> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-07-01.md).

# 2026.07.01

### Release date: 12-July-2026

### Summary

#### Added

* **6 Detectors:** 3 Low, 3 Informational
* **10 Variations:** 2 Medium, 6 Low, 2 Informational

#### Modified Logic

* **92 Detectors:** 1 High, 2 Medium, 12 Low, 77 Informational
* **35 Variations:** 4 Medium, 27 Low, 4 Informational

#### Modified Metadata

* **31 Detectors:** 5 Medium, 11 Low, 15 Informational
* **2 Variations:** 2 Low

### Added

* \[Informational] [A Kubernetes cluster role was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-cluster-role-was-created)
* \[Medium] Administrative Kubernetes cluster role was created for the first time
* \[Low] A Kubernetes cluster role was created for the first time by the identity
* \[Low] A Kubernetes cluster role with administrative permissions was created
* \[Low] [AWS Lambda Cross-Account sensitive permissions configured](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-lambda-cross-account-sensitive-permissions-configured)
* \[Medium] AWS Lambda public sensitive permissions configured
* \[Low] AWS Lambda public permissions configured
* \[Informational] AWS Lambda Cross-Account permissions configured
* \[Informational] [AWS Backup vault was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-backup-vault-was-deleted)
* \[Low] AWS Backup vault was deleted for the first time by this identity
* \[Low] AWS Backup vault was deleted from a production account
* \[Low] [AWS IAM Role Created with Cross-Account Access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-iam-role-created-with-cross-account-access)
* \[Informational] AWS IAM Role Created with Cross-Account Access using CloudFormation
* \[Low] [AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-iam-role-s-trusted-policy-modification-allows-cross-account-access)
* \[Informational] [Unusual file-sharing links for mailbox owner](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-file-sharing-links-for-mailbox-owner)
* \[Low] Unusual file-sharing links for organization

