v1.1.6 includes 23 updates since v1.1.5.
Highlights
- Broader threat coverage out of the box — intel feeds now catch world-writable paths and new LOLBins
- Fewer false policy mismatches — enforcement preflight now recognizes safe Windows path aliases
- AMSI policy tuning controls are back, so you can adjust protections again
- Organization rule pages no longer time out for large teams
Improvements
- Broader threat coverage out of the box — intel feeds now catch world-writable paths and new LOLBins
- Fewer false policy mismatches — enforcement preflight now recognizes safe Windows path aliases
- AMSI policy tuning controls are back, so you can adjust protections again
- Cleaner UI — obsolete preview labels removed
- Clearer triage — filtered-event counts now match what’s actually loaded
- Cleaner booking page — free trial badge removed from Book Demo
- Signer auto-hunt is restored and works with a limited VirusTotal key
- More visibility into macOS — approval-request eviction telemetry now surfaced
- Faster intel loading — collector lookups are now batched
- Detection-rule tables now have sortable columns
- Investigate stats are compacted to fit laptop screens
- Intel updates preload so Apply All is smoother and lifecycle-safe
- Alert details now show which user made an allow request
Fixes
- Organization-member rule pages no longer time out
- Superadmin endpoint reporting now shows accurate data
- Analytics now use the correct last-observed time
- AMSI pilot plan enforcement now initializes correctly
- Webhook and syslog notifications deliver more reliably
- No more duplicate ExtSentry browser-extension rules
- Detections with unusual (NUL) bytes are no longer dropped
- Compliance alerts now resolve correctly after device recovery
Performance
- Preflight UI stays responsive while readiness checks refresh
Features
- Your Devices sort preference is now remembered between sessions


