Release Notes for Snare Windows Agent v5.3.1

Snare Windows Agent v5.3.1 was released on 12th September 2019.

  • Various bug fixes
  • Allows customers to upgrade from v5.3.1 using SAM Centralized Agent Upgrades feature. (Note: Don’t try to upgrade using SAM from v5.3.0)
  • Resolved an issue in the destination handling when a TCP destination was incorrectly treated as TLS destination. Due to this issue the Snare service can stop and require restart. This issue is fixed in this release and now Snare handles the mismatch of destination properly
  • Updated Windows events matching against Exclude objectives: if the event is not matching the exclude filter, the agent will move on to the next objective to look for a match, rather than including the event. This bug made it impossible to have multiple exclude objectives with different criteria
  • Fixed an issue whereby Log Filters were not filtering correctly when more than one filter was configured, and the filter included an "Exclude" filter