Analytics rules - Cortex XSIAM

Cortex XSIAM 3.x Release Notes

Product
Cortex XSIAM
Last date published
2026-06-09
FEATURE DESCRIPTION

Process Anomaly Analytics

Detect malicious processes by identifying abnormal behavior patterns in your Windows environment. We added a new analytics suite that monitors process history to expose hidden threats.

Enhanced RDP Analytics

Protect your network from unauthorized access by automatically flagging unusual remote desktop (RDP) activity. We introduced new alerts that combine session data with behavior analysis to create actionable incidents.

EDR Linux & macOS Abnormal Communication

Spot unusual data transmissions that often signal a security breach on Linux and macOS. We launched a detection suite that profiles network baselines to expose "Command and Control" behavior.

EDR macOS Generic Persistence

Keep your endpoints clean by detecting the subtle methods hackers use to remain hidden after an initial breach. We expanded our coverage to identify new techniques used by infostealers and advanced threats.

Webshell Analytics

Protect both managed and unmanaged servers from unauthorized web-based control. We expanded our detection capabilities and integrated network protocol inspection to cover more server types.

Linux Credential Grabbing

Stop attackers from stealing sensitive configuration files and user credentials through brute-force or system abuse. We improved our behavioral analytics to highlight and block unauthorized attempts to access secret files.