> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-06-10.md).

# 2026.06.10

### Release date: 23-June-2026

### Summary

#### Added

* **12 Detectors:** 6 Low, 6 Informational
* **6 Variations:** 1 Medium, 3 Low, 2 Informational

#### Removed

* **1 Detector:** 1 Informational

#### Modified Logic

* **85 Detectors:** 2 High, 4 Medium, 16 Low, 63 Informational
* **12 Variations:** 2 High, 5 Medium, 3 Low, 2 Informational

#### Modified Metadata

* **1 Detector:** 1 Informational

### Added

* \[Informational] [AI-determined combination of risky alerts under the same actor process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ai-determined-combination-of-risky-alerts-under-the-same-actor-process)
  * \[Medium] AI-determined combination of risky alerts under the same actor process: LDAP traffic from non-standard process with SMB traffic from non-standard process
* \[Low] [Abnormal RDP session to a remote host from a rarely seen host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-rdp-session-to-a-remote-host-from-a-rarely-seen-host)
* \[Low] [Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-sensitive-rpc-traffic-to-multiple-hosts-from-a-rarely-seen-host)
* \[Informational] [Cloud activity from a high-risk IP address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-activity-from-a-high-risk-ip-address)
  * \[Low] Cloud activity from an unusual high-risk IP
* \[Low] [Disable Microsoft Defender Antivirus via registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/disable-microsoft-defender-antivirus-via-registry)
* \[Low] [New cloud identity created with administrative policy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-cloud-identity-created-with-administrative-policy)
  * \[Low] Administrative IAM User Created with Credentials
* \[Low] [Rare Scheduled Task RPC activity from a rarely seen host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-rpc-activity-from-a-rarely-seen-host)
* \[Low] [Setting Windows Auto Logon by uncommon process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/setting-windows-auto-logon-by-uncommon-process)
* \[Informational] [Uncommon access to Microsoft Teams cookies files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-access-to-microsoft-teams-cookies-files)
  * \[Low] Suspicious uncommon access to Microsoft Teams cookies files
* \[Informational] [AI-determined combination of risky alerts under the same causality](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ai-determined-combination-of-risky-alerts-under-the-same-causality)
* \[Informational] [Suspicious sender exhibiting automated sending patterns](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sender-exhibiting-automated-sending-patterns)
  * \[Informational] Suspicious sender with high-volume automated sending patterns
* \[Informational] [Suspicious sending domain with sender address randomization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sending-domain-with-sender-address-randomization)
  * \[Informational] High-volume sender domain with per-message sender randomization

