> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-05-28.md).

# 2026.05.28

### Release date: 15-June-2026

### Summary

#### Added

* **29 Detectors:** 1 High, 13 Low, 15 Informational
* **20 Variations:** 5 Medium, 11 Low, 4 Informational

#### Modified Logic

* **67 Detectors:** 2 Medium, 13 Low, 52 Informational
* **45 Variations:** 7 Medium, 23 Low, 15 Informational

#### Modified Metadata

* **14 Detectors:** 5 Low, 9 Informational
* **19 Variations:** 2 Medium, 14 Low, 3 Informational

### Added

* \[High] [Suspicious AI model usage from a Tor exit node](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ai-model-usage-from-a-tor-exit-node)
  * \[Informational] Failed AI model usage from a Tor exit node
* \[Low] [ML artifacts destruction](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ml-artifacts-destruction)
  * \[Medium] Unusual ML artifacts destruction
* \[Low] [Potential denial of wallet abusing AI services](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-denial-of-wallet-abusing-ai-services)
  * \[Medium] Possible denial of wallet abusing AI services
* \[Low] [Suspicious AI Dataset Download](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ai-dataset-download)
  * \[Medium] Suspicious First-Time AI Dataset Download by Identity
* \[Informational] [Suspicious ML Model Download](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ml-model-download)
  * \[Medium] Suspicious First-Time AI Model Download by Identity
* \[Low] [Unusual AI Knowledge Base Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-ai-knowledge-base-modification)
  * \[Medium] Suspicious AI Knowledge Base Modification
* \[Low] [AI model discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ai-model-discovery)
* \[Informational] [AI safeguards deletion attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ai-safeguards-deletion-attempt)
  * \[Low] AI safeguards were successfully deleted
* \[Informational] [AI safeguards were modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ai-safeguards-were-modified)
  * \[Low] Unusual modification of AI safeguards
  * \[Informational] AI safeguards were created or modified
* \[Low] [AWS Bedrock model invocation logging deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-bedrock-model-invocation-logging-deletion)
  * \[Low] AWS Bedrock model invocation logging was successfully deleted
  * \[Informational] AWS Bedrock model invocation logging deletion by an identity with administrative activity
* \[Low] [Abnormal increase in network-related alerts on the same host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-increase-in-network-related-alerts-on-the-same-host)
* \[Low] [Bedrock model shared with a foreign account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bedrock-model-shared-with-a-foreign-account)
* \[Informational] [Cloud AI agent was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-ai-agent-was-modified)
  * \[Low] Unusual modification of AI agent
* \[Informational] [Massive files deletion in Box](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-files-deletion-in-box)
  * \[Low] Massive files deletion in Box with suspicious parameters
* \[Informational] [Massive files deletion in Dropbox](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-files-deletion-in-dropbox)
  * \[Low] Massive files deletion in Dropbox with suspicious parameters
* \[Informational] [Massive files deletion in Google Drive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-files-deletion-in-google-drive)
  * \[Low] Massive files deletion in Google Drive with suspicious parameters
* \[Informational] [Massive files deletion in Microsoft SharePoint or OneDrive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-files-deletion-in-microsoft-sharepoint-or-onedrive)
  * \[Low] Massive files deletion in Microsoft SharePoint or OneDrive with suspicious parameters
* \[Informational] [Modification of the AD FS IdentityServer configuration file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/modification-of-the-ad-fs-identityserver-configuration-file)
  * \[Low] Suspicious Modification of the AD FS IdentityServer configuration file
* \[Low] [Multiple network-related alerts of different MITRE tactics on the same host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-network-related-alerts-of-different-mitre-tactics-on-the-same-host)
* \[Low] [Multiple network-related alerts produced by different detectors on the same host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-network-related-alerts-produced-by-different-detectors-on-the-same-host)
* \[Informational] [Port Sweep](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/port-sweep)
  * \[Low] Port Sweep to multiple subnets
* \[Informational] [Possible ConsentFix - OAuth Token Theft Detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-consentfix-oauth-token-theft-detected)
  * \[Low] OAuth Token Theft - Potential Session Hijacking Detected from new ASN
* \[Low] [Suspicious AI Dataset Label Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ai-dataset-label-modification)
* \[Low] [Unusual AI RAG Knowledge Base Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-ai-rag-knowledge-base-modification)
* \[Low] [Unusual AI dataset modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-ai-dataset-modification)
  * \[Informational] Unusual AI dataset modification from an internal IP address
* \[Informational] [An RDS snapshot containing sensitive data was exported](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-rds-snapshot-containing-sensitive-data-was-exported)
* \[Informational] [Unusual AI model invocation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-ai-model-invocation)
* \[Informational] [Unusual AWS Bedrock model access request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-bedrock-model-access-request)
* \[Informational] [Unusual AWS SageMaker notebook access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-sagemaker-notebook-access)

