GravityZone Control Center
Version 6.42.1-4
Release date: 2025.05.27
Resolved issues
GravityZone platform
Resolved an issue affecting the GravityZone Update Server, ensuring stability and reliability.
Version 6.42.1-3
Release date: 2025.05.19
Resolved issues
GravityZone platform
Resolved an issue that prevented Active Directory integrations from syncing properly.
Policies
Resolved an issue where Application Control hash exclusions were automatically removed from the policy settings after a period of time.
Version 6.42.1-2
Release date: 2025.05.13
Resolved issues
GravityZone platform
Security fixes.
Version 6.42.1-1
Release interval: The rollout for this update will be performed progressively starting on April 23, 2025.
Improvements
GravityZone platform
We are upgrading GravityZone's underlying operating system to the latest Ubuntu 24.04 version to ensure continued compatibility, enhanced security, and long-term support. For more information about the upgrade process, refer to Update GravityZone to version 6.42.1-1.
Warning
Before proceeding with the update, we strongly advise you to take snapshots of all GravityZone appliances.
Version 6.41.2-1
Release date: 2025.03.03
Resolved issues
GravityZone platform
Security fixes.
Version 6.41.1-2
Release date: 2025.02.18
Resolved issues
GravityZone platform
Resolved a few issues affecting the GravityZone Update Server, ensuring improved stability and reliability.
Version 6.41.1-1
Release interval: 2025.02.12 - 2025.02.26
Improvements
GravityZone platform
This update enhances the GravityZone navigation system by introducing new functionality and usability of menu entries, and more. Each menu entry is now a unique URL that browsers can directly interpret, improving multitasking and bringing a smoother and seamless user experience.
Key updates include:
All main menu and header menu items now have unique URLs. You can open a menu entry in a new tab or window, or access it by entering its specific URL.
Multiple GravityZone sections provide deeper URLs for navigation.
You can use the browser’s Back and Forward buttons to move between previously accessed sections.
Refreshing the GravityZone console no longer redirects you to the landing page.
Policies
The following sections now feature a new design and improved interface texts:
Firewall
Network Protection
Exchange Protection
Device Control
Application Control
NSX
These sections add up to those previously revised. The remaining sections will gradually migrate to the new design in future GravityZone releases.
Accounts
The Disable concurrent logins option is now available when editing or creating GravityZone accounts. When the option is disabled for an account, its user is able to log in to the GravityZone console from multiple browser sessions. If enabled, any existing session will be terminated and the user will automatically be logged out when a new session is started.
The option can also be found in the My account window, under the Login Security section.
EDR
New fields are now available for creating custom exclusion rules. The EDR functionality has been enhanced with additional exclusion parameters, allowing you to exclude events and behaviors related to user connections and email activity on your endpoints.
Some endpoint operations are now going to use the configuration settings in Policies > General > Communication > Communication between Endpoints and Relays/GravityZone.
Resolved issues
GravityZone platform
Resolved an issue that prevented the use of email addresses with multiple dashes when configuring notification settings.
Fixed an issue that affected the database password change.
Security fixes.
Network
Fixed an issue that caused Active Directory virtual machines to incorrectly appear as offline after synchronization.
Version 6.40.1-1 (third-party updates)
Release date: 2024.11.14
Resolved issues
GravityZone platform
Security fixes.
Version 6.40.1-1
Release date: 2024.11.05
Note
This update is intended for GravityZone instances in isolated environments.
Resolved issues
GravityZone platform
Fixed an issue that caused the product kit download to fail in the offline instance.
Fixed an issue that caused the product updates mirroring to fail on slow ring.
Security fixes.
Version 6.40.1-1
Release interval: 2024.09.24 - 2024.10.15
New features
Antimalware
Advanced Threat Control now includes a new capability. The option Sensitive Registry Protection is designed to safeguard critical registry keys including those associated with the Security Account Manager from unauthorized access or exploitation such as malicious registry key dumping. This technology ensures comprehensive protection of user authentication data and system security policies on your systems.
