> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-03-18.md).

# 2026.03.18

### Release date: 13-April-2026

### Summary

#### Added

* **9 Detectors:** 1 Medium, 1 Low, 7 Informational
* **15 Variations:** 1 High, 2 Medium, 10 Low, 2 Informational

#### Modified Logic

* **107 Detectors:** 4 Medium, 24 Low, 79 Informational
* **17 Variations:** 1 Medium, 8 Low, 8 Informational

#### Modified Metadata

* **6 Detectors:** 4 Low, 2 Informational
* **1 Variation:** 1 Informational

### Added

* \[Informational] [Uncommon macOS process communication to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-macos-process-communication-to-a-rare-external-host)
  * \[High] Uncommon macOS process communication to a rare external host by security testing tool
  * \[Medium] Uncommon macOS process communication to a rare external host while using a CLI utility to establish a connection with a messaging service API
  * \[Medium] Uncommon macOS process communication to a rare external host with a frequently abused TLD
  * \[Low] Uncommon macOS process communication to a rare external host related to LOTTunnels
  * \[Low] Uncommon macOS process communication to a rare external host while using a CLI utility
  * \[Low] Uncommon macOS process communication to a rare external host while using a CLI utility and downloading a script
  * \[Low] Uncommon macOS process communication to a rare external host while using a CLI utility and piping to script
  * \[Low] Uncommon macOS process communication to a rare external host while using a CLI utility and saving data to a temporary folder
  * \[Low] Uncommon macOS process communication to a rare external host while using a CLI utility running by an unsigned process
  * \[Low] Uncommon macOS process communication to a rare external host while using a CLI utility to download and change permission
  * \[Low] Uncommon macOS process communication to a rare external host with a rare TLD
* \[Medium] [An unsigned process created scheduled task and performed an injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unsigned-process-created-scheduled-task-and-performed-an-injection)
  * \[Low] Possible an unsigned installer created scheduled task and performed an injection
* \[Informational] [Invalid SAML Detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/invalid-saml-detected)
  * \[Low] Suspicious Invalid SAML Detected
* \[Low] [Unusual ADFS Remote Synchronization network connections from non-ADFS server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-adfs-remote-synchronization-network-connections-from-non-adfs-server)
* \[Informational] [A GCP Cloud SQL DB instance was exported from a production account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-gcp-cloud-sql-db-instance-was-exported-from-a-production-account)
* \[Informational] [An AWS EC2 instance was exported from a production account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-ec2-instance-was-exported-from-a-production-account)
* \[Informational] [An AWS EC2 instance was exported into an unknown S3 bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-ec2-instance-was-exported-into-an-unknown-s3-bucket)
* \[Informational] [An RDS snapshot was exported from a production account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-rds-snapshot-was-exported-from-a-production-account)
* \[Informational] [An uncommon lolbin execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-lolbin-execution-by-scheduled-task)
  * \[Informational] A rare and commonly-abused lolbin execution by scheduled task
  * \[Informational] An uncommon lolbin execution by scheduled task on a sensitive server