### Modified Logic

* \[Informational] [Access to sensitive host files from within a Kubernetes pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/access-to-sensitive-host-files-from-within-a-kubernetes-pod)
  * \[Medium] Access to sensitive host files from within a Kubernetes pod via an interactive shell - Modified Logic
* \[Low] [Known service display name with uncommon image-path](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/known-service-display-name-with-uncommon-image-path)
  * \[Medium] Known service display name with uncommon image-path in a suspicious folder - Modified Metadata
* \[Medium] [Potential Phishing has been detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-phishing-has-been-detected)
* \[Informational] [Rare scheduled task created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-created)
  * \[Medium] Uncommon remote scheduled task created - Modified Metadata
  * \[Low] Uncommon local scheduled task created - Modified Metadata
* \[Low] [Remote usage of an AWS service token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-aws-service-token)
  * \[Medium] Suspicious usage of AWS service token - Added
* \[Low -> Informational] [Suspicious activity on logging bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-activity-on-logging-bucket)
  * \[Medium] Suspicious deletion on CloudTrail logging bucket - Added
* \[Informational -> Medium] [Training simulation email detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/training-simulation-email-detected)
* \[Informational] [Unusual Kubernetes service account file read](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-kubernetes-service-account-file-read)
  * \[Medium] Suspicious Kubernetes service account token read via an interactive shell - Modified Logic
* \[Informational] [Unusual exec into a Kubernetes Pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-exec-into-a-kubernetes-pod)
  * \[Medium] First time execution into Kubernetes Pod at the cluster-level - Modified Metadata
  * \[Low] Identity executed into Kubernetes Pod for the first time - Modified Metadata
  * \[Low] Identity executed into a Kubernetes Pod for the first time - Modified Metadata
  * \[Low] Identity executed into a Kubernetes namespace for the first time - Modified Metadata
  * \[Informational] Failed exec attempt into a Kubernetes Pod - Added
* \[Low -> Informational] [AWS web ACL deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-web-acl-deletion)
  * \[Low] Successful AWS web ACL deletion by a non-admin identity - Added
* \[Low] [Azure AD PIM role settings change](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-role-settings-change)
* \[Informational] [Azure AD account unlock/password reset attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-account-unlock-password-reset-attempt)
  * \[Low] Azure AD account unlock/successful password reset - Modified Logic
* \[Low] [Elevation to SYSTEM via services](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/elevation-to-system-via-services)
* \[Informational] [Email contains URL delivering high-risk file type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-contains-url-delivering-high-risk-file-type)
  * \[Low] External email with URL delivers blocked file types - Modified Logic
* \[Low] [Email was received from an unknown sender using a disposable domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-sender-using-a-disposable-domain)
* \[Low] [Email with file-sharing link containing auto-download parameter](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter)
  * \[Low] External email with file-sharing link containing auto-download parameter - Modified Logic
* \[Informational] [External user created a Microsoft Teams conversation with suspicious operations](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-user-created-a-microsoft-teams-conversation-with-suspicious-operations)
  * \[Low] An external user created a chat and shortly after sent a link with a newly seen domain name - Modified Metadata
  * \[Low] An external user created a chat then sent a link with a file for the first time via Microsoft Teams - Modified Metadata
  * \[Low] An external user created a chat with a suspicious user or chat name and then sent a link via Microsoft Teams - Modified Metadata
  * \[Low] An external user initiated a Microsoft Teams chat in which a link was shared and a member was removed - Modified Metadata
  * \[Low] An external user initiated a Microsoft Teams chat in which a suspicious link was shared and a member was removed - Modified Metadata
  * \[Informational] An external user created a chat and then sent a link via Microsoft Teams - Modified Metadata
  * \[Informational] An external user created a chat then sent a link via Microsoft Teams - Modified Metadata
* \[Informational] [External user started a Microsoft Teams conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-user-started-a-microsoft-teams-conversation)
  * \[Low] An external user started a conversation in Microsoft Teams with a suspicious user or chat name - Modified Metadata
  * \[Low] An external user started multiple conversations in Microsoft Teams - Modified Metadata
  * \[Low] An external user started multiple conversations in Microsoft Teams with suspicious chat names - Modified Metadata
  * \[Informational] An external user started conversations in Microsoft Teams with many internal users - Modified Metadata
  * \[Informational] External user started a Microsoft Teams conversation and sent a message - Modified Metadata
* \[Informational] [Globally uncommon high entropy process was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-high-entropy-process-was-executed)
  * \[Low] Globally uncommon high entropy process was executed by an untrusted CGO - Added
* \[Low] [Large Upload (Generic)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-generic)
  * \[Informational] Large Upload (Generic) Lower than 100 MB - Added
  * \[Informational] Large Upload (Generic) to a Frequently Used Upload Target - Modified Metadata
* \[Low] [Large Upload (HTTPS)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-https)
  * \[Low] Large Upload (HTTPS) to non-standard port - Added
* \[Low] [Possible path traversal via HTTP request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-path-traversal-via-http-request)
* \[Low] [Recurring access to rare domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-access-to-rare-domain)
* \[Low] [Recurring rare domain access from an unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-rare-domain-access-from-an-unsigned-process)
* \[Low] [Recurring rare domain access to dynamic DNS domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-rare-domain-access-to-dynamic-dns-domain)
* \[Low] [Suspicious PowerShell Command Line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powershell-command-line)
