Release Notes
Version 3.1.1 - 07 July 2026
Improved
Network scanner reliability has been improved with configurable per-operation timeouts, preventing unresponsive hosts from delaying scans.
Network scanner error logging has been improved to provide clearer diagnostic details.
IsAnySmbV2V3Active property has been added to Computer entities and can now be used as a filter in Advanced Search.
Fixed
An issue where Credential Discovery scan processes could continue running after cancellation has been fixed.
Weak Certificate Mappings on Domain Controllers issue (FS1161) evaluation has been corrected for environments with multiple Domain Controllers.
SMB Signing issues (FS1017, FS1018, FS1019, FS1020) are now reported only for computers with a confirmed active SMBv2/v3 dialect, reducing false positives.
Unlinked Group Policy Objects issue (FS1071) detection has been improved to use resolved GPO links, preventing inconsistent results.
Network scan operations are now safely skipped when impersonation cannot be established.
Version 3.1.0 - 01 June 2026
Added
AWS IAM scanner module has been added.
AWS IAM Users, Groups, Roles, Policies, Access Keys, Accounts, and Organizations have been added as entities.
10 new AWS issues starting with FS4001 have been added.
11 new AWS attack path edges have been added, including AWS_ASSUME_ROLE, AWS_CAN_CREATE_ACCESS_KEY, AWS_HAS_ACCESS_KEY, AWS_IN_ACCOUNT, and AWS_IN_ORGANIZATION.
GCP IAM scanner module has been added.
GCP Organizations, Folders, Projects, Organizational Units, Users, Groups, Service Accounts, Service Account Keys, Roles and Devices have been added as entities.
7 new GCP issues starting with FS5001 have been added.
29 new GCP attack path edges have been added, including GCP_CAN_IMPERSONATE_SA, GCP_CAN_SET_PROJECT_IAMPOLICY, GCP_CAN_SSH_VM, GCP_HAS_ROLE, and GCP_IN_PROJECT.
Google Workspace integration has been added with 8 new attack path edges, including GWS_GRANT_ROLE, GWS_GROUP_OWNER, GWS_IN_GROUP, and GWS_RESET_PASSWORD.
Azure Resource Management (ARM) scanner module has been added.
Azure Subscriptions, Resource Groups, Management Groups, Virtual Machines, Key Vaults, SQL Servers, ARM Roles, and Managed Identities have been added as entities.
15 new Azure ARM attack path edges have been added, including AZ_ARM_OWNER, AZ_CONTRIBUTOR, AZ_EXECUTE_COMMAND, AZ_HAS_ARM_ROLE, and AZ_IN_SUBSCRIPTION.
9 new Azure ARM issues (FS2017-FS2025) have been added, including Guest Account Has Privileged ARM Role, Custom ARM Role With Wildcard Actions, and Resource Has Tier 0 Managed Identity Assigned.
Compliance module has been added with built-in control-to-issue mappings for ISO 27001, NCA Essential Cybersecurity Controls (ECC 2024), SAMA v1, and IAR frameworks.
Issue Timeline feature has been added to track the history of an issue across scans.
Stale-reason tracking has been added for identities.
API Tokens feature has been added for programmatic API access.
Model Context Protocol (MCP) server has been added, exposing scans, entities, vulnerabilities, attack paths, credential-discovery, and trend data as tools for AI assistants.
ScanPolicy exclusion description field has been added with a comment modal for documenting why an exclusion was created.
Tier 0 identity tracking and comparison across AD, Azure, AWS, and GCP have been added to Trend Insight, with hybrid relationship support.
Certificate Authority Disables SID Security Extension for Everyone-Like Enrollable Clients issue (FS1183) has been added.
Certificate Authority Disables SID Security Extension for Non-Privileged Enrollable Clients issue (FS1184) has been added.
Edge descriptions have been added for AZ_PASSWORD_WRITEBACK, AZ_GROUP_WRITEBACK, CanReadGMSAPassword, CreateDNSNode, and WriteEnrollmentFlag relationships.
CyberArk integration now supports proxy configuration.
Proxy support has been added to the Cloud Scanner and Azure connections.
Kerberos authentication has been added for environments where NTLM is disabled.
Bulk status-change feature has been added to the Issues page.
AZDevice Owner Service Principals relationship has been added.
Group Policy Object baseline export feature has been added.
Improved
Credential Discovery scan rules have been improved.
Hybrid attack paths from Azure to AD for Password Writeback (AZ_PASSWORD_WRITEBACK) and Group Writeback (AZ_GROUP_WRITEBACK) scenarios have been added to Tier 0 analysis.
