August 29, 2022 Service Pack

The following Service Pack versions were released:

Versions (Sensor and Server)

21.1.482

The tables below describe the enhancements, fixed issues, and changes included in each version.

  • The Versions column indicates the versions that include the fix. (For more information, see the note above)

  • The Required Update column indicates if the fix requires sensor/server update.

IMPORTANT: If you want to upgrade your servers to this version, we recommend that you upgrade all components - Registration server, Detection servers, and WebApp server - to this version.

Included issues

Issue

Area

Description

Required Update

Supported OS

DFND-19717

Device Control

When using Device Control, after you disable or enable a Read Only for USB devices, endpoint machine users no longer need to re-mount a USB device to ensure that the sensor enforces the Read Only policy setting.

Sensor and server

Windows, Linux

DFND-20395

Sensor installation

As part of the initiative to meet MVI (Microsoft virus initiative) requirements, we have added a warning and a logic to stop installation when you try to install a sensor on a machine running Windows 7. This installation prevention is due to the fact that the Sectigo certificate used for the MVI compliance is not supported on Windows 7.

Sensor and server

Windows

DFND-22221

Anti-Ransomware

In previous versions, the crsdll.dll file required for Anti-Ransomwaredid not upgrade properly as part of the version upgrade flow.

We have resolved this issue and this DLL file will upgrade correctly in the overall upgrade flow.

Sensor and server

Windows

DFND-15669

Process information collection

At times, when the sensor collected details on the command lines used by processes, the collector on the sensor would add an extra space in the command line string that was sent to the detection server. As a result, if you built a behavioral allowlisting rule to exclude the command line from creating a Malop, the behavioral allowlisting rule would not correctly trigger Malops.

This issue has been resolved and the command line is collected and sent to the Detection server correctly without the extra spaces.

Sensor and server

Windows

DFND-681

Machine isolation

By default, actions sent to offline sensors are queued for 3 days. If, after 3 days, the sensor has not come back online, the action is no longer queued and will not execute if the sensor comes back online at a later time. Now, the queued period can be customized.

Sensor and server

All