After installing any of the 8.9.x Agent versions (8.9.0, 8.9.2, 8.9.4, 8.9.6) Agent is installed or upgraded, the system begins to exhibit high CPU usage and application slowness that gets progressively worse until the system locks up.
Two new features included with Windows Agent 8.9.0+ have caused stalls or additional analysis of file operations that contribute to Agent's performance overhead, especially on very busy systems.
A future release of the Agent will remove the default timeout. In the meantime, this configuration can be disabled:
kernelExpandRulesTimeoutMs=0
By default, Agents track the Process Hollowing operations, but unless the Process Hollowing Rapid Config is enabled this additional tracking can be disabled.
kernelDisableProcessHollowingDetection=1
If the issue persists, attempt a reboot to be sure the settings are fully applied. Follow the steps in Troubleshooting Agent Performance Issues.