Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.

Covering August 23, 2026, 00:00–24:00 UTC · published August 24, 2026 03:54 UTC.

Last checked about 24 hours ago. Summaries are written by claude-code/claude-opus-5; the changes themselves are recorded automatically.

Documentation

433 pages changed +2127 −434

A 431-page metadata and structure pass across Cortex XSIAM; UPN becomes a mandatory XDM authentication field

  • 366 of the 434 changed files touch nothing but their description: frontmatter — a metadata pass over almost the whole Cortex XSIAM book.
  • The XDM authentication mapping reference carries the day’s only substantive change: xdm.source.user.upn is promoted from optional to mandatory, and a new OPERATION_TYPE_AUDIT constant is added.
  • Structural cleanup elsewhere: bold pseudo-headings promoted to real ### headings in 22 files, and “Note”/”Notice” sub-headings stripped from 14 callouts.
  • Five pages moved their numbered procedures into GitBook {% stepper %} blocks.
  • Six pages were retitled. No page was added, removed, or moved — every one of the 434 entries is a modification.
  • Navigation manifest (xsiam)
  • Cortex XDR Agent Releases
  • Automations
  • Agentic Response (Preview)
  • AI Prompts
  • AI prompts role-based access control
  • and 427 more

See what changed →

Analytics rules

166 rules changed +475 −179

Four universal authentication detectors added; 124 identity detectors gain the SaaS Threat Detection module

  • Four new Identity Analytics detectors cover a newly named event class, universal authentication: brute force, password spray, inactive-user authentication, and successful sign-in with suspicious features.
  • 124 detectors were reassigned, adding SaaS Threat Detection alongside Identity Threat Module — 103 identity detectors and 21 that also carry Email.
  • 36 cloud detectors gained a detector_tags grouping for the first time: Cloud Log Tampering Analytics, OCI Analytics, and SSM Remote Management Analytics.
  • One rule was renamed, one variation was withdrawn, and two deduplication periods were retuned. Nothing else changed.
  • A cloud identity executed an API call from an unusual country
  • A domain was added to the trusted domains list
  • A GCP service account was delegated domain-wide authority in Google Workspace
  • A Google Workspace identity created, assigned or modified a role
  • A Google Workspace identity performed an unusual admin console activity
  • A Google Workspace identity used the security investigation tool
  • and 160 more

See what changed →

Content packs

20 packs changed +8588 −2452

ThreatZone rewritten in a 20-pack day; Microsoft Graph Files gains new commands

  • ThreatZone is effectively rewritten at +3,744/-2,333 — 43% of the day’s insertions and 95% of its deletions (#45598).
  • 20 packs move for 8 upstream commits, roughly 8,588 lines added against 2,452 deleted; the snapshot head 92f01ea is same-day.
  • Microsoft Graph Files gains new commands and its standard-connector pack moves in step, +381 and +372 (#45485).
  • Fourteen of the 20 packs are addition-only against a single deleted line — AWS GuardDuty (+298), ePO (+243), Forcepoint DLP (+218), Zscaler ZPA (+215) and Cisco SMA (+161) among them.
  • Modeling-rule housekeeping continues under CRTX-271523: BC107 legacy-id rules are consolidated for force-merge (#45545), and a Slack GR105 duplicate ID is fixed (#45600).
  • AWS-GuardDuty
  • ApiModules
  • CiscoNexus
  • CiscoSMA
  • Citrix
  • CommonScripts
  • and 14 more

See what changed →

BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.