Documentation — August 27, 2026
107 files changed, 767 insertions, 508 deletions — view the commit on the mirror.
Cloud posture onboarding pages retire into the vendor tree; new DSPM Database applet page
- A new Activate DSPM Database page documents a Broker VM applet that connects to on-premise PostgreSQL and MySQL databases to classify content and report risk.
- Six onboarding pages under Cloud Posture and Runtime Security data sources were deleted; that section now has no child pages and its parent links out to the vendor-tree copies instead.
- Activate Registry Scanner turned twelve
broken-referenceplaceholders into working links, while two other pages regressed the other way. - All 86 vendor landing pages gained a “Here are the articles in this section” index, and their descriptions now say “connector” where they said “integration”.
- Nine Extended Threat Intelligence pages changed their description frontmatter only — no body text moved.
Highlights
-
New page: Activate DSPM Database, a Broker VM applet for on-premise databases
It connects to PostgreSQL and MySQL instances over an optional SSL connection, classifies their content on a configurable cadence, and registers each connection as an asset under All Assets → Data → Databases with Provider = On Premise.
-
Six cloud posture onboarding pages deleted as duplicates of the vendor tree
The Databricks, Microsoft 365, Snowflake and Okta onboarding copies under Cloud Posture and Runtime Security were removed and the equivalent pages under the vendor-specific tree are now the only ones, so bookmarks to the old paths break.
-
Registry Scanner prerequisites now point at the registry connector pages
Twelve links that read `broken-reference` — six prerequisites and six "manage a connector" links — resolve to the Docker Hub, Docker V2, GitLab, Harbor, JFrog and Sonatype Nexus pages, and the licence note now admits Cloud Posture Security alongside Cloud Runtime Security.
-
DSPM Fileshare activation rewritten around the Clusters tab
The applet can now be added from either the Brokers or the Clusters tab, and the eleven-step connection walkthrough collapses into two rows added to the settings table for Classification and scan cadence.
-
Two links regressed to broken-reference, and the new source list has three defects
Microsoft 365 (Posture) and Connect Docker Hub registry both lost a working link, while the new supported-sources list points DSPM Fileshare at the DSPM Database page and lists AppSec Transporter twice.
Changes
107 files listed, 13 written up and shaded below.
-
▸ ▾ Threat Intel Dashboard modified +2 −2
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-dashboardRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@------description: >-description: >-Visualize threat intelligence data to monitor distribution, ingestion health,Use the Cortex XSIAM Threat Intel Dashboard to monitor intelligenceand emerging trends.distribution, ingestion health, and emerging threats.------# Threat Intel Dashboard# Threat Intel DashboardThe Threat Intel Dashboard visualizes threat intelligence data, such as threat objects and indicators, within your environment to help you understand data distribution and identify trends.The Threat Intel Dashboard visualizes threat intelligence data, such as threat objects and indicators, within your environment to help you understand data distribution and identify trends.You can use the dashboard as provided or clone and modify it to suit your needs.You can use the dashboard as provided or clone and modify it to suit your needs.Show markdown source
@@ -1,12 +1,12 @@ --- description: >- - Visualize threat intelligence data to monitor distribution, ingestion health, - and emerging trends. + Use the Cortex XSIAM Threat Intel Dashboard to monitor intelligence + distribution, ingestion health, and emerging threats. --- # Threat Intel Dashboard The **Threat Intel Dashboard** visualizes threat intelligence data, such as threat objects and indicators, within your environment to help you understand data distribution and identify trends. You can use the dashboard as provided or clone and modify it to suit your needs.
-
▸ ▾ Threat intel investigation through XQL modified +2 −2
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-investigation-through-xqlRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@------description: >-description: >-Query XTI indicators, threat objects, and their relationships using CortexUse Cortex XSIAM XQL to query XTI indicators, threat objects, andQuery Language.relationships for threat intelligence investigations.------# Threat intel investigation through XQL# Threat intel investigation through XQLXTI is integrated into the Cortex Query Language (XQL) system, empowering you to create investigations and hunt queries using the full depth of the XTI intelligence library.XTI is integrated into the Cortex Query Language (XQL) system, empowering you to create investigations and hunt queries using the full depth of the XTI intelligence library.You can query threat intel indicators and threat objects through the XQL Search Portal by navigating to Investigation & Response → Search → Query Builder.You can query threat intel indicators and threat objects through the XQL Search Portal by navigating to Investigation & Response → Search → Query Builder.Show markdown source
@@ -1,12 +1,12 @@ --- description: >- - Query XTI indicators, threat objects, and their relationships using Cortex - Query Language. + Use Cortex XSIAM XQL to query XTI indicators, threat objects, and + relationships for threat intelligence investigations. --- # Threat intel investigation through XQL XTI is integrated into the Cortex Query Language (XQL) system, empowering you to create investigations and hunt queries using the full depth of the XTI intelligence library. You can query threat intel indicators and threat objects through the XQL Search Portal by navigating to **Investigation & Response → Search → Query Builder**.
