> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-12-03.md).

# 2025.12.03

### Release date: 04-January-2026

### Summary

#### Added

* **12 Detectors:** 12 Informational
* **2 Variations:** 1 Low, 1 Informational

#### Modified Logic

* **23 Detectors:** 1 Medium, 5 Low, 17 Informational
* **15 Variations:** 4 Medium, 9 Low, 2 Informational

### Added

* \[Informational] [Local user enumeration via SAMR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-user-enumeration-via-samr)
  * \[Low] Local user enumeration via SAMR on an internet facing server
* \[Informational] [AWS EBS discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS EBS enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ebs-enumeration-activity)
* \[Informational] [AWS EC2 discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS EC2 infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ec2-infrastructure-enumeration-activity)
* \[Informational] [AWS IAM account discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS IAM permission groups discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
  * \[Informational] Unusual AWS IAM permission groups discovery operation
* \[Informational] [AWS Lambda discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS Lambda infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-lambda-infrastructure-enumeration-activity)
* \[Informational] [AWS S3 Buckets enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-s3-buckets-enumeration-activity)
* \[Informational] [AWS S3 discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Cloud storage object discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)

### Modified Logic

* \[Medium] [RDP Connection to localhost](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rdp-connection-to-localhost)
* \[Informational] [Unsigned DLL Hijack into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-dll-hijack-into-a-microsoft-process)
  * \[Medium] Unsigned DLL Hijack into a recently created Microsoft process which commonly loads the module as signed - Added
* \[Informational] [Unusual cloud Instance Metadata Service (IMDS) access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-cloud-instance-metadata-service-imds-access)
  * \[Low -> Medium] Unusual cloud Instance Metadata Service (IMDS) access from an unusual known shell process - Modified Logic
  * \[Low -> Medium] Unusual cloud Instance Metadata Service (IMDS) access from an unusual known web service - Modified Logic
  * \[Low] Cloud Unusual Instance Metadata Service (IMDS) access from an unusual known shell or scripting process in a Kubernetes pod - Removed
  * \[Low] Cloud Unusual Instance Metadata Service (IMDS) access from an unusual known web service in a Kubernetes pod - Removed
  * \[Low] Cloud Unusual internet-facing Instance Metadata Service (IMDS) access - Removed
  * \[Low] Unusual cloud Instance Metadata Service (IMDS) access from an unusual known scripting process - Added
  * \[Informational] Cloud Unusual Instance Metadata Service (IMDS) access in a Kubernetes pod - Removed
* \[Low] [WmiPrvSe.exe Rare Child Command Line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wmiprvse-exe-rare-child-command-line)
  * \[Medium] 551a388d-0221-44b0-af36-de4c36bbef81 - Modified Logic
* \[Informational] [A process connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-connected-to-a-rare-external-host)
  * \[Low] VSCode extension process connected to a rare external host - Modified Logic
* \[Informational] [Common third-party software name masquerading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/common-third-party-software-name-masquerading)
  * \[Low] Common third-party software name masquerading which was downloaded from an unexpected source - Modified Logic
* \[Low] [Possible network sniffing attempt via tcpdump or tshark](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-network-sniffing-attempt-via-tcpdump-or-tshark)
* \[Low] [Risk indicators detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Low] [Suspicious PowerShell Enumeration of Running Processes](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powershell-enumeration-of-running-processes)
* \[Informational] [Suspicious Unicode character detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-unicode-character-detected-in-email)
  * \[Low] Phishing terms obfuscation using Unicode characters detected in email - Modified Logic
  * \[Informational] Multiple suspicious Unicode characters detected in email - Modified Logic
* \[Informational] [Suspicious secrets dump activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-secrets-dump-activity)
  * \[Low] An identity extracted multiple secrets within the organization across multiple regions - Modified Logic
* \[Low] [Uncommon ARP cache listing via arp.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-arp-cache-listing-via-arp-exe)
* \[Informational] [Uncommon net localgroup command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-localgroup-command-execution)
  * \[Low] Uncommon net localgroup execution - Modified Logic
* \[Informational] [Email has a short body or subject and was sent from an external source](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Email mimics replies or forwards without an actual ongoing conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation)
* \[Informational] [Executable moved to Windows system folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/executable-moved-to-windows-system-folder)
* \[Informational] [External email display name impersonation of internal personnel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel)
* \[Informational] [First-seen email from mailbox owner to external recipient's address in the last 30 days](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days)
* \[Informational] [IAM Enumeration sequence](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-enumeration-sequence)
* \[Informational] [Potential spoofing of internal domain spotted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-spoofing-of-internal-domain-spotted)
* \[Informational] [Unusual IAM enumeration activity by a non-user Identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-iam-enumeration-activity-by-a-non-user-identity)
* \[Informational] [Unusual Identity and Access Management (IAM) activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-identity-and-access-management-iam-activity)
* \[Informational] [Usage of homograph characters detected in an email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-12-03.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
