Content packs — August 31, 2026
17 files changed, 34445 insertions, 2925 deletions — view the commit on the mirror.
Google SecOps 6.0.0 rewrites the Chronicle pack; a SaaS Claude connector splits into its own pack
- GoogleChronicleBackstory added 27,773 lines against 12 removed for “Google SecOps Release 6.0.0” — nine tenths of the day’s churn on its own.
- AnthropicClaudeStandardConnector arrives as a new 306-line pack while AnthropicClaude drops 1,821 lines, the two halves of a SaaS connector split.
- ApiModules grew by 2,307 lines, the day’s second-largest change.
- Integration fixes landed in Mimecast, Doppel, Reco and Akamai_WAF; SpyCloudEnterpriseProtection gained a new data type.
- 17 packs moved in total, from 12 upstream commits.
Highlights
-
Google SecOps Release 6.0.0
GoogleChronicleBackstory gained 27,773 lines and lost only 12, so this is a wholesale addition rather than a rewrite of what was there.
-
The Claude integration splits into a separate SaaS connector pack
AnthropicClaudeStandardConnector is new at 306 lines while AnthropicClaude sheds 1,821 against 70 added, under the subject "saas claude connector".
-
Mimecast v2 migrates a command
Mimecast churned hardest of any pack after the two above — 977 lines added against 730 removed — for a single command migration.
-
Doppel 1.1.0 fixes mirroring in both directions
The pack added 1,765 lines and removed 265 to fix incoming and outgoing mirroring and add per-product entity content.
-
SpyCloud Enterprise Protection adds an Access Data type
578 lines added against 12 removed — a new data type rather than a fix to an existing one.
-
Reco stops fetch-incidents skipping alerts during bursts
A 118-line fix to alert loss under load, which silently drops incidents rather than failing visibly.
Changes
17 files listed, 13 written up and shaded below.
-
▸ ▾ Akamai_WAF modified +128 −11 akamai-get-client-list now handles paginated responses (+128/-11).
Packs/Akamai_WAFRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ AnthropicClaude modified +70 −1821 Lost 1,821 lines and gained 70 as the SaaS connector moved out into its own pack.
Packs/AnthropicClaudeRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ AnthropicClaudeStandardConnector modified +306 −0 New pack, 306 lines, added under the subject "saas claude connector".
Packs/AnthropicClaudeStandardConnectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ApiModules modified +2307 −7 Grew by 2,307 lines against 7 removed, the day's second-largest pack change.
Packs/ApiModulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Base modified +35 −6 Gained 35 lines against 6 removed.
Packs/BaseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Campaign modified +9 −2
Packs/CampaignRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CheckPointHEC modified +316 −38 Gained 316 lines against 38 removed; the day's one unclaimed subject changes fetch to key restore requests off the last fetched request.
Packs/CheckPointHECRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Core modified +23 −1 xdr-retrieve-file gains different separator options (+23/-1).
Packs/CoreRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ CortexXDR modified +12 −1 Twelve lines added for the Cortex update-issue action migration.
Packs/CortexXDRRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Doppel modified +1765 −265 Version 1.1.0 fixes incoming and outgoing mirroring and adds per-product entity content (+1,765/-265).
Packs/DoppelRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ GoogleChronicleBackstory modified +27773 −12 Google SecOps Release 6.0.0: 27,773 lines added against 12 removed.
Packs/GoogleChronicleBackstoryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Mimecast modified +977 −730 Mimecast v2 migrates a command; 977 lines added, 730 removed.
Packs/MimecastRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Phishing modified +14 −3
Packs/PhishingRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Reco modified +118 −14 Fixes fetch-incidents skipping alerts during bursts (+118/-14).
Packs/RecoRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Slack modified +7 −1
Packs/SlackRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ SpyCloudEnterpriseProtection modified +578 −12 Adds an Access Data type (+578/-12).
Packs/SpyCloudEnterpriseProtectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ ctf01 modified +7 −1
Packs/ctf01Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.