-
▸ ▾ Using XTI in playbooks modified +2 −2
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/using-xti-in-playbooksRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@------description: >-description: >-Automate XTI indicator triage, enrichment, and response with supportedUse Cortex XSIAM playbooks to automate XTI indicator triage, enrichment, andplaybook commands.response with supported commands.------# Using XTI in playbooks# Using XTI in playbooksExtended Threat Intelligence (XTI) utilizes existing Threat Intel Management (TIM) to automate triage, enrichment, and response for threat intel use cases.Extended Threat Intelligence (XTI) utilizes existing Threat Intel Management (TIM) to automate triage, enrichment, and response for threat intel use cases.## Playbook commands supported by XTI## Playbook commands supported by XTIShow markdown source
@@ -1,12 +1,12 @@ --- description: >- - Automate XTI indicator triage, enrichment, and response with supported - playbook commands. + Use Cortex XSIAM playbooks to automate XTI indicator triage, enrichment, and + response with supported commands. --- # Using XTI in playbooks Extended Threat Intelligence (XTI) utilizes existing Threat Intel Management (TIM) to automate triage, enrichment, and response for threat intel use cases. ## Playbook commands supported by XTI
-
▸ ▾ Using XTI with Threat Intel Agent modified +3 −1
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/using-xti-with-threat-intel-agentRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,12 @@------description: Use the Threat Intel Agent to list, enrich, and update XTI indicators.description: >-Use the Cortex XSIAM Threat Intel Agent to list, enrich, and update ExtendedThreat Intelligence indicators.------# Using XTI with Threat Intel Agent# Using XTI with Threat Intel AgentAgentic Assistant Threat Intel (TI) Agent works with Extended Threat Intelligence (XTI) and Threat Intel Management (TIM).Agentic Assistant Threat Intel (TI) Agent works with Extended Threat Intelligence (XTI) and Threat Intel Management (TIM).• If you have XTI only enabled, the TI Agent reads from and writes to the XTI dataset. Only the actions listed below are supported.• If you have XTI only enabled, the TI Agent reads from and writes to the XTI dataset. Only the actions listed below are supported.• If you have both XTI and TIM enabled side-by-side:• If you have both XTI and TIM enabled side-by-side:Show markdown source
@@ -1,10 +1,12 @@ --- -description: Use the Threat Intel Agent to list, enrich, and update XTI indicators. +description: >- + Use the Cortex XSIAM Threat Intel Agent to list, enrich, and update Extended + Threat Intelligence indicators. --- # Using XTI with Threat Intel Agent Agentic Assistant Threat Intel (TI) Agent works with Extended Threat Intelligence (XTI) and Threat Intel Management (TIM). * If you have XTI only enabled, the TI Agent reads from and writes to the XTI dataset. Only the actions listed below are supported. * If you have both XTI and TIM enabled side-by-side:
-
▸ ▾ XTI indicator rules modified +2 −2
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-indicator-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@------description: >-description: >-Create rules that detect known threat indicators and generate issues fromCreate Cortex XSIAM XTI indicator rules to detect known threat indicators andmatching data.generate issues from matching data.------# XTI indicator rules# XTI indicator rulesUse XTI indicator rules to monitor your environment for known threat indicators—such as malicious IPs, domains, and file hashes. Configure an indicator rule to scan collected log data and generate an issue for investigation upon a match.Use XTI indicator rules to monitor your environment for known threat indicators—such as malicious IPs, domains, and file hashes. Configure an indicator rule to scan collected log data and generate an issue for investigation upon a match.XTI indicator rules offer smart, dynamic targeting. In addition to manually selecting static lists of indicators, you can build dynamic, attribute-based filters using rich threat intelligence context. For example, you can create a rule that automatically targets "all indicators linked to a specific threat actor with a malicious verdict". As new intel is ingested that matches your filters, the rule dynamically updates its scope without manual intervention.XTI indicator rules offer smart, dynamic targeting. In addition to manually selecting static lists of indicators, you can build dynamic, attribute-based filters using rich threat intelligence context. For example, you can create a rule that automatically targets "all indicators linked to a specific threat actor with a malicious verdict". As new intel is ingested that matches your filters, the rule dynamically updates its scope without manual intervention.Show markdown source
@@ -1,12 +1,12 @@ --- description: >- - Create rules that detect known threat indicators and generate issues from - matching data. + Create Cortex XSIAM XTI indicator rules to detect known threat indicators and + generate issues from matching data. --- # XTI indicator rules Use XTI indicator rules to monitor your environment for known threat indicators—such as malicious IPs, domains, and file hashes. Configure an indicator rule to scan collected log data and generate an issue for investigation upon a match. XTI indicator rules offer smart, dynamic targeting. In addition to manually selecting static lists of indicators, you can build dynamic, attribute-based filters using rich threat intelligence context. For example, you can create a rule that automatically targets "all indicators linked to a specific threat actor with a malicious verdict". As new intel is ingested that matches your filters, the rule dynamically updates its scope without manual intervention.
