[New] Introduced advanced SMB deception service: The decoy now provides an in-memory SMB share with Net-NTLM hash interception capabilities. The service identifies coercion attempts (PetitPotam, etc..), detects SMB relay techniques, and fingerprints incoming sessions to distinguish attacker tooling such as Impacket, NetExec, smbclient, macOS clients, and Windows hosts.
[New] Added OS deception through TCP/IP fingerprint emulation: The decoy now dynamically crafts and modifies low-level network responses to reproduce the TCP/IP fingerprint of a chosen operating system, improving deception against fingerprinting tools such as Nmap.
[New] Added generic device settings to policies: Auto-update, credential capture settings, and OS deception mode selection (Automatic / Manual).
[New] The platform now displays the deployment type directly in the interface, distinguishing between virtual machine and container-based deployments.
[Improvement] Improved agent resilience with recovery fallback service that automatically takes over when the main agent executable fails to start after an update.
[Fix] Fixed an issue where enabling auto-update or the credential capture setting in a policy update did not take effect unless the set of active services also changed in the same push.
[New] Added a rate limit detector to SMB authentication attempts: a brute-force run against the SMB decoy is now collapsed into a single BruteForce event.
[Improvement] Automatic Windows OS deception feature no longer misreads a disabled service’s leftover template or banner.
[Fix] Fixed port scan false positives when a service port was already in use (e.g. another process already holding it, common in container deployments).