### Modified Logic

* \[Low] [A user uploaded malware to SharePoint or OneDrive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-uploaded-malware-to-sharepoint-or-onedrive)
  * \[Medium] A user uploaded malware to SharePoint or OneDrive with suspicious characteristics - Modified Logic
* \[Medium] [An internal Cloud resource performed port scan on external networks](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-internal-cloud-resource-performed-port-scan-on-external-networks)
* \[Medium] [Discovery of misconfigured certificate templates using LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/discovery-of-misconfigured-certificate-templates-using-ldap)
* \[Medium] [Potential Phishing has been detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-phishing-has-been-detected)
* \[Medium] [Unsigned process injecting into a Windows system binary with no command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-process-injecting-into-a-windows-system-binary-with-no-command-line)
* \[Low] [A process queried the ADFS database decryption key via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-queried-the-adfs-database-decryption-key-via-ldap)
* \[Low] [A user attempted to bypass Okta MFA](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-attempted-to-bypass-okta-mfa)
* \[Low] [Discovery of accounts with pre-authentication disabled via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/discovery-of-accounts-with-pre-authentication-disabled-via-ldap)
* \[Low] [Email attachment with Right-to-Left Override Unicode character](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-right-to-left-override-unicode-character)
* \[Informational] [Email contains URL delivering high-risk file type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-contains-url-delivering-high-risk-file-type)
  * \[Low] External email with URL delivers blocked file types - Modified Logic
* \[Low] [Email was received from an unknown sender using a disposable domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-sender-using-a-disposable-domain)
* \[Low] [Email with file-sharing link containing auto-download parameter](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter)
* \[Informational] [Exchange mailbox delegation permissions added](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-mailbox-delegation-permissions-added)
  * \[Low] Addition of Exchange mailbox delegation permissions with suspicious characteristics - Modified Logic
* \[Low] [Impossible traveler - VPN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-traveler-vpn)
* \[Low] [LDAP AD CS Enumeration via Attack Tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ldap-ad-cs-enumeration-via-attack-tool)
* \[Low] [Large Upload (FTP)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-ftp)
* \[Low] [Large Upload (Generic)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-generic)
* \[Low] [Large Upload (HTTPS)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-https)
* \[Low] [Large Upload (SMTP)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-smtp)
* \[Informational] [Member added to a Windows local security group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/member-added-to-a-windows-local-security-group)
  * \[Low] User added to the Windows local Administrator group - Modified Logic
* \[Low] [Office process accessed an unusual .LNK file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/office-process-accessed-an-unusual-lnk-file)
* \[Low] [Possible DLL Search Order Hijacking](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dll-search-order-hijacking)
* \[Informational -> Low] [RDP from an unmanaged endpoint in a typically managed subnet](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rdp-from-an-unmanaged-endpoint-in-a-typically-managed-subnet)
* \[Low] [Rare Windows Remote Management (WinRM) HTTP Activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-windows-remote-management-winrm-http-activity)
* \[Low] [Remote service start from an uncommon source](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-service-start-from-an-uncommon-source)
* \[Low] [Sending unusual file(s) to an external address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sending-unusual-file-s-to-an-external-address)
* \[Low] [Suspicious LDAP queries followed by shared folder access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ldap-queries-followed-by-shared-folder-access)
* \[Informational] [Suspicious SPF Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-spf-result)
  * \[Low] Internal domain SPF deviation - Modified Logic
* \[Informational] [Suspicious Unicode character detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-unicode-character-detected-in-email)
  * \[Low] Phishing terms obfuscation using Unicode characters detected in email - Modified Logic
  * \[Informational] Multiple suspicious Unicode characters detected in email - Modified Logic
* \[Low] [Uncommon VNC server communication](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-vnc-server-communication)
* \[Low] [Uncommon local scheduled task creation via schtasks.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-local-scheduled-task-creation-via-schtasks-exe)
* \[Low] [Unusual process accessed a crypto wallet's files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-crypto-wallet-s-files)
* \[Low] [Unusual process accessed a web browser history file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-web-browser-history-file)
* \[Informational] [User accessed SaaS resource via anonymous link](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-accessed-saas-resource-via-anonymous-link)
  * \[Low] External user accessed a sensitive SaaS file via anonymous link - Modified Logic
* \[Informational] [User moved Exchange sent messages to deleted items](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-moved-exchange-sent-messages-to-deleted-items)
  * \[Low] Sensitive Exchange sent messages moved to deleted items from unusual source - Modified Logic
* \[Informational] [VPN login Brute-Force attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-brute-force-attempt)
  * \[Low] Successful VPN Login Brute Force - Modified Logic
* \[Informational] [A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-dll-signed-by-an-uncommon-vendor-was-hijacked-into-a-microsoft-process)
* \[Informational] [A user executed multiple LDAP enumeration queries](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-executed-multiple-ldap-enumeration-queries)
* \[Informational] [A user modified an Okta MFA factor](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-modified-an-okta-mfa-factor)
* \[Informational] [A user modified an Okta network zone](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-modified-an-okta-network-zone)
* \[Informational] [A user modified an Okta policy rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-modified-an-okta-policy-rule)
* \[Informational] [A user queried AD CS objects via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-queried-ad-cs-objects-via-ldap)
* \[Informational] [Abnormal Communication to a Rare Domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-communication-to-a-rare-domain)
* \[Informational] [Abnormal Recurring Communications to a Rare Domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-recurring-communications-to-a-rare-domain)
* \[Informational] [AppleScript interpreter dynamic library loaded into a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/applescript-interpreter-dynamic-library-loaded-into-a-process)
* \[Informational] [DNS resolution to the Palo Alto Networks sinkhole](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Download pattern that resembles Peer to Peer traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/download-pattern-that-resembles-peer-to-peer-traffic)
* \[Informational] [Email attachment with a potentially malicious file extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension)
* \[Informational] [Email attachment with multiple extensions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-multiple-extensions)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type)
* \[Informational] [Email containing a link with an IP address convention was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-link-with-an-ip-address-convention-was-detected)
* \[Informational] [Email containing a redirected link](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-redirected-link)
* \[Informational] [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values)
* \[Informational] [Email mimics replies or forwards without an actual ongoing conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation)
* \[Informational] [Email was received from an unknown address using a public provider domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-address-using-a-public-provider-domain)
* \[Informational] [Email with URL shortener detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-url-shortener-detected)
* \[Informational] [Exchange email-hiding inbox rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-email-hiding-inbox-rule)