-
▸ ▾ XTI Indicators modified +2 −2
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-indicatorsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@------description: >-description: >-Investigate, manage, and enrich threat indicators, including domains, IPInvestigate, manage, and enrich threat indicators in Cortex XSIAM, includingaddresses, URLs, and file hashes.domains, IP addresses, URLs, and file hashes.------# XTI Indicators# XTI IndicatorsXTI Indicators help you identify and investigate suspicious or malicious activity.XTI Indicators help you identify and investigate suspicious or malicious activity.## Indicator concepts## Indicator conceptsShow markdown source
@@ -1,12 +1,12 @@ --- description: >- - Investigate, manage, and enrich threat indicators, including domains, IP - addresses, URLs, and file hashes. + Investigate, manage, and enrich threat indicators in Cortex XSIAM, including + domains, IP addresses, URLs, and file hashes. --- # XTI Indicators XTI Indicators help you identify and investigate suspicious or malicious activity. ## Indicator concepts
-
▸ ▾ XTI Threat Intel Library modified +2 −2
xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/xti-threat-intel-libraryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@------description: >-description: >-Research curated threat actors, malware families, vulnerabilities, and reportsExplore the Cortex XSIAM XTI Threat Intel Library for Unit 42 threat actors,from Unit 42.malware families, vulnerabilities, and reports.------# XTI Threat Intel Library# XTI Threat Intel LibraryThe XTI Threat Intel Library provides a unified catalog of threat objects, which are durable, conceptual entities used to describe and understand the broader threat landscape. It serves as a repository of curated intelligence, providing detailed information about the primary entities and security flaws observed in the threat landscape: threat actors, malware families, and vulnerabilities. By offering in-depth profiles, associations, and technical indicators, the library is a dedicated research tool that allows you to investigate adversary motivations, track malware evolution, and analyze vulnerability intelligence.The XTI Threat Intel Library provides a unified catalog of threat objects, which are durable, conceptual entities used to describe and understand the broader threat landscape. It serves as a repository of curated intelligence, providing detailed information about the primary entities and security flaws observed in the threat landscape: threat actors, malware families, and vulnerabilities. By offering in-depth profiles, associations, and technical indicators, the library is a dedicated research tool that allows you to investigate adversary motivations, track malware evolution, and analyze vulnerability intelligence.The XTI Threat Intel Library is powered by high-fidelity Unit 42 data.The XTI Threat Intel Library is powered by high-fidelity Unit 42 data.Show markdown source
@@ -1,12 +1,12 @@ --- description: >- - Research curated threat actors, malware families, vulnerabilities, and reports - from Unit 42. + Explore the Cortex XSIAM XTI Threat Intel Library for Unit 42 threat actors, + malware families, vulnerabilities, and reports. --- # XTI Threat Intel Library The XTI Threat Intel Library provides a unified catalog of threat objects, which are durable, conceptual entities used to describe and understand the broader threat landscape. It serves as a repository of curated intelligence, providing detailed information about the primary entities and security flaws observed in the threat landscape: threat actors, malware families, and vulnerabilities. By offering in-depth profiles, associations, and technical indicators, the library is a dedicated research tool that allows you to investigate adversary motivations, track malware evolution, and analyze vulnerability intelligence. The XTI Threat Intel Library is powered by high-fidelity Unit 42 data.