> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/features-introduced-in-cortex-xdr-agent-7.8.md).

# Features Introduced in Cortex XDR Agent 7.8

#### Features Introduced in Cortex XDR Agent 7.8

**Cross-Platform Features**

The following features were added to Cortex XDR agents running on Windows, Linux, and Mac endpoints:

| Feature                                                                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| -------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **File Name Field with Regex Support**                                     | To enable you to drill down further when performing a Forensic File Search, the **File Name** field has been added in the **Forensic File Search** action in the **Action Center**. In the **File Name** field you can add a regular expression from which to search within the file path defined. The search extracts the files that meet the criteria.                                                                                                                                                                                                                                                                                                               |
| <p><strong>Persistent Isolation Message</strong></p><p>Windows and Mac</p> | <p>Cortex XDR enables administrators to show the endpoint users that their machine has been isolated from the network. In order to enable the option, under <strong>Agent Settings</strong>, the following settings must be enabled.</p><ul><li>Persistent Isolation Notification</li><li>Blocked Connectivity Notification</li></ul><p>If settings are enabled, and the endpoint machine is disconnected, an icon appears in the taskbar, indicating that the machine is disconnected from the network. If the endpoint user attempts to re-connect to the network, the following message is displayed. Your network access has been paused by the Administrator.</p> |

**Windows Features**

The following features were added to Cortex XDR agents running on Windows endpoints:

| Feature                                                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **XQL Enhancement to Support EDR user-related operations** | <p>To expand your investigation capabilities, Cortex XDR Query Language (XQL) now supports the following changes related to endpoint detection and response (EDR) for user-related operations.</p><p><strong><code>ENUM.USER\_SESSION</code></strong>, provides information about user-related operations that happened in user sessions with the following event subtypes</p><ul><li><strong><code>ENUM.USER\_SESSION\_GET\_CLIPBOARD</code></strong>—Indicates whether an application has read from the clipboard and lists the application which copied the data into the clipboard.</li><li><strong><code>ENUM.USER\_SESSION\_SET\_CLIPBOARD</code></strong>—Indicates whether an application has set data into the clipboard, where only metadata about the clipboard is sent.</li><li><strong><code>ENUM.USER\_SESSION\_WINDOW\_FOCUS\_CHANGE</code></strong>—Indicates whether the foreground window has changed and supplies the title for the top window of the foreground window.</li><li><strong><code>ENUM.USER\_SESSION\_WINDOW\_TITLE\_CHANGE</code></strong>—Indicates whether the title of the top window of the foreground window has changed.</li></ul> |

**Linux Features**

The following features were added to Cortex XDR agents running on Linux endpoints:

| Feature                                                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **File System Scanning**                                      | <p>Cortex XDR can scan your Linux endpoints for dormant malware. The agent examines the files on the endpoint. There is a default list of scanned directories which can be expanded or minimized. When a malicious file is detected during the scan, the agent reports the malware to Cortex XDR, so you can take action to remove the malware before it attempts to harm the endpoint. You can scan the endpoints in the following ways.</p><ul><li>Periodic scan</li><li>Custom scan</li></ul> |
| <p><strong>Support for Helm charts</strong></p><p>(Linux)</p> | The agent installation now includes the new package type Helm Installer. The Helm Installer is used for fresh installations and upgrades of Cortex XDR agents running on Kubernetes.                                                                                                                                                                                                                                                                                                             |
| **Data Protection for the Support File**                      | To provide an extra layer of protection to the generated support file from the endpoint, the zip file is now password protected by an encrypted password. You can obtain the password by copying the encrypted code and running it in the Retrieve Support File Password option from the **Tokens and Password** button in the **All Endpoints** page.                                                                                                                                           |
| **Support for Openshift**                                     | Cortex XDR agent 7.8 now supports Red Hat OpenShift.                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Support for Red Hat Enterprise Linux 9**                    | Cortex XDR agent now supports RHEL 9.                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Support for Ubuntu 22.04 LTS**                              | Cortex XDR agent now supports Ubuntu 22.04.                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Support for Rocky Linux 8**                                 | Cortex XDR agent now supports Rocky Linux 8.                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Support for AlmaLinux 8**                                   | Cortex XDR agent now supports AlmaLinux 8.                                                                                                                                                                                                                                                                                                                                                                                                                                                       |

**Mac Features**

The following features were added to Cortex XDR agents running on Mac endpoints:

| Feature                                                                     | Description                                                                                                                                                                                                                   |
| --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **New wizard for non-MDM users for support of applying system permissions** | To provide non-MDM users the support of applying system permissions after an installation of the agent on a macOS, a Cortex XDR Configuration Wizard is automatically activated to guide the user through the required steps. |
| **Agent support on macOS version 10.15.4 and above**                        | Cortex XDR agent 7.8 is now supported on macOS 10.15.4 and above. Agent installation or upgrade on versions below that will be blocked.                                                                                       |
| **Domain of user is reported**                                              | Cortex XDR Agent deployed on macOS operating systems now reports the domain of the logged in user.                                                                                                                            |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/7.x/7.8-eol/cortex-xdr-agent-7.8-release-information/features-introduced-in-cortex-xdr-agent-7.8.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
