Changelog

Product updates, reliability work, interface improvements, and release notes for the MagicSword.

Showing 21-30 of 50 releases

September 1, 2026Since v1.1.21

v1.1.22 includes 1 update since v1.1.21. Adds 23 new WDAC rules to block recently disclosed EDR-killer and BYOVD tools, and with enriched identity data.

Highlights

  • 23 new WDAC rules for EDR-killer and BYOVD tools
  • Authenticode and page hash enrichment for improved accuracy

Features

  • New WDAC rules for EDR-killer tools: You now have 23 new WDAC rules to block recently disclosed EDR-killer and BYOVD tools, helping prevent attackers from disabling your endpoint detection and response.
August 31, 2026Since v1.1.20

v1.1.21 includes 2 updates since v1.1.20. Added newly detected actively exploited signers to the portal.

Highlights

  • Newly detected actively exploited signers added

Features

  • Expanded signer coverage: The Portal now includes newly identified signers associated with active exploitation, improving detection of compromised code-signing certificates.

Improvements

  • Preserved historical Authentihash controls: Existing Authentihash controls remain active alongside the new signer intelligence, maintaining your existing protection.
August 28, 2026Since v1.1.19

v1.1.20 includes 1 update since v1.1.19. MagicSword portal now offers a weekly Living Off the Land contributor changelog with archive navigation and a streamlined publishing workflow.

Highlights

  • New weekly LOTL contributor changelog with archive navigation
  • First edition covers eight verified contributors across five projects
  • Streamlined workflow for publishing future LOTL editions

Features

  • Weekly LOTL contributor changelog: A new weekly timeline at /changelog/lotl tracks Living Off the Land contributors, with the first edition covering eight verified contributors across five projects. You can quickly see who contributed and to which projects each week.
August 27, 2026Since v1.1.18

v1.1.19 includes 2 updates since v1.1.18. It adds WDAC policy syncing for RMM deployments, protects Slack community requests with CAPTCHA, and ships macOS agent 1.0.0.434 with reliable break-glass recovery across reboots.

Highlights

  • CAPTCHA verification on Slack community requests
  • WDAC policy sync script for RMM deployments
  • macOS agent 1.0.0.434 with reliable break-glass recovery across reboots

Security

  • Add CAPTCHA verification to Slack community requests: Adds Cloudflare Turnstile verification to the Slack community request form, blocking automated submissions and protecting your contact details.

Features

  • Add WDAC policy sync script for RMM deployments: Introduces a hosted PowerShell script to deploy and update MagicSword WDAC policies across devices via RMM, with automatic cleanup of obsolete policies and safeguards to avoid enforcement gaps.

Fixes

  • Improve break-glass recovery in macOS agent 1.0.0.434: You can now use break-glass access more reliably on macOS: agent 1.0.0.434 preserves recovery readiness across reboots and safely returns endpoints to enforcement if recovery state is interrupted or damaged.
August 24, 2026Since v1.1.17

v1.1.18 includes 5 updates since v1.1.17. This release improves policy deployment accuracy, adds new Devices table features, and fixes Linux rule choices and Investigate filter behavior.

Highlights

  • View assigned policies as clickable links and customize device columns.
  • See deployment counts and expand policies to view assigned endpoints.
  • Policy deployment now correctly scopes to platform and organization.
  • Linux policy editor hides unsupported rule types.
  • Investigate filters stay intact when changing time ranges.

Fixes

  • Policy deployment platform scoping: Policy deployment now correctly targets only devices that match the selected platform and organization, preventing accidental deployment to incompatible devices.
  • Linux rule choices: The Linux policy editor now only shows rule types that are actually supported, preventing invalid configurations.
  • Investigate filter preservation: Investigate filters no longer reset when you change the time range, so you can keep your active status and endpoint filters while adjusting the time window.
  • Policy deployment platform scoping: Policy deployment now correctly targets only devices that match the selected platform and organization, preventing accidental deployment to incompatible devices.

Features

  • Policy links in Devices table: You can now see every assigned policy as a clickable link directly in the Devices table, making it faster to jump to policy details.
August 19, 2026Since v1.1.16

v1.1.17 includes 8 updates since v1.1.16. This release adds AMSI rules-integrity alerts, safer Windows break-glass recovery, and secure Investigate Ask AI queries.

Highlights

  • AMSI rules-integrity failures now create endpoint alerts that resolve when healthy telemetry returns.
  • Windows break-glass recovery now clearly identifies upgrade requirements and verifies recovery-cache readiness before authorization.
  • Investigate Ask AI keeps organization scope, provider settings, quotas, and telemetry access protected on the server.