### Modified Logic

* \[High] [A successful SSO sign-in from TOR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-successful-sso-sign-in-from-tor)
* \[Low] [Okta FastPass reported phishing attack suspected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-fastpass-reported-phishing-attack-suspected)
* \[Medium] Okta FastPass reported phishing attack suspected from a suspicious IP - Added
* \[Medium] [Potential Phishing has been detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-phishing-has-been-detected)
* \[Informational] [Rare scheduled task created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-created)
* \[Medium] Uncommon remote scheduled task created - Modified Metadata
* \[Low] Uncommon local scheduled task created - Modified Metadata
* \[Low] [SSO authentication attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-attempt-by-a-honey-user)
* \[Medium] Abnormal SSO authentication by a honey user - Modified Logic
* \[Low] [SSO authentication by a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-by-a-machine-account)
* \[Medium] SSO authentication by a machine account from a suspicious IP - Added
* \[Medium] [Training simulation email detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/training-simulation-email-detected)
* \[Informational] [A disabled user attempted to authenticate via SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-disabled-user-attempted-to-authenticate-via-sso)
* \[Low] A disabled user attempted to authenticate via SSO from a suspicious IP - Added
* \[Informational] [A possible risky login to Azure](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-possible-risky-login-to-azure)
* \[Low] Azure Risky Login with Suspicious Characteristics - Modified Logic
* \[Informational] [A user connected from a new country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-from-a-new-country)
* \[Low] A user connected from a new country - suspicious characteristics detected - Modified Logic
* \[Low] A user connected from a new country via a suspicious IP - Added
* \[Low] [A user rejected an SSO request from an unusual country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-rejected-an-sso-request-from-an-unusual-country)
* \[Low] [Authentication attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-attempt-by-a-honey-user)
* \[Low] [Email attachment with Right-to-Left Override Unicode character](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-right-to-left-override-unicode-character)
* \[Informational] [Email contains URL delivering high-risk file type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-contains-url-delivering-high-risk-file-type)
* \[Low] External email with URL delivers blocked file types - Modified Logic
* \[Low] [Email was received from an unknown sender using a disposable domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-sender-using-a-disposable-domain)
* \[Low] [Email with file-sharing link containing auto-download parameter](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter)
* \[Low] External email with file-sharing link containing auto-download parameter - Modified Logic
* \[Informational] [External user created a Microsoft Teams conversation with suspicious operations](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-user-created-a-microsoft-teams-conversation-with-suspicious-operations)
* \[Low] An external user created a chat and shortly after sent a link with a newly seen domain name - Modified Metadata
* \[Low] An external user created a chat then sent a link with a file for the first time via Microsoft Teams - Modified Metadata
* \[Low] An external user created a chat with a suspicious user or chat name and then sent a link via Microsoft Teams - Modified Metadata
* \[Low] An external user initiated a Microsoft Teams chat in which a link was shared and a member was removed - Modified Metadata
* \[Low] An external user initiated a Microsoft Teams chat in which a suspicious link was shared and a member was removed - Modified Metadata
* \[Low] External user created a Microsoft Teams conversation with a suspicious user or chat name and shortly after removed a user from it - Modified Metadata
* \[Informational] An external user created a chat and then sent a link via Microsoft Teams - Modified Metadata
* \[Informational] An external user created a chat then sent a link via Microsoft Teams - Modified Metadata
* \[Informational] External user created a Microsoft Teams conversation and shortly after removed a user from it - Modified Metadata
* \[Informational] [First SSO Resource Access in the Organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-resource-access-in-the-organization)
* \[Low] Abnormal first access to a resource via SSO in the organization - Modified Logic
* \[Informational] [First SSO access from ASN for user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-access-from-asn-for-user)
* \[Low] First SSO access from ASN for user - suspicious characteristics detected - Modified Logic
* \[Informational] [First SSO access from ASN in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-access-from-asn-in-organization)
* \[Low] First SSO access from ASN in organization via a suspicious IP - Added
* \[Low] First successful SSO access from ASN in the organization - Modified Metadata
* \[Informational] [First connection from a country in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-connection-from-a-country-in-organization)
* \[Low] First connection from a country in organization via a suspicious IP - Added
* \[Informational] First successful SSO connection from a country in organization - Modified Logic
* \[Low] [Impossible traveler - SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-traveler-sso)
* \[Informational] [Massive file downloads from SaaS service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-file-downloads-from-saas-service)
* \[Low] Massive code file downloads from SaaS service - Modified Metadata
* \[Low] Massive file downloads from SaaS service by terminated user - Modified Metadata
* \[Low] Suspicious SaaS service file downloads - Modified Metadata
* \[Low] [Possible phishing attack via Microsoft Teams](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-phishing-attack-via-microsoft-teams)
* \[Low] [SSO authentication by a service account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-by-a-service-account)
* \[Low] SSO authentication by a service account via a suspicious IP - Added
* \[Informational] [SSO with abnormal user agent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-with-abnormal-user-agent)
* \[Low] SSO with an offensive user agent - Modified Metadata
* \[Low] [Sending unusual file(s) to an external address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sending-unusual-file-s-to-an-external-address)
* \[Informational] [Suspicious Azure AD interactive sign-in using PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-azure-ad-interactive-sign-in-using-powershell)
* \[Low] Unusual Azure AD interactive sign-in using PowerShell - Modified Logic
* \[Informational] [Suspicious SSO access from ASN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sso-access-from-asn)
* \[Low] Suspicious SSO access from ASN via a suspicious IP - Added
* \[Informational] [User attempted to connect from a suspicious country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-attempted-to-connect-from-a-suspicious-country)
* \[Low] User attempted to connect from a suspicious country via a suspicious IP - Added
* \[Low] User successfully connected from a suspicious country - Modified Logic
* \[Informational] [A user accessed multiple unusual resources via SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-multiple-unusual-resources-via-sso)
* \[Informational] [A user logged in at an unusual time via SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-in-at-an-unusual-time-via-sso)
* \[Informational] [Azure virtual machine commands execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-virtual-machine-commands-execution)
* \[Informational] [Cloud instance creation attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-instance-creation-attempt)
* \[Informational] [Display text URL differs from actual URL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/display-text-url-differs-from-actual-url)