Recurring scan reliability has been improved.
OS End-of-Life check has been updated.
Table search inputs now include a clear-search button and improved styling.
PDF report templates have been improved with platform breakdown and refreshed styling.
Issue page export has been improved.
Scans export query and status sorting have been improved.
Audit logging now captures role and authentication-type details.
Bundled PostgreSQL version has been updated to 15.17.2 for new installations.
Fixed
Azure Policy not being selected when creating a new scan has been fixed.
Everyone-like objects privilege detection has been corrected.
Trend Insight visibility bug has been fixed.
Shortest-path queries have been fixed.
Dashboard not loading when no scan is available has been fixed.
Setup issue on Windows Server 2025 has been fixed.
Sort bug in the Edit GPO Custom Baseline table has been fixed.
Privileged-role permissions and sort behavior have been fixed.
Version 3.0.1 - 28 January 2026
Added
Azure/Microsoft Teams scanner module has been added (additional permissions may be required for existing Entra ID integrations).
Azure/Microsoft SharePoint Online scanner module has been added(additional permissions may be required for existing Entra ID integrations).
Microsoft Teams general settings, meeting policies, message policies and external access settings have been added as entities.
Microsoft SharePoint Online general settings and sites have been added as entities.
15 new Azure/Microsoft Teams issues starting with FS3001 have been added.
11 new Azure/Microsoft SharePoint Online issues starting with FS3101 have been added.
Certificate-based authentication support has been added for Azure integration.
Scan-based access control has been added for Azure scan policies.
General user and device settings from Azure have been added to the Tenant Details page.
Client secrets and certificates to Azure Applications have been added to the Azure Application Details page.
Edge descriptions for Azure-related relationships have been added to the Visualize and Issue Details pages.
Network scan health-related information has been added to the Dashboard.
Choke point-related information has been added to the Dashboard.
Statistics similar to those available on the Dashboard have been added to Trend Insight.
Hybrid attack paths (Azure -> AD) for Password Writeback scenarios have been added to the graph (AZ_PASSWORD_WRITEBACK), with configuration available on the Azure Tenant Configuration page.
Hybrid attack paths (Azure -> AD) for Group Writeback scenarios have been added to the graph (AZ_GROUP_WRITEBACK).
Improved
Azure-related attack impacts have been added to the Impacts page.
Azure-related statistics have been added to Trend Insight.
Azure AD Connect Sync identities(MSOL, AAD_*, ADSyncMSA), Azure AD sync server, and related privileged groups(ADSyncAdmins, ADSyncPasswordSet) are now marked as Tier 0.
Edge Descriptions modals have been updated to use an accordion-style layout.
Tier0 Analysis feature has been added for Azure environments.
Audit logs now provide more detailed and clearer information for user-related changes.
Credential Discovery now displays scanned and total computers count while the scan is in progress.
User Description can now be excluded for Plaintext Passwords on Account Attributes issue (FS1074).
Reporter and Labels fields have been added to Jira ticket creation.
SMB share enumeration now uses share-level security descriptors instead of NTFS ACLs, reducing false positives. (Note: Requires local administrator privileges or registry read access on the target systems.)
Advanced Search now supports viewing incoming paths for Tier 0 analysis.
Saved queries on Mail Integration page are now organized by provider.
Issue detail views have been improved.
Fixed
An issue with sorting by Exposure Point on Scans page has been fixed.
An issue with regex-based searching in the Affected Entity tables has been fixed.
An issue with DNSNode exclusions has been fixed.
An issue with the exclusion type display in General Exclusions has been resolved.
Version 3.0.0 - 15 October 2025
Added
Azure/Entra ID scanner module has been added.
Azure tenants, users, groups, devices, applications, service principals, roles, administrative units, and conditional access policies have been added as entities.
16 new Azure/Entra ID issues starting with FS2001 have been added.
Built-in search queries for Azure/Entra ID assessments have been added.
Single sign-on authentication support has been added.
DNSNode objects have been added to the entity inventory.
Dangerous Access Control Entries on DNS Zones from Everyone-Like Objects issue (FS1176) has been added.
Dangerous Access Control Entries on DNS Zones from Non-Privileged Objects issue (FS1177) has been added.
Dangerous Wildcard DNS Node Entry issue (FS1178) has been added.
Dangerous Access Control Entries on DNS Nodes from Everyone-Like Objects issue (FS1179) has been added.
Dangerous Access Control Entries on DNS Nodes from Non-Privileged Objects issue (FS1180) has been added.
CreateDNSNode, WriteDNSRecord, and APPLY_GPO attack-path edges have been added.
Scan policy-based access control has been added.
