<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint Security E80.90 Client released! in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-E80-90-Client-released/m-p/20613#M460</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117536"&gt;&lt;IMG __jive_id="76663" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76663_pastedImage_5.png" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV class="" style="text-align: center;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117536"&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;STRONG&gt;Endpoint Security Homepage&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;E80.90&lt;/STRONG&gt; includes stability and quality fixes. It supports all features of previous releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enterprise Endpoint Security E80.90 for:&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk143452"&gt;Windows Clients&lt;/A&gt;&lt;/STRONG&gt; | &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131152"&gt;&lt;STRONG&gt;Mac Clients (E80.89)&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;New Features&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Windows 10 October 2018 Update Support.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Enhanced Fileless and Malicious Powershell Detections engine extending Behavioral Guard capabilities.&lt;/STRONG&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;This new engine provides a multi-phase ability to detect malicious PowerShell usage that is unique.&lt;/LI&gt;&lt;LI&gt;Includes full AMSI (Advanced Malware Scan Interface) integration to get, analyze and report decoded scripts.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Forensic report overhaul with a new style and enhanced reputation integration.&lt;/STRONG&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Completely redesigned Overview and General screens.&lt;/LI&gt;&lt;LI&gt;Many small usability and visual enhancements throughout the report.&lt;/LI&gt;&lt;LI&gt;View decoded script content as part of the report itself.&lt;/LI&gt;&lt;LI&gt;See the Enhancements section below for additional information.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Forensics now has major performance improvements.&lt;/STRONG&gt; &lt;UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;There is a major reduction (roughly 50% fewer events) in the amount of data stored. This results in lower IO usage and better performance.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;See the enhancements below for the full list of performance enhancements.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Forensics Analysis takes on average 20% less time to complete.&lt;/STRONG&gt;&lt;BR /&gt; For larger reports the time taken will be further reduced. &lt;UL&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Stack Pivoting detection was turned on as a new exploit detection technique for Anti-Exploit.&lt;/STRONG&gt;&lt;BR /&gt; Stack Pivoting involves trying to create a fake stack from attacker controlled memory.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Anti-Exploit now default protects the Equation Editor process.&lt;/STRONG&gt;&lt;BR /&gt;This helps to cover the following CVEs:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;CVE-2017-11882&lt;/LI&gt;&lt;LI&gt;CVE-2018-0802&lt;/LI&gt;&lt;LI&gt;CVE-2018-0812&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Enhancements&lt;/H3&gt;&lt;UL style="padding-left: 30px;"&gt;&lt;LI&gt;&lt;STRONG&gt;Anti-Ransomware, Behavioral Guard and Forensics&lt;/STRONG&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Enhances Behavioral Guard with the ability to perform deep inspections of both behavior and script content of PowerShell and Fileless attacks.&lt;/LI&gt;&lt;LI&gt;Improves Forensic reports with decoded PowerShell scripts from AMSI integration.&lt;BR /&gt;This feature is only available in Windows 10.&lt;/LI&gt;&lt;LI&gt;Adds many new suspicious events for the Forensic report, including new PowerShell related suspicious events.&lt;/LI&gt;&lt;LI&gt;Fixes a crash occurring when Forensics, Anti-Ransomware and Behavior Guard are processing an existing policy while receiving a new policy.&lt;/LI&gt;&lt;LI&gt;Fixes a rare issue with large continuous CPU utilization when the Forensics service is unable to communicate with the driver.&lt;/LI&gt;&lt;LI&gt;Improves Forensic performance by adding static exclusions for well known file operations.&lt;BR /&gt; This addition alone can reduce the number of file operations stored by up to 80% on some machines.&lt;/LI&gt;&lt;LI&gt;Improves Forensics performance by adding dynamic exclusions for file operations based on a new heuristic.&lt;BR /&gt; This can reduce the number of file operations stored by up to 30%.&lt;/LI&gt;&lt;LI&gt;Improves Forensic performance by dynamically excluding registry operations based on a new heuristic.&lt;BR /&gt; On average, 10% of registry operations are now excluded.&lt;/LI&gt;&lt;LI&gt;Fixes an issue which caused duplication of log events in Forensics.&lt;/LI&gt;&lt;LI&gt;Improves Entry Point calculations across multiple scenarios to be more accurate in the Forensic Report.&lt;/LI&gt;&lt;LI&gt;Fixes a majority of issues where the Entry Point of an attack could be empty.&lt;BR /&gt; Now there should almost always be an Entry Point.&lt;/LI&gt;&lt;LI&gt;Improves the Forensics report so that Command Prompts (&lt;EM&gt;cmd.exe&lt;/EM&gt;) opened for typing no longer appear in the Forensic report, but may appear in the Entry Point instead.&lt;/LI&gt;&lt;LI&gt;Improves the Forensic Analysis to consider following files in the argument of processes already included as part of the incident.&lt;/LI&gt;&lt;LI&gt;The Forensics report now shows the termination status for every process present in the report.&lt;/LI&gt;&lt;LI&gt;Fixes an issue that could lead to incomplete termination of processes involved in a Ransomware incident.