Release Notes for Snare Windows Agent with Event Collection v5.3.1

Snare Windows Agent with Event Collection v5.3.1 was released on 12th September 2019.

  • Various bug fixes
  • Resolved an issue in the destination handling when a TCP destination was incorrectly treated as TLS destination. Due to this issue the Snare service can stop and require restart. This issue is fixed in this release and now Snare handles the mismatch of destination properly
  • Updated Windows events matching against Exclude objectives: if the event is not matching the exclude filter, the agent will move on to the next objective to look for a match, rather than including the event. This bug made it impossible to have multiple exclude objectives with different criteria
  • Fixed an issue whereby Log Filters were not filtering correctly when more than one filter was configured, and the filter included an "Exclude" filter

.