Scan policy-based Jira ticket creation capability has been added.
Scan start validation testing has been added.
Group Policy Object baseline import capability has been added.
Edge descriptions have been added to the Visualize and Issue Details pages.
Recurring scan difference email notifications have been added.
Improved
Tier0 analysis graph visualization has been improved.
Search & Report now supports adjusting relation directions.
Security Filter support has been added to the GPO Audit module.
Row-based exclusion management and UI have been improved.
Scan deletion performance has been improved.
Built-in GPO baselines have been refined.
Bundled Python version has been updated to 3.13.5 for new installations and upgrades.
Bundled PostgreSQL version has been updated to 15.14.1 for new installations.
License compliance controls have been improved.
Provider Type attribute has been added to the Policies, Issues, and Search & Reports pages.
Default Credential Discovery exclusions (.venv, node_modules, WindowsApps, Cortana) have been updated for improved performance.
Tier0 objects on the Visualize page now display a dedicated icon.
LDAP access control evaluation now honors SID values.
Affected entity comparison logic has been enhanced.
Graph shortcuts on entity detail pages have been improved.
Search & Report now offers a table view for Tier0 analysis results.
Entity distinguished name values are now displayed on the Visualize page.
Share Audit module has been renamed to Credential Discovery.
Stealth Admin designation has been renamed to Shadow Admin.
Fixed
Audit log file formatting issues have been fixed.
Issues where GPOs were applied to logical false positives have been fixed.
Vulnerability Policy import no longer overwrites existing definitions unintentionally.
DNSAdmin identification logic has been fixed.
Computer description filtering in Search & Report has been corrected.
Multiple scan execution stability has been improved.
Organizational unit-based exclusion controls have been fixed.
API key display on the Jira integration page has been corrected.
Version 2.9.1 - 23 June 2025
Added
Delegated Managed Service Account(dMSA) objects have been added.
Dangerous DMSA Superseded Account issue (FS1173) has been added.
Suspicious DMSA Superseded Account issue (FS1174) has been added.
Dangerous Access Control Entries for BadSuccessor issue (FS1175) has been added.
2 new attack path edges (CreateDMSA and DMSAFullTakeover) have been added.
Import and export functionality has been added for Scan and Vulnerability Policies.
Tier0 Analysis module has been introduced for visualizing choke points. Note: It's a Beta version. You have to enable 'Tier0 Analysis' module from Scan Policy.
Custom tagging feature has been added for Issues.
Customizable Status Info feature has been added for Issues.
Sending reports for finished scans as e-mail has been added.
Audit logs can now be sent to a remote Syslog server.
New policy creation feature based on existing base policies has been added.
DMSAs with Explicit Local Admin Privileges query has been added to Search & Report.
Improved
Scan scheduling has been enhanced to better support Continuous Assessment.
HTTP Endpoint is Enabled for the Certificate Enrollment issue (FS1145) mitigation steps have been improved.
EPA is not in place on HTTPS Endpoint for the Certificate Enrollment issue (FS1146) mitigation steps have been improved.
Bulk action feature has been added to Scan Policy and Custom GPO Baselines tables.
Performance of the Share Audit module has been optimized.
Real-time statistics display feature has been added for active Share Audit scans.
Report access controls are now user-configurable.
Filtering and sorting capabilities have been added to Built-in user Management table.
Session enumeration controls have been improved.
Fixed
Tier0 identification for Group Policy objects has been improved.
Tier0 identification for Cross domain members has been improved.
Broken objects links on Advanced Search and Visualize has been fixed.
Navigate to Visualize page when on Visualize page problem has been fixed.
Tables responsiveness issue on small screens has been fixed.
Version 2.9.0 - 24 February 2025
Added
EveryoneRead and EveryoneWrite controls have been added to ShareAudit module.
Support for multiple LDAP integrations has been added.
Built-in user Management page has been added.
Suspicious Access Control Entries on DPAPI Key (FS1169) issue has been added.
Insecure Trust Configuration for NT4 Systems (FS1170) issue has been added.
Insecure LM/NTLM Authentication Level (FS1171) issue has been added.
Default Password for Pre-Windows 2000 Computer Accounts (FS1172) issue has been added.
2 new attack path edges (SyncLAPSPassword and DCSync) have been added.
Get All Shortest Path to Here from Non-Privileged Objects query has been added to visualize.
Get All Shortest Path to Here from Everyone-Like Objects query has been added to visualize.
Tier0 and Tier2 labels have been added to Entities.
A Tier0 and Tier2 based filtering feature has been added to Advanced Search.
Compare affected entities across scans feature has been added.
