> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-01-28.md).

# 2026.01.28

### Release date: 09-February-2026

### Summary

#### Added

* **3 Detectors:** 2 Low, 1 Informational
* **2 Variations:** 2 Medium

#### Removed

* **1 Detector:** 1 Informational
* **8 Variations:** 1 High, 2 Medium, 5 Low

#### Modified Logic

* **35 Detectors:** 8 Low, 27 Informational
* **28 Variations:** 3 High, 11 Medium, 6 Low, 8 Informational

#### Modified Metadata

* **1 Detector:** 1 Informational

### Added

* \[Low] [Potential kubelet impersonation attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-kubelet-impersonation-attempt)
  * \[Medium] Potential kubelet impersonation attempt by an unusual process
* \[Low] [Suspicious access to Kubernetes API with kubelet credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-to-kubernetes-api-with-kubelet-credentials)
  * \[Medium] Suspicious access to Kubernetes API with kubelet credentials from unusual pod
* \[Informational] [Unrecognized sender domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)

### Removed

* \[Informational] Uncommon process communication to a rare external host
  * \[High] Uncommon process communication to a rare external host by an automated penetration testing tool
  * \[Medium] Uncommon process communication to a rare external host related to LOTTunnels
  * \[Medium] Uncommon process communication to a rare external host with a possible crypto mining tool for the first time
  * \[Low] Uncommon process communication to a rare external host involving a code sharing website
  * \[Low] Uncommon process communication to a rare external host with a possible exfiltration tool
  * \[Low] Uncommon process communication to a rare external host with a rare domain public suffix
  * \[Low] Uncommon process communication to a rare external host with an external IP in the command line
  * \[Low] Uncommon process communication to a rare external host with global anomaly detection

