Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.

Covering August 28, 2026, 00:00–24:00 UTC · published August 29, 2026 09:44 UTC.

Last checked about 18 hours ago. Summaries are written by claude-code/claude-opus-5; the changes themselves are recorded automatically.

Documentation

5 pages changed +58 −76

Onboard Aha.io deleted and rewritten onto the Aha! connector page; 12 SaaS app links un-broken

  • Onboard Aha.io was deleted from Cortex Cloud SaaS Security and its instructions rewritten onto the Aha! vendor connector page — a bookmark break.
  • The SaaS app connection table swapped broken-reference for real links on its first twelve rows, Aha.io through Coveo.
  • The relocated text drops the SaaS Security / SSPM framing for Cortex and the data connector configuration wizard.
  • The XSIAM book is one page smaller, 2,218 to 2,217.
  • README
  • Navigation manifest (xsiam)
  • Connect a SaaS application
  • Onboard Aha.io
  • Aha!

See what changed →

Analytics rules

0 rules changed +0 −0

Synced, and nothing changed upstream.

Content packs

2 packs changed +245 −159

Two Microsoft fetch fixes: Sentinel's fetch limit and Graph Security's first-fetch timestamp

  • A two-pack day for two upstream commits (+245/-159). No pack was added or removed.
  • Both fixes land on incident fetching in a Microsoft integration, so both bear on how much gets ingested rather than on what the integration can do.
  • AzureSentinel (+197/-151) carries the fetch-limit fix and is near line-for-line — insertions and deletions largely cancel.
  • MicrosoftGraphSecurity (+48/-8) corrects fetch-incidents filtering on the first fetch timestamp.
  • AzureSentinel
  • MicrosoftGraphSecurity

See what changed →

BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.