Improved
Computer-based SMB Share filters have been added to Search & Reports.
Coercion enumerations specific module has been added to Scan Policies.
Dashboard performance has been optimized.
Plaintext Passwords on Account Attributes(FS1074) issue control has been improved.
LAPSV2 usage controls has been improved.
WSUS identification controls have been improved.
Fixed
Issues and RSOP Comparison tables export issue has been fixed.
Advanced Search IP Range filter issue has been fixed.
GPLINK relations were not found across different domains issue has been fixed.
Custom Tier0 mark issue for Group Entities has been fixed.
Missing failed scan emailing checks has been fixed.
Scan status hanging on Share Audit issue has been fixed.
Version 2.8.9 - 13 November 2024
Added
Trend Insight Dashboard has been introduced for enhanced data visualization
Run on Graph functionality is now available in Advanced Search
Suppress feature has been added to the Share Audit Secrets table
Exposure Point metrics are now included in Issues, Entities, Impacts, and Scans
Comprehensive General Health Check feature has been implemented
Scan Failure Email Notification feature has been introduced
Shortcuts for Explicit and Group Delegated Local Admin queries are now accessible on User and Computer details pages
Computer IP Range filter has been added to Advanced Search
General Exclusion feature, allowing exclusions by IP, Share Name, and Folder Path, has been added to the Share Audit module.
Feature to retrieve the n characters immediately before and after a detected secret has been added to the Share Audit module.
Improved
The Scan Dashboard user interface has been enhanced.
The Computers Added into Domain by Unprivileged Users issue (FS1098) now includes a two-way definition.
Performance of the Share Audit module has been optimized.
Automatic update of ticket URLs is now available when the Jira URL is modified.
Enhanced messaging for LDAP authentication failures.
LDAP base search validation has been added.
Improved performance for Stealth Admin identification and related queries.
Inter-Domain/Forest-based issues (FS1122, FS1123, FS1125) scan performance has been optimized.
Affected Entity Bulk Exclusion feature has been enhanced.
Updated page size options (10, 25, 50, 100, 250, 500) across all tables.
Optimized performance on the Impacts page.
MITRE tactics are now included in the Issues table and details page.
Enhanced severity-based sorting for the Issues table.
Exploitation Privilege and Exploitation Certainty variables have been added to the Issue details page.
PDF reports now include Forest, Domain, Policy, and Exposure Point details.
Fixed
Resolved an issue with identifying Privileged Groups Cross-Domain Members.
Fixed the incorrect link issue in vulnerability visualization.
Addressed the incorrect scan duration issue in email notifications.
Corrected the license read permission control issue on the frontend.
Version 2.8.8-3 - 08 October 2024
Added
Certificate Template Allows Everyone-Like Clients to Specify Arbitrary SAN and Application Policies (FS1167 - ESC15) issue has been added.
Certificate Template Allows Non-Privileged Clients to Specify Arbitrary SAN and Application Policies (FS1168 - ESC15) issue has been added.
Version 2.8.8 - 29 August 2024
Added
Share Audit feature has been added to SMB Shared folder secret finding.
Environment-specific Tier Zero Asset addition feature has been added.
Custom baseline feature has been added to Group Policy Audit.
SMTP relay feature has been added to Mail Configuration.
MITRE ATT&CK Tactics, Impact and Tag based 20 Built-in Scan Policies has been added.
Display Specifier objects have been added.
Abnormal Display Specifiers (FS1165) issue has been added.
Certificate Template Enables Authentication & Contains No Security Extension Flag (FS1160) issue has been added.
Weak Certificate Mappings on Domain Controllers (FS1161) issue has been added.
ICertRequest Encryption is not Enforced (FS1166) issue has been added.
FSProtect Server IpAddress and IIS Certificate change scripts have been added to Scripts directory.
License expiration message bar has been added.
Improved
Active Directory object and relation enumeration performance has been improved.
Scan failure messages have been improved and added to scan stage section.
Automatic last scan selection feature has been added when authenticating.
A message has been added for cases where the last scan is not selected.
The auto-refresh feature for the issue count has been added to the navigation bar.
Empty string filter option has been added to Affected Entity Table.
Select/Deselect All option has been added to Affected Entity Table ACL columns.
IsEmpty filter property has been added to GPO entities for Advanced Search.
The performance of the built-in query runner function visualization has been improved.
The queries for visualizing Local Admin findings have been enhanced.
The function for finding IP addresses of Active Directory Computer objects has been improved.
Fixed
Inter Domain/Forest graph queries have been fixed by excluding script objects.
AffectedEntityTable invalid regex filter exception has been fixed.