The option is located in the policy under Antimalware > On-Execute > Advanced Threat Control.
You can find and further analyze this type of event by generating a Security Audit or Blocked Applications report.
Improvements
GravityZone platform
This release brings an architectural change designed to provide more focused functionality for communication servers in GravityZone environments.
The Communication Server role is replaced with the following new roles with distinct functionalities:
Endpoint Communication Server: enables endpoint communication with the GravityZone environment.
Endpoint Events Processing Server: processes endpoint-related data such as policy changes, tasks, security events, and others.
The old role is automatically replaced in all existing installations starting with this update, requiring no action from your side.
For new installations, the new roles are available and it is recommended to install them together on the same virtual appliance.
You can view the new roles in the System status and Configuration > Update pages.
Network Protection
You can now enable the Inspect TLS Handshake feature in the policy in Network Protection > General > Network Protection > Intercept TLS handshake.
This feature intercepts malicious domains during TLS Handshake phase, detecting potential threats without decrypting traffic. It scans outbound processes except the ones defined in the policy settings under Network Protection > General > Network Protection > Intercept encrypted traffic > Scan HTTPS, and allows you to respond by denying access to the page or by resetting the connection.
This feature is compatible only with Windows operating systems.
Application Control
New filtering options have been added to Application Inventory, allowing you to enhance application management efficiency by identifying applications that are not used in any policies or found on any endpoints.
Security Server Multi-Platform
Security Server Multi-Platform is now available only as a stand-alone role and can be downloaded from Network > Installation Packages. To improve resource availability to core GravityZone services the Security Server Multi-Platform is no longer embedded into the GravityZone appliance.
Existing installations are not affected by this change.
EDR
Automatic response actions for custom detection rules are now available. Once set up, these actions execute on protected endpoints even when disconnected from GravityZone Control Center. This new feature ensures your security measures stay robust and responsive.
All actions are visible in GravityZone for complete oversight.
Policies
This update comes with a new design and improved interface texts for the following policy sections:
Relay
Sandbox Analyzer
These sections add up to those revised previously. The remaining sections will gradually migrate to the new design in future GravityZone releases.
Public API
Network API
The getNetworkInventoryItems
and getEndpointsList
methods now have improved return values: the items will now be ordered based on their database identifier, as opposed to the prior categorization, which was based on their name.
This change will also resolve the issue caused when returning multiple items on the same name. It would occur when the number of items with the same name was higher than the number of items returned per page.
Resolved issues
GravityZone platform
Fixed an issue where changes to the AD logon name were not updated correctly after synchronization, causing some users to be unable to log in GravityZone anymore.
Security fixes.
Reports
Resolved an issue causing the following error to appear when attempting to create a report: The report processor is offline error
.
Version 6.39.1-1 (third-party updates)
Release date: 2024.08.22
Resolved issues
GravityZone platform
Security fixes.
Version 6.39.1-1
Release interval: 2024.07.17 - 2024.08.07
New features
Antimalware
The Antimalware module capabilities are now enriched with a new feature that enables Unified Extensible Firmware Interface (UEFI) scanning. The new Scan UEFI option ensures the security and integrity of the system's boot process and protects against sophisticated threats that can persist at the firmware level.
The feature is available for on-demand scheduled tasks in the policy and malware scan tasks from the Network page. The option is located under the Miscellaneous section of each Full, Quick, and Custom scan type and is enabled by default when the security level is set to Aggressive.
You can find and further analyze this type of detection event by generating a Security Audit report.
Improvements
Policies
This update comes with a new design and improved interface texts for the following policy sections:
Patch Management
Encryption
Incidents Sensor
Storage Protection
The remaining sections will gradually migrate to the new design in future GravityZone releases.
All pages with new design now include a link to related GravityZone documentation under Get help from Support Center.
You can now create a maintenance window directly in the Patch Management section of the policy settings if none is available for selection. This maintenance window includes patch scanning settings only. To install patches, go to the main menu and edit the window in the Configuration profiles section.
You now receive relevant messages when trying to import exclusion files with errors in the Storage Protection section.
