Build Notes: ZeroLock® Endpoint Agent 3.x

Build notes describe the changes that are included in each build that is created for Vali Cyber’s ZeroLock Agents.

Before you install one of these builds, familiarize yourself with the new features, resolved issues, and other changes. For more information, see the Vali Cyber Support Page.

Summary of Changes 

The changes that are included in the ZeroLock Agent builds are listed in the following tables: 

 

  Build 3.5.11 – August 28, 2024 
Item Number Description 
TYR-91

Addressed the issue of Agent failing to get activated from the ZMC after exhausting restart attempts.

   
PM-216

Alert Mode Only

 

  Build 3.5.10 – August 21, 2024 
Item Number Description 
 LIBI-36

Intercept tkill and tgkill syscalls

Simplified code to pass tkill/tgkill to process_monitor as kill.

   
PM-216

Alert Mode Only

On the ACTIONS dropdown for the endpoints page, the options for ENABLE ALERT ONLY mode and DISABLE ALERT ONLY  mode are now available. These buttons only work with Agent version 3.5.10 and newer.

When activating Alert Only mode, the user must select a timeout. The default is 24 hours from the current time. Upon reaching the timeout, the agent will automatically revert to its normal mode of operation.

 

  Build 3.5.9 – August 21, 2024 
Item Number Description 
 PM-211

Reduced memory usage for constrained environments.

   
TYR-88 Upgrade libcurl from 8.6.0 to 8.9.1 to resolve CVE.

 

  Build 3.5.5 – July 31, 2024 
Item Number Description 
 PM-209

Local MFA

An agent can now perform MFA authentication without requiring the ZMC. The agent no longer needs to be connected to the ZMC when the user sets up MFA because the ZMC will send the user’s username and MFA secret to the agent.

Additionally, the agent will only ask for the username and token once. If either is incorrect, there is a five-second pause and the session is terminated.

 

  Build 3.5.4 – July 30, 2024 
Item Number Description 
 PM-208

Increased efficiency of Program Filter by configuring scans to run only when required by specific events such as on start up after initial install. 

   
TYR-83

Added robustness to Tyr to prevent multiple concurrent Tyr/Baldur processes. i

 

  Build 3.5.3 – July 29, 2024 
Item Number Description 
 PM-205

Addressed the issue of SSH connection failures on ESXi 6.7 and 7.

   
TYR-85

Addressed the issue of Endpoint SHELL from ZMC not working with ESXi Endpoints.

 

  Build 3.1.17 – July 16, 2024 
Item Number Description 
AGENT-427

Addressed the issue of periodic timeout failures when running Ansible. 

   
 PM-202 

Agent logging efficiency improved as it will not log whenever it injects into a process but will log the name of that process. 

   
PM-200

Monitoring of SLPD (Service Level Protocol Daemon) added to prevent exploitation of service vulnerabilities. 

 

  Build 3.1.16 – June 27, 2024 
Item Number Description 
AGENT-424

Enable Fully Automated Installation with Lifecycle Manager.


  Build 3.1.15 – June 24, 2024 
Item Number Description 
PM-198

Automatically Update the Program Filter if ESXi version is updated.

   
BALD-170 Log system information in Baldur logs. Baldur will now print the information provided by uname -a in the logs.

 

   Build 3.1.13 – June 18, 2024 
Item Number Description
AGENT-410 Changes to support installation from vCenter Server. 

   Build 3.1.12 – June 18, 2024 
Item Number Description

LIBI-33

Incremented version of Libinject to resolve coredumps being generated by SSH timeouts.

 


   Build 3.1.11 – June 09, 2024 
Item Number Description

BALD-69

Reduced time for monitoring new local ESXi shell sessions. 

 


   Build 3.1.10 – May 30, 2024 
Item Number Description

TYR-77

Enhanced DNS resolution capabilities. 

 


   Build 3.1.6 – May 16, 2024 
Item Number Description

TYR-64

The tyr.log file now logs the agent package version to aid in troubleshooting.

PTRACE-40

A diagnostic enhancement to log additional register information.

 LOG-20 

Logs enhanced to check log levels sooner to avoid levels getting too high.

Also, month/day was added to log statements. 


 

   Build 3.1.4 – May 07, 2024 
Item Number Description

PTRACE-39

This change fixes an issue causing coredumps on systems with old kernels and high CPU utilization. 

 

   Build 3.1.3 – April 18, 2024 
Item Number Description

AGENT-384

Addressed issue of installing agent not honoring ‘ESXi default’ configuration setting.

PM-155

Improved performance of Filesystem under intensive workloads.

 


   Build 3.1.2 – April 18, 2024 
Item Number Description

TYR-63

When log is set to debug or trace the log messages are no longer trimmed.

 


   Build 3.1.1 – April 03, 2024 
Item Number Description

TYR-56

Tyr rewritten using C++.

BALD-59

Enhanced AES-256 encryption for Baldur executables.

PM-178

Logging enhanced to provide information on dependency exceptions.

ENC-19

New methods were added for file encryption and decryption using AES-256.

TYR-58

Addressed transitive 3rd party dependencies.