For the complete documentation index, see llms.txt. This page is also available as Markdown.

Release Notes

Version 3.1.1 - 07 July 2026

Improved

  • Network scanner reliability has been improved with configurable per-operation timeouts, preventing unresponsive hosts from delaying scans.

  • Network scanner error logging has been improved to provide clearer diagnostic details.

  • IsAnySmbV2V3Active property has been added to Computer entities and can now be used as a filter in Advanced Search.

Fixed

  • An issue where Credential Discovery scan processes could continue running after cancellation has been fixed.

  • Weak Certificate Mappings on Domain Controllers issue (FS1161) evaluation has been corrected for environments with multiple Domain Controllers.

  • SMB Signing issues (FS1017, FS1018, FS1019, FS1020) are now reported only for computers with a confirmed active SMBv2/v3 dialect, reducing false positives.

  • Unlinked Group Policy Objects issue (FS1071) detection has been improved to use resolved GPO links, preventing inconsistent results.

  • Network scan operations are now safely skipped when impersonation cannot be established.

Version 3.1.0 - 01 June 2026

Added

  • AWS IAM scanner module has been added.

  • AWS IAM Users, Groups, Roles, Policies, Access Keys, Accounts, and Organizations have been added as entities.

  • 10 new AWS issues starting with FS4001 have been added.

  • 11 new AWS attack path edges have been added, including AWS_ASSUME_ROLE, AWS_CAN_CREATE_ACCESS_KEY, AWS_HAS_ACCESS_KEY, AWS_IN_ACCOUNT, and AWS_IN_ORGANIZATION.

  • GCP IAM scanner module has been added.

  • GCP Organizations, Folders, Projects, Organizational Units, Users, Groups, Service Accounts, Service Account Keys, Roles and Devices have been added as entities.

  • 7 new GCP issues starting with FS5001 have been added.

  • 29 new GCP attack path edges have been added, including GCP_CAN_IMPERSONATE_SA, GCP_CAN_SET_PROJECT_IAMPOLICY, GCP_CAN_SSH_VM, GCP_HAS_ROLE, and GCP_IN_PROJECT.

  • Google Workspace integration has been added with 8 new attack path edges, including GWS_GRANT_ROLE, GWS_GROUP_OWNER, GWS_IN_GROUP, and GWS_RESET_PASSWORD.

  • Azure Resource Management (ARM) scanner module has been added.

  • Azure Subscriptions, Resource Groups, Management Groups, Virtual Machines, Key Vaults, SQL Servers, ARM Roles, and Managed Identities have been added as entities.

  • 15 new Azure ARM attack path edges have been added, including AZ_ARM_OWNER, AZ_CONTRIBUTOR, AZ_EXECUTE_COMMAND, AZ_HAS_ARM_ROLE, and AZ_IN_SUBSCRIPTION.

  • 9 new Azure ARM issues (FS2017-FS2025) have been added, including Guest Account Has Privileged ARM Role, Custom ARM Role With Wildcard Actions, and Resource Has Tier 0 Managed Identity Assigned.

  • Compliance module has been added with built-in control-to-issue mappings for ISO 27001, NCA Essential Cybersecurity Controls (ECC 2024), SAMA v1, and IAR frameworks.

  • Issue Timeline feature has been added to track the history of an issue across scans.

  • Stale-reason tracking has been added for identities.

  • API Tokens feature has been added for programmatic API access.

  • Model Context Protocol (MCP) server has been added, exposing scans, entities, vulnerabilities, attack paths, credential-discovery, and trend data as tools for AI assistants.

  • ScanPolicy exclusion description field has been added with a comment modal for documenting why an exclusion was created.

  • Tier 0 identity tracking and comparison across AD, Azure, AWS, and GCP have been added to Trend Insight, with hybrid relationship support.

  • Certificate Authority Disables SID Security Extension for Everyone-Like Enrollable Clients issue (FS1183) has been added.

  • Certificate Authority Disables SID Security Extension for Non-Privileged Enrollable Clients issue (FS1184) has been added.

  • Edge descriptions have been added for AZ_PASSWORD_WRITEBACK, AZ_GROUP_WRITEBACK, CanReadGMSAPassword, CreateDNSNode, and WriteEnrollmentFlag relationships.

  • CyberArk integration now supports proxy configuration.

  • Proxy support has been added to the Cloud Scanner and Azure connections.

  • Kerberos authentication has been added for environments where NTLM is disabled.

  • Bulk status-change feature has been added to the Issues page.

  • AZDevice Owner Service Principals relationship has been added.

  • Group Policy Object baseline export feature has been added.

Improved

  • Credential Discovery scan rules have been improved.

  • Hybrid attack paths from Azure to AD for Password Writeback (AZ_PASSWORD_WRITEBACK) and Group Writeback (AZ_GROUP_WRITEBACK) scenarios have been added to Tier 0 analysis.

  • Recurring scan reliability has been improved.

  • OS End-of-Life check has been updated.

  • Table search inputs now include a clear-search button and improved styling.