Open SMB Shares on Computers issue when scanning with Local Administrator accounts has been fixed.
Affected Entity PDF generation bug has been fixed for issue related to DNSZone.
Version 2.8.7 - 06 June 2024
Added
Row-based exclusion feature has been added on the Affected Entity tables.
Relation-based advanced search feature has been added.
CyberArk integration has been added to automate the synchronization of scan access information.
One new attack path edge (ManageGPLink) has been added.
Issues for Non-Privileged Authorized LAPS Decryptors (FS1163) and Everyone-Like Authorized LAPS Decryptors (FS1164) have been added.
Insecure WSUS HTTP Protocol (FS1162) issue has been added.
Five new built-in advanced search queries have been added.
Issue cards in the dashboard have been made clickable.
Graph v2 has been released.
Graph v2: Multiple new Graph layouts have been added.
Graph v2: A new widget allows viewing relationships in a table format.
Graph v2: Settings within the Graph visualization are now configurable.
Graph v2: A new widget for filtering relationships in the Graph has been introduced.
Graph v2: Clusters can now be created based on relationship type, relationship direction, and object type.
Graph v2: Relationships are now highlighted for better visibility.
Graph v2: The widget displaying the relationships of objects has been updated.
Improved
Performance of Stealth Admin and Dangerous Path Count identification queries has been improved.
LAPS identification has been improved for LAPS V2.
Hangfire version has been upgraded to 1.8.12.
Hangfire values has been moved to PostgreSQL.
Count query for Affected Entity tables has been improved.
IsEmpty filter has been added to Search & Report module.
IsWindowsClient column has been replaced with IsWindowsOS.
Fixed
Scan Policies connected with a Scan have been made editable.
Deletion of initial scan access information has been enabled.
New automated permission sync feature has been added.
ManagedServiceAccount host service formatter has been fixed.
OS identifying has been improved for CVE-based scanner.
Recurring Scan Policy changing issue has been fixed.
Version 2.8.6 - 22 April 2024
Added
Column based filter has been added to Affected Entity Tables.
Role-based Access Control(RBAC) feature has been added.
JIRA bulk ticket creation feature has been added.
WebClient is Active on Computers(FS1156) and WebClient is Active on Critical Computers(FS1157) issues have been added.
DNSZone object enumeration has been added.
Insecure DNSZone Dynamic Update(FS1158) issue has been added.
Dangerous Access Control Entries on Containers(FS1159) issue has been added.
3 new attack path edges (CreateComputer, CreateUser, CreateAny) have been added.
Container objects have been added as affected entity to the FS1046 and FS1093 issues.
Ldap Signing based connection type has been added.
Improved
Container object parsing process has been improved.
The default database has been changed with PostgreSQL for performance imrovements.
Affected entity tables have been moved to PostgreSQL for performance imrovements.
Resultant Set of Policy (RSoP) analysis has been improved.
NetworkCredential usage method has been improved.
PDCTime control has been improved.
Standalone Managed Service Account control has been improved.
Ldap authentication dependency has been updated.
The exclusion type of the Built-in group membership issues (FS1049, FS1050, FS1051, FS1052, FS1057, FS1060, FS1087, FS1108) has been updated from one-way to two-way definition.
PolicyRulesFileBuilder file has been moved to the Temp directory.
Fixed
Global IP, IPRange and OU exclusion issue has been fixed.
Domain Controller identification has been fixed.
Loading bug of the FS1147 issue detail page has been fixed.
SMBv1 Parser has been fixed.
SpoolerScanner impersonation has been fixed.
Version 2.8.5 - 12 February 2024
Added
Scan comparison feature has been added to Dashboard.
Scan comparison feature has been added to Issues.
Scan based caching has been added to filterable issue table columns.
Improved
CVE Scanner has been improved.
Query for calculating GPO Linked Entity Count has been improved.
Loading performance of the issues table has been improved.
IsComputerClient and IsWindowsServer properties have been added to Computers.
Fixed
Sorting issue in the Affected Computer table for the 'Online' column has been fixed.
Access issue to the Policies page from some remote clients has been fixed.
Access permission for the API folder has been fixed.
Parser issue with ForeignSecurityPrincipal has been fixed.
Issue with forest trust identification has been fixed.
Large Index exception for Computer, User, MSA, and GMSA indexes has been fixed.
Performance issue with InheritedObjectType migration has been fixed.
CreateInitialGroupsMembership exception has been fixed.
FS1084 - 'LDAP Channel Binding is not Enabled on Domain Controllers' issue check has been fixed.
Version 2.8.4 - 15 January 2024
Added
Column Hide/Show feature has been added to Issue, Attack Surface and RSoP Comparison tables.
