> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2025/february-2025.md).

# February 2025

This section describes the new features and updates introduced in the Cortex XSOAR SaaS 8.9 release.

## Release highlights

The Cortex XSOAR 8.9 release includes the following highlights:

| Feature                                        | Description                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ---------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| A new look and feel for playbooks              | <p>The latest enhancements in user experience improve playbook readability and clarity through an updated look and feel.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com//go/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Use-the-Work-Plan-in-an-investigation">Use the Work Plan in an investigation</a>.</p>                                                                                        |
| Collapsible playbook sections                  | <p>The updated collapsible playbook sections enable users to stay focused on the relevant playbook details without distractions, allowing for easier navigation through complex playbooks and increased productivity.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-section-header">Create a section header</a>.</p>                         |
| Unlimited user license for development tenants | <p>With no license limit for users on development tenants, you can build, test, and refine automations at scale. This drives faster innovation, more reliable workflows, and scalable solutions as your organization grows.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Understand-Cortex-XSOAR-licenses">Understand Cortex XSOAR licenses</a>.</p> |
| Notifications for deprecated content           | <p>New automated user notifications about deprecated playbooks, sub-playbooks, and scripts ensure updated, effective, and accurate security workflows.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/User-preferences">User preferences</a>.</p>                                                                                                      |

## Feature enhancements

The Cortex XSOAR 8.9 release includes the following enhancements:

**Incidents**

| Feature                                            | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| -------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Allow bulk action for Retain/Undo Retain Incidents | <p>You can now Retain and Undo Retain Incidents from the incidents table on all incidents, including closed incidents. This feature allows you to keep incidents for compliance or incident management purposes, ensuring critical data is preserved and not deleted due to retention enforcement or accidental removal.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Investigate-an-incident">Investigate an incident</a>.</p> |
| War room filtering                                 | In the War Room, when selecting multiple filters, you can now view the results with any of the selected filters.                                                                                                                                                                                                                                                                                                                                                                                                       |

**Engines**

| Feature                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced engine upgrades | <p>Gain greater flexibility and control over the upgrade process by setting upgrade variables, such as <code>https\_proxy</code>, using a new <code>upgrade.conf</code> file.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Upgrade-an-engine">Upgrade an engine</a>.</p><p>You can use this feature when upgrading engines to Cortex XSOAR 8.10 and later.</p> |
| Platform support         | <p>Cortex XSOAR now supports the following platforms for engine installation:</p><ul><li>RHEL version 9.5</li><li>Oracle Linux version 9.4</li><li>Amazon Linux 2023</li><li>Ubuntu 24.04</li></ul><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Engine-requirements">Engine requirements</a>.</p>                                                                 |

**Remote Repositories**

| Feature                                                                                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ---------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced version compatibility notifications for development and production environments | <p>Receive clear warnings and visual indicators for potential version mismatches when syncing content between development and production, ensuring seamless upgrades.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Push-content-from-a-development-tenant">Push content from a development tenant</a>.</p>                                                                                               |
| Support for the **ed25519 algorithm** to connect to private content repositories         | <p>Cortex XSOAR now supports the high-speed, high-security <strong>ed25519 algorithm</strong> for SSH connections to content repositories. This aligns with industry best practices, providing a more secure method for access and enhancing your overall security posture.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Set-up-a-private-remote-repository">Set up a private remote repository</a>.</p> |

**Troubleshooting**

| Feature                                                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ----------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Analyst actions recorded in audit logs                      | <p>Audit logs now record commands entered by analysts in the War Room and Playground, which improves visibility into analyst actions taken during the incident response and troubleshooting processes.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Management-audit-logs">Management audit logs</a>.</p>                                                        |
| Forward integration logs to the Syslog server               | <p>You can now forward integration logs to the Syslog server, which enables you to quickly manage and address any issues in your environment.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Configure-notification-forwarding">Configure notification forwarding</a></p>                                                                                          |
| Forward Guard Rail alerts and warnings to the Syslog Server | <p>You can now forward guard rail warnings and alerts to your Syslog Server, which enables you to quickly manage and address any issues that may occur in your environment.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/View-service-limit-errors-and-warnings-on-the-Guard-Rails-page">View service limit errors and warnings on the Guard Rails page</a>.</p> |
| Guard Rails performance-related alerts and warnings         | Guard Rails includes new performance-related alerts and warnings that can be used as a guide to detect and prevent actions that may cause performance or instability issues. This ensures a reliable way to maintain a secure and stable environment.                                                                                                                                                                                                   |

**API**

| Feature                           | Description                                                                                                                                                                                                                                                                                                                                                                                                        |
| --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| New administration APIs           | <p>Significantly enhance the management and configuration experience for engines, syslog, and authentication settings by adding new APIs.</p><ul><li>Automate the deployment and management of engines.</li><li>Facilitate easier management of syslog servers at scale.</li><li>Configure IdP and SSO, enabling administrators greater control and efficiency in enforcing and managing access control.</li></ul> |
| Support of additional Cortex APIs | <p>The following data management APIs are now supported:</p><ul><li>Editing indicators</li><li>Deleting batches of incidents:</li></ul>                                                                                                                                                                                                                                                                            |

## Marketplace content changes

This section describes the changes in content (integrations, playbooks, and indicators) from October 2024 to February 2025.

Reusing topic #UUID-ae766b8f-db61-39aa-e790-dce11ba4c9a4


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2025/february-2025.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
