Content packs — July 28, 2026
25 files changed, 656 insertions, 90 deletions — view the commit on the mirror.
PAN-OS polling timeouts made configurable; ServiceNow gains note-formatted attachments
- PAN-OS made the polling timeout/interval configurable on its content-, antivirus-, WildFire-, and GlobalProtect-update download/install commands, replacing a hardcoded 300s timeout / 10s interval with defaults of 3600s / 30s.
- ServiceNow v2 added a Mark attachment as note parameter and an Interpret comments in a specific format parameter (Source, Text, or HTML), plus a Docker image bump.
- Microsoft Graph Files (Standard Connector) was un-deprecated (the
deprecated: trueflag was removed from the integration YAML). - A routine auto-generated Docker image update PR bumped images across 22 unrelated packs (AccentureCTI_Feed, MISP, GitHub, Zabbix, and others) — bookkeeping, not functional change.
- Core picked up a release-notes/metadata-only bump (3.5.75 → 3.5.76) from an automated RN sync.
Highlights
-
PAN-OS polling timeout/interval no longer hardcoded
The eight pan-os-*-latest-*-update download/install commands gained timeout_in_seconds (default 3600) and interval_in_seconds (default 30) arguments, replacing a fixed 300s/10s polling loop.
-
ServiceNow v2 can mark attachments as notes and format comments
New mark_attachments_as_note and comment_format (Source/Text/HTML) configuration parameters, so a notes filter can surface both comments and attachments.
-
Microsoft Graph Files (Standard Connector) un-deprecated
The deprecated: true flag was removed from the integration YAML.
Changes
25 files listed, 4 written up and shaded below.
-
▸ ▾ AccentureCTI_Feed modified +9 −2
Packs/AccentureCTI_FeedRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ AnomaliThreatStreamFeed modified +10 −3
Packs/AnomaliThreatStreamFeedRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Anomali_ThreatStream modified +9 −2
Packs/Anomali_ThreatStreamRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ArcherRSA modified +9 −2
Packs/ArcherRSARead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CommunityCommonDashboards modified +9 −2
Packs/CommunityCommonDashboardsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CommunityCommonScripts modified +7 −2
Packs/CommunityCommonScriptsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Core modified +13 −3 Automated release-notes/metadata-only version bump (3.5.75 to 3.5.76).
Packs/CoreRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CyberArkIdentity modified +9 −2
Packs/CyberArkIdentityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CyberX-CentralManager modified +9 −2
Packs/CyberX-CentralManagerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Dropbox modified +9 −2
Packs/DropboxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedAlienVault modified +12 −5
Packs/FeedAlienVaultRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedGCPWhitelist modified +9 −2
Packs/FeedGCPWhitelistRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedMalwareBazaar modified +9 −2
Packs/FeedMalwareBazaarRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedTAXII modified +9 −2
Packs/FeedTAXIIRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ GitHub modified +9 −2
Packs/GitHubRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ JARM modified +9 −2
Packs/JARMRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ MISP modified +9 −2
Packs/MISPRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ MicrosoftGraphFilesStandardConnector modified +7 −2 Un-deprecated; metadata and documentation improvements.
Packs/MicrosoftGraphFilesStandardConnectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Mimecast modified +9 −2
Packs/MimecastRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ PAN-OS modified +178 −15 Made polling timeout/interval configurable on content/antivirus/WildFire/GlobalProtect update commands.
Packs/PAN-OSRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SEKOIAIntelligenceCenter modified +9 −2
Packs/SEKOIAIntelligenceCenterRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ServiceNow modified +247 −20 Added attachment-as-note and comment-format parameters; Docker image bump.
Packs/ServiceNowRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SuspiciousDomainHunting modified +29 −6
Packs/SuspiciousDomainHuntingRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ThalesCipherTrustManager modified +9 −2
Packs/ThalesCipherTrustManagerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Zabbix modified +9 −2
Packs/ZabbixRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.