&lt;/LI&gt;&lt;LI&gt;Processes, showing in a report, that are closed at the time of the generation of the report will now correctly show as terminated, even if the remediation policy for termination is disabled.&lt;/LI&gt;&lt;LI&gt;Fixes an issue where some Forensic report icons may be missing when upgrading to E80.89.&lt;BR /&gt; The icons are now present when upgrading to E80.90.&lt;/LI&gt;&lt;LI&gt;Fixes an issue with the scroll bar not appearing correctly if there are multiple nodes in the Entry Point view of the Forensics Report.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Fixes a Forensics Analysis issue where script processes like PowerShell do not appear in the report when &lt;EM&gt;Cmd&lt;/EM&gt; is involved and the script process is not the trigger.&lt;/LI&gt;&lt;LI&gt;Process arguments and script contents are now encoded in the Forensic reports.&lt;BR /&gt; This prevents the deletion of the reports by Anti-Viruses looking for specific signatures found in the argument or script content.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Adds support to include the Malware Family from URL reputation if present in the Forensic report.&lt;/LI&gt;&lt;LI&gt;Fixes an issue which could result in the User Name appearing empty in the Forensic Report.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Fixes a visual issue in the Forensic report where the distance between processes could be very large if a process has a lot of lines of text.&lt;/LI&gt;&lt;LI&gt;Updates the default exclusions for Anti-Ransomware.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Threat Emulation and Anti-Exploit&lt;/STRONG&gt; &lt;UL&gt;&lt;LI&gt;Anti-Exploit now has an additional exploit prevention technology called stack pivoting.&lt;/LI&gt;&lt;LI&gt;Anti-Exploit now protects Equation Editor from known and unknown exploit attempts.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Anti-Bot&lt;/STRONG&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Fixes a crash when the Anti-Bot database is held by another process in the system.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;SandBlast Agent Updater&lt;/STRONG&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Adds support for Static Analysis updates running in parallel to other updates using the Updater.&lt;BR /&gt;Fixes an issue where the wrong service is restarted when updating two products together.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; macOS 10.14 (Mojave) can only work with E80.89 clients. &lt;P&gt;You must upgrade the Endpoint Security client to this version before you can upgrade the operating system.&lt;/P&gt;&lt;P&gt;It is strongly recommended that you read the Client Release Notes, before installing this release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Jan 2019 08:16:35 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2019-01-03T08:16:35Z</dc:date>
    <item>
      <title>Endpoint Security E80.90 Client released!</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-E80-90-Client-released/m-p/20613#M460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117536"&gt;&lt;IMG __jive_id="76663" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76663_pastedImage_5.png" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV class="" style="text-align: center;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117536"&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;STRONG&gt;Endpoint Security Homepage&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;E80.90&lt;/STRONG&gt; includes stability and quality fixes. It supports all features of previous releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enterprise Endpoint Security E80.90 for:&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk143452"&gt;Windows Clients&lt;/A&gt;&lt;/STRONG&gt; | &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131152"&gt;&lt;STRONG&gt;Mac Clients (E80.89)&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;New Features&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Windows 10 October 2018 Update Support.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Enhanced Fileless and Malicious Powershell Detections engine extending Behavioral Guard capabilities.&lt;/STRONG&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;This new engine provides a multi-phase ability to detect malicious PowerShell usage that is unique.&lt;/LI&gt;&lt;LI&gt;Includes full AMSI (Advanced Malware Scan Interface) integration to get, analyze and report decoded scripts.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Forensic report overhaul with a new style and enhanced reputation integration.&lt;/STRONG&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Completely redesigned Overview and General screens.&lt;/LI&gt;&lt;LI&gt;Many small usability and visual enhancements throughout the report.&lt;/LI&gt;&lt;LI&gt;View decoded script content as part of the report itself.&lt;/LI&gt;&lt;LI&gt;See the Enhancements section below for additional information.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Forensics now has major performance improvements.&lt;/STRONG&gt; &lt;UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;There is a major reduction (roughly 50% fewer events) in the amount of data stored. This results in lower IO usage and better performance.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;See the enhancements below for the full list of performance enhancements.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Forensics Analysis takes on average 20% less time to complete.&lt;/STRONG&gt;&lt;BR /&gt; For larger reports the time taken will be further reduced. &lt;UL&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Stack Pivoting detection was turned on as a new exploit detection technique for Anti-Exploit.&lt;/STRONG&gt;&lt;BR /&gt; Stack Pivoting involves trying to create a fake stack from attacker controlled memory.