> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-08-05.md).

# 2026.08.05

### Release date: 16-August-2026

### Summary

#### Added

* **10 Detectors:** 1 High, 1 Medium, 6 Low, 2 Informational
* **13 Variations:** 4 High, 5 Medium, 3 Low, 1 Informational

#### Modified Logic

* **34 Detectors:** 2 Medium, 9 Low, 23 Informational
* **11 Variations:** 1 High, 1 Medium, 9 Low

#### Modified Metadata

* **2 Detectors:** 2 Informational

#### Temporarily Removed

* **1 Detector:** 1 Informational
* **2 Variations:** 2 Low

### Added

* \[Low] [Uncommon AppleScript containing a potential defense-evasion command was executed via the command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-applescript-containing-a-potential-defense-evasion-command-was-executed-via-the-command-line)
  * \[High] Uncommon AppleScript containing a potential defense-evasion command was executed via the command line disabling the Gatekeeper security feature
  * \[Medium] Uncommon AppleScript containing a potential defense-evasion command was executed via the command line manipulating the 'hosts' file
  * \[Low] Uncommon AppleScript containing a potential defense-evasion command was executed via the command line deleting attributes from a file
  * \[Low] Uncommon AppleScript containing a potential defense-evasion command was executed via the command line setting a network proxy
* \[Low] [Uncommon AppleScript containing a potential obfuscation technique was executed](broken://spaces/5O67gr80iLneA56jiuO2/pages/Qaf96BnjzkubElZBGroD)
  * \[High] Uncommon AppleScript containing a potential obfuscation technique was executed by an uncommon parent process
  * \[Medium] Uncommon AppleScript containing a potential obfuscation technique was executed subsequently running a shell command
* \[Low] [Uncommon AppleScript containing a potential system information discovery command was executed via the command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-applescript-containing-a-potential-system-information-discovery-command-was-executed-via-the-command-line)
  * \[High] Uncommon AppleScript containing a potential system information discovery command was executed via the command line querying virtual environment information
  * \[Medium] Uncommon AppleScript containing a potential system information discovery command was executed via the command line, querying hardware or software information
* \[High] [Uncommon AppleScript designed to access sensitive application data was executed via the command line](broken://spaces/5O67gr80iLneA56jiuO2/pages/zAA2dfXrlV4kwugUvyNn)
* \[Low] [Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords](broken://spaces/5O67gr80iLneA56jiuO2/pages/EEwSos3k0t7LBOu1iQcX)
  * \[High] Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords leveraging the 'dscl -authonly' command to covertly verify the captured password
* \[Medium] [Uncommon AppleScript designed to access credential files was executed via the command line](broken://spaces/5O67gr80iLneA56jiuO2/pages/1WrfZPSylBKxJfcBaaIO)
* \[Informational] [Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line](broken://spaces/5O67gr80iLneA56jiuO2/pages/zoFVda8L84MTlODYxZKY)
  * \[Medium] Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line accessed crypto wallet's files
* \[Low] [Uncommon AppleScript was executed via the command line to contact an external server](broken://spaces/5O67gr80iLneA56jiuO2/pages/XLn45D5IXJDeagPlWvKy)
  * \[Medium] Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to transfer a .zip file
  * \[Low] Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to upload a file
* \[Low] [Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line](broken://spaces/5O67gr80iLneA56jiuO2/pages/z6jHGOrXxJ5SjA5dJpAw)
* \[Informational] [Analytics enhanced - Rare Internal Firewall Vulnerability Threat Alert](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/analytics-enhanced-rare-internal-firewall-vulnerability-threat-alert)
  * \[Informational] Analytics enhanced - Rare Internal Firewall Vulnerability Threat Alert Categorized as code-execution/info-leak