* \[Informational] [Uncommon net localgroup execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-localgroup-execution)
  * \[Low] Uncommon net localgroup execution by an untrusted CGO - Added
* \[Informational] [Uncommon user management via net.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-user-management-via-net-exe)
  * \[Low] Uncommon user management via net.exe by an untrusted CGO - Added
* \[Informational] [User discovery via WMI query execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-discovery-via-wmi-query-execution)
  * \[Low] User discovery via WMI query execution by an unsigned process - Modified Metadata
  * \[Low] User modification via WMIC query execution - Modified Metadata
  * \[Informational] User discovery via WMIC query execution - Modified Metadata
* \[Informational] [Windows CGO, actor and action processes with anomalous characteristics](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-cgo-actor-and-action-processes-with-anomalous-characteristics)
  * \[Low] Windows CGO, actor and action processes with anomalous characteristics by an untrusted CGO - Added
* \[Informational] [A WMI subscriber was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-wmi-subscriber-was-created)
* \[Informational] [An identity accessed cloud storage containing sensitive data](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [DLP sensitive data exposed to external users](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/dlp-sensitive-data-exposed-to-external-users)
* \[Informational] [Email attachment with a potentially malicious file extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type)
* \[Informational] [Email containing a link with an IP address convention was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-link-with-an-ip-address-convention-was-detected)
* \[Informational] [Email containing a redirected link](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-redirected-link)
* \[Informational] [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values)
* \[Informational] [Email mimics replies or forwards without an actual ongoing conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation)
* \[Informational] [Email was received from an unknown address using a public provider domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-address-using-a-public-provider-domain)
* \[Informational] [Email with URL shortener detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-url-shortener-detected)
* \[Informational] [External email display name impersonation of internal personnel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel)
* \[Informational] [External email with a single internal recipient hidden in BCC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc)
* \[Informational] [GCP Storage Bucket deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-storage-bucket-deletion)
  * \[Informational] GCP Storage Bucket containing sensitive data was deleted - Added
* \[Informational] [Google Workspace automation was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/google-workspace-automation-was-created)
* \[Informational] [Near-empty email from an external sender](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/near-empty-email-from-an-external-sender)
* \[Informational] [New process created via a WMI call](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Numerous emails sent by a single sender to multiple internal recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients)
* \[Informational] [Outbound email contains file-sharing service link sent to external recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-contains-file-sharing-service-link-sent-to-external-recipient)
* \[Informational] [PKINIT TGT authentication request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/pkinit-tgt-authentication-request)
* \[Informational] [Port Scan](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/port-scan)
* \[Informational] [Punycode characters detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/punycode-characters-detected-in-url-s)
* \[Informational] [Rare DLP rule match by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-dlp-rule-match-by-user)
* \[Informational] [Rarely seen URL(s) within a well-known domain detected in your organization's email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-url-s-within-a-well-known-domain-detected-in-your-organization-s-email)
* \[Informational] [Rarely seen sender address in the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-sender-address-in-the-organization)
* \[Informational] [Rarely seen sender domain in the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-sender-domain-in-the-organization)
* \[Informational] [Suspicious DKIM Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dkim-result)
* \[Informational] [Suspicious DMARC result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dmarc-result)
  * \[Informational] DMARC deviation from historically compliant domain - Modified Logic
  * \[Informational] DMARC failed with non-enforcing policy - Modified Logic
  * \[Informational] DMARC failure bypassed domain policy - Modified Logic
* \[Informational] [Suspicious SPF Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-spf-result)
  * \[Low -> Informational] Internal domain SPF deviation - Modified Logic
  * \[Low -> Informational] Known domain SPF deviation - Modified Logic
  * \[Informational] Known domain unusual SPF result - Modified Metadata
* \[Informational] [Suspicious Unicode character detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-unicode-character-detected-in-email)
* \[Informational] [System profiling WMI query execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/system-profiling-wmi-query-execution)
* \[Informational] [Uncommon recurring rare external host access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-recurring-rare-external-host-access)
* \[Informational] [Unpopular domains detected in email URLs for a recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-domains-detected-in-email-urls-for-a-recipient)
* \[Informational] [Unusual display name in From header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-display-name-in-from-header)
* \[Informational] [Unusual hostname for the sending mail server in the email headers](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-hostname-for-the-sending-mail-server-in-the-email-headers)
* \[Informational] [Usage of homograph characters detected in an email attachment(s) name](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-attachment-s-name)
* \[Informational] [Well-known brand in sender headers with header inconsistencies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/well-known-brand-in-sender-headers-with-header-inconsistencies)

