Changelog

Product updates, reliability work, interface improvements, and release notes for the MagicSword.

Showing 11-20 of 25 releases

July 23, 2026Since v1.1.6

Investigate is fast and reliable again, even across large, multi-organization datasets.

Highlights

  • Faster initial loading with results appearing before expensive totals finish calculating
  • Smooth, deterministic paging through large volumes of endpoint activity
  • Consistent ordering across organizations and event timestamps

Fixes

  • Resolved query timeouts that could leave Investigate blank or return a 500 error
  • Restored the indexed data path for dramatically faster searches
  • Preserved existing filters, sorting, organization scoping, and backwards compatibility
July 23, 2026Since v1.1.5

v1.1.6 includes 23 updates since v1.1.5.

Highlights

  • Broader threat coverage out of the box — intel feeds now catch world-writable paths and new LOLBins
  • Fewer false policy mismatches — enforcement preflight now recognizes safe Windows path aliases
  • AMSI policy tuning controls are back, so you can adjust protections again
  • Organization rule pages no longer time out for large teams

Improvements

  • Broader threat coverage out of the box — intel feeds now catch world-writable paths and new LOLBins
  • Fewer false policy mismatches — enforcement preflight now recognizes safe Windows path aliases
  • AMSI policy tuning controls are back, so you can adjust protections again
  • Cleaner UI — obsolete preview labels removed
  • Clearer triage — filtered-event counts now match what’s actually loaded
  • Cleaner booking page — free trial badge removed from Book Demo
  • Signer auto-hunt is restored and works with a limited VirusTotal key
  • More visibility into macOS — approval-request eviction telemetry now surfaced
  • Faster intel loading — collector lookups are now batched
  • Detection-rule tables now have sortable columns
  • Investigate stats are compacted to fit laptop screens
  • Intel updates preload so Apply All is smoother and lifecycle-safe
  • Alert details now show which user made an allow request

Fixes

  • Organization-member rule pages no longer time out
  • Superadmin endpoint reporting now shows accurate data
  • Analytics now use the correct last-observed time
  • AMSI pilot plan enforcement now initializes correctly
  • Webhook and syslog notifications deliver more reliably
  • No more duplicate ExtSentry browser-extension rules
  • Detections with unusual (NUL) bytes are no longer dropped
  • Compliance alerts now resolve correctly after device recovery

Performance

  • Preflight UI stays responsive while readiness checks refresh

Features

  • Your Devices sort preference is now remembered between sessions
July 15, 2026Since v1.1.4

This release restores SSO access for provider-bound accounts to ensure seamless portal authentication.

Highlights

  • Restored SSO access for provider-bound accounts.

Fixes

  • SSO portal access: You can now log in to the portal using your provider-bound SSO credentials again, resolving an issue that prevented access for specific account types.
July 14, 2026Since v1.1.3
Fleet Activity
Fleet Activity

This release introduces a streamlined policy creation wizard, a new fleet-wide activity dashboard, and significant performance optimizations for policy delivery.

Highlights

  • Simplified policy creation wizard reduces steps from four to three.
  • New fleet-wide Activity tab provides a unified view of endpoint check-ins and command queues.
  • Policy delivery performance is significantly improved through automated artifact caching.
  • Health-check reporting now provides more accurate endpoint and event data.

Features

  • Simplified policy creation wizard: You can now create policies in three steps instead of four, allowing for a faster and more intuitive setup process.
  • Fleet-wide Activity tab: You can now monitor command queues and recent check-in heartbeats across your entire fleet in a single, unified view on the Devices page.

Security

  • DefenderKiller KSLDriver intel: You are now protected against the DefenderKiller KSLDriver with the addition of its specific Authentihash to our threat intelligence database.

Fixes

  • Accurate health-check reporting: Health-check reports now provide more reliable data by using canonical endpoint identification and improved pagination, ensuring large organizations receive complete and accurate insights.

Improvements

  • Landing page animations: Problem stat animations now trigger immediately upon entering the viewport, providing a smoother and more responsive experience when first visiting the site.
  • Updated email branding: Email notifications now feature a consistent, modern dark-mode design that matches the rest of the MagicSword platform.

Performance

  • Cached policy delivery artifacts: Faster policy delivery is now available as the system caches verified artifacts, reducing the need for repeated, resource-intensive policy generation during endpoint check-ins.
July 9, 2026Since v1.1.2

This release improves command-line observation processing reliability and ensures WDAC intel metadata remains accurate during policy updates.

Highlights

  • Improved stability for command-line observation processing.
  • Enhanced data integrity for WDAC intel metadata.

Fixes

  • Command-line observation processing: You will experience fewer processing errors during high-volume periods as the system now dynamically adjusts batch sizes to prevent statement timeouts.
July 9, 2026Since v1.1.1

This release improves agent update reliability, enhances audit and reporting privacy, and refines user entity privilege labeling.

Highlights

  • Improved agent update status accuracy and retry reliability.
  • More accurate privilege labeling for standard user entities.
  • Improved performance for large policy rule fetches and command-line observation processing.

