Content packs — August 25, 2026
42 files changed, 3077 insertions, 328 deletions — view the commit on the mirror.
A broad 42-pack day of additions: AWS, Okta, Netskope and ApiModules lead
- 42 packs move for 15 upstream commits — 3,077 lines added against 328 deleted, so a day of new material rather than rewrites.
- AWS (+647/-161), Okta (+453/-1), Netskope (+332/-13) and ApiModules (+270/-5) are over half the day’s insertions between them.
- Three integration fixes land on auth and request handling: OpenAI, ThreatConnect and GitHub.
- Fifteen packs each gained an identical 10-line block, matching the day’s “Add License Requirements section to readme” commit (#45591).
- Modeling-rule work continues:
identity.*fields are added as the first of seven planned PRs (CRTX-271527, #45463).
Highlights
-
identity.* fields are added to modeling rules, first of seven PRs
CRTX-271527 (#45463) is explicitly labelled "PR 1 of 7", so this ingestion-mapping work will span further days; the snapshot does not say which pack carried it.
-
OpenAI now sends a Bearer scheme on the Compliance API auth header
CIAC-17723 (#45633) moves the pack +197/-16 — a change to how the integration authenticates, not just what it sends.
-
ANY.RUN Sandbox gains a root_url parameter and an updated SDK
The pack update also fixes minor bugs, and at +195/-72 it has the day's second-highest deletion count, so existing code was replaced rather than extended (#45561).
-
Google Drive gains the capability to upload content
#45641 moves both the Google Drive pack (+18/-3) and its standard connector (+17/-3), and is the snapshot head for the day.
-
ThreatConnect adds sanitize_large_ints for large object IDs
XSUP-75257 (#45638) gains 175 lines against a single deletion to handle ThreatConnect object IDs the integration was mishandling.
-
Atlassian Confluence Cloud returns generic-file-get content as Markdown
#45603 (+44/-9) changes the output format of that command's result.
Changes
42 files listed, 15 written up and shaded below.
-
▸ ▾ ANYRUN modified +195 −72 +195/-72 fixing minor bugs, adding a root_url parameter for Sandbox and updating the SDK version (#45561).
Packs/ANYRUNRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ AWS modified +647 −161 +647/-161, the day's largest pack change and largest deletion count, on a test that the yml and py files match (CRTX-265696, #45344).
Packs/AWSRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Absolute modified +10 −0
Packs/AbsoluteRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Akamai_SIEM modified +12 −0
Packs/Akamai_SIEMRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ AnthropicClaude modified +10 −0
Packs/AnthropicClaudeRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ApiModules modified +270 −5 +270/-5 to the shared API module code, with no commit subject naming it.
Packs/ApiModulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ AtlassianConfluenceCloud modified +44 −9 +44/-9 returning generic-file-get content as Markdown (#45603).
Packs/AtlassianConfluenceCloudRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ BrandefenseDRPS modified +10 −0
Packs/BrandefenseDRPSRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Core modified +68 −0 +68/-0, unattributed in the day's commit subjects.
Packs/CoreRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CortexXDR modified +17 −5
Packs/CortexXDRRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CrowdStrikeFalcon modified +26 −1
Packs/CrowdStrikeFalconRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CybelAngel modified +28 −1
Packs/CybelAngelRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Doppel modified +10 −0
Packs/DoppelRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Elasticsearch modified +10 −0
Packs/ElasticsearchRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ExabeamSecurityOperationsPlatform modified +10 −0
Packs/ExabeamSecurityOperationsPlatformRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ GitHub modified +152 −25 +152/-25 improving request handling (#45578).
Packs/GitHubRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ GoogleDrive modified +18 −3 +18/-3 adding the capability to upload content to Google Drive (#45641).
Packs/GoogleDriveRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ GoogleDriveStandardConnector modified +17 −3 +17/-3, moved by the same Google Drive upload commit (#45641).
Packs/GoogleDriveStandardConnectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ GoogleThreatIntelligence modified +27 −1
Packs/GoogleThreatIntelligenceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ HashiCorpTerraform modified +28 −1
Packs/HashiCorpTerraformRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ HelloWorld modified +65 −2 +65/-2 to the reference pack, unattributed in the day's commit subjects.
Packs/HelloWorldRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ MicrosoftGraphMail modified +10 −0
Packs/MicrosoftGraphMailRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ MicrosoftGraphSecurity modified +10 −0
Packs/MicrosoftGraphSecurityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ NetQuestOMX modified +28 −1
Packs/NetQuestOMXRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Netcraft_V2 modified +10 −0
Packs/Netcraft_V2Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Netskope modified +332 −13 +332/-13 on "Fix netskope issue" (#45550).
Packs/NetskopeRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Okta modified +453 −1 +453/-1, the day's largest near-pure addition; the snapshot names no commit for it.
Packs/OktaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ OpenAI modified +197 −16 +197/-16 sending a Bearer scheme on the Compliance API auth header (CIAC-17723, #45633).
Packs/OpenAIRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ PAN-OS modified +10 −0
Packs/PAN-OSRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Rapid7_Nexpose modified +21 −2
Packs/Rapid7_NexposeRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Reco modified +10 −0
Packs/RecoRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Salesforce modified +10 −0
Packs/SalesforceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ServiceNow modified +14 −1 +14/-1 on an add-comment change (XSUP-75154, #45605).
Packs/ServiceNowRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SpecterOpsBloodHoundEnterprise modified +10 −0
Packs/SpecterOpsBloodHoundEnterpriseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SplunkPy modified +10 −0
Packs/SplunkPyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Tenable_io modified +14 −0
Packs/Tenable_ioRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Tenable_sc modified +29 −1
Packs/Tenable_scRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ThreatConnect modified +175 −1 +175/-1 adding a sanitize_large_ints function for large ThreatConnect object IDs (XSUP-75257, #45638).
Packs/ThreatConnectRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ThreatMon modified +10 −0
Packs/ThreatMonRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ThreatMonThreatFeed modified +12 −0
Packs/ThreatMonThreatFeedRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ThreatZone modified +9 −2 +9/-2 across two commits: an XSUP-75189 resolution (#45615) and a threatzone-sdk Docker bump (#45645).
Packs/ThreatZoneRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ qualys modified +29 −1
Packs/qualysRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.