When disabling Use Bitdefender Global Protective Network to enhance protection in the policy settings, the confirmation message now informs you that you must switch to Local Scan engines if you are using Hybrid Scan engines.
Patch Management
Manually approved patches, including Microsoft Windows Feature Updates and security tools, are now available for Windows endpoints. These updates cannot be installed automatically.
Some highlights:
GravityZone sections such as Dashboard, Network, Tasks, Patch Inventory, Maintenance Windows, and User Activity have been updated to support Manually approved patches.
The Network Patch Status report now includes information related to Manually approved patches.
Network protection
The Time Limiter tab, which allowed you to configure time-based access restrictions, has been removed from Network Protection > Content Control > Web Access Control > Settings.
The Block/Schedule/Allow selector, previously used for auto-selecting intervals in the Time Limiter feature, has also been removed from the Web Access Control section, simplifying the user interface and reducing complexity.
You can now define schedulers in Configuration Profiles > Web Access Control Scheduler without needing to select a category, thus making the Categories field optional.
You must still indicate the required time and day. This modification enables schedulers to accurately represent time-limiter intervals, offering more flexibility in scheduling without being limited by pre-established categories.
You can now add a maximum of 20 schedulers for each Schedule created in Configuration Profiles > Web Access Control Scheduler.
Tasks
The Delete button on the Tasks page now also removes pending subtasks of tasks that are in progress. The confirmation window and the User activity page have been updated to reflect the changes.
Resolved issues
GravityZone platform
The email notification for Product Registration event was partially translated into German. The issue was fixed.
Resolved an issue causing quarantined endpoints to be visible to GravityZone accounts that did not have access to their original folder.
Security fixes.
Version 6.38.1-5
Release date: 2024.06.19
Improvements
Enhanced the security of the GravityZone virtual appliance.
Version 6.38.1-4
Release date: 2024.06.11
Resolved issues
Security fixes.
Version 6.38.1-3
Release date: 2024.05.22
Resolved issues
GravityZone platform
Fixed an issue causing an error message to sometimes appear when trying to edit GravityZone user accounts with SSO enabled.
eXtended Detection and Response
Smart Views are now correctly being displayed in the Response tab for On-Premises environments created after 2024.04.24.
Version 6.38.1-2
Release date: 2024.04.24
Resolved issues
GravityZone platform
Security fixes.
Version 6.38.1-1
Release interval: 2024.04.15 - 2024.05.14
New features
Anti-tampering
Anti-tampering enables you to view when vulnerable drivers are detected on endpoints, and when advanced attack attempts are made to disable the security agent, leading to compromised product integrity.
The feature capabilities are divided in two main categories with distinct targets:
Vulnerable drivers
This pre-tampering technology detects vulnerable drivers on endpoints that can be exploited by attackers, posing threats to the integrity of the product. The technology is compatible with Windows and Linux operating systems.
Callback evasion
This post-tampering technology can detect when the security agent callback functions have been maliciously removed or disabled. New threats or unintentional human error could be engineered to potentially allow unauthorized access to the kernel, leading to compromised product integrity. The technology is compatible with Windows operating systems.
You can enable or disable the feature and configure different actions in the policy under the Antimalware > Anti-tampering section.
To view more information about detection events you can generate a Security Audit or Blocked Applications report or use portlets. Additionally, you can be notified whenever the security agent callbacks are maliciously removed or disabled, or vulnerable drivers are detected on endpoints by using the new Anti-tampering event notification.
Improvements
Patch Management for Mac
GravityZone extends support for Patch Management to macOS endpoints. Using the same settings in Control Center as for Windows and Linux, you can now keep macOS applications and the operating system up to date in a simple, efficient and unified manner.
Some highlights:
GravityZone sections such as Dashboard, Installation Packages, Network, Tasks, Patch Inventory, Maintenance Windows, and User Activity have been updated to support Patch Management for Mac.
When configuring a maintenance window, macOS applications are displayed separately from the Windows and Linux versions in the Vendors and Products section.
