Arc v2.11.0
The release notes for Arc v2.11.0.
New features
A list of new features that have been introduced in this release.
- Arc-1218: Alerts generated from YARA or
Structured Threat Information Expression (STIX) detection engines now contain
the:
- Detected file path
- Real file path
- Process name and process ID (PID) that triggered the event
- Username that triggered the event
- Type of event (for example, file creation, file rename)
- Engine that reported the event (for example, Event Tracing for Windows (ETW), EaseFilter)
- ENG-3155: Updated YARA to solve multiple security issues that have no associated Common Vulnerabilities and Exposures (CVE) identifier (ID)s.
- ENG-3295: Discovery: Improved selection of available interfaces.
- ENG-3331: A Traffic summary option has been introduced for Arc as a network sensor. Arc now summarizes encrypted (transport layer security (TLS), WireGuard/VPN) and multimedia (Axis video) traffic as metadata instead of forwarding the full payloads upstream. This considerably reduces bandwidth consumption without any loss of useful data.
- ENG-3807: Security Technical Implementation Guide (STIG) Compliance: Arc can now download the SCAP Compliance Checker (SCC) dependency.
- ENG-3951: You can now enable the new Arc local user interface (UI) navigation layout.
- ENG-4092: Updated the Npcap dependency to version 1.89.
- ENG-4391: Arc now features DISA STIG Compliance capabilities, and automatically executes and reports checks requested by the upstream.
Resolved issues
A list of the bugs and defects that have been addressed in this release.
- Arc-1185: Fixed an issue in libmelco.so that caused a random segmentation fault to happen in Arc. The Arc v1.7.0 libmelco.so file contains the fix. It also deprecates the use of some functions. Installations with Arc v2.1.0 need to be updated to Arc v2.2.0, or later to be compatible with the Arc v1.7.0 libmelco.so file.
- ENG-3122: Fixed an issue that caused Offline mode to stop executing after a local UI refresh.
- ENG-3741: Fixed an issue related to the lifetime management of ETW objects.
- ENG-3787: Smart Polling: When a universal plug and play (UPnP) device is discovered, but it advertises a different address, Smart Polling only uses that address if it corresponds to the discovered device.
- ENG-3803: Smart Polling: The Schneider HTTP(S) strategy now refuses to authenticate an address that does not belong to the device targeted by the plan.
- ENG-3955: Updated system dependencies to address:
- ENG-3973: Updated system dependencies to address: