> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-11.md).

# 2026.02.11

### Release date: 23-February-2026

### Summary

#### Added

* **6 Detectors:** 1 Low, 5 Informational
* **3 Variations:** 2 Low, 1 Informational

#### Removed

* **2 Detectors:** 1 Low, 1 Informational

#### Modified Logic

* **70 Detectors:** 1 High, 5 Medium, 22 Low, 42 Informational
* **37 Variations:** 7 High, 12 Medium, 12 Low, 6 Informational

#### Modified Metadata

* **5 Detectors:** 1 Low, 4 Informational
* **5 Variations:** 1 High, 3 Low, 1 Informational

### Added

* \[Informational] [AWS Security Service Enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-security-service-enumeration)
  * \[Low] AWS Multiple Security Services Enumeration
* \[Low] [Machine Account NTLM Relay](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/machine-account-ntlm-relay)
* \[Informational] [Sensitive browser credential files accessed by a rare non browser process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sensitive-browser-credential-files-accessed-by-a-rare-non-browser-process)
  * \[Low] Sensitive browser credential files accessed by a rare non browser process from a commonly abused directory
* \[Informational] [A cloud storage configuration was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-storage-configuration-was-modified)
* \[Informational] [An RDS snapshot was exported to an unknown bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-rds-snapshot-was-exported-to-an-unknown-bucket)
  * \[Informational] Failed RDS snapshot export attempt to an unknown bucket
* \[Informational] [Unusual internal access to network device management interface](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-internal-access-to-network-device-management-interface)

### Removed

* \[Low] Sensitive browser credential files accessed by a rare non browser process
* \[Informational] A cloud storage configuration was modified