Reports such as Network Patch Status and Network Protection Status and notifications such as Missing patch issue now include information related to Patch Management on macOS endpoints.
Patch Management for Mac is available with existing GravityZone keys and it is licensed per managed endpoint, the same as for Windows and Linux.
This feature is available for macOS Big Sur (11.0) and later and requires Full Disk Access for the Bitdefender agent installed on endpoints.
To use Patch Management on macOS endpoints, you must reconfigure the security agent installed on them.
Note
GravityZone applies operating system patches only for minor versions, for example from version 13.5 (Ventura) to 13.6 (Ventura), but not from 13.9 (Ventura) to 14.0 (Sonoma).
Notifications
GravityZone email notifications are now available in a modern design and have revised email subjects, notification titles, and email content. Additionally, some notifications in GravityZone Control Center have been renamed. You can find more information in Changes to GravityZone email notifications.
The New incident notification has been improved: all configuration options have been merged into one. Existing users, with any of the three settings activated prior to the update, now have the New incident notification enabled by default.
Public API
Maintenance Windows API
The
os
attribute is now available undervendorProductsPairs
for thespecificVendorAndProduct
parameter. You can use it to specify the operating system the vendor-products pair is compatible with.The attribute is available for requests made using the
createPatchManagementMaintenanceWindow
andupdatePatchManagementMaintenanceWindow
methods and is returned by requests made with thegetMaintenanceWindowDetails
method.
Quarantine API
The behavior of the
getQuarantineItemsList
method has changed. If thecompanyId
parameter is not included in the request, the method now returns all the quarantined items within user's company. The user's company is determined by the API key used to make the request.
Packages API
A new method is now available:
updatePackage
. You can use it to update installation packages.
EDR
The Response tab is now also available for EDR incidents.
On demand endpoint actions executed from an incident graph are now displayed in the response grid of that incident.
The status of tasks resulting from EDR response actions is now changed to Failed after being unresponsive for two days.
The Remediation button and the associated section have been removed from the Endpoint Incidents tab and are now available in the new EDR Response tab.
You can now manually mark endpoint response actions as done or dismissed from the Response grid.
Sandbox Analyzer
The Sandbox Analyzer page now displays more specific messages for failed detonations.
Policies
The Actions button from Configuration Profiles > Exclusions has been removed.
The Export Selection and Delete options, previously located under Configuration Profiles > Exclusions > Actions, have been added to the interface for better accessibility and ease of use.
Help & Support
The Help & Support page has a new design, easier to navigate. Topics are displayed on cards organized in two tabs:
Basics - covers GravityZone general use, technical assistance, legal aspects, and more.
Advanced Configuration - provides information on specific GravityZone features.
As with the previous Help & Support page, the content depends on the license you are using.
Limitations
EDR
Custom detection rules and Custom exclusion rules features will only work if GravityZone Control Center is updated to this latest version and your endpoints have the following version of BEST or newer, as announced in Anti-tampering banner in January:
7.9.5.324 (Windows)
7.0.3.2271 (Linux)
7.14.32.200019 (macOS)
Removed features
Policies
The Update Linux EDR modules using product update option has been removed from the General > Update page in the policy settings.
Resolved issues
Tasks
In some cases, expired Reconfigure agent tasks ran on endpoints after they came back online.
Reports
Resolved an issue related to the cleanup of reports that exceeded the retention period.
GravityZone platform
Endpoints incorrectly connected to a different Security Server when the one configured in the policy was shut down, leading to system slowdown and overloaded Security Servers in the network.
Security fixes.
Known issues
Notifications
GravityZone users from companies using Business Security Premium license are not receiving New incident notifications.
Version 6.37.1-1
Release date: 2024.03.13
Resolved issues
GravityZone platform
The VMware vCenter integrations that experienced communication issues with the GravityZone console could not be removed, resulting in an unknown error.
Security fixes.
Version 6.36.1-1
Release date: 2024.03.05
Resolved issues
GravityZone platform
For some users, the synchronization process did not stop after adding an AD integration, leading to a significant increase in disk space usage.