  • PDF report templates have been improved with platform breakdown and refreshed styling.

  • Issue page export has been improved.

  • Scans export query and status sorting have been improved.

  • Audit logging now captures role and authentication-type details.

  • Bundled PostgreSQL version has been updated to 15.17.2 for new installations.

Fixed

  • Azure Policy not being selected when creating a new scan has been fixed.

  • Everyone-like objects privilege detection has been corrected.

  • Trend Insight visibility bug has been fixed.

  • Shortest-path queries have been fixed.

  • Dashboard not loading when no scan is available has been fixed.

  • Setup issue on Windows Server 2025 has been fixed.

  • Sort bug in the Edit GPO Custom Baseline table has been fixed.

  • Privileged-role permissions and sort behavior have been fixed.

Version 3.0.1 - 28 January 2026

Added

  • Azure/Microsoft Teams scanner module has been added (additional permissions may be required for existing Entra ID integrations).

  • Azure/Microsoft SharePoint Online scanner module has been added(additional permissions may be required for existing Entra ID integrations).

  • Microsoft Teams general settings, meeting policies, message policies and external access settings have been added as entities.

  • Microsoft SharePoint Online general settings and sites have been added as entities.

  • 15 new Azure/Microsoft Teams issues starting with FS3001 have been added.

  • 11 new Azure/Microsoft SharePoint Online issues starting with FS3101 have been added.

  • Certificate-based authentication support has been added for Azure integration.

  • Scan-based access control has been added for Azure scan policies.

  • General user and device settings from Azure have been added to the Tenant Details page.

  • Client secrets and certificates to Azure Applications have been added to the Azure Application Details page.

  • Edge descriptions for Azure-related relationships have been added to the Visualize and Issue Details pages.

  • Network scan health-related information has been added to the Dashboard.

  • Choke point-related information has been added to the Dashboard.

  • Statistics similar to those available on the Dashboard have been added to Trend Insight.

  • Hybrid attack paths (Azure -> AD) for Password Writeback scenarios have been added to the graph (AZ_PASSWORD_WRITEBACK), with configuration available on the Azure Tenant Configuration page.

  • Hybrid attack paths (Azure -> AD) for Group Writeback scenarios have been added to the graph (AZ_GROUP_WRITEBACK).

Improved

  • Azure-related attack impacts have been added to the Impacts page.

  • Azure-related statistics have been added to Trend Insight.

  • Azure AD Connect Sync identities(MSOL, AAD_*, ADSyncMSA), Azure AD sync server, and related privileged groups(ADSyncAdmins, ADSyncPasswordSet) are now marked as Tier 0.

  • Edge Descriptions modals have been updated to use an accordion-style layout.

  • Tier0 Analysis feature has been added for Azure environments.

  • Audit logs now provide more detailed and clearer information for user-related changes.

  • Credential Discovery now displays scanned and total computers count while the scan is in progress.

  • User Description can now be excluded for Plaintext Passwords on Account Attributes issue (FS1074).

  • Reporter and Labels fields have been added to Jira ticket creation.

  • SMB share enumeration now uses share-level security descriptors instead of NTFS ACLs, reducing false positives. (Note: Requires local administrator privileges or registry read access on the target systems.)

  • Advanced Search now supports viewing incoming paths for Tier 0 analysis.

  • Saved queries on Mail Integration page are now organized by provider.

  • Issue detail views have been improved.

Fixed

  • An issue with sorting by Exposure Point on Scans page has been fixed.

  • An issue with regex-based searching in the Affected Entity tables has been fixed.

  • An issue with DNSNode exclusions has been fixed.

  • An issue with the exclusion type display in General Exclusions has been resolved.

Version 3.0.0 - 15 October 2025

Added

  • Azure/Entra ID scanner module has been added.

  • Azure tenants, users, groups, devices, applications, service principals, roles, administrative units, and conditional access policies have been added as entities.

  • 16 new Azure/Entra ID issues starting with FS2001 have been added.

  • Built-in search queries for Azure/Entra ID assessments have been added.

  • Single sign-on authentication support has been added.

  • DNSNode objects have been added to the entity inventory.

  • Dangerous Access Control Entries on DNS Zones from Everyone-Like Objects issue (FS1176) has been added.

  • Dangerous Access Control Entries on DNS Zones from Non-Privileged Objects issue (FS1177) has been added.

  • Dangerous Wildcard DNS Node Entry issue (FS1178) has been added.

  • Dangerous Access Control Entries on DNS Nodes from Everyone-Like Objects issue (FS1179) has been added.

  • Dangerous Access Control Entries on DNS Nodes from Non-Privileged Objects issue (FS1180) has been added.

  • CreateDNSNode, WriteDNSRecord, and APPLY_GPO attack-path edges have been added.

  • Scan policy-based access control has been added.

  • Scan policy-based Jira ticket creation capability has been added.

  • Scan start validation testing has been added.

  • Group Policy Object baseline import capability has been added.

