> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.0/agent-9.0-release-information/feature-enhancements.md).

# Feature Enhancements

The following tables describe the new features introduced in Cortex XDR agent 9.0, according to the supported agent operating systems. The release will be divided into three deployments; 9 November 2025, 16 November 2025, and 23 November 2025.

#### macOS

| Feature                  | Description                                                                                                                                    |
| ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| File examination on-load | Detect and prevent execution of malicious Mach-O files when being loaded on macOS-based endpoints, using this new Cortex XDR agent capability. |
| OS Support               | Adding support for macOS 26                                                                                                                    |

#### Windows

| Feature                           | Description                                                                                                                                                                                                                                                                                   |
| --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ML-based JScript file examination | Enhance your defense against script-based threats with a new machine-learning protection module for the XDR Agent on Windows, trained to analyze and block malicious JScript files before they can execute or when written to disk.                                                           |
| Malicious LDAP Query Protection   | Malicious LDAP Query Protection: Identify and block malicious reconnaissance activity targeting Windows Domain Controllers. Customers with the ITDR add-on can now use the XDR agent for real-time prevention against attack techniques used by tools like BloodHound's SharpHound collector. |
| XDR Agent for Windows on ARM64    | Extend the industry-leading prevention and detection capabilities of Cortex XDR to Windows endpoints running on ARM processors.                                                                                                                                                               |
| OS support                        | Adding support for Windows 11 25H2                                                                                                                                                                                                                                                            |

#### Linux

| Feature                            | Description                                                                                                                                                                                                                                               |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Child Process Protection for Linux | Cortex XDR introduces an additional prevention module for Linux (in KM mode) that examines the relations between parent and child processes to detect suspicious relations. This module provides improved detection and protection coverage capabilities. |
| Forensics for Linux                | Customers with the Forensics add-on can now run complete investigations across Windows and Linux, with deeper artifact collection and analysis from Linux endpoints.                                                                                      |
| CaaS distribution                  | Support added for Google Kubernetes Engine (GKE) Autopilot                                                                                                                                                                                                |
| Linux distribution support         | <ul><li>Rocky Linux 10 x86\_64</li><li>AlmaLinux 10 x86\_64</li><li>Oracle Linux 10 x86\_64 and aarch64</li><li>SUSE Linux Enterprise Server 15 SP7</li></ul>                                                                                             |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xdr-agent-release-notes/9.0/agent-9.0-release-information/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