* \[Informational] [External email display name impersonation of internal personnel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel)
* \[Informational] [External email with a single internal recipient hidden in BCC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc)
* \[Informational] [First-seen email from mailbox owner to external recipient's address in the last 30 days](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days)
* \[Informational] [Globally uncommon image load from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-image-load-from-a-signed-process)
* \[Informational] [Globally uncommon process execution from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-process-execution-from-a-signed-process)
* \[Informational] [Microsoft Teams application setup policy was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-teams-application-setup-policy-was-modified)
* \[Informational] [Microsoft Teams external communication policy was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-teams-external-communication-policy-was-modified)
* \[Informational] [Moniker link detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/moniker-link-detected-in-url-s)
* \[Informational] [Near-empty email from an external sender](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/near-empty-email-from-an-external-sender)
  * \[Informational] Blank email with an inline attachment from an external sender - Modified Logic
* \[Informational] [Numerous emails sent by a single sender to multiple internal recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients)
* \[Informational] [Okta account reset password attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-reset-password-attempt)
* \[Informational] [Okta account unlock](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-unlock)
* \[Informational] [Okta account unlock by admin](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-unlock-by-admin)
* \[Informational] [Okta admin privilege assignment](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-admin-privilege-assignment)
* \[Informational] [Outbound email contains file-sharing service link sent to external recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-contains-file-sharing-service-link-sent-to-external-recipient)
* \[Informational] [Outbound email includes an external BCC recipient observed for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-includes-an-external-bcc-recipient-observed-for-the-first-time)
* \[Informational] [Outbound email to an address hosted by a public email service provider](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-to-an-address-hosted-by-a-public-email-service-provider)
* \[Informational] [Port Scan](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/port-scan)
* \[Informational] [Possible GPO Enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-gpo-enumeration)
* \[Informational] [Possible LDAP Enumeration Tool Usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-ldap-enumeration-tool-usage)
* \[Informational] [Possible LDAP Enumeration of Microsoft Configuration Manager](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-ldap-enumeration-of-microsoft-configuration-manager)
* \[Informational] [Possible SPN enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-spn-enumeration)
* \[Informational] [Potential Okta access limit breach](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-okta-access-limit-breach)
* \[Informational] [Potential spoofing of internal domain spotted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-spoofing-of-internal-domain-spotted)
* \[Informational] [Punycode characters detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/punycode-characters-detected-in-url-s)
* \[Informational] [Rare scheduled task created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-created)
* \[Informational] [Rarely seen URL(s) within a well-known domain detected in your organization's email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-url-s-within-a-well-known-domain-detected-in-your-organization-s-email)
* \[Informational] [Sudden spike in outbound email volume](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sudden-spike-in-outbound-email-volume)
* \[Informational] [Suspicious DKIM Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dkim-result)
* \[Informational] [Suspicious DMARC result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dmarc-result)
* \[Informational] [Suspicious access to cloud credential files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-to-cloud-credential-files)
* \[Informational] [Uncommon URL domain(s) in your organization detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-url-domain-s-in-your-organization-detected-in-email)
* \[Informational] [Unpopular domains detected in email URLs for a recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-domains-detected-in-email-urls-for-a-recipient)
* \[Informational] [Unrecognized internal address (AAD mismatch)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unrecognized-internal-address-aad-mismatch)
* \[Informational] [Unrecognized sender address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unrecognized sender domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unsigned DLL Side-Loading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-dll-side-loading)
* \[Informational] [Unusual attachment volume in outbound emails](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-attachment-volume-in-outbound-emails)
* \[Informational] [Unusual display name in From header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-display-name-in-from-header)
* \[Informational] [Unusual hostname for the sending mail server in the email headers](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-hostname-for-the-sending-mail-server-in-the-email-headers)
* \[Informational] [Unusual process accessed web browser cookies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-web-browser-cookies)
* \[Informational] [Unusual process accessed web browser credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-web-browser-credentials)
* \[Informational] [Upload pattern that resembles Peer to Peer traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/upload-pattern-that-resembles-peer-to-peer-traffic)
* \[Informational] [Usage of homograph characters detected in an email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email)
* \[Informational] [Usage of homograph characters detected in an email attachment(s) name](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-attachment-s-name)
* \[Informational] [Usage of homograph characters detected in an email's from header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-s-from-header)
* \[Informational] [User added a new device to Okta Verify instance](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-added-a-new-device-to-okta-verify-instance)
* \[Informational] [VPN Login Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-password-spray)
* \[Informational] [Well-known brand in sender headers with header inconsistencies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/well-known-brand-in-sender-headers-with-header-inconsistencies)
* \[Informational] [X-Forefront-Antispam-Report has flagged this email as a potential threat](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/x-forefront-antispam-report-has-flagged-this-email-as-a-potential-threat)
  * \[Informational] X-Forefront-Antispam-Report flagged this email as spam - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged this email as a bulk email - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged this email as impersonating a specific user within the organization - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged this email as impersonating the organization's domain - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged this email as using advanced impersonation techniques - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has strongly flagged this email as spam - Modified Logic

### Modified Metadata

* \[Low] [Interactive at.exe privilege escalation method](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-at-exe-privilege-escalation-method)
* \[Low] [Rare unsigned process execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-unsigned-process-execution-by-scheduled-task)
* \[Low] [Uncommon remote scheduled task creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-scheduled-task-creation)
* \[Low] [Unsigned process creates a scheduled task via file access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-process-creates-a-scheduled-task-via-file-access)
* \[Informational] [AWS Security Service Enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-security-service-enumeration)
  * \[Low -> Informational] AWS Multiple Security Services Enumeration - Modified Metadata
* \[Informational] [Uncommon signed process execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-signed-process-execution-by-scheduled-task)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-03-18.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