### Modified Logic

* \[Informational] [A process is masquerading as a common Microsoft product](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-is-masquerading-as-a-common-microsoft-product)
  * \[High] An unsigned and rare actor executing masqueraded process with uncommon characteristics - Added
  * \[Medium] A process that was executed by remote causality actor is masquerading as a common Microsoft product - Added
* \[Informational] [Rare scheduled task created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-created)
  * \[High] Rare scheduled task created by an injected actor - Added
  * \[Medium] Uncommon remote scheduled task created - Modified Metadata
  * \[Low] Highly rare scheduled task created - Modified Logic
  * \[Low] Uncommon local scheduled task created - Modified Logic
* \[Low] [Uncommon driver loaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-driver-loaded)
  * \[High] Uncommon driver loaded by a Web server process - Modified Metadata
  * \[Medium] Globally rare and unsigned driver loaded - Modified Logic
  * \[Medium] Uncommon driver with a globally rare vendor loaded as a service - Modified Metadata
* \[Informational] [A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-dll-signed-by-an-uncommon-vendor-was-hijacked-into-a-microsoft-process)
  * \[High -> Medium] A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process which was executed by unsigned causality actor - Modified Metadata
  * \[High -> Medium] A rare DLL, signed by an uncommon vendor, was hijacked into an injected Microsoft process - Modified Metadata
  * \[Medium -> Low] A rare DLL, signed by an uncommon vendor, was downloaded from an uncommon source and was loaded into Microsoft process - Modified Metadata
* \[Informational] [An identity attached an administrative policy to an IAM user or role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-attached-an-administrative-policy-to-an-iam-user-or-role)
  * \[Medium] An identity failed to attach an administrative policy to an IAM user or role - Modified Logic
  * \[Low] A suspicious identity attached an administrative policy to an IAM user/role - Modified Logic
* \[Informational] [An identity initiated a download of multiple cloud objects](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-initiated-a-download-of-multiple-cloud-objects)
  * \[Medium] An identity initiated a download of multiple cloud objects in large volume compared to the project's usual volume - Modified Logic
  * \[Low] An identity initiated a download of multiple cloud objects in large volume compared to the bucket's usual volume - Modified Logic
* \[Informational] [An identity performed a suspicious download of multiple cloud storage objects](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-performed-a-suspicious-download-of-multiple-cloud-storage-objects)
  * \[Medium] An identity performed a suspicious download of multiple cloud storage objects - Modified Logic
* \[Informational] [Uncommon attempt at discovering a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-discovering-a-sensitive-file)
  * \[Medium] Uncommon attempt at discovering a sensitive file by a potentially known credential dumper or enumeration script - Modified Logic
* \[Informational] [Uncommon attempt at grabbing credentials from a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-grabbing-credentials-from-a-sensitive-file)
  * \[Medium] Uncommon attempt at grabbing credentials from a sensitive file by a potentially known credential dumper or enumeration script - Modified Logic
* \[Informational] [An identity created or updated password for an IAM user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-created-or-updated-password-for-an-iam-user)
  * \[Low] A suspicious identity created or updated password for an IAM user - Modified Logic
* \[Low] [Email attachment with Right-to-Left Override Unicode character](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-right-to-left-override-unicode-character)
* \[Informational -> Low] [Email with file-sharing link containing auto-download parameter](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter)
* \[Low] [Execution of command from within a Kubernetes pod using kubelet credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-command-from-within-a-kubernetes-pod-using-kubelet-credentials)
* \[Low] [Risk indicators detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Low] [Sending unusual file(s) to an external address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sending-unusual-file-s-to-an-external-address)
* \[Low] [Suspicious access of the System Management Container](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-of-the-system-management-container)
* \[Low] [Suspicious modification of the AdminSDHolder's ACL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-modification-of-the-adminsdholder-s-acl)
* \[Informational] [An uncommon file added to startup-related Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-file-added-to-startup-related-registry-keys)
* \[Informational] [An unusual read activity of cloud object](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unusual-read-activity-of-cloud-object)
* \[Informational] [Cloud impersonation attempt by unusual identity type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-impersonation-attempt-by-unusual-identity-type)
* \[Informational] [Email attachment with a potentially malicious file extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type)
* \[Informational] [Email contains URL delivering high-risk file type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-contains-url-delivering-high-risk-file-type)
* \[Informational] [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values)
* \[Informational] [Moniker link detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/moniker-link-detected-in-url-s)
* \[Informational] [Near-empty email from an external sender](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/near-empty-email-from-an-external-sender)
  * \[Informational] Blank email with an attachment from an external sender - Added
  * \[Informational] Blank email with an inline attachment from an external sender - Added
  * \[Informational] Email has empty body or subject and was sent from an external source - Removed
  * \[Informational] Empty email from an external sender - Modified Metadata
* \[Informational] [Possible Privilege Escalation using Delegated MSA account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-privilege-escalation-using-delegated-msa-account)
* \[Informational] [Punycode characters detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/punycode-characters-detected-in-url-s)
* \[Informational] [Suspicious DKIM Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dkim-result)
  * \[Informational] DKIM results lacking sender correlation - Modified Logic
  * \[Informational] Known domain DKIM deviation - Modified Logic
  * \[Informational] Known domain suspicious DKIM result - Modified Logic
* \[Informational] [Uncommon URL domain(s) in your organization detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-url-domain-s-in-your-organization-detected-in-email)
* \[Informational] [Unpopular URL(s) detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unpopular domains detected in email URLs for a recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-domains-detected-in-email-urls-for-a-recipient)
* \[Informational] [Unrecognized sender address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
  * \[Informational] Email was received from an unknown sender with an unrecognized domain - Removed
* \[Informational] [Unusual secret management activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-secret-management-activity)
* \[Informational] [User signed in to an application via Power Automate for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-signed-in-to-an-application-via-power-automate-for-the-first-time)

### Modified Metadata

* \[Informational] [Email with URL shortener detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-url-shortener-detected)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-01-28.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
