Content packs — August 10, 2026
101 files changed, 5883 insertions, 551 deletions — view the commit on the mirror.
Eight new AWS Network Firewall commands; SOC Framework Pack Manager 1.1.0 reworks pack installation
- Amazon Web Services 2.5.0 added eight
aws-network-firewall-*commands covering resource policies, resource tagging and logging configuration. - SOC Framework Pack Manager 1.1.0 now upgrades packs in place instead of installing each release as a separate pack, adds a
diagnoseaction, and no longer needs the XSIAMContentPackInstaller automation. - Three ingestion and mirroring fixes: CrowdStrike Falcon event fetch past 10,000 records, SplunkPy v2 mirror-out to Splunk Enterprise Security 8.2.x, and Microsoft Defender for Cloud Apps dropping low-volume event types.
- Cloud Posture remediation content moved off the deprecated
azure-nsg-*andazure-disk-*commands onto the newazure-vn-*andazure-compute-*names. - An automated Docker bump touched 85 packs, and eight core packs were re-released as dependency locks with no functional change.
Highlights
-
AWS gains resource-policy, tagging and logging commands for Network Firewall
Six commands manage resource policies and tags on rule groups and firewall policies, and two describe or update a firewall's logging configuration.
-
SOC Framework Pack Manager stopped installing every release as its own pack
It also stripped a trailing non-version component from pack names such as soc-v3-tools, installing them under the wrong pack ID, and compared pre-release suffixes so 1.0.6-pr1008 ranked above 1.0.7.
-
CrowdStrike Falcon event fetch failed beyond 10,000 records
Fetching events errored with "offset + limit must be less than or equal to 10000".
-
SplunkPy v2 mirror-out to Splunk Enterprise Security 8.2.x fixed
The outgoing finding mapper was updated for 8.2.x, and the processed-mirrored-events cache made concurrency-safe so parallel executions no longer overwrite each other's integration context.
-
Cloud Posture playbooks moved to the new Azure command names
NSG remediation now calls azure-vn-security-rule-* and the public-access auto-remediation calls azure-compute-disk-update; the rule creation argument action was renamed access.
-
Active Directory Query v2 can write binary attribute values
A new optional attribute-type argument adds Octet String support to ad-update-user, ad-update-contact and ad-update-group.
Changes
101 files listed, 10 written up and shaded below.
-
▸ ▾ AWS modified +1483 −9 Added eight aws-network-firewall-* commands: resource policy put/describe/delete, resource tag/untag, tag listing, and logging configuration describe/update.
Packs/AWSRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Active_Directory_Query modified +196 −11 Added an attribute-type argument for binary (Octet String) values in ad-update-user, ad-update-contact and ad-update-group.
Packs/Active_Directory_QueryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ AnsibleTower modified +9 −2
Packs/AnsibleTowerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ArcherRSA modified +9 −2
Packs/ArcherRSARead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Attlasian modified +9 −2
Packs/AttlasianRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ AwakeSecurity modified +9 −2
Packs/AwakeSecurityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Base modified +4 −1
Packs/BaseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ BeyondTrust_Password_Safe modified +9 −2
Packs/BeyondTrust_Password_SafeRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ BigFix modified +9 −2
Packs/BigFixRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ BluecatAddressManager modified +9 −2
Packs/BluecatAddressManagerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ C2sec modified +9 −2
Packs/C2secRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CIRCL modified +9 −2
Packs/CIRCLRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CarbonBlackDefense modified +9 −2
Packs/CarbonBlackDefenseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CarbonBlackEnterpriseEDR modified +9 −2
Packs/CarbonBlackEnterpriseEDRRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CarbonBlackProtect modified +9 −2
Packs/CarbonBlackProtectRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Carbon_Black_Enterprise_Response modified +14 −3
Packs/Carbon_Black_Enterprise_ResponseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Change_Management modified +9 −2
Packs/Change_ManagementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CheckPhish modified +9 −2
Packs/CheckPhishRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Cherwell modified +42 −8
Packs/CherwellRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CircleCI modified +9 −2
Packs/CircleCIRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CiscoFirepower modified +9 −2
Packs/CiscoFirepowerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CloudIncidentResponse modified +34 −7
Packs/CloudIncidentResponseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CloudSecurityPolicyManagement modified +123 −88 NSG remediation playbook and AzureIdentifyNSGExposureRule moved to the azure-vn-* commands; the rule creation argument action was renamed access.
Packs/CloudSecurityPolicyManagementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CloudSecurityPostureManagement modified +9 −3 Azure Public Access Misconfiguration auto-remediation replaced the deprecated azure-disk-update with azure-compute-disk-update.
Packs/CloudSecurityPostureManagementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CommonPlaybooks modified +4 −1
Packs/CommonPlaybooksRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CommonScripts modified +47 −2 ReadQRCode now returns a warning entry instead of erroring on a zero-byte image file.
Packs/CommonScriptsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CommonTypes modified +4 −1
Packs/CommonTypesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ContentManagement modified +9 −2
Packs/ContentManagementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Core modified +4 −1
Packs/CoreRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CounterTack modified +9 −2
Packs/CounterTackRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CrowdStrikeFalcon modified +105 −4 Fixed event fetching failing with an "offset + limit must be less than or equal to 10000" error.