AD Users Import Sync is now able to import Security Groups for clients with lowercase abbreviations for components in their Distinguished Names.
Security fixes.
Version 6.35.1-3
Release date: 2024.02.19
Note
This update is intended for GravityZone instances in isolated environments.
Improvements
GravityZone platform
The GravityZone offline update system features the following enhancements:
Offline full and lite update archives that are optimized resulting in a reduced file size.
A new design and structure that help you identify components easily along with adding more granularity in selecting kits, product updates, and signature updates.
Separate creation time interval selectors: Lite Archive creation interval (in hours) and Full Archive creation interval (in days).
Separate buttons for creating archives: Create Lite archive and Create Full archive.
A new option Keep previous files on disk, regardless of selected kits that enables you to maintain previously downloaded files on disk, regardless of your current selection of kits.
Version 6.35.1-3
Release date: 2024.01.30
Resolved issues
Network Protection
The Last modified filter at Configuration Profiles > Web Access Control Scheduler is no longer limited to 90 days.
Version 6.35.1-2 (third-party updates)
Release date: 2024.01.23
Resolved issues
GravityZone platform
Security fixes.
Version 6.35.1-2
Release date: 2023.12.20
Resolved issues
GravityZone platform
The endpoints update encountered a failure following the upgrade of the GravityZone console to the most recent version, 6.35.1-1.
In some cases, the GravityZone console update became unresponsive for all-in-one environments.
Version 6.35.1-1
Release interval: 2023.12.12 - 2023.12.18
New features
Unified Incidents
The Incidents page is improved with multiple new features including a new grid. It offers an improved overall user experience and the possibility to create customized views based on your needs.
The new unified grid combines Endpoint and Detected threats in a single view.
The release comes with a more flexible and improved Smart View, along with new filters and options that allow you to create customized views based on your needs.
Improvements
Antimalware
All on-demand scan tasks now include the setting Preserve last access time. Using this new option, you can control whether to preserve the last access time for a file during a scan, or to allow the scanning process to modify the timestamp of that file. The option is available in the Options tab of each type of scan task, under Settings > Miscellaneous, and is enabled by default.
Patch Management
We are currently developing Patch Management for macOS. Although now you have the option to install macOS patches, they are not yet visible in GravityZone. We recommend you wait until the feature is fully released in 2024.
Firewall
Firewall is now available for Windows Servers. This update focuses on simplifying rule management, ensuring essential network traffic, and providing more flexibility.
Users can now edit and delete all existing predefined rules in the policy.
The Firewall can be enabled on the Windows Server operating systems by performing the Reconfigure Task. The activation of the Firewall module is not automatic, even if Firewall is enabled in the policy.
Before enabling the module on their systems, it is important for users to assess and design their Firewall rules for servers. This is necessary to avoid potential service disruptions caused by the configuration of the ruleset, which may block traffic.
The Firewall icon from Installation Packages was updated, and now includes both Windows servers and workstations.
To find the supported Windows Server operating systems refer to this kb article.
Network
In the Endpoint details page, the Content Control module now consists of three separate modules: Content Control, Web Traffic Scan, and Antiphishing.
There is now consistent behavior between the delete button and the drag-and-drop action within the deleted folder. Any endpoint that is moved to the deletion folder, either through the delete button or drag-and-drop, will be uninstalled immediately via the uninstall task or later when it reconnects online and communicates. For more details, visit the Deleting endpoints page.
Network protection
Multiple schedules are now available in Configuration Profiles > Web Access Control Scheduler. This allows users to have more flexibility in setting up different time windows for Web Access Control. The Web rules list found in Content Control > Web Access Control Settings > Web Categories Filter has been moved under Policies > Configuration Profiles > Web Access Control Scheduler > Category Scheduler.
Users can now create new schedules with multiple time window settings and assign categories to each schedule. The categories will be removed from the policy and the new schedule will be mapped to a policy.
You can now exclude from scanning any financial domains from Network Protection > General > Network Protection > Intercept Encrypted Traffic > Exclude financial domains.
