Tip |
---|
Snare Windows Agent v5.1.0 was released on 11th April 2018. |
New Features
- Introducing the File Integrity Monitoring (FIM) module to provide file or directory hash details . The FIM module can be used to scan files/directories and compare against a known baseline of file details including file attributes and hash (sha512) details. Events are generated upon changes to file contents or attributes. The new screen in the agent allows the user to select a file, directory and recursively scan multiple directories to include or exclude files or directory locations as needed. This new feature will generate a new Snare log type called FIMLog. For reporting in Snare Central the system will need to be patched to 7.3.0 to understand the new log type, prior to this version it will show up as GenericLog. As part of this new feature in the agent the Latest Events page in the agent has a new tab " File Integrity" to show the FIM events. This new FIM feature is designed to complement the other FIM/FAM file activity event log reporting the agent current has.
- As of <INSERT DATE> the Snare windows agent has achieved Veracode VerAfied security compliance to VL4 status. The 5.1.0 version of the Snare Windows agent now meets the Veracode VL4 certification policy criteria. By using Veracode independent source code static analysis methods there are no very high, high, or medium security rated vulnerabilities present based on OWASP top 10 and SANS top 25 coding vulnerabilities. See the following for more information https://www.veracode.com/get-verafied-and-listed
...