  • Edge descriptions have been added to the Visualize and Issue Details pages.

  • Recurring scan difference email notifications have been added.

Improved

  • Tier0 analysis graph visualization has been improved.

  • Search & Report now supports adjusting relation directions.

  • Security Filter support has been added to the GPO Audit module.

  • Row-based exclusion management and UI have been improved.

  • Scan deletion performance has been improved.

  • Built-in GPO baselines have been refined.

  • Bundled Python version has been updated to 3.13.5 for new installations and upgrades.

  • Bundled PostgreSQL version has been updated to 15.14.1 for new installations.

  • License compliance controls have been improved.

  • Provider Type attribute has been added to the Policies, Issues, and Search & Reports pages.

  • Default Credential Discovery exclusions (.venv, node_modules, WindowsApps, Cortana) have been updated for improved performance.

  • Tier0 objects on the Visualize page now display a dedicated icon.

  • LDAP access control evaluation now honors SID values.

  • Affected entity comparison logic has been enhanced.

  • Graph shortcuts on entity detail pages have been improved.

  • Search & Report now offers a table view for Tier0 analysis results.

  • Entity distinguished name values are now displayed on the Visualize page.

  • Share Audit module has been renamed to Credential Discovery.

  • Stealth Admin designation has been renamed to Shadow Admin.

Fixed

  • Audit log file formatting issues have been fixed.

  • Issues where GPOs were applied to logical false positives have been fixed.

  • Vulnerability Policy import no longer overwrites existing definitions unintentionally.

  • DNSAdmin identification logic has been fixed.

  • Computer description filtering in Search & Report has been corrected.

  • Multiple scan execution stability has been improved.

  • Organizational unit-based exclusion controls have been fixed.

  • API key display on the Jira integration page has been corrected.

Version 2.9.1 - 23 June 2025

Added

  • Delegated Managed Service Account(dMSA) objects have been added.

  • Dangerous DMSA Superseded Account issue (FS1173) has been added.

  • Suspicious DMSA Superseded Account issue (FS1174) has been added.

  • Dangerous Access Control Entries for BadSuccessor issue (FS1175) has been added.

  • 2 new attack path edges (CreateDMSA and DMSAFullTakeover) have been added.

  • Import and export functionality has been added for Scan and Vulnerability Policies.

  • Tier0 Analysis module has been introduced for visualizing choke points. Note: It's a Beta version. You have to enable 'Tier0 Analysis' module from Scan Policy.

  • Custom tagging feature has been added for Issues.

  • Customizable Status Info feature has been added for Issues.

  • Sending reports for finished scans as e-mail has been added.

  • Audit logs can now be sent to a remote Syslog server.

  • New policy creation feature based on existing base policies has been added.

  • DMSAs with Explicit Local Admin Privileges query has been added to Search & Report.

Improved

  • Scan scheduling has been enhanced to better support Continuous Assessment.

  • HTTP Endpoint is Enabled for the Certificate Enrollment issue (FS1145) mitigation steps have been improved.

  • EPA is not in place on HTTPS Endpoint for the Certificate Enrollment issue (FS1146) mitigation steps have been improved.

  • Bulk action feature has been added to Scan Policy and Custom GPO Baselines tables.

  • Performance of the Share Audit module has been optimized.

  • Real-time statistics display feature has been added for active Share Audit scans.

  • Report access controls are now user-configurable.

  • Filtering and sorting capabilities have been added to Built-in user Management table.

  • Session enumeration controls have been improved.

Fixed

  • Tier0 identification for Group Policy objects has been improved.

  • Tier0 identification for Cross domain members has been improved.

  • Broken objects links on Advanced Search and Visualize has been fixed.

  • Navigate to Visualize page when on Visualize page problem has been fixed.

  • Tables responsiveness issue on small screens has been fixed.

Version 2.9.0 - 24 February 2025

Added

  • EveryoneRead and EveryoneWrite controls have been added to ShareAudit module.

  • Support for multiple LDAP integrations has been added.

  • Built-in user Management page has been added.

  • Suspicious Access Control Entries on DPAPI Key (FS1169) issue has been added.

  • Insecure Trust Configuration for NT4 Systems (FS1170) issue has been added.

  • Insecure LM/NTLM Authentication Level (FS1171) issue has been added.

  • Default Password for Pre-Windows 2000 Computer Accounts (FS1172) issue has been added.

  • 2 new attack path edges (SyncLAPSPassword and DCSync) have been added.

  • Get All Shortest Path to Here from Non-Privileged Objects query has been added to visualize.

  • Get All Shortest Path to Here from Everyone-Like Objects query has been added to visualize.

  • Tier0 and Tier2 labels have been added to Entities.

  • A Tier0 and Tier2 based filtering feature has been added to Advanced Search.

  • Compare affected entities across scans feature has been added.

Improved

  • Computer-based SMB Share filters have been added to Search & Reports.

  • Coercion enumerations specific module has been added to Scan Policies.

  • Dashboard performance has been optimized.

