> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-18.md).

# 2026.02.18

### Release date: 01-March-2026

### Summary

#### Added

* **4 Detectors:** 4 Informational
* **26 Variations:** 2 High, 9 Medium, 15 Low

#### Removed

* **3 Detectors:** 3 Informational
* **17 Variations:** 1 High, 6 Medium, 6 Low, 4 Informational

#### Modified Logic

* **47 Detectors:** 2 High, 9 Low, 36 Informational
* **7 Variations:** 3 Medium, 2 Low, 2 Informational

#### Modified Metadata

* **5 Detectors:** 2 Low, 3 Informational
* **4 Variations:** 4 Low

### Added

* \[Informational] [Uncommon net group command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-group-command-execution)
  * \[High] Uncommon unsigned net group administrators command execution
  * \[High] Uncommon unsigned net group administrators command execution - fixed localization issues
  * \[Medium] Uncommon administrator net group execution by scripting engine or command prompt
  * \[Medium] Uncommon net group administrators command execution
  * \[Low] Uncommon net group execution
  * \[Low] Uncommon remote net group administrators command execution
  * \[Low] Uncommon remote net group execution
* \[Informational] [Uncommon access to /etc/passwd](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-access-to-etc-passwd)
  * \[Medium] Uncommon access to /etc/passwd by a potential Webshell
  * \[Medium] Uncommon access to /etc/passwd by a potentially known credential dumper or enumeration script
  * \[Medium] Uncommon access to /etc/passwd by a security testing tool
  * \[Low] Uncommon access to /etc/passwd from temporary or world writable directories
  * \[Low] Uncommon access to /etc/passwd using an interactive binary
  * \[Low] Uncommon access to /etc/passwd using an interactive shell
  * \[Low] Uncommon access to /etc/passwd via a new inline bash script
  * \[Low] Uncommon access to /etc/passwd with additional sensitive files in the command line
  * \[Low] Uncommon access to /etc/passwd with both /etc/passwd and /etc/shadow in the command line
  * \[Low] Uncommon access to /etc/passwd, involving a network utility
  * \[Low] Uncommon link creation to /etc/passwd
* \[Informational] [Uncommon net localgroup command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-localgroup-command-execution)
  * \[Medium] Uncommon net localgroup administrators command execution by a web server process or CGO
  * \[Medium] Uncommon remote net localgroup execution
  * \[Medium] Uncommon unsigned net localgroup administrators command execution
  * \[Medium] Uncommon unsigned net localgroup administrators command execution - fixed localization issues
  * \[Low] Uncommon administrator net localgroup execution by scripting engine or command prompt
  * \[Low] Uncommon net localgroup administrators command execution
  * \[Low] Uncommon net localgroup execution
* \[Informational] [LOLBAS executable injects into another process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbas-executable-injects-into-another-process)
  * \[Low] LOLBAS executable injects into another process under an uncommon CGO

### Removed

* \[Informational] Uncommon net group command execution
  * \[High] Uncommon unsigned net group administrators command execution
  * \[Medium] Uncommon administrator net group execution by scripting engine or command prompt
  * \[Medium] Uncommon net group administrators command execution
  * \[Low] Uncommon net group execution
  * \[Low] Uncommon remote net group administrators command execution
  * \[Low] Uncommon remote net group execution
* \[Informational] LOLBAS executable injects into another process
  * \[Medium] Rare LOLBAS executable injects into another process
  * \[Informational] LOLBAS executable injects into another process using process hollowing
  * \[Informational] LOLBAS executable that's used to host DLLs injects into another process
  * \[Informational] LOLBAS executable that's used to host DLLs injects into another process
  * \[Informational] Scripting engine injects into another process
* \[Informational] Uncommon net localgroup command execution
  * \[Medium] Uncommon administrator net localgroup execution by scripting engine or command prompt
  * \[Medium] Uncommon net localgroup administrators command execution by a web server process or CGO
  * \[Medium] Uncommon unsigned net localgroup administrators command execution
  * \[Low] Uncommon net localgroup administrators command execution
  * \[Low] Uncommon net localgroup execution
  * \[Low] Uncommon remote net localgroup execution

