> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-08-12.md).

# 2026.08.12

### Release date: 23-August-2026

### Summary

#### Added

* **4 Detectors:** 4 Informational
* **15 Variations:** 5 Medium, 5 Low, 5 Informational

#### Modified Logic

* **42 Detectors:** 1 High, 11 Low, 30 Informational
* **28 Variations:** 1 High, 6 Medium, 13 Low, 8 Informational

#### Modified Metadata

* **1 Detector:** 1 Medium
* **1 Variation:** 1 Medium

### Added

* \[Informational] [Possible Brute Force in universal authentication](broken://spaces/5O67gr80iLneA56jiuO2/pages/YOQ8JgEfuIUj36BOt2jj)
  * \[Medium] Possible Brute Force in universal authentication on a honey user
  * \[Medium] Suspicious Brute Force in universal authentication
  * \[Low] Brute Force in universal authentication
  * \[Informational] Abnormal Possible Brute Force in universal authentication
* \[Informational] [Possible Password Spray in universal authentication](broken://spaces/5O67gr80iLneA56jiuO2/pages/l5e5Rcht6pvLDJETuwFY)
  * \[Medium] Possible Password Spray in universal authentication Involving a Honey User
  * \[Medium] Suspicious Password Spray in universal authentication
  * \[Low] Password Spray in universal authentication
  * \[Informational] Possible Password Spray in universal authentication with successful authentication
* \[Informational] [Successful universal authentication with suspicious features](broken://spaces/5O67gr80iLneA56jiuO2/pages/yLTPEE2iaKoDiP1MB0rl)
  * \[Medium] Successful universal authentication sign-in from a TOR exit node
  * \[Low] Successful universal authentication from a suspicious tunnel operator
  * \[Informational] Successful universal authentication from a new country in organization
  * \[Informational] Suspicious successful universal authentication from ASN
* \[Informational] [An inactive user attempted to authenticate](broken://spaces/5O67gr80iLneA56jiuO2/pages/6mHta6ojXWm64Lp0YIvU)
  * \[Low] An inactive user attempted to authenticate from a risky IP address
  * \[Low] Successful authentication by an inactive user from a risky IP address
  * \[Informational] Successful authentication by an inactive user

