Features introduced in Cortex XDR agent 8.9
Describes the new features introduced in Cortex XDR agent 8.9 releases
The following tables describe the new features introduced in Cortex XDR agent 8.9, according to the supported agent operating systems. The release will be divided into three deployments, 20 July 2025, 03 August 2025, and 10 August 2025.
General features
Feature
Description
Flexible control over automatic agent upgrades
Gain granular control over agent upgrades by setting automatic upgrade schedules for each endpoint profile, creating a safer, more efficient upgrade workflow that minimizes disruption while keeping your security up-to-date.
BAS (Breach and Attack simulation) tools
An enhanced handling of BAS tools is incorporated, adding heightened security when detecting malicious processes.
Linux features
The following is added to Cortex XDR agents running on Linux endpoints.
Feature
Description
Kernel module examination in Linux
Detect and prevent malicious kernel modules from being loaded in Linux, stopping sophisticated attacks.
Improved Adaptive Policy Mechanism
Cortex XDR agent 8.9 implements an improved, robust and granular Adaptive Policy mechanism that adds an additional safeguard from overconsumption of memory or CPU resources.
Linux cloud distribution
Support added for Amazon Linux 2023 (aarch64)
Linux operating systems
Support added for Red Hat Enterprise Linux 10 (x86_64 and aarch64)
Windows features
The following is added to Cortex XDR agents running on Windows endpoints.
Feature
Description
Enhanced driver threat prevention for Windows
Strengthen your defense against driver abuse by gaining unique visibility into user-to-kernel interactions to detect and block privilege escalation attempts at the source.
VBScript file examination
Added the capability to detect malicious VBScript files being written to disk.
MacOS features
The following is added to Cortex XDR agents running on MacOS endpoints.
Feature
Description
Network Packet Inspection for macOS
Enhance security and enrich EDR telemetry by detecting and preventing malicious network activity directly from macOS endpoints, providing comprehensive visibility and an additional layer of protection against threats.
Changed behavior
Feature
Description
BAS (Breach and Attack simulation) tools
Changed product behavior, when BAS (Breach and Attack simulation) tools are identified.
Currently, only the simulation itself is terminated, while the BAS tool continues to run.
New Behavior: BAS tools will be treated like any other malicious process, unless the new BAS tool mode in malware profile is switched on.
Last updated
Was this helpful?
