Snare for Windows Changelog

What's new in Snare for Windows 4.3.8

Apr 5, 2017
  • Add support for outputting logs in RFC5424 in the 03 Core
  • OpenSSL library version updated to 1.0.1u
  • Fix a bug where the count of characters listed as truncated was wrong in messages
  • Corrected checks for out of memory issues in a number of places

New in Snare for Windows 4.0.2.0 (Oct 17, 2013)

  • Fixed bug in micro webserver upon multiple requests

New in Snare for Windows 4.0.1.2a (Oct 17, 2013)

  • Fixed Unquoted Service Path vulnerability for installs and upgrades

New in Snare for Windows 4.0.1.2 (Jan 9, 2012)

  • Fixed bug in silent deployment of remote access password

New in Snare for Windows 4.0.1.1 (Jan 9, 2012)

  • Fixed objective re-order buttons
  • Added Remote/EnableCookies option to control the use of cookies

New in Snare for Windows 4.0.1.0 (Jan 9, 2012)

  • Updated micro web server authentication (digest). WARNING: this will require you to reset the password
  • Removed MD5 string from /remote web page
  • Added cookie support for Change Tokens
  • Added POST support to micro web server
  • Added pre-submit MD5 hashing of remote access password in /remote web page
  • Added quotes to string values when generating a template file (snarecore.exe -x)
  • Improved Windows 2000 support for new installer

New in Snare for Windows 4.0.0.2 (Jan 9, 2012)

  • [Vista/08/Win7] Fixed problem with DNS name override setting

New in Snare for Windows 4.0.0.1 (Jan 9, 2012)

  • Updated installer to remove CRT dependency

New in Snare for Windows 4.0.0 (Jun 10, 2011)

  • Merged Windows agents in a new installer with in built silent install support
  • Added configuration export feature for silent install support (snarecore.exe -x)
  • Minor updates to the micro web interface service
  • Rebuilt log collection and monitoring system
  • Fixed bug in DomainGroupMembers which caused the agent to crash on x64 systems
  • Added support for collecting both FRS and DFS-Replication logs

New in Snare for Windows 3.1.9.1 (Jan 7, 2011)

  • Bug fix in RegDump function

New in Snare for Windows 3.1.9 (Jan 7, 2011)

  • Fixed bug in DomainUsers function
  • Added feature to objective registry syntax to allow the use of keywords, therefore, future updates to High Level events willautomatically be applied

New in Snare for Windows 3.1.8 (Jan 7, 2011)

  • Security update to prevent Cross Site Request Forgery
  • Default configuration updated

New in Snare for Windows 3.1.7 (Jan 7, 2011)

  • Updated the REG_BINARY output module in "Registry Dump" to correctly output binary data
  • Fixed socket problem when using multiple hosts (supported version)
  • Updated web interface to re-enable event ID filter for non-Security events

New in Snare for Windows 3.1.6 (Jan 7, 2011)

  • Added event IDs 551 and 552 to the logon/logoff category
  • Stripped special HTML characters from records shown in Latest Events
  • Fixed problem resolving variables in some event records
  • Fixed problem resolving event records when multiple files are listed in "EventMessageFile" registry entry
  • Corrected "empty" comments in Domain/Local Users
  • All user/group reports now use pre-Windows 2000 names (eg group names in DomainGroupMembers)
  • Fixed DomainUsers report where non-DCs would use local account SIDs in DomainUsers report
  • Modified the objective rules to allow "Access a file or directory" to configure any path if "handle file audit settings" is disabled

New in Snare for Windows 3.1.5 (Jan 7, 2011)

  • Added target arch/actual arch reporting to the Status window
  • Updated objective order processing, now top to bottom. This means any exclusion objectives should be moved to the top of the list
  • Config/LeaveRetention(DWORD) added to prevent agent froms etting "overwrite as needed"
  • Fixed minor string error in remote control interface
  • ixed category lookup problem
  • Fixed slowdown when sending to multiple hosts using DNS names and one or more DNS names does not exist
  • Fixed error in LocalUsers causing blank username, full name and SID
  • Included extra user account flags in local/domain users

New in Snare for Windows 3.1.4 (Jan 7, 2011)

  • Further speed improvements
  • Added capability to re-order objectives
  • Fixed problem matching event IDs under certain conditions
  • Sped up DomainGroupMemebers

New in Snare for Windows 3.1.3 (Jan 7, 2011)

  • Fixed potential buffer truncation
  • Improved backend objective handling, significantly reducing CPU usage

New in Snare for Windows 3.1.2 (Jan 7, 2011)

  • Fixed issue causing excessive page faults

New in Snare for Windows 3.1.1 (Jan 7, 2011)

  • Minor remote control interface update

New in Snare for Windows 3.1.0 (Jan 7, 2011)

  • Re-introduced USB auditing with modifications
  • Further code simplification
  • Added service description and changed default service recovery options (this update only applied when using the installer)
  • Fixed auditing inheritance for auditing sub-folders
  • Added feature to strip CR and LF characters from user and group output
  • Fixed objective matching bug when an event matches all available objectives
  • Extended supported features (see website for details)

New in Snare for Windows 3.0.0 (Jan 7, 2011)

  • Fixed audit policy configuration logic
  • Changed "Latest Events" refresh timeout to 30 sec
  • Improved corrupt event log detection and notification
  • Fixed bug in user and group retrieval routines
  • Removed USB device tracking support

New in Snare for Windows 2.6.4 (Dec 15, 2006)

  • Updated exception handling to prevent application failures