### Removed

* \[Informational] New process created via a WMI call

### Modified Logic

* \[Medium] [A cloud storage object was copied to a foreign cloud account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-storage-object-was-copied-to-a-foreign-cloud-account)
  * \[High] A cloud storage object from a sensitive bucket was copied to a foreign cloud account from a production account - Modified Logic
* \[Medium] [A mail forwarding rule was configured in Google Workspace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-mail-forwarding-rule-was-configured-in-google-workspace)
  * \[High] A mail forwarding rule was configured in Google Workspace to an uncommon domain - Modified Logic
* \[High] [Multiple risk indicators for a cloud identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-risk-indicators-for-a-cloud-identity)
* \[High] [Suspicious objects encryption in an AWS bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-objects-encryption-in-an-aws-bucket)
* \[Low] [An identity successfully extracted multiple secrets within the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-successfully-extracted-multiple-secrets-within-the-organization)
  * \[Medium] An identity successfully enumerated and extracted multiple secrets within the organization - Added
  * \[Medium] An identity successfully extracted multiple secrets within the organization across multiple regions - Removed
  * \[Medium] An identity successfully extracted multiple secrets within the organization across multiple regions - Added
  * \[Medium] An unusual identity successfully extracted multiple secrets within the organization - Removed
* \[Medium] [Potential Phishing has been detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-phishing-has-been-detected)
* \[Medium] [Training simulation email detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/training-simulation-email-detected)
* \[Informational] [Vulnerable certificate template loaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vulnerable-certificate-template-loaded)
  * \[Medium] First detection of AD CS ESC vulnerability in certificate template - Modified Logic
  * \[Low] Certificate template vulnerable to AD CS ESC attack - Modified Logic
* \[Low] [Email attachment with Right-to-Left Override Unicode character](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-right-to-left-override-unicode-character)
* \[Low] [Email was received from an unknown sender using a disposable domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-sender-using-a-disposable-domain)
* \[Low] [Email with file-sharing link containing auto-download parameter](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter)
* \[Low] [Exchange DKIM signing configuration disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-dkim-signing-configuration-disabled)
* \[Low] [Exchange Safe Attachment policy disabled or removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-safe-attachment-policy-disabled-or-removed)
* \[Low] [Exchange Safe Link policy disabled or removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-safe-link-policy-disabled-or-removed)
* \[Low] [Exchange anti-phish policy disabled or removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-anti-phish-policy-disabled-or-removed)
* \[Low] [Exchange audit log disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-audit-log-disabled)
* \[Low] [Exchange mailbox audit bypass](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-mailbox-audit-bypass)
* \[Low] [Exchange malware filter policy removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-malware-filter-policy-removed)
* \[Low] [Exchange transport forwarding rule configured](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-transport-forwarding-rule-configured)
* \[Low] [Exchange user mailbox forwarding](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-user-mailbox-forwarding)
* \[Informational] [Foreign account was granted permissions to S3 bucket via resource-based policy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/foreign-account-was-granted-permissions-to-s3-bucket-via-resource-based-policy)
  * \[Low] Foreign account was granted permissions to S3 bucket containing sensitive information via resource-based policy - Modified Logic
* \[Low] [Sending unusual file(s) to an external address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sending-unusual-file-s-to-an-external-address)
* \[Low] [Uncommon creation or access operation of sensitive shadow copy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-creation-or-access-operation-of-sensitive-shadow-copy)
* \[Low] [Unusual process accessed a crypto wallet's files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-crypto-wallet-s-files)
* \[Informational] [Unusual resource access by Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-resource-access-by-azure-application)
  * \[Low] Suspicious resource access by Azure application - Modified Logic
* \[Informational] [A process is masquerading as a common Microsoft product](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-is-masquerading-as-a-common-microsoft-product)
* \[Informational] [DLP sensitive data exposed to external users](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/dlp-sensitive-data-exposed-to-external-users)
* \[Informational] [EBS snapshots were created from an EC2 instance](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ebs-snapshots-were-created-from-an-ec2-instance)
  * \[Medium -> Informational] EBS snapshots were created from an EC2 instance attached one or more volumes with sensitive data - Modified Logic
* \[Informational] [EBS volume attachment attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ebs-volume-attachment-attempt)
  * \[Medium -> Informational] EBS volume attachment attempt for volume with sensitive data - Modified Logic
* \[Informational] [Email attachment with a potentially malicious file extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension)
* \[Informational] [Email attachment with multiple extensions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-multiple-extensions)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type)
* \[Informational] [Email containing a link with an IP address convention was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-link-with-an-ip-address-convention-was-detected)
* \[Informational] [Email containing a redirected link](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-redirected-link)
* \[Informational] [Email contains URL delivering high-risk file type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-contains-url-delivering-high-risk-file-type)
* \[Informational] [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values)
* \[Informational] [Email mimics replies or forwards without an actual ongoing conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation)
* \[Informational] [Email was received from an unknown address using a public provider domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-address-using-a-public-provider-domain)
* \[Informational] [Email with URL shortener detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-url-shortener-detected)