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Anti-Exploit now default protects the Equation Editor process.&lt;/STRONG&gt;&lt;BR /&gt;This helps to cover the following CVEs:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;CVE-2017-11882&lt;/LI&gt;&lt;LI&gt;CVE-2018-0802&lt;/LI&gt;&lt;LI&gt;CVE-2018-0812&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Enhancements&lt;/H3&gt;&lt;UL style="padding-left: 30px;"&gt;&lt;LI&gt;&lt;STRONG&gt;Anti-Ransomware, Behavioral Guard and Forensics&lt;/STRONG&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Enhances Behavioral Guard with the ability to perform deep inspections of both behavior and script content of PowerShell and Fileless attacks.&lt;/LI&gt;&lt;LI&gt;Improves Forensic reports with decoded PowerShell scripts from AMSI integration.&lt;BR /&gt;This feature is only available in Windows 10.&lt;/LI&gt;&lt;LI&gt;Adds many new suspicious events for the Forensic report, including new PowerShell related suspicious events.&lt;/LI&gt;&lt;LI&gt;Fixes a crash occurring when Forensics, Anti-Ransomware and Behavior Guard are processing an existing policy while receiving a new policy.&lt;/LI&gt;&lt;LI&gt;Fixes a rare issue with large continuous CPU utilization when the Forensics service is unable to communicate with the driver.&lt;/LI&gt;&lt;LI&gt;Improves Forensic performance by adding static exclusions for well known file operations.&lt;BR /&gt; This addition alone can reduce the number of file operations stored by up to 80% on some machines.&lt;/LI&gt;&lt;LI&gt;Improves Forensics performance by adding dynamic exclusions for file operations based on a new heuristic.&lt;BR /&gt; This can reduce the number of file operations stored by up to 30%.&lt;/LI&gt;&lt;LI&gt;Improves Forensic performance by dynamically excluding registry operations based on a new heuristic.&lt;BR /&gt; On average, 10% of registry operations are now excluded.&lt;/LI&gt;&lt;LI&gt;Fixes an issue which caused duplication of log events in Forensics.&lt;/LI&gt;&lt;LI&gt;Improves Entry Point calculations across multiple scenarios to be more accurate in the Forensic Report.&lt;/LI&gt;&lt;LI&gt;Fixes a majority of issues where the Entry Point of an attack could be empty.&lt;BR /&gt; Now there should almost always be an Entry Point.&lt;/LI&gt;&lt;LI&gt;Improves the Forensics report so that Command Prompts (&lt;EM&gt;cmd.exe&lt;/EM&gt;) opened for typing no longer appear in the Forensic report, but may appear in the Entry Point instead.&lt;/LI&gt;&lt;LI&gt;Improves the Forensic Analysis to consider following files in the argument of processes already included as part of the incident.&lt;/LI&gt;&lt;LI&gt;The Forensics report now shows the termination status for every process present in the report.&lt;/LI&gt;&lt;LI&gt;Fixes an issue that could lead to incomplete termination of processes involved in a Ransomware incident.&lt;/LI&gt;&lt;LI&gt;Processes, showing in a report, that are closed at the time of the generation of the report will now correctly show as terminated, even if the remediation policy for termination is disabled.&lt;/LI&gt;&lt;LI&gt;Fixes an issue where some Forensic report icons may be missing when upgrading to E80.89.&lt;BR /&gt; The icons are now present when upgrading to E80.90.&lt;/LI&gt;&lt;LI&gt;Fixes an issue with the scroll bar not appearing correctly if there are multiple nodes in the Entry Point view of the Forensics Report.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Fixes a Forensics Analysis issue where script processes like PowerShell do not appear in the report when &lt;EM&gt;Cmd&lt;/EM&gt; is involved and the script process is not the trigger.&lt;/LI&gt;&lt;LI&gt;Process arguments and script contents are now encoded in the Forensic reports.&lt;BR /&gt; This prevents the deletion of the reports by Anti-Viruses looking for specific signatures found in the argument or script content.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Adds support to include the Malware Family from URL reputation if present in the Forensic report.&lt;/LI&gt;&lt;LI&gt;Fixes an issue which could result in the User Name appearing empty in the Forensic Report.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Fixes a visual issue in the Forensic report where the distance between processes could be very large if a process has a lot of lines of text.&lt;/LI&gt;&lt;LI&gt;Updates the default exclusions for Anti-Ransomware.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Threat Emulation and Anti-Exploit&lt;/STRONG&gt; &lt;UL&gt;&lt;LI&gt;Anti-Exploit now has an additional exploit prevention technology called stack pivoting.&lt;/LI&gt;&lt;LI&gt;Anti-Exploit now protects Equation Editor from known and unknown exploit attempts.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Anti-Bot&lt;/STRONG&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Fixes a crash when the Anti-Bot database is held by another process in the system.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;SandBlast Agent Updater&lt;/STRONG&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Adds support for Static Analysis updates running in parallel to other updates using the Updater.&lt;BR /&gt;Fixes an issue where the wrong service is restarted when updating two products together.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; macOS 10.14 (Mojave) can only work with E80.89 clients. &lt;P&gt;You must upgrade the Endpoint Security client to this version before you can upgrade the operating system.&lt;/P&gt;&lt;P&gt;It is strongly recommended that you read the Client Release Notes, before installing this release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 08:16:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-E80-90-Client-released/m-p/20613#M460</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-01-03T08:16:35Z</dc:date>
    </item>
  </channel>
</rss>