  • Plaintext Passwords on Account Attributes(FS1074) issue control has been improved.

  • LAPSV2 usage controls has been improved.

  • WSUS identification controls have been improved.

Fixed

  • Issues and RSOP Comparison tables export issue has been fixed.

  • Advanced Search IP Range filter issue has been fixed.

  • GPLINK relations were not found across different domains issue has been fixed.

  • Custom Tier0 mark issue for Group Entities has been fixed.

  • Missing failed scan emailing checks has been fixed.

  • Scan status hanging on Share Audit issue has been fixed.

Version 2.8.9 - 13 November 2024

Added

  • Trend Insight Dashboard has been introduced for enhanced data visualization

  • Run on Graph functionality is now available in Advanced Search

  • Suppress feature has been added to the Share Audit Secrets table

  • Exposure Point metrics are now included in Issues, Entities, Impacts, and Scans

  • Comprehensive General Health Check feature has been implemented

  • Scan Failure Email Notification feature has been introduced

  • Shortcuts for Explicit and Group Delegated Local Admin queries are now accessible on User and Computer details pages

  • Computer IP Range filter has been added to Advanced Search

  • General Exclusion feature, allowing exclusions by IP, Share Name, and Folder Path, has been added to the Share Audit module.

  • Feature to retrieve the n characters immediately before and after a detected secret has been added to the Share Audit module.

Improved

  • The Scan Dashboard user interface has been enhanced.

  • The Computers Added into Domain by Unprivileged Users issue (FS1098) now includes a two-way definition.

  • Performance of the Share Audit module has been optimized.

  • Automatic update of ticket URLs is now available when the Jira URL is modified.

  • Enhanced messaging for LDAP authentication failures.

  • LDAP base search validation has been added.

  • Improved performance for Stealth Admin identification and related queries.

  • Inter-Domain/Forest-based issues (FS1122, FS1123, FS1125) scan performance has been optimized.

  • Affected Entity Bulk Exclusion feature has been enhanced.

  • Updated page size options (10, 25, 50, 100, 250, 500) across all tables.

  • Optimized performance on the Impacts page.

  • MITRE tactics are now included in the Issues table and details page.

  • Enhanced severity-based sorting for the Issues table.

  • Exploitation Privilege and Exploitation Certainty variables have been added to the Issue details page.

  • PDF reports now include Forest, Domain, Policy, and Exposure Point details.

Fixed

  • Resolved an issue with identifying Privileged Groups Cross-Domain Members.

  • Fixed the incorrect link issue in vulnerability visualization.

  • Addressed the incorrect scan duration issue in email notifications.

  • Corrected the license read permission control issue on the frontend.

Version 2.8.8-3 - 08 October 2024

Added

  • Certificate Template Allows Everyone-Like Clients to Specify Arbitrary SAN and Application Policies (FS1167 - ESC15) issue has been added.

  • Certificate Template Allows Non-Privileged Clients to Specify Arbitrary SAN and Application Policies (FS1168 - ESC15) issue has been added.

Version 2.8.8 - 29 August 2024

Added

  • Share Audit feature has been added to SMB Shared folder secret finding.

  • Environment-specific Tier Zero Asset addition feature has been added.

  • Custom baseline feature has been added to Group Policy Audit.

  • SMTP relay feature has been added to Mail Configuration.

  • MITRE ATT&CK Tactics, Impact and Tag based 20 Built-in Scan Policies has been added.

  • Display Specifier objects have been added.

  • Abnormal Display Specifiers (FS1165) issue has been added.

  • Certificate Template Enables Authentication & Contains No Security Extension Flag (FS1160) issue has been added.

  • Weak Certificate Mappings on Domain Controllers (FS1161) issue has been added.

  • ICertRequest Encryption is not Enforced (FS1166) issue has been added.

  • FSProtect Server IpAddress and IIS Certificate change scripts have been added to Scripts directory.

  • License expiration message bar has been added.

Improved

  • Active Directory object and relation enumeration performance has been improved.

  • Scan failure messages have been improved and added to scan stage section.

  • Automatic last scan selection feature has been added when authenticating.

  • A message has been added for cases where the last scan is not selected.

  • The auto-refresh feature for the issue count has been added to the navigation bar.

  • Empty string filter option has been added to Affected Entity Table.

  • Select/Deselect All option has been added to Affected Entity Table ACL columns.

  • IsEmpty filter property has been added to GPO entities for Advanced Search.

  • The performance of the built-in query runner function visualization has been improved.

  • The queries for visualizing Local Admin findings have been enhanced.

  • The function for finding IP addresses of Active Directory Computer objects has been improved.

Fixed

  • Inter Domain/Forest graph queries have been fixed by excluding script objects.

  • AffectedEntityTable invalid regex filter exception has been fixed.

  • Open SMB Shares on Computers issue when scanning with Local Administrator accounts has been fixed.

  • Affected Entity PDF generation bug has been fixed for issue related to DNSZone.

Version 2.8.7 - 06 June 2024

Added

  • Row-based exclusion feature has been added on the Affected Entity tables.