* \[Informational] [Exchange compliance search created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-compliance-search-created)
* \[Informational] [Exchange email-hiding inbox rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-email-hiding-inbox-rule)
* \[Informational] [Exchange email-hiding transport rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-email-hiding-transport-rule)
* \[Informational] [Exchange inbox forwarding rule configured](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-inbox-forwarding-rule-configured)
* \[Informational] [Exchange mailbox delegation permissions added](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-mailbox-delegation-permissions-added)
* \[Informational] [Exchange mailbox folder permission modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-mailbox-folder-permission-modification)
* \[Informational] [External email display name impersonation of internal personnel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel)
* \[Informational] [External email with a single internal recipient hidden in BCC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc)
* \[Informational] [First-seen email from mailbox owner to external recipient's address in the last 30 days](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days)
* \[Informational] [Google Workspace automation was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/google-workspace-automation-was-created)
* \[Informational] [Massive file downloads from SaaS service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-file-downloads-from-saas-service)
* \[Informational] [Microsoft 365 DLP policy disabled or removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-365-dlp-policy-disabled-or-removed)
* \[Informational] [Moniker link detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/moniker-link-detected-in-url-s)
* \[Informational] [Near-empty email from an external sender](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/near-empty-email-from-an-external-sender)
* \[Informational] [Numerous emails sent by a single sender to multiple internal recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients)
* \[Informational] [Outbound email contains file-sharing service link sent to external recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-contains-file-sharing-service-link-sent-to-external-recipient)
* \[Informational] [Outbound email includes an external BCC recipient observed for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-includes-an-external-bcc-recipient-observed-for-the-first-time)
* \[Informational] [Outbound email to an address hosted by a public email service provider](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-to-an-address-hosted-by-a-public-email-service-provider)
* \[Informational] [Potential spoofing of internal domain spotted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-spoofing-of-internal-domain-spotted)
* \[Informational] [Punycode characters detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/punycode-characters-detected-in-url-s)
* \[Informational] [Quarantined email released to recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/quarantined-email-released-to-recipients)
* \[Informational] [Rare DLP rule match by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-dlp-rule-match-by-user)
* \[Informational] [Rarely seen URL(s) within a well-known domain detected in your organization's email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-url-s-within-a-well-known-domain-detected-in-your-organization-s-email)
* \[Informational] [Rarely seen sender address in the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-sender-address-in-the-organization)
* \[Informational] [Rarely seen sender domain in the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-sender-domain-in-the-organization)
* \[Informational] [Security tools detection attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/security-tools-detection-attempt)
* \[Informational] [Sensitive Exchange mail sent to external users](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sensitive-exchange-mail-sent-to-external-users)
* \[Informational] [Sudden spike in outbound email volume](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sudden-spike-in-outbound-email-volume)
* \[Informational] [Suspicious DKIM Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dkim-result)
* \[Informational] [Suspicious DMARC result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dmarc-result)
* \[Informational] [Suspicious SPF Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-spf-result)
* \[Informational] [Suspicious Unicode character detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-unicode-character-detected-in-email)
* \[Informational] [Uncommon URL domain(s) in your organization detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-url-domain-s-in-your-organization-detected-in-email)
* \[Informational] [Unpopular domains detected in email URLs for a recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-domains-detected-in-email-urls-for-a-recipient)
* \[Informational] [Unrecognized internal address (AAD mismatch)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unrecognized-internal-address-aad-mismatch)
* \[Informational] [Unusual attachment volume in outbound emails](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-attachment-volume-in-outbound-emails)
* \[Informational] [Unusual display name in From header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-display-name-in-from-header)
* \[Informational] [Unusual hostname for the sending mail server in the email headers](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-hostname-for-the-sending-mail-server-in-the-email-headers)
* \[Informational] [Unusual sender IP subnet](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-sender-ip-subnet)
* \[Informational] [Usage of homograph characters detected in an email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email)
* \[Informational] [Usage of homograph characters detected in an email attachment(s) name](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-attachment-s-name)
* \[Informational] [Usage of homograph characters detected in an email's from header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-s-from-header)
* \[Informational] [User moved Exchange sent messages to deleted items](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-moved-exchange-sent-messages-to-deleted-items)
* \[Informational] [VM Detection attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vm-detection-attempt)
* \[Informational] [Well-known brand in sender headers with header inconsistencies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/well-known-brand-in-sender-headers-with-header-inconsistencies)
* \[Informational] [X-Forefront-Antispam-Report has flagged this email as a potential threat](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/x-forefront-antispam-report-has-flagged-this-email-as-a-potential-threat)

### Modified Metadata

* \[Informational] [Suspicious theme and sentiment in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-theme-and-sentiment-in-email)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-06-10.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