Packs/CrowdStrikeFalconRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CrowdStrikeOpenAPI modified +9 −2
Packs/CrowdStrikeOpenAPIRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CuckooSandbox modified +9 −2
Packs/CuckooSandboxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CyberArkEPM modified +9 −2
Packs/CyberArkEPMRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ DBotTruthBombs modified +17 −3
Packs/DBotTruthBombsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ DemistoRESTAPI modified +4 −1
Packs/DemistoRESTAPIRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ EasyVista modified +9 −2
Packs/EasyVistaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Envoy modified +9 −2
Packs/EnvoyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedAlienVault modified +9 −2
Packs/FeedAlienVaultRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedBlocklist_de modified +9 −2
Packs/FeedBlocklist_deRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedBruteForceBlocker modified +9 −2
Packs/FeedBruteForceBlockerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedCloudflare modified +9 −2
Packs/FeedCloudflareRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedDShield modified +9 −2
Packs/FeedDShieldRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedFeodoTracker modified +9 −2
Packs/FeedFeodoTrackerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedMajesticMillion modified +9 −2
Packs/FeedMajesticMillionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedSpamhaus modified +9 −2
Packs/FeedSpamhausRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedTorExitAddresses modified +9 −2
Packs/FeedTorExitAddressesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FeedURLhaus modified +9 −2
Packs/FeedURLhausRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Feedsslabusech modified +9 −2
Packs/FeedsslabusechRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FidelisElevateNetwork modified +9 −2
Packs/FidelisElevateNetworkRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FidelisEndpoint modified +9 −2
Packs/FidelisEndpointRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FiltersAndTransformers modified +13 −3
Packs/FiltersAndTransformersRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Forescout modified +9 −2
Packs/ForescoutRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FortiManager modified +9 −2
Packs/FortiManagerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FortiSIEM modified +9 −2
Packs/FortiSIEMRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ FreshDesk modified +9 −2
Packs/FreshDeskRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ HelloIAMWorld modified +9 −2
Packs/HelloIAMWorldRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ImageOCR modified +97 −3 image-ocr-extract-text now returns a warning instead of erroring on an empty or truncated image file.
Packs/ImageOCRRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Imperva_WAF modified +9 −2
Packs/Imperva_WAFRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Incapsula modified +29 −6
Packs/IncapsulaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ IvantiHeat modified +19 −4
Packs/IvantiHeatRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ JsonWhoIs modified +9 −2
Packs/JsonWhoIsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ LogRhythmRest modified +9 −2
Packs/LogRhythmRestRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Lokpath_Keylight modified +9 −2
Packs/Lokpath_KeylightRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ MITRECoA modified +14 −3
Packs/MITRECoARead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ MailListener_-_POP3 modified +9 −2
Packs/MailListener_-_POP3Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ MajorBreachesInvestigationandResponse modified +44 −9
Packs/MajorBreachesInvestigationandResponseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ MaxMind_GeoIP2 modified +9 −2
Packs/MaxMind_GeoIP2Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ McAfee_ESM modified +9 −2
Packs/McAfee_ESMRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Mimecast modified +9 −2
Packs/MimecastRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Okta modified +9 −2
Packs/OktaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ OnboardingIntegration modified +9 −2
Packs/OnboardingIntegrationRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Packetsled modified +9 −2
Packs/PacketsledRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Perch modified +9 −2
Packs/PerchRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ PhishLabs modified +17 −3
Packs/PhishLabsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Pipl modified +9 −2
Packs/PiplRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ PrismaAccess modified +9 −2
Packs/PrismaAccessRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ RSANetWitnessEndpoint modified +9 −2
Packs/RSANetWitnessEndpointRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ RTIR modified +9 −2
Packs/RTIRRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Ransomware modified +14 −3
Packs/RansomwareRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Salesforce modified +14 −3
Packs/SalesforceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ShiftManagement modified +19 −4
Packs/ShiftManagementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SignalSciences modified +9 −2
Packs/SignalSciencesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SocFrameworkManager modified +2120 −206 1.1.0 installs packs in place, resolves mandatory dependencies before installing, adds a diagnose action and a Pack catalog URL parameter, and surfaces upload failures.
Packs/SocFrameworkManagerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SplunkPy modified +250 −6 Fixed mirror-out to Splunk Enterprise Security 8.2.x and made the processed mirrored events cache concurrency-safe; outgoing mapper updated for 8.2.x.
Packs/SplunkPyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SymantecBlueCoatMalwareAnalysis modified +9 −2
Packs/SymantecBlueCoatMalwareAnalysisRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SymantecEndpointProtection modified +9 −2
Packs/SymantecEndpointProtectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SymantecManagementCenter modified +9 −2
Packs/SymantecManagementCenterRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Tanium modified +9 −2
Packs/TaniumRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ TaniumThreatResponse modified +9 −2
Packs/TaniumThreatResponseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Telegram modified +9 −2
Packs/TelegramRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ThreatExchange modified +9 −2
Packs/ThreatExchangeRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ThreatMiner modified +9 −2
Packs/ThreatMinerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ThreatX modified +9 −2
Packs/ThreatXRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Troubleshoot modified +39 −8
Packs/TroubleshootRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Vega modified +456 −3 Alert event JSON fields are parsed and fields._raw promoted to top level, expanding dotted and {}-suffixed keys; added the Vega.AlertEvents.Events context output.
Packs/VegaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ VulnDB modified +9 −2
Packs/VulnDBRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ WindowsForensics modified +9 −2
Packs/WindowsForensicsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ cisco-ise modified +9 −2
Packs/cisco-iseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ctf01 modified +14 −3
Packs/ctf01Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.