Fixes

  • Microsoft intel blocklist retirement: Microsoft-backed vulnerable driver and recommended blocklist sources have been removed to streamline your intelligence configuration.
  • Stale agent update state: The portal now correctly clears update status when an agent reaches its target version, preventing endpoints from appearing stuck in an 'Installing' state.
  • Endpoint policy assignment: Policy assignment now correctly handles endpoint metadata, preventing errors when assigning policies to agentless devices.
  • User privilege posture labeling: Standard users are no longer incorrectly labeled as 'Privileged' due to the presence of non-privileged posture evidence.
  • Pilot intel update cloning: Pilot users will no longer encounter errors when updating policies that previously contained premium intelligence sources.
  • SSO signup provisioning: SSO-authenticated users now correctly map to their organization roles without being incorrectly provisioned with trial pilot access.
  • Stale agent update heartbeat reports: The portal now ignores stale heartbeat reports that incorrectly claim an update failed after the agent has already successfully reached the target version.

Features

  • Paginated changelog: You can now browse the changelog more efficiently with server-side pagination, which improves page load performance as the release history grows.
  • Improved audit and compliance reporting: You can now export full audit and compliance reports without UI-imposed row caps, and audit logs now include readable details instead of truncated text.
  • User entity privilege tooltips: You can now hover over privilege badges and posture labels to see clear explanations of what specific privilege states mean for your user entities.

Performance

  • Optimized command-line and check-in processing: Faster and more reliable agent check-ins and command-line processing are achieved through non-blocking locks and increased timeout thresholds for large policies.
  • Data retention worker optimization: The data retention worker now processes organizations with shorter retention periods first, ensuring aged heartbeat logs are cleaned up more efficiently.
July 7, 2026Since v1.1.0

This release improves system stability for high-volume telemetry ingestion, introduces automated agent authentication rotation, and refines the landing page navigation.

Highlights

  • Improved reliability for high-volume filesystem inventory and process telemetry ingestion.
  • Added support for automated agent authentication token rotation to prevent stale endpoint connections.
  • Refined landing page navigation for better visual alignment and accessibility.

Fixes

  • Filesystem inventory ingestion stability: You can now process large filesystem inventory payloads without encountering database argument limits, ensuring complete visibility into endpoint file metadata.

Features

  • Agent authentication token rotation: Agents can now automatically rotate authentication tokens during heartbeat and check-in, ensuring continuous connectivity without manual re-enrollment.

Improvements

  • Landing page navigation alignment: Enjoy a more polished experience with improved visual alignment and spacing for navigation links, dropdowns, and call-to-action buttons on the landing page.
July 7, 2026Since v1.0.7

User Entities
User Entities
Agent Collection Settings
Agent Collection Settings

This release introduces legacy Windows 8+ and Server 2016+ support, bulk deployment tools for fleets, improved agent collection controls, and more reliable telemetry processing.

Highlights

  • Added full support for legacy Windows 8+ and Windows 2016+ environments, including AppLocker and WDAC policy management.
  • Introduced a new bulk deployment UI for assigning and deploying policies across your fleet.
  • Added agent collection controls for optional telemetry and inventory settings.
  • Improved user and process visibility across Windows, macOS, and Linux endpoints.
  • Enhanced telemetry reliability with staging queues for process observations, analytics events, and high-volume endpoint activity.

Features

  • Legacy Windows support: You can now manage AppLocker and WDAC policies on legacy Windows systems, helping maintain consistent security coverage across older and newer endpoints.
  • Fleet bulk deployment UI: You can now assign and deploy policies to multiple endpoints at once, simplifying policy rollout for larger environments.
  • Agent collection controls: You can now tune optional telemetry and inventory collection by category, giving teams more control over what endpoint data is collected.
  • Improved endpoint visibility: User context and process attribution are now richer across Windows, macOS, and Linux, making it easier to understand endpoint activity.

Fixes

  • AppLocker compatibility: MagicSword-managed policies now coexist more safely with customer-managed AppLocker rules.
  • Telemetry reliability: Process observations, analytics events, and endpoint activity are processed more reliably in high-volume environments.
  • Performance improvements: Heartbeat payloads are smaller, improving check-in performance and reducing bandwidth usage.
  • Diagnostics improvements: Windows event logging and support bundle diagnostics are cleaner and easier to use.
  • Database migration reliability: The system now applies updates more reliably by deferring heavy historical data processing, ensuring new features are deployed without interruption.
July 3, 2026Since v1.0.6

This update improves UI consistency and resolves performance issues with table statistics.

Highlights

  • Improved light mode visual consistency across the dashboard.
  • Resolved performance timeouts for table statistics.

Fixes

  • Dashboard UI and Light Mode: Fixed dropdown positioning issues and improved light mode surface styling.
  • Sort same-day releases by semver
  • Order portal releases by version

Performance

  • Table Statistics: Resolved timeout issues occurring during table analysis.

Improvements

  • Changelog Ordering: Improved release sorting logic to ensure chronological and version-based accuracy.
July 3, 2026Since v1.0.5

This update includes general site improvements and maintenance for the MagicSword portal.

Highlights

  • General site maintenance and stability improvements.

Improvements

  • Site updates: Applied general site enhancements and maintenance updates.
Page 2 of 3 · 25 releases