### Modified Logic

* \[High] [Cloud penetration testing tool activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-penetration-testing-tool-activity)
* \[High] [Suspicious API call from a Tor exit node](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-api-call-from-a-tor-exit-node)
* \[Informational] [Globally uncommon image load from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-image-load-from-a-signed-process)
  * \[Medium] Globally uncommon and very rare image load from a signed process - Modified Logic
* \[Informational] [Uncommon attempt at discovering a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-discovering-a-sensitive-file)
  * \[Medium] Uncommon attempt at discovering a sensitive file by a potentially known credential dumper or enumeration script - Modified Logic
* \[Informational] [Uncommon attempt at grabbing credentials from a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-grabbing-credentials-from-a-sensitive-file)
  * \[Medium] Uncommon attempt at grabbing credentials from a sensitive file by a potentially known credential dumper or enumeration script - Modified Logic
* \[Low] [A rare file path was added to the AppInit\_DLLs registry value](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-file-path-was-added-to-the-appinit-dlls-registry-value)
* \[Low] [Authentication attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-attempt-by-a-honey-user)
* \[Low] [Azure AD PIM role settings change](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-role-settings-change)
* \[Low] [Azure Event Hub Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-event-hub-deletion)
* \[Informational] [Azure storage account cross-tenant object replication was enabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-storage-account-cross-tenant-object-replication-was-enabled)
  * \[Low] Azure storage account cross-tenant object replication was enabled for the first time in a subscription - Modified Metadata
* \[Informational] [First VPN access from ASN for user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-vpn-access-from-asn-for-user)
  * \[Low] Unusual VPN access from ASN - Modified Metadata
* \[Low] [Possible multistage attack in Microsoft Teams](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-multistage-attack-in-microsoft-teams)
* \[Low] [Risk indicators detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Low] [SSO authentication attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-attempt-by-a-honey-user)
* \[Low] [Uncommon ARP cache listing via arp.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-arp-cache-listing-via-arp-exe)
* \[Low] [VPN login attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-attempt-by-a-honey-user)
* \[Informational] [A cloud identity executed an API call from an unusual country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-executed-an-api-call-from-an-unusual-country)
* \[Informational] [A possible risky login to Azure](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-possible-risky-login-to-azure)
* \[Informational] [An Azure Firewall rule collection group was modified or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-firewall-rule-collection-group-was-modified-or-deleted)
* \[Informational] [An Azure Key Vault key was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-key-vault-key-was-modified)
* \[Informational] [An identity attached an administrative policy to an IAM user or role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-attached-an-administrative-policy-to-an-iam-user-or-role)
* \[Informational] [An identity created or updated password for an IAM user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-created-or-updated-password-for-an-iam-user)
* \[Informational] [Authentication method added to an Azure account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-method-added-to-an-azure-account)
* \[Informational] [Azure AD account unlock/password reset attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-account-unlock-password-reset-attempt)
* \[Informational] [Azure Automation Account Creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-account-creation)
* \[Informational] [Azure Automation Runbook Creation/Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-runbook-creation-modification)
* \[Informational] [Azure Automation Runbook Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-runbook-deletion)
* \[Informational] [Azure Key Vault modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-key-vault-modification)
* \[Informational] [Azure Resource Group Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-resource-group-deletion)
* \[Informational] [Cloud access key creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-access-key-creation)
  * \[Informational] Successful access key creation by an unusual identity type - Modified Metadata
  * \[Informational] Unusual successful cloud access key creation - Modified Metadata
* \[Informational] [Cloud resource logging was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-resource-logging-was-disabled)
* \[Informational] [Cloud user performed multiple actions that were denied](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-user-performed-multiple-actions-that-were-denied)
* \[Informational] [Compute activity in dormant cloud region](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/compute-activity-in-dormant-cloud-region)
* \[Informational] [First SSO Resource Access in the Organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-resource-access-in-the-organization)
* \[Informational] [First SSO access from ASN for user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-access-from-asn-for-user)
* \[Informational] [First SSO access from ASN in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-access-from-asn-in-organization)
* \[Informational] [First VPN access from ASN in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-vpn-access-from-asn-in-organization)
* \[Informational] [Okta account unlock](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-unlock)
* \[Informational] [Okta account unlock by admin](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-unlock-by-admin)
* \[Informational] [Potential Okta access limit breach](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-okta-access-limit-breach)
* \[Informational] [Rare NTLM Access By User To Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ntlm-access-by-user-to-host)
* \[Informational] [SSO Brute Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-brute-force)
* \[Informational] [Suspicious SSO access from ASN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sso-access-from-asn)
* \[Informational] [Unusual cloud Instance Metadata Service (IMDS) access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-cloud-instance-metadata-service-imds-access)
* \[Informational] [Unverified domain added to Azure AD](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unverified-domain-added-to-azure-ad)
* \[Informational] [User attempted to connect from a suspicious country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-attempted-to-connect-from-a-suspicious-country)
* \[Informational] [Windows CGO, actor and action processes with anomalous characteristics](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-cgo-actor-and-action-processes-with-anomalous-characteristics)

### Modified Metadata

* \[Informational] [Execution of an uncommon process at an early startup stage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage)
  * \[Medium -> Low] Execution of an uncommon process at an early startup stage with suspicious characteristics - Modified Metadata
* \[Low] [Execution of an uncommon process at an early startup stage by Windows system binary](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage-by-windows-system-binary)
  * \[Medium -> Low] Execution of an uncommon process at an early startup stage by Windows system binary with suspicious characteristics - Modified Metadata
* \[Informational] [Execution of an uncommon process with a local/domain user SID at an early startup stage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage)
  * \[Medium -> Low] Execution of an uncommon process with a local/domain user SID at an early startup stage with suspicious characteristics - Modified Metadata
* \[Low] [Execution of an uncommon process with a local/domain user SID at an early startup stage by Windows system binary](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage-by-windows-system-binary)
  * \[Medium -> Low] Execution of an uncommon process with a local/domain user SID at an early startup stage with a suspicious characteristics by Windows system binary - Modified Metadata
* \[Informational] [Rare DLP rule match by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-dlp-rule-match-by-user)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-18.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