Incidents
Incidents generated by the EDR or Prevention Modules now display the name of the endpoint in the Entities column.
For a better visualization, you can now expand the following panels further:
Node details panel
Alert details panel opened from a node
Alert details panel opened from the Alerts/Events section
The new Smart views feature allows you to customize the information that is displayed by the grid:
All incidents
Assigned to you
A new column and filter is available in the Incidents page:
Entities: it indicates the number and types of incidents involved in an event.
Accounts
The Manage Networks right for GravityZone user accounts has been replaced by the following options:
Manage Networks. Create and download installation packages; install security agents; manage tasks and quarantined files. You can choose between two levels of customization:
View and Analyze Data
Advanced Investigation
Manage Endpoint Settings. View or manage policies, configuration profiles, assignment rules and any other endpoint setting from other GravityZone areas. You can choose between two levels of customization:
Read only
Read and Write
Resolved issues
Network
The sorting settings in Network did not accurately reflect the specified sorting settings for the Last Seen filter.
GravityZone platform
Security fixes.
Version 6.34.1-2
Release date: 2023.11.07
Improvements
Patch Management
Added support for the upcoming release of Patch Management for Mac. This feature uses a new catalog format, which affects the existing installations for Windows and Linux. To accommodate these changes, make sure you update the GravityZone console to version 6.34.1-2 or later.
Version 6.34.1-1 (third-party updates)
Release date: 2023.11.01
Resolved issues
GravityZone platform
Security fixes.
Version 6.34.1-1
Release interval: 2023.10.03 - 2023.10.17
Improvements
GravityZone platform
Implemented internal optimizations for enhanced performance and stability of GravityZone.
Warning
Before proceeding with the update, we strongly advise you to take snapshots of all GravityZone appliances.
Resolved issues
GravityZone platform
The GravityZone integration with VMware vCenter failed to synchronize and remained in a loading state when using the Cloud Workloads network view.
The GravityZone console failed to check for kits and repository updates when generating a full archive. This issue affected freshly deployed offline environments.
Security fixes.
Version 6.33.1-1
Release interval: 2023.09.05 - 2023.09.19
Improvements
EDR
The Incidents > Custom Rules section has been divided in two sections: Custom detection rules and Custom exclusion rules.
The grids and rule configuration pages have a new design.
Rule settings now include targets. You can now decide whether to apply the rule to the entire company or to specific groups by endpoint tags.
Clicking a grid entry brings up the details panel of the rule. It contains information about the rule, options for navigating rules and for editing the current rule.
GravityZone platform
You can no longer remove the license from a company if no other licenses are assigned. You need to first add a different license key.
Public API
New limitations are in place to the number of API requests allowed per second. For more information, refer to this kb article.
Resolved issues
Network Protection
Fixed an issue where specific websites from the Mature Content category remained accessible despite the rule defined in Web Access Control.
Endpoint tags
The Tag column on the Network > Tags page was unusable if placed after the first visible columns.
Tasks
In some cases, GravityZone tasks older than 30 days were not deleted when the sub-tasks remained in pending state.
Notifications
On the Notification Settings page, a single icon for sending options was visible, despite all options being enabled. The issue occurred when the browser window was horizontally resized to a smaller scale.
Reports
The Security Audit report incorrectly displayed the command line used in Advanced Threat Control events when quotation marks were used.
GravityZone platform
Korean characters from events in JSON format that were transmitted to a syslog server were converted into ASCII code.
Security fixes.
Version 6.32.1-1 (third-party updates)
Release date: 2023.08.16
Improvements
GravityZone platform
The GravityZone offline update archives have been optimized, resulting in reduced file sizes. Furthermore, obsolete product kits have been eliminated.
Resolved issues
GravityZone platform
Security fixes.
Version 6.32.1-1 (third-party updates)
Release date: 2023.07.11
Resolved issues
GravityZone platform
Security fixes.
Version 6.32.1-1
Release interval: The rollout for this update will be performed progressively starting with June 6, 2023.