* \[Informational] [Email attachment with a potentially malicious file extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension)
* \[Informational] [Email attachment with multiple extensions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-multiple-extensions)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type)
* \[Informational] [Email containing a link with an IP address convention was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-link-with-an-ip-address-convention-was-detected)
* \[Informational] [Email containing a redirected link](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-redirected-link)
* \[Informational] [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values)
* \[Informational] [Email mimics replies or forwards without an actual ongoing conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation)
* \[Informational] [Email was received from an unknown address using a public provider domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-address-using-a-public-provider-domain)
* \[Informational] [Email with URL shortener detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-url-shortener-detected)
* \[Informational] [External email display name impersonation of internal personnel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel)
* \[Informational] [External email with a single internal recipient hidden in BCC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc)
* \[Informational] [First-seen email from mailbox owner to external recipient's address in the last 30 days](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days)
* \[Informational] [IP Rotation Pattern in SSO Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ip-rotation-pattern-in-sso-spray)
* \[Informational] [Intense SSO failures](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/intense-sso-failures)
* \[Informational] [Invalid SAML Detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/invalid-saml-detected)
* \[Informational] [Massive files deletion in Box](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-files-deletion-in-box)
* \[Informational] [Massive files deletion in Dropbox](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-files-deletion-in-dropbox)
* \[Informational] [Massive files deletion in Google Drive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-files-deletion-in-google-drive)
* \[Informational] [Massive files deletion in Microsoft SharePoint or OneDrive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-files-deletion-in-microsoft-sharepoint-or-onedrive)
* \[Informational] [Moniker link detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/moniker-link-detected-in-url-s)
* \[Informational] [Multiple Okta MFA requests sent to a user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-okta-mfa-requests-sent-to-a-user)
* \[Informational] [Near-empty email from an external sender](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/near-empty-email-from-an-external-sender)
* \[Informational] [Numerous emails sent by a single sender to multiple internal recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients)
* \[Informational] [Outbound email contains file-sharing service link sent to external recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-contains-file-sharing-service-link-sent-to-external-recipient)
* \[Informational] [Outbound email includes an external BCC recipient observed for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-includes-an-external-bcc-recipient-observed-for-the-first-time)
* \[Informational] [Outbound email to an address hosted by a public email service provider](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-to-an-address-hosted-by-a-public-email-service-provider)
* \[Informational] [Possible Impossible Travel Pattern - SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-impossible-travel-pattern-sso)
* \[Informational] [Potential spoofing of internal domain spotted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-spoofing-of-internal-domain-spotted)
* \[Informational] [Punycode characters detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/punycode-characters-detected-in-url-s)
* \[Informational] [Quarantined email released to recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/quarantined-email-released-to-recipients)
* \[Informational] [Rarely seen URL(s) within a well-known domain detected in your organization's email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-url-s-within-a-well-known-domain-detected-in-your-organization-s-email)
* \[Informational] [Rarely seen sender address in the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-sender-address-in-the-organization)
* \[Informational] [Rarely seen sender domain in the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-sender-domain-in-the-organization)
* \[Informational] [SSO Brute Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-brute-force)
* \[Informational] [SSO Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-password-spray)
* \[Informational] [SSO with abnormal operating system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-with-abnormal-operating-system)
* \[Informational] [SSO with new operating system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-with-new-operating-system)
* \[Informational] [Sudden spike in outbound email volume](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sudden-spike-in-outbound-email-volume)
* \[Informational] [Suspicious DKIM Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dkim-result)
* \[Informational] [Suspicious DMARC result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dmarc-result)
* \[Informational] [Suspicious SPF Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-spf-result)
* \[Informational] [Suspicious SSO authentication](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sso-authentication)
* \[Informational] [Suspicious Unicode character detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-unicode-character-detected-in-email)
* \[Informational] [Suspicious sender exhibiting automated sending patterns](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sender-exhibiting-automated-sending-patterns)
* \[Informational] [Suspicious sending domain with sender address randomization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sending-domain-with-sender-address-randomization)
* \[Informational] [Uncommon URL domain(s) in your organization detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-url-domain-s-in-your-organization-detected-in-email)
* \[Informational] [Unpopular domains detected in email URLs for a recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-domains-detected-in-email-urls-for-a-recipient)
* \[Informational] [Unrecognized internal address (AAD mismatch)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unrecognized-internal-address-aad-mismatch)
* \[Informational] [Unusual attachment volume in outbound emails](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-attachment-volume-in-outbound-emails)
* \[Informational] [Unusual display name in From header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-display-name-in-from-header)
* \[Informational] [Unusual hostname for the sending mail server in the email headers](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-hostname-for-the-sending-mail-server-in-the-email-headers)
* \[Informational] [Unusual sender IP subnet](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-sender-ip-subnet)
* \[Informational] [Usage of homograph characters detected in an email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email)
* \[Informational] [Usage of homograph characters detected in an email attachment(s) name](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-attachment-s-name)
* \[Informational] [Usage of homograph characters detected in an email's from header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-s-from-header)
* \[Informational] [Well-known brand in sender headers with header inconsistencies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/well-known-brand-in-sender-headers-with-header-inconsistencies)
* \[Informational] [X-Forefront-Antispam-Report has flagged this email as a potential threat](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/x-forefront-antispam-report-has-flagged-this-email-as-a-potential-threat)

