For the complete documentation index, see llms.txt. This page is also available as Markdown.

Features introduced in Cortex XDR agent 8.9

Describes the new features introduced in Cortex XDR agent 8.9 releases

The following tables describe the new features introduced in Cortex XDR agent 8.9, according to the supported agent operating systems. The release will be divided into three deployments, 20 July 2025, 03 August 2025, and 10 August 2025.

General features

Feature

Description

Flexible control over automatic agent upgrades

Gain granular control over agent upgrades by setting automatic upgrade schedules for each endpoint profile, creating a safer, more efficient upgrade workflow that minimizes disruption while keeping your security up-to-date.

BAS (Breach and Attack simulation) tools

An enhanced handling of BAS tools is incorporated, adding heightened security when detecting malicious processes.

Linux features

The following is added to Cortex XDR agents running on Linux endpoints.

Feature

Description

Kernel module examination in Linux

Detect and prevent malicious kernel modules from being loaded in Linux, stopping sophisticated attacks.

Improved Adaptive Policy Mechanism

Cortex XDR agent 8.9 implements an improved, robust and granular Adaptive Policy mechanism that adds an additional safeguard from overconsumption of memory or CPU resources.

Linux cloud distribution

Support added for Amazon Linux 2023 (aarch64)

Linux operating systems

Support added for Red Hat Enterprise Linux 10 (x86_64 and aarch64)

Windows features

The following is added to Cortex XDR agents running on Windows endpoints.

Feature

Description

Enhanced driver threat prevention for Windows

Strengthen your defense against driver abuse by gaining unique visibility into user-to-kernel interactions to detect and block privilege escalation attempts at the source.

VBScript file examination

Added the capability to detect malicious VBScript files being written to disk.

MacOS features

The following is added to Cortex XDR agents running on MacOS endpoints.

Feature

Description

Network Packet Inspection for macOS

Enhance security and enrich EDR telemetry by detecting and preventing malicious network activity directly from macOS endpoints, providing comprehensive visibility and an additional layer of protection against threats.

Changed behavior

Feature

Description

BAS (Breach and Attack simulation) tools

Changed product behavior, when BAS (Breach and Attack simulation) tools are identified.

Currently, only the simulation itself is terminated, while the BAS tool continues to run.

New Behavior: BAS tools will be treated like any other malicious process, unless the new BAS tool mode in malware profile is switched on.

Last updated

Was this helpful?