> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-07-15.md).

# 2026.07.15

### Release date: 26-July-2026

### Summary

### Added

* **4 Detectors:** 4 Informational
* **4 Variations:** 3 Low, 1 Informational

### Modified Logic

* **25 Detectors:** 4 Medium, 3 Low, 18 Informational
* **8 Variations:** 1 High, 1 Medium, 5 Low, 1 Informational

### Modified Metadata

* **10 Detectors:** 10 Informational
* **8 Variations:** 3 High, 2 Medium, 3 Low

### Added

* \[Informational] [AWS SSM association created with inventory collection document](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ssm-association-created-with-inventory-collection-document)
  * \[Low] Unusual AWS SSM association created with inventory collection document
* \[Informational] [AWS Systems Manager hosts enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-systems-manager-hosts-enumeration)
  * \[Low] AWS Systems Manager hosts enumeration via programmatic access
* \[Informational] [Impossible travel by a cloud identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-travel-by-a-cloud-identity)
  * \[Low] Impossible travel by an unusual cloud identity
* \[Informational] [Email sent using an automated system or script detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-sent-using-an-automated-system-or-script-detected)
  * \[Informational] Unusual automated email or script usage detected from a known sender

### Modified Logic

* \[Medium] [Suspicious Kubernetes pod token access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-kubernetes-pod-token-access)
  * \[High] Suspicious Kubernetes pod token access via remote access - Added
* \[Medium] [Potential Phishing has been detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-phishing-has-been-detected)
* \[Informational] [Suspicious activity on logging bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-activity-on-logging-bucket)
  * \[Medium] Suspicious deletion on S3 access logs bucket - Added
* \[Medium] [TGT request with a spoofed sAMAccountName - Event log](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tgt-request-with-a-spoofed-samaccountname-event-log)
* \[Medium] [Training simulation email detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/training-simulation-email-detected)
* \[Low] [Impossible traveler - SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-traveler-sso)
* \[Low] [Impossible traveler - VPN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-traveler-vpn)
* \[Informational] [Port Sweep](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/port-sweep)
  * \[Low] Port Sweep to multiple subnets - Modified Logic
* \[Informational] [Suspicious Unicode character detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-unicode-character-detected-in-email)
  * \[Low] Phishing terms obfuscation using Unicode characters detected in email - Modified Logic
* \[Informational] [Suspicious access to cloud credential files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-to-cloud-credential-files)
  * \[Low] Suspicious access to Windows cloud credential files by an unusual process - Modified Logic
  * \[Low] Suspicious access to cloud credential files by an unusual process - Modified Logic
  * \[Low] Suspicious access to cloud credential files of various cloud providers within a cloud instance - Modified Logic
  * \[Informational] Suspicious access to cloud credential files within a cloud instance - Modified Logic
* \[Low] [Suspicious cloud user data modification attempt followed by VM restart](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-cloud-user-data-modification-attempt-followed-by-vm-restart)
* \[Informational] [AI-determined combination of risky alerts under the same causality](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ai-determined-combination-of-risky-alerts-under-the-same-causality)
* \[Informational] [External email display name impersonation of internal personnel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel)
* \[Informational] [IP Rotation Pattern in SSO Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ip-rotation-pattern-in-sso-spray)
* \[Informational] [Intense SSO failures](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/intense-sso-failures)
* \[Informational] [Outbound email to an address hosted by a public email service provider](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-to-an-address-hosted-by-a-public-email-service-provider)
* \[Informational] [Possible Impossible Travel Pattern - SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-impossible-travel-pattern-sso)
* \[Informational] [SSO Brute Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-brute-force)
* \[Informational] [SSO Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-password-spray)
* \[Informational] [Suspicious brand affiliation detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-brand-affiliation-detected)
* \[Informational] [Uncommon access to cloud platforms' sensitive files by a scripting engine](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-access-to-cloud-platforms-sensitive-files-by-a-scripting-engine)
* \[Informational] [Unusual URL(s) sent by a brand were observed in the email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-url-s-sent-by-a-brand-were-observed-in-the-email)
* \[Informational] [VPN Login Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-password-spray)
* \[Informational] [VPN login Brute-Force attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-brute-force-attempt)
* \[Informational] [Well-known brand in sender headers with header inconsistencies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/well-known-brand-in-sender-headers-with-header-inconsistencies)

### Modified Metadata

* \[Informational] [A cloud identity executed an API call from an unusual country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-executed-an-api-call-from-an-unusual-country)
  * \[High] A cloud identity executed an API call from an unusual country using a compromised AWS access key - Modified Metadata
* \[Informational] [Compute activity in dormant cloud region](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/compute-activity-in-dormant-cloud-region)
  * \[High] Compute activity in dormant cloud region by a compromised AWS access key - Modified Metadata
* \[Informational] [Multiple failed logins from a single IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-failed-logins-from-a-single-ip)
  * \[High] Multiple failed logins from a single IP by a compromised AWS access key - Modified Metadata
* \[Informational] [GCP Storage Bucket deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-storage-bucket-deletion)
  * \[Medium] First time seen deleting a GCP Storage Bucket containing sensitive data - Modified Metadata
  * \[Low] GCP Storage Bucket containing sensitive data was deleted - Modified Metadata
* \[Informational] [Unusual user-agent for a cloud identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-user-agent-for-a-cloud-identity)
  * \[Medium] Unusual user-agent for a cloud identity by a compromised AWS access key - Modified Metadata
* \[Informational] [EBS snapshots were created from an EC2 instance](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ebs-snapshots-were-created-from-an-ec2-instance)
  * \[Informational -> Low] EBS snapshots were created from an EC2 instance attached one or more volumes with sensitive data - Modified Metadata
* \[Informational] [EBS volume attachment attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ebs-volume-attachment-attempt)
  * \[Informational -> Low] EBS volume attachment attempt for volume with sensitive data - Modified Metadata
* \[Informational] [An AWS EC2 instance containing sensitive data was exported](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-ec2-instance-containing-sensitive-data-was-exported)
* \[Informational] [An RDS snapshot containing sensitive data was exported](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-rds-snapshot-containing-sensitive-data-was-exported)
* \[Low -> Informational] [Suspicious PowerShell Enumeration of Running Processes](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powershell-enumeration-of-running-processes)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-07-15.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
