Cortex platform tools and projects

Open-source tooling for detection engineering, threat hunting, content development and security testing across Cortex XSIAM, Cortex XDR, Cortex XSOAR and Cortex Cloud. Every project is maintained in the open on GitHub.

Threat Advisory Consultant, MITRE ATT&CK detection coverage

Skills: Threat Advisory Consultant v0.40.22026-09-13

Skill
A GoCortexIO skill bundle. Somebody names a technology they run; the bundle returns what that technology, its product class or its vendor has historically been caught up in, and the detection logic that goes with each case.
SkillAGPL-3.0-or-later
XDM Rule Author, XDM modelling rules in Cortex XQL

Skills: XDM Rule Author v2.15.02026-09-12

Skill
A GoCortexIO skill bundle. Authors Palo Alto Networks Cortex XSIAM Data Model Rules in Cortex Query Language (XQL) from raw vendor log samples.
SkillAGPL-3.0-or-later
GCGit, syncing Cortex XSIAM configuration to a Git repository

GCGit v2.6.12026-08-30

Active
Go Cortex Git is a Rust-based CLI tool designed to serve as a lightweight abstraction layer between local Git operations and the Cortex XSIAM REST API. It enables security teams to version-control and deploy XSIAM configuration objects.
Rust
Spellbook feat not-Orko

Spellbook v1.23.02026-08-08

Active
Spellbook is a development workbench for creating Cortex Platform content. It provides tools for pack creation, validation, and packaging while keeping your content in a separate repository that you control. The key design principle is separation of concerns: Spellbook is the tool, your content is yours. You create a content instance with Spellbook, then push that instance to your own Git repository.
Python
GoCortex Broken Bank, a deliberately vulnerable app for Cortex Cloud training

GoCortex Broken Bank v1.6.02026-07-19

Active
An intentionally vulnerable application designed to support Palo Alto Networks Cortex Cloud and XSIAM/XDR training. Features a wide range of deliberately implemented security vulnerabilities for assessment and testing.
Python
Gremlin in a box

GremlinBox v2.0.12026-07-04

Active
GremlinBox is a collection of packages published across multiple package ecosystems for supply chain security testing and policy compliance evaluation.
Python
SignalBench, generating MITRE ATT&CK endpoint telemetry on Linux

SignalBench v1.8.72026-06-27

Active
A Rust-based application for Linux that generates endpoint telemetry aligned with MITRE ATT&CK techniques for security analytics, research, and training environments. SignalBench allows security professionals to generate realistic endpoint telemetry patterns.
Rust
XDRTop terminal demo showing real-time case monitoring

XDRTop v2.1.12025-12-26

Active
A high-performance Rust CLI monitoring tool for Cortex XSIAM, CLOUD and XDR, delivering real-time, interactive case tracking with advanced terminal-based visualisation and comprehensive filtering capabilities.
Rust
AckbarX SNMP trap forwarding architecture

AckbarX v0.6.22025-11-30

Active
A robust Rust-based SNMP trap forwarder designed to reliably capture SNMP v1/v2c/v3 traps from multiple ports and hosts and securely forward them to Cortex XSIAM HTTP endpoints.
Rust
MockTAXII, a STIX/TAXII 2.1 test server for Cortex threat intelligence

MockTAXII v0.7.02025-11-29

Active
A comprehensive TAXII 2.x server designed for testing XSIAM and XSOAR Threat Intelligence Management (TIM). MockTAXII offers a complete STIX/TAXII 2.1 implementation, generating realistic indicators, campaigns and reports, all with rich, interlinked relationships.
Python

sigma2xsiam v1.22025-10-16

Active
A custom pySigma backend specifically designed to convert Sigma rules into functional and accurate Cortex XSIAM XQL queries. Bridges the gap left by the standard pysigma-backend-cortexxdr.
Python
A web-based platform for running simulated cyber attacks in containerised environments. It automatically downloads and manages the Rust-based Snellen CLI, so no manual setup or terminal access is required.
TypeScript