Cortex XDR Agent for Linux Requirements - Administrator Guide - 8.5 - Cortex XDR Agent - Cortex XDR - Advanced Endpoint Protection - Cortex - Security Operations

Cortex XDR Agent Administrator Guide

Product
Cortex XDR Agent
Cortex XDR
Version
8.5
Creation date
2024-05-06
Last date published
2024-12-01
Category
Administrator Guide
Abstract

Linux endpoints must meet the following requirements to install the Cortex XDR agent

The Cortex XDR agent for Linux has the following requirements:

Requirement

Minimum Specification

Processor

Processor 2.3 GHz dual-core processor

RAM

4GB; 8GB recommended

Hard disk space

10 GB

Architecture

x86_64 (x86 64bit)

For aarch64 (ARM 64 bit) see Cortex XDR Agent for Linux Requirements for details.

Operating system versions

See the Cortex XDR Agent Compatibility Matrix.

Kernel version

Kernel Mode

On Linux endpoints, to perform malware analysis of Executable and Linkable Format (ELF) files and collect data for endpoint detection and response (EDR) and behavioral threat analysis, the Cortex XDR agent requires one of the Linux Kernels that are listed in supported Kernel Module Versions.

If you deploy the Cortex XDR agent on a Linux server that is not running one of the kernel versions required for these additional protection capabilities, the agent will operate in asynchronous mode.

User Space Mode

User Space operation mode is supported from Cortex XDR agent version 7.7

User space operation mode requires Kubernetes node to run one of the supported operation systems with Kernel version 5.0 or later.

Software packages

Networking

  • Allow communication on the TCP port from the Cortex XDR agent to the server (the default is port 443).

  • Allow your Cortex management console and Cortex XDR agent to communicate with external and internal resources required for enforcing endpoint protection. Refer to the Resources Required to Enable Access section of your Cortex Admin Guide.