### Modified Logic

* \[Low] [ClickFix - PowerShell executed through the run application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/clickfix-powershell-executed-through-the-run-application)
  * \[High] ClickFix - Schedule task PowerShell command executed through the run application - Added
* \[Informational] [Compute activity in dormant cloud region](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/compute-activity-in-dormant-cloud-region)
  * \[High] Compute activity in dormant cloud region by a compromised AWS access key - Modified Metadata
  * \[Informational] Compute activity in dormant cloud region from a non-VPN IP address - Added
* \[Informational] [Multiple cloud snapshots export](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-cloud-snapshots-export)
  * \[High] 062ca644-b34a-4d95-9ddb-41bce814f5a9 - Added
  * \[High] f17228e4\_558f\_46bd\_bb83\_5c26896ef9bb - Removed
* \[Informational] [Remote usage of AWS Lambda's role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-aws-lambda-s-role)
  * \[High] Remote command line usage of AWS Lambda's role - Removed
  * \[High] Remote command line usage of AWS Lambda's role - Added
* \[High] [Suspicious API call from a Tor exit node](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-api-call-from-a-tor-exit-node)
* \[Informational] [Unsigned DLL Side-Loading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-dll-side-loading)
  * \[High] DLL Side-Loading of module bearing an invalid Microsoft signature - Modified Logic
  * \[Medium] Unsigned DLL Side-Loading to a signed microsoft process by a rare causality actor - Modified Logic
  * \[Low] Unsigned high entropy DLL Side-Loading by untrusted causality actor - Modified Logic
* \[Medium] [A Kubernetes dashboard service account was used outside the cluster](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-dashboard-service-account-was-used-outside-the-cluster)
* \[Low] [A process queried the ADFS database decryption key via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-queried-the-adfs-database-decryption-key-via-ldap)
  * \[Medium] A process explicitly queried the ADFS database decryption key (DKM key) via LDAP - Modified Logic
* \[Medium] [Azure AD PIM alert disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-alert-disabled)
* \[Low] [Azure account deletion by a non-standard account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-account-deletion-by-a-non-standard-account)
  * \[Medium] A suspicious Azure account deletion by a non-standard account - Modified Logic
* \[Informational] [Azure application credentials added](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-application-credentials-added)
  * \[Medium] Suspicious credential operation on an Azure application - Modified Logic
  * \[Low] Unusual certificate operation on an Azure application - Modified Logic
* \[Medium] [Kubernetes vulnerability scanning tool usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-vulnerability-scanning-tool-usage)
  * \[Medium] External Kubernetes vulnerability scanning tool usage - Modified Logic
* \[Low] [Multiple user accounts failed login due to account lockouts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-user-accounts-failed-login-due-to-account-lockouts)
  * \[Medium] Excessive user account login failure due to lockout from a suspicious source - Removed
  * \[Medium] Excessive user account login failure due to lockout from a suspicious source - Added
* \[Low] [Possible DCSync from a non domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dcsync-from-a-non-domain-controller)
  * \[Medium] Possible DCSync from an internet-facing server - Removed
  * \[Medium] Possible DCSync from an internet-facing server - Added
* \[Medium] [Script file added to startup-related Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/script-file-added-to-startup-related-registry-keys)
* \[Medium] [Suspicious PowerSploit's recon module (PowerView) net function was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powersploit-s-recon-module-powerview-net-function-was-executed)
* \[Low] [Suspicious usage of EC2 token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-usage-of-ec2-token)
  * \[Medium] Suspicious usage of EC2 token - Modified Logic
* \[Informational] [Uncommon SQL like command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-sql-like-command-line)
  * \[Medium] Uncommon SQL like command line executed by a remote actor - Modified Metadata
  * \[Medium] Uncommon SQL like command line executed by an RMM tool - Modified Logic
  * \[Low] Uncommon SQL like command line executed by an uncommon CGO - Modified Logic
* \[Informational] [A Kubernetes node service account activity from external IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-node-service-account-activity-from-external-ip)
  * \[Low] A Kubernetes node service account was used outside the cluster - Modified Logic
* \[Informational] [A process connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-connected-to-a-rare-external-host)
  * \[Low] UNIX LOLBIN process connected to a rare external host - Modified Logic
* \[Informational] [Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-network-communication-with-a-rare-combination-of-http-user-agent-and-http-server)
  * \[Low] Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server where both the User Agent and the HTTP Server are rare - Removed
  * \[Low] Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server where both the User Agent and the HTTP Server are rare - Added
* \[Informational] [An AWS database service master user password was changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-database-service-master-user-password-was-changed)
  * \[Low] An AWS Database Service master user password was changed from an unusual country - Modified Logic
* \[Low] [Azure AD PIM role settings change](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-role-settings-change)
* \[Low] [Azure domain federation settings modification attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-domain-federation-settings-modification-attempt)
* \[Low] [First Azure AD PowerShell operation for a user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-azure-ad-powershell-operation-for-a-user)
* \[Low] [Impossible traveler - SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-traveler-sso)
  * \[Informational] SSO impossible traveler from a VPN or proxy - Removed
  * \[Informational] SSO impossible traveler from a VPN or proxy - Added
* \[Informational] [Kubernetes service account activity outside the cluster](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-service-account-activity-outside-the-cluster)
  * \[Low] Kubernetes service account activity outside the cluster from non-cloud IP - Modified Logic
* \[Low] [MFA was disabled for an Azure identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mfa-was-disabled-for-an-azure-identity)
* \[Low] [Multiple Azure AD admin role removals](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-azure-ad-admin-role-removals)
* \[Low] [Possible multistage attack in Microsoft Teams](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-multistage-attack-in-microsoft-teams)
* \[Low] [Potential kubelet impersonation attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-kubelet-impersonation-attempt)
