Arc v2.10.0

The release notes for Arc v2.10.0.

New features

A list of new features that have been introduced in this release.

  • ENG-1736: All Arc alerts, except those generated by Arc Embedded, now contain the list of users that were logged on the machine.
  • ENG-2103: Smart Polling: The new SEL Axion strategy can be used to poll SEL Axion devices that expose the REST API over hypertext transfer protocol secure (HTTPS).
  • ENG-2187: The Arc Federal Information Processing Standards (FIPS) bundle no longer requires the supporting operating system (OS) to provide the FIPS-140 cryptographic libraries. For example, you can now run an Arc FIPS executable from a Windows machine that is not configured in FIPS mode. Previously, this was explicitly blocked.
  • ENG-2270: Dependency management is now available from Vantage and from N2OS v26.5.0, allowing each dependency to be installed, uninstalled, or updated for individual Arc sensors or globally. For Sysmon, where only the latest version is distributed by default, older versions can also be uploaded from Vantage to run on Windows 7 hosts.
  • ENG-2427: Improved Asset information software extraction for entries that previously did not show the install date.
  • ENG-2520: Due to architecture-dependent issues, the Open folder option for offline archives is no longer available on macOS. To address this issue, a Download option for offline archives has been implemented.
  • ENG-2615: Arc now supports configuring web proxies for the upstream connection.
  • ENG-2679: The Sigma engine has been extended to support ImageLoaded fields.
  • ENG-2710: Asset information extraction intervals are now displayed in the local user interface (UI).
  • ENG-2807: The Sigma engine has been extended to support LogonType fields.
  • ENG-2901: Smart Polling: The default timeout for the WMI strategy has been increased to 180 seconds.
  • ENG-2954: The representation of the software version for Linux applications has been improved.
  • ENG-3006: Smart Polling: The SNMPv3 strategy can now better distinguish between a missing connection and wrong credentials.

Resolved issues

A list of the bugs and defects that have been addressed in this release.

  • ENG-2891: Smart Polling: Improved robustness of the Schneider HTTP(S) strategy.
  • ENG-3150: Smart Polling: The WinRM strategy has been enhanced to fix a regression compared to the legacy strategy and to improve the error reporting in case of failure.