### Modified Logic

* \[High] [A successful SSO sign-in from TOR](broken://spaces/5O67gr80iLneA56jiuO2/pages/l6Iofv96gu23ZUXNOtjc)
* \[Low] [AWS S3 bucket was exposed to public access](broken://spaces/5O67gr80iLneA56jiuO2/pages/yNcvI0AkMPif3rxIJwsV)
  * \[High] AWS S3 bucket was exposed to public access containing sensitive information - Modified Metadata
  * \[Informational] AWS S3 bucket was exposed to public access by admin cloud identity - Modified Logic
* \[Low] [Okta FastPass reported phishing attack suspected](broken://spaces/5O67gr80iLneA56jiuO2/pages/Ka1rItECP6wGbzZnkeak)
  * \[Medium] Okta FastPass reported phishing attack suspected from a suspicious IP - Modified Logic
* \[Low] [SSO authentication attempt by a honey user](broken://spaces/5O67gr80iLneA56jiuO2/pages/4uL5AX5L6ziBnyeBthy8)
  * \[Medium] Abnormal SSO authentication by a honey user - Modified Logic
* \[Low] [SSO authentication by a machine account](broken://spaces/5O67gr80iLneA56jiuO2/pages/rZDEG73mpqDEVq3p3uvY)
  * \[Medium] SSO authentication by a machine account from a suspicious IP - Modified Logic
* \[Low] [SSO authentication by a service account](broken://spaces/5O67gr80iLneA56jiuO2/pages/OKQrQzqGUrccxXtyJv06)
  * \[Medium] First time SSO authentication by a service account - Modified Logic
  * \[Low] SSO authentication by a service account via a suspicious IP - Modified Logic
* \[Low] [Uncommon reverse SSH tunnel to external domain/ip](broken://spaces/5O67gr80iLneA56jiuO2/pages/roEpswM056XUxElDx0Se)
  * \[Medium] Uncommon reverse SOCKS proxy SSH tunnel to external domain/ip - Added
  * \[Medium] Uncommon reverse SSH tunnel to external domain/ip to a sensitive port via a non-default bind port - Added
  * \[Low] Uncommon reverse SSH tunnel to external domain/ip using a sensitive port - Modified Metadata
* \[Informational] [A disabled user attempted to authenticate via SSO](broken://spaces/5O67gr80iLneA56jiuO2/pages/SxeFM8MGY1SPNtZvqow7)
  * \[Low] A disabled user attempted to authenticate via SSO from a suspicious IP - Modified Logic
* \[Informational] [A possible risky login to Azure](broken://spaces/5O67gr80iLneA56jiuO2/pages/i5ZNdqBJN09lHn5W1aPV)
  * \[Low] Azure Risky Login with Suspicious Characteristics - Modified Logic
* \[Informational] [A user connected from a new country](broken://spaces/5O67gr80iLneA56jiuO2/pages/lC2FatUi0AnvyRSJNKzu)
  * \[Low] A user connected from a new country via a suspicious IP - Modified Logic
* \[Low] [A user rejected an SSO request from an unusual country](broken://spaces/5O67gr80iLneA56jiuO2/pages/GIBGYdddNRCVO6XEZcpv)
* \[Informational] [First SSO Resource Access in the Organization](broken://spaces/5O67gr80iLneA56jiuO2/pages/gq1LdpGl8JzmMMNp36Ae)
  * \[Low] Abnormal first access to a resource via SSO in the organization - Modified Logic
* \[Informational] [First SSO access from ASN for user](broken://spaces/5O67gr80iLneA56jiuO2/pages/FyUbaZfqVy7PgkZVEcFV)
  * \[Low] First SSO access from ASN for user - suspicious characteristics detected - Modified Logic
  * \[Informational] Google Workspace - First SSO access from ASN for user - Modified Logic
* \[Informational] [First SSO access from ASN in organization](broken://spaces/5O67gr80iLneA56jiuO2/pages/ngCCbVwIDLaIfZL8JJdl)
  * \[Low] First SSO access from ASN in organization via a suspicious IP - Modified Logic
  * \[Informational] Google Workspace - First SSO access from ASN in organization - Modified Logic
* \[Informational] [First connection from a country in organization](broken://spaces/5O67gr80iLneA56jiuO2/pages/FIMCM9JyVH2wTqVN7ErR)
  * \[Low] First connection from a country in organization via a suspicious IP - Modified Logic
  * \[Informational] First successful SSO connection from a country in organization - Modified Logic
* \[Low] [Impossible traveler - SSO](broken://spaces/5O67gr80iLneA56jiuO2/pages/YkIdzUtQybtzmdMCtQlh)
* \[Low] [Possible path traversal via HTTP request](broken://spaces/5O67gr80iLneA56jiuO2/pages/wrh2b13hpx4Ox8a7XR6H)
* \[Low] [Possible phishing attack via Microsoft Teams](broken://spaces/5O67gr80iLneA56jiuO2/pages/edx3oaaKmPPDBxemJ2ku)