### Modified Metadata

* \[Informational] [Identity assigned an Azure AD Administrator Role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/identity-assigned-an-azure-ad-administrator-role)
  * \[Medium] Identity assigned an Azure AD Administrator Role by an Application - Modified Metadata
* \[Low] [MFA was disabled for an Azure identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mfa-was-disabled-for-an-azure-identity)
  * \[Medium] Suspicious MFA was disabled for an Azure identity - Modified Metadata
  * \[Informational] MFA was disabled for an Azure identity regularly by the user - Modified Metadata
* \[Informational] [Azure application URI modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-application-uri-modification)
  * \[Low] Suspicious Azure application URI modification - Modified Metadata
* \[Informational] [Cloud snapshot created or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-snapshot-created-or-modified)
  * \[Low] Cloud snapshot was configured for public access - Modified Metadata
* \[Low] [Exchange DKIM signing configuration disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-dkim-signing-configuration-disabled)
  * \[Informational] A recently configured Exchange DKIM signing configuration was disabled - Modified Metadata
* \[Low] [Exchange anti-phish policy disabled or removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-anti-phish-policy-disabled-or-removed)
  * \[Informational] Recently configured Exchange anti-phish policy disabled or removed - Modified Metadata
* \[Low] [First Azure AD PowerShell operation for a user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-azure-ad-powershell-operation-for-a-user)
* \[Informational] [Kubernetes Pod Created with host Inter Process Communications (IPC) namespace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-pod-created-with-host-inter-process-communications-ipc-namespace)
  * \[Low] Kubernetes Pod Created with host Inter Process Communications (IPC) namespace for the first time by the identity - Modified Metadata
  * \[Low] Kubernetes Pod Created with host Inter Process Communications (IPC) namespace for the first time in the cluster - Modified Metadata
  * \[Low] Kubernetes Pod Created with host Inter Process Communications (IPC) namespace for the first time in the namespace - Modified Metadata
* \[Informational] [Kubernetes Pod created with host process ID (PID) namespace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-pod-created-with-host-process-id-pid-namespace)
  * \[Low] Kubernetes Pod created with host process ID (PID) namespace for the first time by the identity - Modified Metadata
  * \[Low] Kubernetes Pod created with host process ID (PID) namespace for the first time in the cluster - Modified Metadata
  * \[Low] Kubernetes Pod created with host process ID (PID) namespace for the first time in the namespace - Modified Metadata
* \[Informational] [Kubernetes Privileged Pod Creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-privileged-pod-creation)
  * \[Low] Kubernetes Privileged Pod Creation for the first time by the identity - Modified Metadata
  * \[Low] Kubernetes Privileged Pod Creation for the first time in the cluster - Modified Metadata
  * \[Low] Kubernetes Privileged Pod Creation for the first time in the namespace - Modified Metadata
* \[Informational] [Kubernetes pod creation with host network](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-pod-creation-with-host-network)
  * \[Low] Kubernetes pod creation with host network for the first time by the identity - Modified Metadata
  * \[Low] Kubernetes pod creation with host network for the first time in the cluster - Modified Metadata
  * \[Low] Kubernetes pod creation with host network for the first time in the namespace - Modified Metadata
* \[Low] [User collected remote shared files in an archive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-collected-remote-shared-files-in-an-archive)
* \[Informational] [Owner added to Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/owner-added-to-azure-application)
* \[Informational] [Successful unusual guest user invitation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/successful-unusual-guest-user-invitation)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-05-28.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
