166 rules changed +475 −179Four universal authentication detectors added; 124 identity detectors gain the SaaS Threat Detection module
- Four new Identity Analytics detectors cover a newly named event class, universal authentication: brute force, password spray, inactive-user authentication, and successful sign-in with suspicious features.
- 124 detectors were reassigned, adding
SaaS Threat DetectionalongsideIdentity Threat Module— 103 identity detectors and 21 that also carryEmail. - 36 cloud detectors gained a
detector_tagsgrouping for the first time: Cloud Log Tampering Analytics, OCI Analytics, and SSM Remote Management Analytics. - One rule was renamed, one variation was withdrawn, and two deduplication periods were retuned. Nothing else changed.
- A cloud identity executed an API call from an unusual country
- A domain was added to the trusted domains list
- A GCP service account was delegated domain-wide authority in Google Workspace
- A Google Workspace identity created, assigned or modified a role
- A Google Workspace identity performed an unusual admin console activity
- A Google Workspace identity used the security investigation tool
- and 160 more
Content packs
20 packs changed +8588 −2452ThreatZone rewritten in a 20-pack day; Microsoft Graph Files gains new commands
- ThreatZone is effectively rewritten at +3,744/-2,333 — 43% of the day’s insertions and 95% of its deletions (#45598).
- 20 packs move for 8 upstream commits, roughly 8,588 lines added against 2,452 deleted; the snapshot head
92f01eais same-day. - Microsoft Graph Files gains new commands and its standard-connector pack moves in step, +381 and +372 (#45485).
- Fourteen of the 20 packs are addition-only against a single deleted line — AWS GuardDuty (+298), ePO (+243), Forcepoint DLP (+218), Zscaler ZPA (+215) and Cisco SMA (+161) among them.
- Modeling-rule housekeeping continues under CRTX-271523: BC107 legacy-id rules are consolidated for force-merge (#45545), and a Slack GR105 duplicate ID is fixed (#45600).
- AWS-GuardDuty
- ApiModules
- CiscoNexus
- CiscoSMA
- Citrix
- CommonScripts
- and 14 more
BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.