Last state storage feature for Scan, Issue and all Entity tables has been added.
Include Disabled and Include Inactive filter options has been added to Scan Policy.
Inactive filter option has added to Search&Report for User, Computer, Managed Service Account and Group Managed Service Account.
Inactive Users, Inactive Computers, Inactive Managed Service Accounts and Inactive Group Managed Service Accounts built-in queries has been added.
MSA and GMSA tabs has been added to Group entity details page.
FSID and Comment count columns has been added to Issue table.
Improved
FS1043 and FS1046 issues control have been improved.
Core App Memory optimization has been improved.
Issues table loading performance has been improved.
JDK version upgraded to 15.0.2.
IsComputerClient and IsWindowsServer properties have been added to Computers.
Fixed
ACE issue has been fixed with ACE Inheritance Filter.
ForeignSecurityPrincipals parse issue has been fixed.
User Local Memberships count issue has been fixed.
Open entity in different scan on graph page issue has been fixed.
FS1063 issue control has been disabled by default.
Version 2.8.3 - 25 December 2023
Added
Added Scheduled Scan Date Time and Frequency change feature.
Added 'Not like' filtering option for string variables in Advanced Search.
Added Shortcut Link to Graph Page Nodes.
GPO Flags property has been added to GPO Details page.
Improved
FS1066 issue has been improved.
Core App chunk insertion has been improved.
OS End-of-Life check for FS1009 and FS1010 issues has been updated.
Added Enabled and Windows control to Network Scanner.
Exception based EPA/HTTP Connection retry has been added.
GPO Descriptions updated for Baseline and RSoP pages.
Added pending system update check.
Details pages row format has been improved.
DomainControl control has been improved.
Added API link to login failed message.
Scan Policy Info titles has been changed.
Computer Sessions table columns has been improved.
Visualize Range Counter values (Min: 50, Max: 1.000, Step:50) has been changed.
Removed record not found logs for RecycleBin and DsHeuristics.
Removed Initial HTTP Request 404 status log for certificate.
Fixed
SSPI error(supported ssl/tls protocol) fixed.
Group Policy rules parsing issue has been fixed.
Fixed conflict issue in Add Generic SPNs.
Conflicts of adding collected sessions has been fixed.
Domain related Entity SID dictionary conflict has ben fixed.
Baseline and RSoP table total page number confusion has been fixed.
Computer Shares table row key not found issue has been fixed.
Version 2.8.2 - 15 November 2023
Added
Password check in user description to FS1074 issue has been added.
Policy change feature for scheduled scans has been added.
Improved
FS1082 and FS1108 issue checking have been improved.
Open SMB Share IsEveryone access control has been improved.
Number formatting added to OU, GPO and Group detail pages.
Operating System empty check has been added to FS1069 issue.
Advanced Search filterable attributes updated for LocalUser.
Stealth Admin finding query has been updated to start from unprivileged accounts.
PDC time check has been improved.
Generate Excel Report process has been moved to new url.
Empty check has been added to Number Formatter.
ACE Identity Type value has been updated for MSSQLSvc accounts.
Contains a value check has been added for Generic SPNs.
Fixed
Service-Based Security Assessment module control has been fixed.
Forest name duplicate issue has been fixed.
CanReadGMSAPassword Access Control Entry typo has been fixed.
Tab components were changed for pagination of server-side tables was not working correctly.
Excel Report row limit bug has been fixed.
Version 2.8.1 - 16 October 2023
Added
Container objects have been added.
AdminSDHolder-related issue (FS1091) has been added.
Standalone Managed Service Account (sMSA) related issue (FS1155) has been added.
A new attack path edge (DUMP_SMSA_PASSWORD) has been added.
Links for Stealth Admin and Risky Admin have been added to the Dashboard.
Stealth Admin User Count has been added to the Dashboard.
Stealth Admin search query has been added to Built-in Queries.
A different email sender input has been added for email relay.
Block Inheritance attribute has been added to Domain objects.
Improved
Sorting on vulnerability-specific columns in affected entity tables has been improved.
The MITRE risk score format in the Dashboard has been changed to A-F.
Links in the Dashboard have been updated to open stats in a new tab.
The Search & Report module has been improved to retain the searched query value.
GPO processing for Domain and OU objects has been improved.
CVEScanner files have been moved to the Main Directory ($INSTALLED_PATH\core\Temp).
Dots have been added to numbers for a better user experience.
An auto-reset has been added for the password input on the scan clone page if forest, username, or IP values are changed.