  • Relation-based advanced search feature has been added.

  • CyberArk integration has been added to automate the synchronization of scan access information.

  • One new attack path edge (ManageGPLink) has been added.

  • Issues for Non-Privileged Authorized LAPS Decryptors (FS1163) and Everyone-Like Authorized LAPS Decryptors (FS1164) have been added.

  • Insecure WSUS HTTP Protocol (FS1162) issue has been added.

  • Five new built-in advanced search queries have been added.

  • Issue cards in the dashboard have been made clickable.

  • Graph v2 has been released.

  • Graph v2: Multiple new Graph layouts have been added.

  • Graph v2: A new widget allows viewing relationships in a table format.

  • Graph v2: Settings within the Graph visualization are now configurable.

  • Graph v2: A new widget for filtering relationships in the Graph has been introduced.

  • Graph v2: Clusters can now be created based on relationship type, relationship direction, and object type.

  • Graph v2: Relationships are now highlighted for better visibility.

  • Graph v2: The widget displaying the relationships of objects has been updated.

Improved

  • Performance of Stealth Admin and Dangerous Path Count identification queries has been improved.

  • LAPS identification has been improved for LAPS V2.

  • Hangfire version has been upgraded to 1.8.12.

  • Hangfire values has been moved to PostgreSQL.

  • Count query for Affected Entity tables has been improved.

  • IsEmpty filter has been added to Search & Report module.

  • IsWindowsClient column has been replaced with IsWindowsOS.

Fixed

  • Scan Policies connected with a Scan have been made editable.

  • Deletion of initial scan access information has been enabled.

  • New automated permission sync feature has been added.

  • ManagedServiceAccount host service formatter has been fixed.

  • OS identifying has been improved for CVE-based scanner.

  • Recurring Scan Policy changing issue has been fixed.

Version 2.8.6 - 22 April 2024

Added

  • Column based filter has been added to Affected Entity Tables.

  • Role-based Access Control(RBAC) feature has been added.

  • JIRA bulk ticket creation feature has been added.

  • WebClient is Active on Computers(FS1156) and WebClient is Active on Critical Computers(FS1157) issues have been added.

  • DNSZone object enumeration has been added.

  • Insecure DNSZone Dynamic Update(FS1158) issue has been added.

  • Dangerous Access Control Entries on Containers(FS1159) issue has been added.

  • 3 new attack path edges (CreateComputer, CreateUser, CreateAny) have been added.

  • Container objects have been added as affected entity to the FS1046 and FS1093 issues.

  • Ldap Signing based connection type has been added.

Improved

  • Container object parsing process has been improved.

  • The default database has been changed with PostgreSQL for performance imrovements.

  • Affected entity tables have been moved to PostgreSQL for performance imrovements.

  • Resultant Set of Policy (RSoP) analysis has been improved.

  • NetworkCredential usage method has been improved.

  • PDCTime control has been improved.

  • Standalone Managed Service Account control has been improved.

  • Ldap authentication dependency has been updated.

  • The exclusion type of the Built-in group membership issues (FS1049, FS1050, FS1051, FS1052, FS1057, FS1060, FS1087, FS1108) has been updated from one-way to two-way definition.

  • PolicyRulesFileBuilder file has been moved to the Temp directory.

Fixed

  • Global IP, IPRange and OU exclusion issue has been fixed.

  • Domain Controller identification has been fixed.

  • Loading bug of the FS1147 issue detail page has been fixed.

  • SMBv1 Parser has been fixed.

  • SpoolerScanner impersonation has been fixed.

Version 2.8.5 - 12 February 2024

Added

  • Scan comparison feature has been added to Dashboard.

  • Scan comparison feature has been added to Issues.

  • Scan based caching has been added to filterable issue table columns.

Improved

  • CVE Scanner has been improved.

  • Query for calculating GPO Linked Entity Count has been improved.

  • Loading performance of the issues table has been improved.

  • IsComputerClient and IsWindowsServer properties have been added to Computers.

Fixed

  • Sorting issue in the Affected Computer table for the 'Online' column has been fixed.

  • Access issue to the Policies page from some remote clients has been fixed.

  • Access permission for the API folder has been fixed.

  • Parser issue with ForeignSecurityPrincipal has been fixed.

  • Issue with forest trust identification has been fixed.

  • Large Index exception for Computer, User, MSA, and GMSA indexes has been fixed.

  • Performance issue with InheritedObjectType migration has been fixed.

  • CreateInitialGroupsMembership exception has been fixed.

  • FS1084 - 'LDAP Channel Binding is not Enabled on Domain Controllers' issue check has been fixed.

Version 2.8.4 - 15 January 2024

Added

  • Column Hide/Show feature has been added to Issue, Attack Surface and RSoP Comparison tables.

  • Last state storage feature for Scan, Issue and all Entity tables has been added.

  • Include Disabled and Include Inactive filter options has been added to Scan Policy.

