What’s new in 5.0¶
Warning
Before upgrading from version 4.10 or lower, you have to get a new license key. Rollback to the previous version leads to loss of data.
Licensing, management of agents and accounts¶
IP-addresses can be excluded from scanning when installing remotely from the admin panel;
indication of both accounts and computers with revoked licenses in the admin panel;
flexible export of data to “CSV” from the admin panel for the pages “Computers” and “Accounts” (with the ability to select demanded fields);
[fix] Bug with license revoking from users disconnected in AD;
if a user got disconnected in AD, logs will have the name of the user and the reason of disconnection;
additional logging of info about assigning/revoking licenses and attempts to synchronization with AD.
Reports, fixtures, time tracking¶
- New fixtures are added, including:
reveal of mouse activity simulation programs;
“lockapp” process is excluded from activity calculation;
verification of Luhn’s algorithm for Mir and UnionPay cards;
a separate policy for capturing “user’s password” and other minor improvements.
Adding web-sites/applications into policies from reports and “Analysis – Table”;
“Neutral time” column was added to “User activity report for period”, “Summary report” and “Group summary report”4
“Default GUI dimension” parameter was moved to report settings;
“Combined report” has received extended and structured table columns with the column indicating the assigned schedule;
more detailed and convenient notifications for vocabularies and filters with search by content;
new setting for reports: expanded or toggled view by default;
assigning schedules by “Company” attribute;
ability to add or remove fields from “Extended time sheet”;
check of the value “Minimum activity time to start workday (sec.)”;
configurable parameter for workday end;
[fix] Incorrect time tracking calculations if the session is closed after 12AM;
calculation and displaying of time spent on remote connection to a workstation;
all the policies triggered by an event are now displayed;
grouping options for software and hardware inventory reports.
Working with data¶
New attributes for “File” dimension: “Source file name”, “Source file path”, “Source file extension”;
“Mail” events received from IMAP-grabber now contain details from user profiles in AD;
configuration assignment by threshold triggering;
relation of events to the source of file interception; new dimension attributes in the admin panel;
“Manager” attribute was added to the “Account” dimension;
new filtration element – “Lists” is added. It allows to filter by the dimension set in a list;
“Company” field was added to “Control panel” – “Accounts”;
screen video recordings get downloaded as a file which name contains metadata (name of the workstation, username, data);
[fix] Drill-down to events from messaging graph.
Architecture¶
New role model for access to data;
refactoring of StaffCop logs;
content parser based on Apache Tika;
support for Ubuntu 20.04 for server part;
new group of administrators with configurable rights;
changes in the principles of working schedules and their assignment to the data;
[fix] Id doesn’t get reset after implementing of “Recognition server”.
Security¶
Check the administrator’s password strength when setting it;
tracking of login/logout events of system administrators and displaying them in “History of actions”;
detailed logging of data export from the admin panel;
fixed vulnerabilities found during the number of penetration tests.
UI¶
Application logos are displayed in the event lens;
“OS version” field is added to “Control panel -> Computers”;
settings of policies are removed from dimension cards;
several search queries are simultaneously highlighted in case with regular expression;
2 new interface themes;
paging of messaging;
bright coloring of the slider against the background of sound track;
additional field “Description” for filters and policies;
more abilities for searching, sorting and filtering on the “Accounts” page;
[fix] Incorrect display of contacts of participants of messaging;
”Cutoff threshold” for anomaly detector was moved to the settings of the report;
ability to display on those workstations for which remote control is available;
[fix] Drop-down menu goes over the bottom panel on displays with low resolution;
[fix] The right panel blinks when the interface gets loaded.
Integrations¶
Ability to import files from PerCO;
import data on absence of employees from 1C data sheets into StaffCop calendar;
synchronization with AD by several OU;
import of an employee’s photo from AD’s field «thumbnailPhoto»;
[fix] The maximum number of messages that can be processed by the mail grabber during a single session has been increased.
Misc¶
Users can start/stop monitoring of their workplaces using a tray icon;
the ability to automatically create incidents from the pre-set policies;
e-mail reports in Excel format;
notifications for a group of filters;
tips are displayed when cursor is at a regular expression in a filter;
interface of the page “Tags and access blocking” has been improved;
[fix] E-mail of “admin” account can’t be changed;
[fix] Policies “Auto cleanup” and “Event deletion policy” have been improved for the new processing;
[fix] One-tine tasks from the Task scheduler are removed if they are finished with errors;
[fix] “Delete an object and all its data” – doesn’t revoke a license;
[fix] Update the statuses of users to the correct ones;
usage of Rust for processing data;
notification on any change in hardware configuration.
Linux agent¶
Interception of e-mail from Thunderbird;
interception of files sent to printing;
monitoring of web-activity in the latest version of Opera;
refactoring of agent logs;
compatibility with AppArmor;
check and disable SELinux at the agent installation phase.
Windows Agent¶
Interception of MS Teams;
interception of Bitrix24 Desktop;
detection of files cyphered with CryptoPro;
blocking of clipboard;
display of UUID for USB devices at the moment of connection;
interception of Telegram when login with qr-code;
new remote installer tool;
OS dumps now more easily allow to reveal if the agent was the reason of excessive memory consumption;
[fix] Search queries in google.com and youtube.com don’t get tracked in Firefox;
[fix] Outcoming emails from Outlook don’t get intercepted in some conditions;
[fix] Monitoring of web activity in Chrome, Edge and FireFox for Hebrew;
[fix] Errors with web monitoring in Yandex browser;
unified mechanism of installation of agent’s drivers and transferring them to WDK10;
comodia proxy was removed from Agent;
agent protection with s password.