The 'Create Jira Ticket' link on the Issues page is hidden when the Jira configuration is incomplete.
Local Admin accounts have been excluded from Dangerous ACL-related issues.
The JWT default settings insert process has been moved to migration.
The scan description is now allowed to be empty.
Update packages have been moved to license.forestall.io for easy whitelisting.
Fixed
Error related to IIS TLS certificate update has been fixed.
The issue with the incorrect selection of the scan's policy when cloning a scan has been fixed.
The GPO Conflict checklist item for 'Minimum Password Length' has been fixed.
Issues with GPO Linked Entities and their count have been fixed.
JWT refresh token generation issue has been fixed.
Version 2.8.0 - 05 September 2023
Added
Coercion related issues added (FS1153, FS1154)
JWT Token Expiration configuration has been added
Default restriction on settings pages has been added. Only Admin accounts can see the settings related pages now
Improved
FS1069 SMBGhost Vulnerability has been improved to reduce false positives
CVE-Based vulnerability scanner moved into the application folder
Fixed
FS1041 Kerberoasting Vulnerability rendering bug has been fixed
PDF report generation bug has been fixed
Version 2.7.9 - 10 August 2023
Added
Coercion related issues added (FS1151, FS1152)
New attack path edges added (AddKeyCredentialLink, WriteAccountRestrictions)
LDAP authentication added
Improved
GPO Baseline comparison improved
Fixed
On premise Jira connection issue has been fixed
Version 2.7.8.7 - 14 July 2023
Added
Bulk add/delete operation feature has been added to the Vulnerability Policy
Quick search input has been added to the Advanced Search
Improved
Server-side pagination has been implemented for Entity Detail Page to enhance performance
SPNs have been relocated to objects for performance improvement
SPN insert operations have been improved for better performance
Scan policy name has been made editable
Fixed
Entity table export queries have been fixed
Version 2.7.8.3 - 03 July 2023
Improved
Calculations for Stealth Admin have been improved
Admin accounts are now excluded from the issue, Domain Group Has Local Administrator Rights on Computer (FS1104)
Domain objects marked as Admin
Fixed
Affected Objects Count bug has been resolved
Duplicate OS Version information has been removed from issues
SSL/TLS verification requirement has been removed for Jira integration
Version 2.7.8 - 20 June 2023
Added
Active Directory Trusts related issues added (FS1127, FS1128, FS1129, FS1130, FS1131)
MS-EFSCRPC coercion aka PetitPotam related issues added (FS1149, FS1150)
Stig and CIS GPO Baselines added
Comment widget added to the Issues
Docs website link added to navbar
Clone shortcut added to the Scan Policy
Column filter added to the Issues table
Improved
Scan stage info and status added to Scans
Specific columns added to Affected Entity Tables
Microsoft GPO Baselines optimized
GPO Conflicts module converted to RSoP Comparison
Filter added to GPO RSoP Comparison
RSoP(Resultant Set of Policy) added to GPO RSoP Comparison
GPO Baseline and GPO RSoP Comparison controls improved
Affected entity query improved for FS1066 and FS1098
Code highlighting added for FS1134
GPO Password Parsing module improved
Vulnerability policy UI improved
Fixed
Identification check fixed for FS1069
Mitigation script fixed for FS1069
Vulnerability Policy Relation order fixed
Scheduled scan stop/delete issue fixed
Vulnerability Policy required input field typing issue fixed
Version 2.7.7 - 05 May 2023
Added
2 new Critical Issues added
Improved
Memory management has been optimized
Reporting module has been optimized
Graph query performance has been optimized
Parallelization improved for Local Entity enumeration
SMB Share nodes moved into the Computer object
Forest Trust relation moved into Forest object
IsStealth badge added to objects other than Computer
Members of the Domain Controllers group marked as Admin
Loading added to Graph View
Fixed
Domain IP resolve issue fixed
Query limit removed for Saved Queries
Version 2.7.6 - 13 March 2023
Added
HTTPS feature added to installation
Improved
Dashboard has been optimized
Attack Surface entity tables have been optimized
Entity details pages have been optimized
Issues page has been optimized
Affected entity tables has been optimized
GPO Audit Baseline Comparison module has been optimized
Search & Report module has been optimized
Manual attack path iteration over graph has been optimized
Fixed
ADCS impersonation issue fixed
SidHistory enumeration issue fixed
Version 2.7.5 - 21 February 2023
Improved
Performance of the derivative attribute calculations
Local enumeration changed to use SAM calls
Network related scan functions combined
LocalUser and LocalGroup properties updated
