Malware Protection (28) - Content Update Release Notes - Cortex XDR - Cortex - Cortex XDR

Cortex XDR and Traps Content Update Release Notes (Version 1420)

Product
Cortex XDR
Creation date
2024-07-23
Last date published
2024-07-23
Category
Content Update Release Notes

Module Name

Issue ID

OS

Action

Description

Behavioral Threat Protection (agents 6.1 and above)

CTNG-9622

CTNG-9805

CTNG-9861

CTNG-9882

CTNG-9905

CTNG-9932

CTNG-9934

CTNG-9947

CTNG-9959

CTNG-9979

CTNG-9980

CTNG-10014

CTNG-10070

Windows

MacOS

Linux

Modified

Behavioral Threat Protection rules (prevention and silent) were updated both for compatibility reasons and to increase security coverage

EDR detection module

CTNG-9416

CTNG-9805

CTNG-9878

CTNG-9882

CTNG-9905

CTNG-9951

CTNG-9953

Windows

MacOS

Linux

Modified

EDR detection module rules were updated for compatibility reasons

EDR DotNet Protection Module

CTNG-9947

Windows

Modified

EDR DotNet Protection Module rules were updated for compatibility reasons

CLAD protection module

CTNG-9899

Linux

Modified

CLAD Protection Module rules were updated for compatibility reasons

Trusted Signers module

CTNG-9906

Windows

Modified

Trusted Signers list was updated for compatibility reasons

Reverse Shell Protection

CTNG-9622

CTNG-9861

Linux

Modified

Reverse Shell Protection Module rules were updated for compatibility reasons

Host Firewall Protection module

CTNG-9754

Windows

Modified

Host Firewall Protection Module rules were updated for compatibility reasons

Local Threat-Evaluation Engine protection module

CTNG-9415

CTNG-9657

CTNG-9797

CTNG-9859

CTNG-9916

MacOS

Modified

Local Threat-Evaluation Engine rules were updated for compatibility reasons

Kernel modules compatibility support

CTNG-9825

CTNG-9589

Linux

Modified

Kernel module compatibility support list was updated for compatibility reasons

Yara protection module

CTNG-9903

CTNG-9974

CTNG-10039

Windows

MacOS

Linux

Modified

Yara Protection Module allow list was updated for compatibility reasons

Enhanced vulnerability assessment detection module

-

Windows

MacOS

Modified

Enhanced vulnerability assessment detection module database was updated for compatibility reasons