Endpoint agent 4.33.21

Endpoint Agent 4.33.21

New Features
Enhanced DNS Monitoring for Windows

  • Added DNS event collection capabilities on Windows using Event Tracing for Windows (ETW)
  • Enabled DNS request attribution to specific processes (PID) when applications use the Windows DnsCache service
  • Implemented intelligent DNS deduplication with TTL-based caching to reduce redundant events and improve performance

Improvements
Increased System Stability

  • Improved reliability of sensor installation on Windows by adding automatic retry logic when system services temporarily lock required files
  • Significantly reduced log verbosity during high-activity periods
  • Increased internal buffer sizes for process and network tracking to better handle traffic bursts and reduce data loss

Enhanced Performance

  • Expanded kernel-level network monitoring buffers to accommodate higher connection volumes
  • Optimized default configuration settings for better out-of-the-box performance

Bug Fixes

  • Resolved memory leak in file type tracking component