WatchGuard Endpoint Security Release 18 is now available!
WatchGuard Endpoint Security Release 18 is now available!
This release introduces features that enhance protection, expedite investigations, and streamline day-to-day operations. Here’s what’s new:
- Incident-centric investigations. Autonomous alert correlation consolidates scattered signals into a single incident and attack story, complete with a timeline and the who, what, where, when, why, and how, enabling analysts to investigate and respond more efficiently.
- Endpoint GenAI Assistant. Ask in natural language (any language). The assistant translates questions into optimized queries, runs them safely, and returns results in seconds, reducing training needs and accelerating investigations.
- Scripting policies (Advanced EPDR, Windows). Reduce script risk with top-down rules to monitor and allow or block scripts, applied sequentially like firewall rules.
- Zero-Trust Application Service Report. Make Zero Trust tangible by tracking metrics on unknown program classification, outcomes (including GW, PUPs, and malware), method (auto vs. analyst), time to classification, and malware details. Multi-tenant in Endpoint Manager starting Oct 2.
- Maintenance Windows for restarts. Schedule restart windows after patch tasks or protection updates across WatchGuard Endpoint Security products.
- Protection improvements and protocol support. AI-based enhancements improve detection of malicious scripts, MSI installers, and .NET runtime abuse on Windows. Web Access Control adds HTTP/3 (QUIC) on Windows and macOS.
- Endpoint Access Enforcement. Inbound peer connection blocking is now available in WatchGuard EDR and EPDR to help reduce lateral movement.
- macOS support. macOS Tahoe is supported from version 3.07.00.0000 (included in R18).
- Endpoint Manager in WatchGuard Cloud updates. Update product versions directly from Endpoint Manager. Account delegation now includes endpoint management (not just licenses), displays delegated accounts in the Service Provider tree, and enables Service Provider-level tasks and configurations to be applied to delegated accounts, depending on the setup.
We will continue adding capabilities that deliver simpler operations and stronger security.