  • Inactive filter option has added to Search&Report for User, Computer, Managed Service Account and Group Managed Service Account.

  • Inactive Users, Inactive Computers, Inactive Managed Service Accounts and Inactive Group Managed Service Accounts built-in queries has been added.

  • MSA and GMSA tabs has been added to Group entity details page.

  • FSID and Comment count columns has been added to Issue table.

Improved

  • FS1043 and FS1046 issues control have been improved.

  • Core App Memory optimization has been improved.

  • Issues table loading performance has been improved.

  • JDK version upgraded to 15.0.2.

  • IsComputerClient and IsWindowsServer properties have been added to Computers.

Fixed

  • ACE issue has been fixed with ACE Inheritance Filter.

  • ForeignSecurityPrincipals parse issue has been fixed.

  • User Local Memberships count issue has been fixed.

  • Open entity in different scan on graph page issue has been fixed.

  • FS1063 issue control has been disabled by default.

Version 2.8.3 - 25 December 2023

Added

  • Added Scheduled Scan Date Time and Frequency change feature.

  • Added 'Not like' filtering option for string variables in Advanced Search.

  • Added Shortcut Link to Graph Page Nodes.

  • GPO Flags property has been added to GPO Details page.

Improved

  • FS1066 issue has been improved.

  • Core App chunk insertion has been improved.

  • OS End-of-Life check for FS1009 and FS1010 issues has been updated.

  • Added Enabled and Windows control to Network Scanner.

  • Exception based EPA/HTTP Connection retry has been added.

  • GPO Descriptions updated for Baseline and RSoP pages.

  • Added pending system update check.

  • Details pages row format has been improved.

  • DomainControl control has been improved.

  • Added API link to login failed message.

  • Scan Policy Info titles has been changed.

  • Computer Sessions table columns has been improved.

  • Visualize Range Counter values (Min: 50, Max: 1.000, Step:50) has been changed.

  • Removed record not found logs for RecycleBin and DsHeuristics.

  • Removed Initial HTTP Request 404 status log for certificate.

Fixed

  • SSPI error(supported ssl/tls protocol) fixed.

  • Group Policy rules parsing issue has been fixed.

  • Fixed conflict issue in Add Generic SPNs.

  • Conflicts of adding collected sessions has been fixed.

  • Domain related Entity SID dictionary conflict has ben fixed.

  • Baseline and RSoP table total page number confusion has been fixed.

  • Computer Shares table row key not found issue has been fixed.

Version 2.8.2 - 15 November 2023

Added

  • Password check in user description to FS1074 issue has been added.

  • Policy change feature for scheduled scans has been added.

Improved

  • FS1082 and FS1108 issue checking have been improved.

  • Open SMB Share IsEveryone access control has been improved.

  • Number formatting added to OU, GPO and Group detail pages.

  • Operating System empty check has been added to FS1069 issue.

  • Advanced Search filterable attributes updated for LocalUser.

  • Stealth Admin finding query has been updated to start from unprivileged accounts.

  • PDC time check has been improved.

  • Generate Excel Report process has been moved to new url.

  • Empty check has been added to Number Formatter.

  • ACE Identity Type value has been updated for MSSQLSvc accounts.

  • Contains a value check has been added for Generic SPNs.

Fixed

  • Service-Based Security Assessment module control has been fixed.

  • Forest name duplicate issue has been fixed.

  • CanReadGMSAPassword Access Control Entry typo has been fixed.

  • Tab components were changed for pagination of server-side tables was not working correctly.

  • Excel Report row limit bug has been fixed.

Version 2.8.1 - 16 October 2023

Added

  • Container objects have been added.

  • AdminSDHolder-related issue (FS1091) has been added.

  • Standalone Managed Service Account (sMSA) related issue (FS1155) has been added.

  • A new attack path edge (DUMP_SMSA_PASSWORD) has been added.

  • Links for Stealth Admin and Risky Admin have been added to the Dashboard.

  • Stealth Admin User Count has been added to the Dashboard.

  • Stealth Admin search query has been added to Built-in Queries.

  • A different email sender input has been added for email relay.

  • Block Inheritance attribute has been added to Domain objects.

Improved

  • Sorting on vulnerability-specific columns in affected entity tables has been improved.

  • The MITRE risk score format in the Dashboard has been changed to A-F.

  • Links in the Dashboard have been updated to open stats in a new tab.

  • The Search & Report module has been improved to retain the searched query value.

  • GPO processing for Domain and OU objects has been improved.

  • CVEScanner files have been moved to the Main Directory ($INSTALLED_PATH\core\Temp).

  • Dots have been added to numbers for a better user experience.

  • An auto-reset has been added for the password input on the scan clone page if forest, username, or IP values are changed.

  • The 'Create Jira Ticket' link on the Issues page is hidden when the Jira configuration is incomplete.

  • Local Admin accounts have been excluded from Dangerous ACL-related issues.

  • The JWT default settings insert process has been moved to migration.

  • The scan description is now allowed to be empty.

  • Update packages have been moved to license.forestall.io for easy whitelisting.

