EDR Core (Total Security Suite) Release Notes

For more information about new features, go to the What's New in Endpoint Security PowerPoint presentation.

Latest EDR Core Update 26 April 2024
Release Notes Revision Date

26 April 2024

Protection and Agent Versions for WatchGuard EDR Core 4.30.00

  • Windows protection: 8.00.22.0024
  • macOS protection: 2.00.10.1000 and 3.04.01.0000 for macOS Catalina, Big Sur, Monterey, Ventura, and Sonoma
  • Linux protection: 3.03.00.0001
  • Android agent and protection: 3.9.6
  • iOS agent and protection: 2.01.17.0006
  • Windows agent: 1.21.03.0000
  • macOS agent: 1.13.10.0000
  • Linux agent: 1.13.00.0000

WatchGuard periodically updates Endpoint Security products and modules to provide enhancements and resolve reported issues. New versions roll out gradually to accounts. Some features and enhancements listed here might not be available to your account. When a new version is available, upgrade notifications appear as alerts in the upper-right corner of the management UI. If an upgrade is available, we recommend that you upgrade to the most recent version. If there is no alert in the management UI and you need to upgrade to the latest version of the product, contact your WatchGuard representative to request an upgrade. For more information, go to the Knowledge Base article: WatchGuard Endpoint Security Upgrade Schedule.

Latest Release

Release Date: 26 April 2024

Resolved Issues

  • This release resolves an issue that caused immediate and scheduled scans to crash. [WGUA-623]
  • The Shadow Copies feature no longer causes the system process to use high CPU after an upgrade. [WGUA-2617]
  • This release improves performance issues caused by the firewall infrastructure. These issues sometimes occurred when any of these protections were enabled on the affected endpoint: advanced protection, antivirus, firewall protection, or web access control. [WGUA-2320 / WGUA-2152]
  • Performance issues and high CPU usage on Windows servers that are monitored by SysMon are improved. [KER-608 ]
  • General high RAM and CPU usage issues are improved. [WGUA-1976]
  • Performance issues with Data Control rules-based monitoring of files are improved. [WGUA-991]
  • This release resolves an issue that caused third-party antivirus programs to be disabled in Windows Security Center (WSC). [WGUA-2243]
  • AMSI detection technology no longer causes issues with WatchGuard Endpoint Security. [WGUA-2246]
  • Domain and URL categorization of IPv6 traffic no longer causes issues. [WGUA-1993]
  • Firewall infrastructure crashes (BSOD) that reference the NNSDNS.sys driver no longer occur. The BSOD errors occurred when any of these protections were enabled on the affected endpoint: advanced protection, antivirus, firewall protection, or web access control. [WGUA-1881]
  • When the user selects, “Do not detect again”, the protection software does not detect Trj/RansomDecoy. [WGUA-2030]
  • When the Decoy File feature is enabled, protection software errors on Windows computers with multibyte character sets (MBCS) do not occur. [WGUA-1389]
  • This release resolves file transfer errors for Server Message Block (SMB) traffic on domain controller servers. [WGUA-1681]
  • When you upgrade the protection software for certain Windows versions, the installed application now appears in Windows Security Center (WSC). [WGUA-1731]
  • Connection timeout errors no longer occur for some HTTPS web pages with the protection software installed. [WGUA-1636]
  • Self-diagnosis failures in Windows Security Center (WSC) do not cause the PSANHost.exe service to restart. These failures caused the service to restart when it could not get the necessary module configuration information. [WGUA-2746]

Previous Releases