Endpoint Agent 4.33.21
New Features
Enhanced DNS Monitoring for Windows
- Added DNS event collection capabilities on Windows using Event Tracing for Windows (ETW)
- Enabled DNS request attribution to specific processes (PID) when applications use the Windows DnsCache service
- Implemented intelligent DNS deduplication with TTL-based caching to reduce redundant events and improve performance
Improvements
Increased System Stability
- Improved reliability of sensor installation on Windows by adding automatic retry logic when system services temporarily lock required files
- Significantly reduced log verbosity during high-activity periods
- Increased internal buffer sizes for process and network tracking to better handle traffic bursts and reduce data loss
Enhanced Performance
- Expanded kernel-level network monitoring buffers to accommodate higher connection volumes
- Optimized default configuration settings for better out-of-the-box performance
Bug Fixes
- Resolved memory leak in file type tracking component