[New] Added a rate limit detector to SMB authentication attempts: a brute-force run against the SMB decoy is now collapsed into a single BruteForce event.
[Improvement] Automatic Windows OS deception feature no longer misreads a disabled service’s leftover template or banner.
[Fix] Fixed port scan false positives when a service port was already in use (e.g. another process already holding it, common in container deployments).
[Fix] Fixed an issue where enabling auto-update or the credential capture setting in a policy update did not take effect unless the set of active services also changed in the same push.
[New] Added generic device settings to policies: Auto-update, credential capture settings, and OS deception mode selection (Automatic / Manual).
[New] The platform now displays the deployment type directly in the interface, distinguishing between virtual machine and container-based deployments.
[Improvement] Improved agent resilience with recovery fallback service that automatically takes over when the main agent executable fails to start after an update.
[New] Introduced advanced SMB deception service: The decoy now provides an in-memory SMB share with Net-NTLM hash interception capabilities. The service identifies coercion attempts (PetitPotam, etc..), detects SMB relay techniques, and fingerprints incoming sessions to distinguish attacker tooling such as Impacket, NetExec, smbclient, macOS clients, and Windows hosts.
[New] Added OS deception through TCP/IP fingerprint emulation: The decoy now dynamically crafts and modifies low-level network responses to reproduce the TCP/IP fingerprint of a chosen operating system, improving deception against fingerprinting tools such as Nmap.
[Improvement] The agent now periodically checks for a dynamically assigned IPv4 address on the network interface. When an IPv4 address becomes available while operating over IPv6 at startup, the agent will automatically switch to IPv4.