Improvements
GravityZone platform
At Bitdefender, we are continuously improving GravityZone, the world's best-in-class cybersecurity solution. This time, we enhanced the performance of the GravityZone Database Server by upgrading MongoDB, the database management system, and other important components.
The MongoDB upgrade brings some security and operational improvements along with a new requirement. GravityZone console now automatically checks if AVX instructions are enabled on the virtual machine. This requirement concerns appliances with old versions that are upgraded to the current one and systems that may be incompatible with AXV at a hardware level. Learn more
Warning
Before proceeding with the update, we strongly advise you to take snapshots of all GravityZone appliances.
A full installation kit is now available for BEST Windows endpoints that use ARM CPUs.
Public API
Network API
The
createScanTask
method now return all task IDs created as a result of the request instead of the most recent one.
Resolved issues
Policies
A validation issue prevented Firewall rules from being imported into policies when they started with a backslash (\).
GravityZone platform
In some situations, scheduling a database backup failed when the password for the network share location contained special characters.
Security fixes.
Version 6.31.1-3
Release date: 2023.05.10
Resolved issues
GravityZone platform
Logging in to the GravityZone console using an Active Directory account in the Domain\Username format resulted in an error message. The issue affected appliances with version 6.31.1-1.
Version 6.31.1-1
Release interval: 2023.04.26 - 2023.05.11
Improvements
Installation Packages
The Network > Packages page has a new design and a new name: Installation Packages.
The Add button has become Create.
All other buttons except Download have been moved under More actions.
The package configuration form also has a new look.
Tasks
The Network > Tasks page has a new look and new options for a better user experience. Some highlights:
Filters and search boxes
Expandable and sortable columns
New details panel for sub-tasks.
Tasks in the Network page have now more intuitive and consistent names. For example, Scan has become Malware scan, Install is now Install agent, and Reconfigure client has been renamed to Reconfigure agent.
The new names are also reflected in the Network > Tasks page, under the Task type category.
With this update, the User Activity page records actions on tasks under the new names. Existing records under old names remain unchanged.
For the complete list of renamed tasks, refer to Changes to task names in GravityZone On-premises Control Center.
Licensing
You can now uninstall the Patch Management and Full Disk Encryption modules after their corresponding license keys have expired.
Offline license keys are now generated using a new format. You are no longer able to add previously generated license keys and their corresponding offline codes to your GravityZone On Premise Console.
Note
Keys already assigned to companies remain valid, as long as they are not removed.
Accounts
The Accounts page has been redesigned and restructured. The page now provides an improved overall user account management experience.
Policies
In the Policies > Assignment Rules page, you can now apply policies via location rules only to targets you manage.
From now on, the Targets section is always active when you configure a rule to prevent it from being applied outside its scope. If you do not specify targets, GravityZone automatically selects all the available entities when saving the rule.
Old rules with no targets specified will continue to function as before until you manually save them again.
You now receive an explanatory message every time you cannot save a policy due to invalid data in the Sandbox Analyzer > Endpoint Sensor section.
Notifications
You can now choose to receive notifications via email in plain text format. The new option is available for all notification types and you can find it on the Notifications Settings page.
The notifications email subject is now editable. You can customize the subject according to your needs using the new option Set custom email subject when configuring the notification. The option is available for most notification types.
The Centralized Quarantine Issues notification includes the endpoint name.
The Login from New Device notification includes the username of the account used.
Endpoint tags
Each tag in the Tags Management page now includes an inline menu to delete it or to easily create copies and apply them in your network. These actions are recorded in the User Activity page.
In the Network page, you can now create custom tags directly in the Assign custom tags window.
In the Unassign custom tags window, you can remove all custom tags from endpoints at once.
Network Protection
The Web rules list found in Content Control > Web Access Control Settings > Web Categories Filter has been updated with additional categories. All existing policies are automatically updated to reflect the changes made regarding the updated categories.
Newly added categories:
Astrology
Auto
Food
Kids
Lifestyle
Occult
Pets
Real Estate
Society
Updated categories:
Drugs category was split into the following categories: Alcohol, Tobacco, Pharmacy.