Fixes

  • Send the correct AMSI rule identity: AMSI rule deployments now send the rule identity expected by Windows agents, helping deployed detection rules apply reliably.
  • Require verified break-glass recovery readiness: You now receive a clear upgrade-required response when an older Windows agent cannot prepare its recovery cache, while capable agents remain blocked until the cache is explicitly ready.
  • Enforce supported Linux and macOS policy rules: You can no longer save or promote Linux and macOS policy rule combinations that agents do not support, preventing policies from appearing valid while failing to apply.

Features

  • Show AMSI rules-integrity alerts: You can now see a durable endpoint alert when Windows reports an AMSI rules-integrity failure, and the alert resolves automatically after healthy telemetry returns.
August 18, 2026Since v1.1.15

v1.1.16 includes 2 updates since v1.1.15. API access now correctly respects customer subscriptions.

Highlights

  • Subscription-based API access is now enforced correctly.

Fixes

  • Honor subscriptions for customer API access: You can access the API according to the subscription associated with your account, preventing incorrect access restrictions or permissions.
  • Honor subscriptions for customer API access
August 18, 2026Since v1.1.14

v1.1.15 includes nine updates across the MagicSword Portal and macOS agent. This release adds Private Intelligence feeds and customer APIs, verifies live macOS enforcement health, hardens macOS support bundles, and makes Apple trust telemetry less noisy.

Highlights

  • Manage customer-owned Private Intelligence feeds with up to 500 indicators each.
  • Use APIs and MCP to work with intelligence, policies, endpoints, alerts, releases, enrollment, and MSSP provisioning.
  • Verify that macOS enforcement is truly active before reporting an endpoint as compliant.
  • See when a macOS system extension is disabled, missing, unhealthy, awaiting approval, or stale.
  • Keep Apple Gatekeeper and XProtect records searchable without generating actionable alerts.

Features

  • Manage Private Intelligence feeds: Create, edit, enable, disable, and delete up to three customer-owned intelligence feeds, with support for filename, filepath, AuthentiHash, page hash, generic hash, and publisher/TBS indicators. Attach Private Intelligence to policies and review intelligence activity and update history.
  • Explore Magic-Atomics on the exposure page: Learn how Magic-Atomics tests controls against adversary techniques through an overview of prevention tests, MITRE ATT&CK coverage, intelligence sources, and the attack-validation workflow.

Fixes

  • Submit dashboard feedback without a captcha error: Authenticated users can now submit feedback and bug reports without encountering a missing captcha token error. Anonymous contact submissions remain protected by captcha.
  • Report macOS enforcement health accurately: The agent now verifies that the MagicSword system extension is enabled, running in the current boot session, ready to receive Endpoint Security events, and has Full Disk Access before reporting enforcement as active.
  • Show macOS extension health in endpoint compliance: Endpoints are shown as non-compliant when their system extension is disabled, missing, unhealthy, awaiting approval, or stale. Endpoint details, the menu-bar app, and daemon status output provide the reason and correct System Settings remediation.
  • Start new organizations with intel-backed default policies: New organizations receive macOS, Windows, and Linux default policies with intelligence attached, so protection is ready without a separate intel setup step.

Improvements

  • Treat Apple trust events as observed telemetry: Gatekeeper and XProtect records now appear as neutral, searchable Observed telemetry instead of actionable blocked events. This prevents macOS-reported evidence from creating unnecessary alerts, notifications, or review-priority items.
  • Simplify Windows endpoint status views: Fleet tables, Devices reports, and CSV exports now use the existing Status and Compliance signals without overlapping Windows-control readiness labels.

Operations

  • Create safer, more useful macOS support bundles: Support bundles now include normalized extension health and additional diagnostic context while redacting enrollment credentials. Bundles are securely delivered as owner-only archives to the requesting user’s Downloads or Desktop folder.
  • Keep coverage reports downloadable: Coverage reports are now packaged reliably for artifact upload, allowing teams to continue downloading test coverage results after automated checks complete.
August 12, 2026Since v1.1.13

v1.1.14 includes 8 updates since v1.1.13. This release improves Gatekeeper and XProtect triage, clarifies Windows control readiness, and makes password recovery, alerts, telemetry, and high-volume views more reliable.

Highlights

  • Improve Gatekeeper and XProtect attribution: Apple reporting services are now separated from the application or file being assessed. Redacted targets remain clearly identified as redacted instead of being incorrectly attributed to syspolicyd.
  • Strengthen macOS application control: New app_bundle rules resolve applications to the executable macOS actually launches, including Cryptex-backed applications such as Safari.
  • Add macOS CDHash enforcement: The agent can now enforce CDHash rules synchronously and accurately report this capability to the Portal.
  • Close macOS launch enforcement gaps: LaunchServices, Finder, and open launches now reach policy evaluation instead of being hidden by broad Endpoint Security path mutes.
  • Clarify Windows control readiness: Supported but unconfigured Windows controls now show as Control Available instead of requiring attention.