FS1031, FS1066, FS1068 and FS1064 vulnerabilities details updated
Performance of the derivative attribute calculations
admin_to relation removed from domain admins and enterprise admins
Derivative query fixed for Domain Controllers
ParallelForeach improvement for Derivative Attributes
Custom Actions moved to external ps files
Neo4j service status checker added before configurations
Scan issue severities are set to static variables
Fixed
FS1027, FS1028, FS1120 and FS1126 severity updated
Language based issues fixed
Version 2.7.4 - 04 January 2023
Added
2 new issues related to LDAP
1 new attack path edge
Table visualization for detection log sources
Improved
API performance on the object details page
Access Control Entry enumeration
Code highlighting in issue scripts
Identification and Mitigation scripts
Fixed
Broken reference links
LDAP queries to support LDAP Server Signing
Logon method to support LDAP Server Signing
Minor bug in Domain Controller enumeration
Minor bug in Group Policy Object parsing
Error messages in scan start page
Version 2.7.3 - 14 December 2022
Added
2 new vulnerabilities
1 new attack path edge
Extra feature to Vulnerability Policy
On-premises Jira integration
Improved
Improved performance on Service-Based Vulnerability Scanner
Added thread-safe feature to parallel operations
Excel reports improved
Advanced Search & Reports queries has been improved
Visualize module has been improved
Fixed
Domain Controller enumeration access problems has been fixed
Issue with saved queries table pagination
Version 2.7.2 - 03 November 2022
Fixed
Issue with entities with a TRUSTED_BY relationship
Issue with redirecting to entity pages on pages with multiple types of affected entity
Issue with that the columns in the Sessions tab are blank
Version 2.7.1 - 27 October 2022
Fixed
Export CSV feature of issues entity
Version 2.7.0 - 22 June 2022
Added
ADCS specific issues
Clone action for scans
Improved
Exclusion logic for old scans
Wording for module names
Neo4j version from 3 to 4
Fixed
Bug in GPO RSOP processing
Bug in CSV export for affected objects
Bug in timezone for object attributes
Bug in GPO total linked entity count calculation
Bug in License validation
Bug in Jira integration
Version 2.6.0 - 15 February 2022
Added
License detail and upload page
New issues based on Trust attributes and relationships
Mail integration with Search & Reports module
New saved queries into Search & Reports module
Scan exlusions for different entities
Dangerous Path Count metric in Dashboard
New builtin queries into Graph module
Improved
Saved Queries UI in Search & Reports module
Fixed
Minor bugs in Search & Reports module
UI fixes on tables
Client side and server side search bugs
Access Control Entry label for ExtendedRights
Stop action for scan
Version 2.5.0 - 15 November 2021
Added
Mail integration module
Custom reporting module
Jira integration
Issue and entity exclusion module
Issue based PDF reporting
Trust enumeration
Domain details page
Readonly user profile
Detalied request logging
Improved
CVE based vulnerability scanning
PDF report improvements
Frontend performance improvements
Scan performance improvements
Database methods for performance improvoment
Fixed
Minor bug in parsing plain text passwords in Group Policy objects
Session enumeration for multiple forest/domain
Local group membership enumeration for multiple forest/domain
Version 2.4.0 - 08 June 2021
Added
New issues
New GPO conflict settings
Multi forest enumeration
New advanced search queries
Scan policy module
Scoring based on Tags, Impacts and MITRE ATT&CK Tactics
Improved
Dashboard interface
Fixed
Minor bug fixes
Version 2.3.0 - 23 April 2021
Added
New issues
New GPO conflict settings
GMSA enumeration
New attributes into entities
Multi Domain enumeration
Domain-wide 2-Way Transitive Trust enumeration
Local Service and Account enumeration
Improved
Graph Interface
RSOP Analysis
Fixed
Minor bug fixes
Version 2.0.0 - 01 January 2021
Added
Advanced Search module
Excel reporting
Risk scoring for scan
Builtin search queries for Advanced Search
Privilege based issues
Improved
Dashboard based on scan risk score
PDF Reporting
Version 1.6.0 - 10 December 2020
Added
Sessions into entity details
Groups into entity details
Network shares into entity details
Local memberships into entity details
Service principal names into entity details
IsLocalAdmin attribute into entities
Improved
Graph module layout
Data transport layer improvements
Fixed
Minor bug fixes
Version 1.5.6 - 30 November 2020
Added
New issues
Group Policy Audit module
Group Policy Baseline Comparison module
Fixed
Minor bug fixes
Version 1.5.0 - 13 November 2020
Added
Service User enumeration
Privileged Account enumeration
ShortestPath module
PathFinder module
Node specific queries into Graph module
Improved
Last updated
Was this helpful?