Fixed

  • Error related to IIS TLS certificate update has been fixed.

  • The issue with the incorrect selection of the scan's policy when cloning a scan has been fixed.

  • The GPO Conflict checklist item for 'Minimum Password Length' has been fixed.

  • Issues with GPO Linked Entities and their count have been fixed.

  • JWT refresh token generation issue has been fixed.

Version 2.8.0 - 05 September 2023

Added

  • Coercion related issues added (FS1153, FS1154)

  • JWT Token Expiration configuration has been added

  • Default restriction on settings pages has been added. Only Admin accounts can see the settings related pages now

Improved

  • FS1069 SMBGhost Vulnerability has been improved to reduce false positives

  • CVE-Based vulnerability scanner moved into the application folder

Fixed

  • FS1041 Kerberoasting Vulnerability rendering bug has been fixed

  • PDF report generation bug has been fixed

Version 2.7.9 - 10 August 2023

Added

  • Coercion related issues added (FS1151, FS1152)

  • New attack path edges added (AddKeyCredentialLink, WriteAccountRestrictions)

  • LDAP authentication added

Improved

  • GPO Baseline comparison improved

Fixed

  • On premise Jira connection issue has been fixed

Version 2.7.8.7 - 14 July 2023

Added

  • Bulk add/delete operation feature has been added to the Vulnerability Policy

  • Quick search input has been added to the Advanced Search

Improved

  • Server-side pagination has been implemented for Entity Detail Page to enhance performance

  • SPNs have been relocated to objects for performance improvement

  • SPN insert operations have been improved for better performance

  • Scan policy name has been made editable

Fixed

  • Entity table export queries have been fixed

Version 2.7.8.3 - 03 July 2023

Improved

  • Calculations for Stealth Admin have been improved

  • Admin accounts are now excluded from the issue, Domain Group Has Local Administrator Rights on Computer (FS1104)

  • Domain objects marked as Admin

Fixed

  • Affected Objects Count bug has been resolved

  • Duplicate OS Version information has been removed from issues

  • SSL/TLS verification requirement has been removed for Jira integration

Version 2.7.8 - 20 June 2023

Added

  • Active Directory Trusts related issues added (FS1127, FS1128, FS1129, FS1130, FS1131)

  • MS-EFSCRPC coercion aka PetitPotam related issues added (FS1149, FS1150)

