Resolved issues

Prev Next

The following issues were resolved in the Endpoint Security Agent (HX) 35.31.28 release.

Tracking number

Summary

ENDPT-112466

The Enterprise Search agent audit feature encountered restraints during data collection which prevented it from examining some processes and files. Instances when audit package actions are not visible to Enterprise Search are logged. Audits have a constraint setting to prevent abnormal results using excessive disc space on the HX server. Excessive logging of audit packages that are not visible to Enterprise Search caused performance issues with the audit constraint. This issue prevented the Enterprise Search from retrieving the SHA256 file hash. This issue has been resolved.

ENDPT-111598

Proxy settings are manually created using the command line netssh winhttp for agents running on Windows version 64 environments, committing the DefaultConnectionSetting for the proxy to the appropriate registry key. The agent referenced the base registry key to acquire the value for that proxy setting. This prevented the agent from acquiring the correct proxy setting if the setting had been applied via the netssh winhttp command line. This issue has been resolved.

ENDPT-111469

The persistence audit is a form of data acquisition that searches for files via registry entries. This permits the audit to search for files missing an extension. The persistence audit would frequently reference network files during data acquisition. Verifying the network file with multiple extension types over the network frequently caused the audit to expire due to excessive memory usage. This issue has been resolved.

ENDPT-111164

A debugger process launch, such as lldb, prompts other debug process attempts in a macOS environment. The lldb debugger process prompts the Golang delve debugger to launch. Malware protection blocked the authorization of the process ID, preventing the debugger from attaching to the Golang process running beneath lldb. This issue has been resolved.

ENDPT-110834

The On-Demand Scan feature was configured to scan single files as directories in a Windows environment for Malware protection. This configuration caused the scan to fail. This issue has been resolved.

ENDPT-110365

macOS network filtering provides security details to registered third-party network systems extensions, such as Symantec WSS. This caused DNS performance issues for third-party products when the DNS and Web Protection features were enabled. Inbound DNS requests with responses to the filter mechanism in the operating system failed to reach the application leading to a DNS timeout. This issue has been resolved.

ENDPT-111107

An AMSI module policy containing an array of unnamed MD5 exclusions prevented the exportation of the agent config file. This issue has been resolved.

ENDPT-111241

Network process exclusions were not honored if the network process started before the agent software. This issue has been resolved.