* \[Informational] [Suspicious Azure AD interactive sign-in using PowerShell](broken://spaces/5O67gr80iLneA56jiuO2/pages/Kp2JywM3u5fgnwr9b6sb)
  * \[Low] Unusual Azure AD interactive sign-in using PowerShell - Modified Logic
* \[Informational] [Suspicious SSO access from ASN](broken://spaces/5O67gr80iLneA56jiuO2/pages/3hCnafpvxH4MFvtjRuIJ)
  * \[Low] Suspicious SSO access from ASN via a suspicious IP - Modified Logic
  * \[Informational] Google Workspace - Suspicious SSO access from ASN - Modified Logic
* \[Low] [Unusual Process Spawned by Nginx in Ingress-Nginx pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/89nI9dU89b34EbMDeOmB)
* \[Informational] [User attempted to connect from a suspicious country](broken://spaces/5O67gr80iLneA56jiuO2/pages/5YFXe1e4UZi9YuAwHetB)
  * \[Low] User attempted to connect from a suspicious country via a suspicious IP - Modified Logic
  * \[Low] User successfully connected from a suspicious country - Modified Logic
* \[Informational] [A user accessed multiple unusual resources via SSO](broken://spaces/5O67gr80iLneA56jiuO2/pages/NH9eHEqiPcKUzkq5H8wF)
* \[Informational] [A user logged in at an unusual time via SSO](broken://spaces/5O67gr80iLneA56jiuO2/pages/jFVw4i8UoB1SPXY7BsIX)
  * \[Informational] Google Workspace - A user logged in at an unusual time via SSO - Modified Logic
* \[Informational] [AWS SSM parameters retrieval](broken://spaces/5O67gr80iLneA56jiuO2/pages/nnovTvawT2mNZk4suxQh)
  * \[Informational] Unusual AWS SSM parameters retrieval - Removed
* \[Informational] [Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert](broken://spaces/5O67gr80iLneA56jiuO2/pages/axdq6dF1gFS1lBO48mqn)
  * \[Informational] Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert Categorized as code-execution/info-leak - Modified Logic
* \[Informational] [Bucket's object ownership controls were modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/Y8RAZN0kH2f5OCDMRE4y)
* \[Informational] [Foreign account was granted permissions to S3 bucket via resource-based policy](broken://spaces/5O67gr80iLneA56jiuO2/pages/yTnwCQRkhBkTKePouftp)
* \[Informational] [IP Rotation Pattern in SSO Spray](broken://spaces/5O67gr80iLneA56jiuO2/pages/mHIJl93IEfdYBhrf3Pa2)
* \[Informational] [Intense SSO failures](broken://spaces/5O67gr80iLneA56jiuO2/pages/CQ1CjZHIere2PcggNso8)
* \[Informational] [Invalid SAML Detected](broken://spaces/5O67gr80iLneA56jiuO2/pages/eGiIu3csCutcACnZLSbk)
* \[Informational] [Multiple Okta MFA requests sent to a user](broken://spaces/5O67gr80iLneA56jiuO2/pages/WQamBlkPTbj7q3imjbEA)
* \[Informational] [Possible Impossible Travel Pattern - SSO](broken://spaces/5O67gr80iLneA56jiuO2/pages/RPF4sjJlSZP1AbdDMdX3)
* \[Informational] [SSO Brute Force](broken://spaces/5O67gr80iLneA56jiuO2/pages/NTqIaZGFy806o4UU141r)
* \[Informational] [SSO Password Spray](broken://spaces/5O67gr80iLneA56jiuO2/pages/kyeZ8ow8uOOpPOrmqQpo)
* \[Informational] [SSO with abnormal operating system](broken://spaces/5O67gr80iLneA56jiuO2/pages/ydIpP8Ir02iMSFmjPxje)
* \[Informational] [SSO with abnormal user agent](broken://spaces/5O67gr80iLneA56jiuO2/pages/LxiLIKyfnS4H3YHBpzBA)
* \[Informational] [SSO with new operating system](broken://spaces/5O67gr80iLneA56jiuO2/pages/KLkmbuK8DWiTGinWme5e)
* \[Informational] [Suspicious brand affiliation detected](broken://spaces/5O67gr80iLneA56jiuO2/pages/zwfiRlnrmvIJ6H7rXbHm)
* \[Informational] [Unrecognized internal address (AAD mismatch)](broken://spaces/5O67gr80iLneA56jiuO2/pages/PJooCZ2OkA0NcvwQLkPi)
* \[Informational] [Unusual Kubernetes service account file read](broken://spaces/5O67gr80iLneA56jiuO2/pages/xRZoznMTGRMDjU2ZEngV)
* \[Informational] [Unusual URL(s) sent by a brand were observed in the email](broken://spaces/5O67gr80iLneA56jiuO2/pages/y6VqeLBg6UmtbKkHoOh9)

### Modified Metadata

* \[Medium] [Windows LOLBIN executable connected to a rare external host](broken://spaces/5O67gr80iLneA56jiuO2/pages/Y5Hp6bAEuMLClMBkD0sJ)
  * \[Medium] Windows LOLBIN executable utilizing known port to connect to a rare external host - Modified Metadata


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-08-12.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