### Modified Metadata

* \[Medium] [Possible code downloading from a remote host by Regsvr32](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-code-downloading-from-a-remote-host-by-regsvr32)
* \[Medium] [PowerShell suspicious flags](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-suspicious-flags)
* \[Medium] [Rundll32.exe running with no command-line arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-running-with-no-command-line-arguments)
* \[Medium] [Rundll32.exe spawns conhost.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-spawns-conhost-exe)
* \[Medium] [Suspicious certutil command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-certutil-command-line)
* \[Low] [A user uploaded malware to SharePoint or OneDrive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-uploaded-malware-to-sharepoint-or-onedrive)
* \[Low] [Cached credentials discovery with cmdkey](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cached-credentials-discovery-with-cmdkey)
* \[Low] [Conhost.exe spawned a suspicious cmd process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/conhost-exe-spawned-a-suspicious-cmd-process)
* \[Low] [Execution of dllhost.exe with an empty command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-dllhost-exe-with-an-empty-command-line)
* \[Low] [Mshta.exe launched with suspicious arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mshta-exe-launched-with-suspicious-arguments)
* \[Low] [Mshta.exe spawns from a browser process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mshta-exe-spawns-from-a-browser-process)
* \[Informational] [Possible Kerberos User Enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-kerberos-user-enumeration)
* \[Low] Possible Kerberos User Enumeration Involving Exposed Users - Modified Metadata
* \[Low] [Rundll32.exe executes a rare unsigned module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-executes-a-rare-unsigned-module)
* \[Informational] [SAAS - Email was reported by the user or administrator as a phishing attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/saas-email-was-reported-by-the-user-or-administrator-as-a-phishing-attempt)
* \[Low] SAAS - Phishing report with suspicious verdict on internal domain sender - Modified Metadata
* \[Low] [Uncommon msiexec execution of an arbitrary file from a remote location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-msiexec-execution-of-an-arbitrary-file-from-a-remote-location)
* \[Low] [Unusual Lolbins Process Spawned by InstallUtil.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-lolbins-process-spawned-by-installutil-exe)
* \[Low] [Unusual Netsh PortProxy rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-netsh-portproxy-rule)
* \[Low] [Wscript/Cscript loads .NET DLLs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wscript-cscript-loads-net-dlls)
* \[Informational] [A user accessed an abnormal number of files on a remote shared folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-an-abnormal-number-of-files-on-a-remote-shared-folder)
* \[Informational] [A user accessed an abnormal number of remote shared folders](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-an-abnormal-number-of-remote-shared-folders)
* \[Informational] [A user performed suspiciously massive file activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-performed-suspiciously-massive-file-activity)
* \[Informational] [DLP sensitive data exposed to external users](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/dlp-sensitive-data-exposed-to-external-users)
* \[Informational] [DSC (Desired State Configuration) lateral movement using PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/dsc-desired-state-configuration-lateral-movement-using-powershell)
* \[Informational] [External SaaS file-sharing activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-saas-file-sharing-activity)
* \[Informational] [LOLBIN created a PSScriptPolicyTest PowerShell script file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbin-created-a-psscriptpolicytest-powershell-script-file)
* \[Informational] [Large volume of files potentially containing credentials accessed in Google Drive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-volume-of-files-potentially-containing-credentials-accessed-in-google-drive)
* \[Informational] [MSI accessed a web page running a server-side script](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/msi-accessed-a-web-page-running-a-server-side-script)
* \[Informational] [Massive file activity abnormal to process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-file-activity-abnormal-to-process)
* \[Informational] [Massive upload to SaaS service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-upload-to-saas-service)
* \[Informational] [Massive upload to a rare storage or mail domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-upload-to-a-rare-storage-or-mail-domain)
* \[Informational] [Msiexec execution of an executable from an uncommon remote location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/msiexec-execution-of-an-executable-from-an-uncommon-remote-location)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-07-01.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