Video Online category was replaced by the Videos category.
Banks category was replaced by the Financial category.
Casual Games, Online Games and Computer Games categories have been merged to the Games category.
You can now enable outbound traffic monitoring for Network Attack Defense over SFTP and SCP/SSH protocols on Linux machines. The new options are available in the Network Protection > General section of the policy settings. In addition, the Scan SSL option has been renamed to Intercept Encrypted Traffic and Scan HTTP has become Scan HTTPS.
GravityZone platform
The Amazon EC2 integration now supports the following optional regions that can be disabled or enabled from the integration: Cape Town, Hong Kong, Hyderabad, Jakarta, Osaka, Spain, Zurich, United Arab Emirates, Milan.
You can now create and restore GravityZone database backups that include your current staging settings and the status of the published packages. The new option is available only for environments with staging enabled.
The Gather logs feature from Network > endpoint details > Troubleshooting tab has been enhanced. You can now select between three new types of logs:
Product general issues
Malware infection
Malware infection (no cloud services)
Public API
Accounts API
The following Notifications Visibility Options are now available:
setCustomEmailSubject
- iftrue
, changes the default subject used for GravityZone notification emails.emailSubject
- it contains the custom text to be used for GravityZone notification emails ifsetCustomEmailSubject
is set to yes.
Note
These options are only available for specific notification types.
The
sendOnlyPlainTextEmail
parameter is now available for theconfigureNotificationsSettings
method. Enabling this option sends all notification emails in plain text format.The
getNotificationsSettings
method now returns an additional option:sendOnlyPlainTextEmail
.
Network API
The
productOutdated
parameter is now available for thegetEndpointsList
method. The parameter indicates if the endpoint is missing one or more agent updates.The
createScanTask
method now return all task IDs created as a result of the request instead of the most recent one.
Resolved issues
Patch Management
Fixed an issue on patch blacklisting. Some selected patches were not blacklisted because the selected targets were no longer valid for blacklisting. The error occurred also when trying to restore a patch without selecting valid targets.
GravityZone platform
User Activity logs for API key creation are now visible to all users with the necessary rights.
Security fixes.
Known issues
GravityZone platform
Logging in to the GravityZone platform using an Active Directory (AD) account in the down-level logon name format (Domain\User) is currently not available. Attempting to do so results in a session expired error message.
Note
As an alternative, we recommend using the User Principal Name (UPN) format, such as [email protected].
Version 6.30.4-1
Release date: 2023.03.29
Improvements
Sandbox Analyzer
Security improvements for Sandbox Analyzer cloud portal.
Important
Due to these changes, starting May 2, 2023, manual submission will no longer work with GravityZone versions older than 6.30.4-1 released before March 29, 2023. To continue using this feature, you must update your console to version 6.30.4-1 or newer.
Resolved issues
Integrations
Registering an integration with NSX-V Manager failed if the default policy contained exclusion lists.
GravityZone platform
Security fixes.
Version 6.30.3-1
Release date: 2023.03.02
Improvements
Exchange Protection
The Send a Copy To secondary action is now available for the Replace file with text, Delete file, and Reject/Delete email actions. The settings can be found in the Policies > Exchange protection > Content Control page, under the Attachment filtering section.
Resolved issues
GravityZone platform
Security fixes.
Version 6.30.2-3
Release date: 2023.02.02
Resolved issues
GravityZone platform
GravityZone experienced delays and errors when processing a large number of policy status events, which affected communication between the Virtual Appliance and endpoints.
Security Containers and Security Container hosts no longer appear as having issues in the Network page despite there being no problems with the endpoints.
Fixed an issue that caused the GravityZone Virtual Appliance to create network entries for the Instant Clone internal templates.
Security fixes.
Version 6.30.2-2
Release date: 2023.01.19
Resolved issues
GravityZone platform
In several situations, the GravityZone console failed to create scheduled backups for large databases in the specified network locations.
Security fixes.
Archived Release Notes
For GravityZone release notes covering 2019–2022, refer to this document.