* \[Low] [Rare unsigned process execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-unsigned-process-execution-by-scheduled-task)
* \[Low] [Remote usage of an AWS service token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-aws-service-token)
* \[Low] [Remote usage of an Azure Managed Identity token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-azure-managed-identity-token)
* \[Low] [Risk indicators detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [SSH authentication brute force attempts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ssh-authentication-brute-force-attempts)
  * \[Low] Successful SSH Brute Force - Removed
  * \[Low] Successful SSH Brute Force - Added
* \[Low] [Suspicious access to Kubernetes API with kubelet credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-to-kubernetes-api-with-kubelet-credentials)
* \[Low] [Uncommon local scheduled task creation via schtasks.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-local-scheduled-task-creation-via-schtasks-exe)
* \[Low] [Uncommon remote monitoring and management tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-monitoring-and-management-tool)
* \[Low] [Uncommon remote scheduled task creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-scheduled-task-creation)
* \[Low -> Informational] [Windows event logs were cleared with PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-event-logs-were-cleared-with-powershell)
  * \[Low] Windows event logs were cleared with uncommon PowerShell command line - Added
* \[Informational] [A cloud identity executed an API call from an unusual country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-executed-an-api-call-from-an-unusual-country)
* \[Informational] [A compute-attached identity executed API calls outside the instance's region](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-compute-attached-identity-executed-api-calls-outside-the-instance-s-region)
* \[Informational] [Authentication method added to an Azure account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-method-added-to-an-azure-account)
* \[Informational] [Azure AD PIM elevation request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-elevation-request)
* \[Informational] [Azure AD account unlock/password reset attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-account-unlock-password-reset-attempt)
* \[Informational] [Azure Temporary Access Pass (TAP) registered to an account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-temporary-access-pass-tap-registered-to-an-account)
* \[Informational] [Azure account creation by a non-standard account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-account-creation-by-a-non-standard-account)
* \[Informational] [Azure application consent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-application-consent)
* \[Informational] [Azure device code authentication flow used](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-device-code-authentication-flow-used)
* \[Informational] [BitLocker key retrieval](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bitlocker-key-retrieval)
* \[Informational] [Bucket's block public access setting turned off](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bucket-s-block-public-access-setting-turned-off)
* \[Informational] [Device Registration Policy modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/device-registration-policy-modification)
* \[Informational] [Email attachment with a potentially malicious file extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type)
* \[Informational] [External Login Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-login-password-spray)
  * \[Informational] External Login Password Spray from Multiple Source Hosts - Added
* \[Informational] [External email with a single internal recipient hidden in BCC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc)
* \[Informational] [Globally uncommon IP address by a common process (sha256)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-ip-address-by-a-common-process-sha256)
* \[Informational] [Multiple failed logins from a single IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-failed-logins-from-a-single-ip)
* \[Informational] [Numerous emails sent by a single sender to multiple internal recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients)
* \[Informational] [Owner added to Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/owner-added-to-azure-application)
* \[Informational] [Possible DLL Hijack into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dll-hijack-into-a-microsoft-process)
  * \[Informational] Possible DLL Side-Loading into a Microsoft process from a suspicious folder - Removed
  * \[Informational] Possible DLL Side-Loading into a Microsoft process from a suspicious folder - Added
* \[Informational] [Rare scheduled task created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-created)
* \[Informational] [Remote usage of VM Service Account token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-vm-service-account-token)
* \[Informational] [Remote usage of an App engine Service Account token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-app-engine-service-account-token)
* \[Informational] [Remote usage of an Azure Service Principal token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-azure-service-principal-token)
* \[Informational] [Uncommon attempt at discovering a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-discovering-a-sensitive-file)
* \[Informational] [Uncommon attempt at grabbing credentials from a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-grabbing-credentials-from-a-sensitive-file)
* \[Informational] [Uncommon signed process execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-signed-process-execution-by-scheduled-task)
* \[Informational] [Unusual Conditional Access operation for an identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-conditional-access-operation-for-an-identity)

### Modified Metadata

* \[Informational] [Suspicious process loads a known PowerShell module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-loads-a-known-powershell-module)
  * \[High] Office process loads a known PowerShell DLL - Modified Metadata
* \[Low] [Possible DLL Search Order Hijacking](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dll-search-order-hijacking)
  * \[Low] Possible DLL Search Order Hijacking - DLL downloaded from an uncommon source - Modified Metadata
  * \[Low] Possible DLL Search Order Hijacking - DLL extracted from an internet-downloaded archive - Modified Metadata
  * \[Low] Possible DLL Search Order Hijacking by DLL Substitution - Modified Metadata
* \[Informational] [First-seen email from mailbox owner to external recipient's address in the last 30 days](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days)
* \[Informational] [Local group enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-group-enumeration)
  * \[Low -> Informational] Local group enumeration using a builtin Windows binary - Modified Metadata
* \[Informational] [Unrecognized sender address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-11.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