Improvements

  • Use consistent primary-action styling: The Add New Rule and AI Report buttons now use MagicSword green.
  • Preserve macOS trust-event evidence: The agent retains original timestamps, reporter identity, target confidence, signing metadata, and event provenance.
  • Prevent duplicate macOS trust events: Deterministic event IDs make overlapping Gatekeeper and XProtect collection windows idempotent.
  • Improve macOS rule evaluation: Specific deny rules can no longer be hidden by broader allow rules.
  • Refresh macOS authorization state: The agent clears its authorization cache when an application bundle changes.

Fixes

  • Restore protected password recovery: Turnstile verification is now included with password-reset requests.
  • Prevent malformed Unicode from blocking heartbeats: Invalid or PostgreSQL-incompatible Unicode is sanitized before telemetry is queued.
  • Open the correct alert details: Alert panels now remain associated with the selected event and endpoint, even when events share an executable or hash.
  • Finalize agent runs correctly: Completion time, status, knowledge-graph metrics, and errors are now recorded reliably.
  • Improve Gatekeeper classification: Cache updates, housekeeping activity, and observed user overrides are no longer presented as authoritative enforcement events.
  • Improve XProtect classification: The agent emits XProtect observations only for high-confidence detection or remediation activity.

Performance

  • Speed up Overview event paging: More efficient time filtering improves responsiveness for large audited and blocked event collections.
  • Reduce high-volume database pressure: Bounded processing improves heartbeat queues, background workers, and large-portfolio views.
August 10, 2026Since v1.1.12

v1.1.13 includes 10 updates since v1.1.12. This release improves endpoint reporting accuracy, Windows policy readiness, policy editing, and heartbeat reliability while adding stronger WDAC and form protection.

Highlights

  • Endpoint reports now match canonical live endpoint counts, including more accurate stale-device lists and policy assignments.
  • Windows 23H2 devices show clearer WDAC reboot requirements, while 24H2+ is documented as the preferred baseline.
  • Policy editors can switch between Audit and Enforce with the same readiness checks used in the policy manager.
  • Heartbeat processing is more reliable, with fewer retry storms and less duplicate transfer overhead.

Fixes

  • Correct duplicate endpoint counts in reports: You now get accurate Device, Compliance, and Policy report totals, stale-device lists, exports, and compliance rates that match the Fleet page, even after uninstall and re-enrollment events.
  • Classify CodeIntegrity 3004 events as audited evidence: Windows CodeIntegrity 3004 events are now ingested and classified as audited exe_dll evidence by default, giving you more complete visibility into application-control activity.

Improvements

  • Focus Investigate on the last hour by default: Investigate now opens to a focused one-hour time range instead of 24 hours, helping you reach relevant activity faster and reducing the initial amount of data to load.
  • Enable the tray icon by default when deploying agents: New agent install commands now start the tray icon at user logon by default, making endpoint status easier for users to access without additional configuration.
  • Simplify Windows rule creation and support Notepad++ filenames: Windows policy authors now see a clearer new-rule type list and can create version-scoped Filename rules for values such as notepad++.exe and Notepad++.

Security

  • Protect Prevention Lab and enterprise trial forms with Turnstile: You can now submit Prevention Lab and Enterprise Trial forms with CAPTCHA verification, while rejected tokens produce clear form errors instead of blocking valid trial activation.
  • Clarify Windows WDAC and AppLocker support: You now get clearer platform guidance: Windows 11 22H2 uses the limited AppLocker-compatible path, 23H2 is the oldest fully supported WDAC baseline, and 24H2+ is the preferred posture.
  • Add supplemental WDAC and LOLBin bypass intel: You now have broader WDAC coverage for bypass-relevant tools including dbgsrv.exe, TextTransform.exe, WSL container aliases, lli.exe, datacollector.exe, slui.exe, and updated imgmgr.exe guidance.

Features

  • Change policy status directly in the Policy Editor: You can now switch a policy between Audit and Enforce while editing it, with readiness checks and enforcement guidance that match the policy manager experience.

Performance

  • Reduce heartbeat retry storms and transfer overhead: Heartbeat and checkin traffic is now less likely to trigger duplicate retries or 503 responses, improving telemetry delivery reliability and reducing unnecessary endpoint data transfers.
Page 3 of 5 · 50 releases