  • Stig and CIS GPO Baselines added

  • Comment widget added to the Issues

  • Docs website link added to navbar

  • Clone shortcut added to the Scan Policy

  • Column filter added to the Issues table

Improved

  • Scan stage info and status added to Scans

  • Specific columns added to Affected Entity Tables

  • Microsoft GPO Baselines optimized

  • GPO Conflicts module converted to RSoP Comparison

  • Filter added to GPO RSoP Comparison

  • RSoP(Resultant Set of Policy) added to GPO RSoP Comparison

  • GPO Baseline and GPO RSoP Comparison controls improved

  • Affected entity query improved for FS1066 and FS1098

  • Code highlighting added for FS1134

  • GPO Password Parsing module improved

  • Vulnerability policy UI improved

Fixed

  • Identification check fixed for FS1069

  • Mitigation script fixed for FS1069

  • Vulnerability Policy Relation order fixed

  • Scheduled scan stop/delete issue fixed

  • Vulnerability Policy required input field typing issue fixed

Version 2.7.7 - 05 May 2023

Added

  • 2 new Critical Issues added

Improved

  • Memory management has been optimized

  • Reporting module has been optimized

  • Graph query performance has been optimized

  • Parallelization improved for Local Entity enumeration

  • SMB Share nodes moved into the Computer object

  • Forest Trust relation moved into Forest object

  • IsStealth badge added to objects other than Computer

  • Members of the Domain Controllers group marked as Admin

  • Loading added to Graph View

Fixed

  • Domain IP resolve issue fixed

  • Query limit removed for Saved Queries

Version 2.7.6 - 13 March 2023

Added

  • HTTPS feature added to installation

Improved

  • Dashboard has been optimized

  • Attack Surface entity tables have been optimized

  • Entity details pages have been optimized

  • Issues page has been optimized

  • Affected entity tables has been optimized

  • GPO Audit Baseline Comparison module has been optimized

  • Search & Report module has been optimized

  • Manual attack path iteration over graph has been optimized

Fixed

  • ADCS impersonation issue fixed

  • SidHistory enumeration issue fixed

Version 2.7.5 - 21 February 2023

Improved

  • Performance of the derivative attribute calculations

  • Local enumeration changed to use SAM calls

  • Network related scan functions combined

  • LocalUser and LocalGroup properties updated

  • FS1031, FS1066, FS1068 and FS1064 vulnerabilities details updated

  • Performance of the derivative attribute calculations

  • admin_to relation removed from domain admins and enterprise admins

  • Derivative query fixed for Domain Controllers

  • ParallelForeach improvement for Derivative Attributes

  • Custom Actions moved to external ps files

  • Neo4j service status checker added before configurations

  • Scan issue severities are set to static variables

Fixed

  • FS1027, FS1028, FS1120 and FS1126 severity updated

  • Language based issues fixed

Version 2.7.4 - 04 January 2023

Added

  • 2 new issues related to LDAP

  • 1 new attack path edge

  • Table visualization for detection log sources

Improved

  • API performance on the object details page

  • Access Control Entry enumeration

  • Code highlighting in issue scripts

  • Identification and Mitigation scripts

Fixed

  • Broken reference links

  • LDAP queries to support LDAP Server Signing

  • Logon method to support LDAP Server Signing

  • Minor bug in Domain Controller enumeration

  • Minor bug in Group Policy Object parsing

  • Error messages in scan start page

Version 2.7.3 - 14 December 2022

Added

  • 2 new vulnerabilities

  • 1 new attack path edge

  • Extra feature to Vulnerability Policy

  • On-premises Jira integration

Improved

  • Improved performance on Service-Based Vulnerability Scanner

  • Added thread-safe feature to parallel operations

  • Excel reports improved

  • Advanced Search & Reports queries has been improved

  • Visualize module has been improved

Fixed

  • Domain Controller enumeration access problems has been fixed

  • Issue with saved queries table pagination

Version 2.7.2 - 03 November 2022

Fixed

  • Issue with entities with a TRUSTED_BY relationship

  • Issue with redirecting to entity pages on pages with multiple types of affected entity

  • Issue with that the columns in the Sessions tab are blank

Version 2.7.1 - 27 October 2022

Fixed

  • Export CSV feature of issues entity

Version 2.7.0 - 22 June 2022

Added

  • ADCS specific issues

  • Clone action for scans

Improved

  • Exclusion logic for old scans

  • Wording for module names

  • Neo4j version from 3 to 4

Fixed

  • Bug in GPO RSOP processing

  • Bug in CSV export for affected objects

  • Bug in timezone for object attributes

  • Bug in GPO total linked entity count calculation

  • Bug in License validation

  • Bug in Jira integration

Version 2.6.0 - 15 February 2022

Added

  • License detail and upload page

  • New issues based on Trust attributes and relationships

  • Mail integration with Search & Reports module

  • New saved queries into Search & Reports module

  • Scan exlusions for different entities

  • Dangerous Path Count metric in Dashboard

  • New builtin queries into Graph module

Improved

  • Saved Queries UI in Search & Reports module

Fixed

  • Minor bugs in Search & Reports module

  • UI fixes on tables

  • Client side and server side search bugs

  • Access Control Entry label for ExtendedRights

  • Stop action for scan

Version 2.5.0 - 15 November 2021

Added

  • Mail integration module

  • Custom reporting module

  • Jira integration

  • Issue and entity exclusion module

  • Issue based PDF reporting

  • Trust enumeration

  • Domain details page

  • Readonly user profile

  • Detalied request logging

Improved

  • CVE based vulnerability scanning

  • PDF report improvements

  • Frontend performance improvements

  • Scan performance improvements

  • Database methods for performance improvoment

Fixed

  • Minor bug in parsing plain text passwords in Group Policy objects

  • Session enumeration for multiple forest/domain

  • Local group membership enumeration for multiple forest/domain

Version 2.4.0 - 08 June 2021

Added

  • New issues

  • New GPO conflict settings

  • Multi forest enumeration

  • New advanced search queries

  • Scan policy module

  • Scoring based on Tags, Impacts and MITRE ATT&CK Tactics

Improved

  • Dashboard interface

Fixed

  • Minor bug fixes

Version 2.3.0 - 23 April 2021

Added

  • New issues

  • New GPO conflict settings

  • GMSA enumeration

  • New attributes into entities

  • Multi Domain enumeration

  • Domain-wide 2-Way Transitive Trust enumeration

  • Local Service and Account enumeration

Improved

  • Graph Interface

  • RSOP Analysis

Fixed

  • Minor bug fixes

Version 2.0.0 - 01 January 2021

Added

  • Advanced Search module

  • Excel reporting

  • Risk scoring for scan

  • Builtin search queries for Advanced Search

  • Privilege based issues

Improved

  • Dashboard based on scan risk score

  • PDF Reporting

Version 1.6.0 - 10 December 2020

Added

  • Sessions into entity details

  • Groups into entity details

  • Network shares into entity details

  • Local memberships into entity details

  • Service principal names into entity details

  • IsLocalAdmin attribute into entities

Improved

  • Graph module layout

  • Data transport layer improvements

Fixed

  • Minor bug fixes

Version 1.5.6 - 30 November 2020

Added

  • New issues

  • Group Policy Audit module

  • Group Policy Baseline Comparison module

Fixed

  • Minor bug fixes

Version 1.5.0 - 13 November 2020

Added

  • Service User enumeration

  • Privileged Account enumeration

  • ShortestPath module

  • PathFinder module

  • Node specific queries into Graph module

Improved

Last updated

Was this helpful?