### Modified Logic

* \[Informational] [AppleScript process executed with a rare command line](broken://spaces/5O67gr80iLneA56jiuO2/pages/QL6rDC2FbAiKWVBicRFS)
  * \[High] AppleScript process executed with a rare command line containing uncommon arguments - Added
  * \[Low] AppleScript process executed with a rare command line that muted the audio output - Added
  * \[Low] AppleScript process executed with a rare command line that possibly establishes persistence - Removed
  * \[Low] AppleScript process executed with a rare command line that possibly installs a proxy - Removed
* \[Medium] [Potential Phishing has been detected](broken://spaces/5O67gr80iLneA56jiuO2/pages/ZW7MrHGYUx40swpKX5xE)
* \[Informational] [Uncommon macOS process communication to a rare external host](broken://spaces/5O67gr80iLneA56jiuO2/pages/8O9nmOa5qXZusK8xrSQR)
  * \[Medium] Uncommon macOS process communication to a rare external host involving a code sharing website by a high-risk actor - Added
  * \[Low] Uncommon macOS process communication to a rare external host involving a code sharing website - Added
* \[Medium] [Windows LOLBIN executable connected to a rare external host](broken://spaces/5O67gr80iLneA56jiuO2/pages/Y5Hp6bAEuMLClMBkD0sJ)
  * \[Low] Windows LOLBIN executable connected to a rare external host by an RMM CGO - Added
* \[Low] [A disabled user attempted to log in to a VPN](broken://spaces/5O67gr80iLneA56jiuO2/pages/wch80Y8cICOswD18yW9M)
* \[Low] [A user rejected an SSO request from an unusual country](broken://spaces/5O67gr80iLneA56jiuO2/pages/GIBGYdddNRCVO6XEZcpv)
* \[Low] [AWS S3 bucket was exposed to public access](broken://spaces/5O67gr80iLneA56jiuO2/pages/yNcvI0AkMPif3rxIJwsV)
* \[Informational] [An uncommon RDP session was established](broken://spaces/5O67gr80iLneA56jiuO2/pages/u0JyQfzdY4AGerCNtmqK)
  * \[Low] An uncommon RDP session was established by an RMM actor - Added
* \[Low] [Impossible traveler - VPN](broken://spaces/5O67gr80iLneA56jiuO2/pages/VW8YfDUGHHA1oIni9uXQ)
* \[Low] [Logs were not collected from a data source for an abnormally long time](broken://spaces/5O67gr80iLneA56jiuO2/pages/XXrSqz1S3HtgOiJbcU5k)
* \[Informational] [Rare WinRM Session](broken://spaces/5O67gr80iLneA56jiuO2/pages/Wallbw80bXMn12x2gOqr)
  * \[Low] Rare WinRM Session by an RMM actor - Added
* \[Low] [Rare binary connected to a rare external host](broken://spaces/5O67gr80iLneA56jiuO2/pages/uBMzQfrk34dACjEJY28I)
  * \[Low] Rare binary executing under an RMM CGO connected to a rare external host - Added
* \[Low] [Suspicious identity downloaded multiple objects from a bucket](broken://spaces/5O67gr80iLneA56jiuO2/pages/N80bBVJ1XIibX5RN78vK)
* \[Informational] [Uncommon net localgroup command execution](broken://spaces/5O67gr80iLneA56jiuO2/pages/HA91OZ3I2GgB9boIdsbp)
  * \[Low] Uncommon net localgroup command execution by an RMM CGO - Added
* \[Low] [Unusual process accessed a crypto wallet's files](broken://spaces/5O67gr80iLneA56jiuO2/pages/PZ71ci3ZgbkC7FrwJEBh)
* \[Low] [Unusual process accessed a web browser history file](broken://spaces/5O67gr80iLneA56jiuO2/pages/2xU8Ovi1UVUrGtik2O7n)
* \[Informational] [A user connected to a VPN from a new country](broken://spaces/5O67gr80iLneA56jiuO2/pages/NJqmhLPuCFE207yUAGp8)
* \[Informational] [An AWS S3 bucket configuration was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/UV8DoVHrCUBV0wTP0l8x)
* \[Informational] [AppleScript interpreter dynamic library loaded into a process](broken://spaces/5O67gr80iLneA56jiuO2/pages/XFtiQogRCIPH2AL29q2S)
* \[Informational] [Bucket's block public access setting turned off](broken://spaces/5O67gr80iLneA56jiuO2/pages/0J1ABIVR09YcrgC8TziG)
* \[Informational] [IAM role trust policy modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/ZVtGrck9pcOcoJkdA1Fg)
* \[Informational] [Member added to a Windows local security group](broken://spaces/5O67gr80iLneA56jiuO2/pages/VUtpmSBM7X14Bulklz0C)
* \[Informational] [S3 configuration deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/DxME62rvfdHMLMVXX6UG)
* \[Informational] [SSO with abnormal operating system](broken://spaces/5O67gr80iLneA56jiuO2/pages/ydIpP8Ir02iMSFmjPxje)
* \[Informational] [SSO with new operating system](broken://spaces/5O67gr80iLneA56jiuO2/pages/KLkmbuK8DWiTGinWme5e)
* \[Informational] [Storage enumeration activity](broken://spaces/5O67gr80iLneA56jiuO2/pages/mZsGmZedPJeiDt5orjnT)
* \[Informational] [Suspicious SSO authentication](broken://spaces/5O67gr80iLneA56jiuO2/pages/lZFr9XqsoBQpJvpyF5Xl)
* \[Informational] [Unusual process accessed web browser cookies](broken://spaces/5O67gr80iLneA56jiuO2/pages/KZvGhRJNeYE4sXUG6v3h)
* \[Informational] [Unusual process accessed web browser credentials](broken://spaces/5O67gr80iLneA56jiuO2/pages/3UcILpTEEtPr8m49qxgR)
* \[Informational] [Unusual sender IP subnet](broken://spaces/5O67gr80iLneA56jiuO2/pages/g3tJ6TgKpOTQIJGy8XAu)
* \[Informational] [User attempted to connect from a suspicious country](broken://spaces/5O67gr80iLneA56jiuO2/pages/5YFXe1e4UZi9YuAwHetB)
* \[Informational] [VPN Login Password Spray](broken://spaces/5O67gr80iLneA56jiuO2/pages/3XTViya6TKUz3JCFHUyv)
* \[Informational] [VPN access with an abnormal operating system](broken://spaces/5O67gr80iLneA56jiuO2/pages/dWf1weFFQ2AoPggTF9Rs)
* \[Informational] [VPN login Brute-Force attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/CEgXfZkoMdVJnYun2dsA)

### Modified Metadata

* \[Informational] [First-time attachment exchange](broken://spaces/5O67gr80iLneA56jiuO2/pages/oQUigZ1QqGF0HauBCXLB)
* \[Informational] [Initial person-to-person email contact](broken://spaces/5O67gr80iLneA56jiuO2/pages/GxrlDmnCXVvO6ZvUDchN)

### Temporarily Removed

* \[Informational] Slack Connect direct message invite was accepted
  * \[Low] Abnormal Slack Connect direct message invite was accepted
  * \[Low] Slack Connect direct message invite was accepted from a suspicious external user


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-08-05.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
