Axonius Release Notes 9.0.3

Release Date: July 26th 2026

These Release Notes contain new features and enhancements added in version 9.0.3

Cyber Assets New Features and Enhancements

Users Page

The following new features and enhancements were added to the Users page.

New “Preferred Last Seen” Field for Users

A new Preferred Last Seen field was added to the Users table. This is an aggregated date field that shows the most recent `last_seen` timestamp across all adapters for a given user. It provides customers with a unified timestamp that reflects the most recent time a specific identity was seen across all adapters - as opposed to the Last Seen field, whose value is returned separately from each adapter.

Exposures New Features and Enhancements

The following new features and enhancements were added to Exposures:

Recommended Actions - New Export Option for the AI Recommended Action Plans

An optional field titled AI Recommended Action Plans was added to the Recommended Actions table. Users who want to export a CSV file with the detailed AI recommended action plan of one or more recommended action records, can now add this field to the table and include its contents in the export.

New Security Finding Count Fields for Devices

Users can now add to the Devices table fields that indicate the number of open Security Findings from each Risk Level that exist on the device.
The relevant fields are as follows (Security Findings are abbreviated to SF):

  • Total SF Count: Critical Axonius Risk Level
  • Total SF Count: High Axonius Risk Level
  • Total SF Count: Medium Axonius Risk Level
  • Total SF Count: Low Axonius Risk Level

These new fields allow users to query not only for CVE counts but also for general, non-CVE Security Findings and count them per Risk Level.

Axonius Platform New Features and Enhancements

System Settings

The following updates were made to various System settings:

Download a Gateway Package with a curl Command

A gateway install package can now be downloaded with a curl command. After filling out the configuration, click Create and Copy curl command. The command is copied to the clipboard. Open a CLI, paste it in, add your API Key and API Secret, and run the command.




New Adapters

  • CrowdStrike Adaptive Shield - CrowdStrike Adaptive Shield is an AI-powered, fully managed SaaS Security Posture Management (SSPM) solution designed to protect critical SaaS applications. (Fetches: Audit Activities, Devices, SaaS Applications, Software, Users)

  • Entro Security - Entro Security is a non-human identity and secrets management platform that provides discovery, classification, posture monitoring, and lifecycle management for service accounts, tokens, and exposed credentials across hybrid environments. (Fetches: Users, Secrets)

  • Lark - Lark (Feishu) is a collaboration and HR platform that provides user identity, organizational structure, and employment information management. (Fetches: Users)

  • Microsoft Windows DNS Server - Windows DNS Server hosting DNS zones and resource records. (Fetches: Network Services)

  • Nudge Security - Nudge Security is a SaaS management platform that provides discovery, governance, and security controls for SaaS applications, accounts, and users across an organization. (Fetches: Application Addons, SaaS Applications, Application Addon Instances, Admin Managed Extensions, Admin Managed Extension Instances, Users, User Initiated Extension Instances, User Initiated Extensions, Extensions, Application Keys, User Extensions)

  • SAP S/4HANA (On-Prem) - SAP S/4HANA is an ERP suite that offers integrated applications supporting finance, supply chain, and operational data processing across core enterprise workflows. (Fetches: Users)

  • Sweet Security - Sweet Security is a runtime CNAPP platform that provides cloud workload visibility, threat detection, and vulnerability management through eBPF-based sensors. (Fetches: Devices)

Updated Adapters

  • 1E - Added an optional "JWT Audience (AUD)" connection parameter to support JWT-based authentication configurations.

  • Akamai CDN Cloud- Added two new optional enrichment endpoints that retrieve Origin Type and Origin Server Hostname fields for CDN content delivery resources.

  • Akamai Kona WAF - Added a new optional "Fetch Property Versions" advanced setting that retrieves additional property version metadata, including the Latest Version Updated By field and other version-related fields.

  • Amazon Web Services (AWS) - Removed the "Correlate EKS Containers with their EC2 Instance" advanced setting; cloud identifiers are now automatically applied to EKS cluster assets.

  • Archer IRM

    • Added a new configurable "Devices Page Size" advanced setting with a range of 50 to 1000 and a default of 200.
    • Improved device ID and name parsing for more accurate asset identification.
  • Atlassian - Added Atlassian Teams as a new Group asset type.

  • Axonius BACnet Scanner - Added a new optional "BACnet Network ID" connection setting to support remote network discovery through routers.

  • Checkmarx SAST - The Checkmarx adapter now supports an optional OData API connection method. This provides an alternative API integration path for environments where the OData API endpoints are preferred or required. Users can enable this option through a new connection setting when configuring the adapter.

  • Cisco - Added a new optional "Fetch Firewall Rules" advanced setting that retrieves ACL and NAT rules from Cisco devices.

  • Cisco CX Cloud - Added the option to enrich hardware and network elements with Field Notices.

  • Custom Files - This adapter and other file-based adapters now support Kerberos/GSSAPI authentication when using SMB Share (relevant for SMB v2 and v3 connections).

    • Supported adapters include the following: Bently Nevada, BIND DNS, Bloomberg BPKG, CSV Network Services, Honeywell Experion, Honeywell FSC PDF, Honeywell TDC 3000, Huawei iMaster MAE, Rockwell FactoryTalk, Schneider Electric Triconex, Steel Cloud, Steel Cloud CVX, Yokogawa BK Rev Info
  • Delinea Privileged Remote Access - Added an optional "Platform Users" endpoint for cloud instances to retrieve platform user data.

  • Docebo - Added the Enrich Users with Certifications option that fetches certification awards for users from the Docebo certifications endpoint.

  • Dynatrace - Added five new vulnerability fields: Dynatrace Exposure, Data Assets, Davis Risk Level, Davis Risk Score, and Dynatrace Vulnerable Components.

  • IBM QRadar

    • Added a new Incidents asset type that fetches QRadar offenses as incidents.
    • Added three new advanced settings that allow users to control offense fetching behavior, including time-based filtering and status filtering. Additionally, devices are now enriched with related offense information, enabling correlation between assets and security events.
  • Infoblox DDI - Added an option to skip fixed addresses with no MAC address, thus excluding fixed addresses without a MAC address from device ingestion.

  • Lenel OnGuard - Improved connection configuration guidance in the Host Name field to help users correctly configure the adapter connection.

  • Microsoft Entra ID - This adapter now fetches agent identities as Application Resources.

  • Mimecast Incydr - The Code42 Incydr adapter was rebranded to Mimecast Incydr.

  • Ninja One (RMM)

    • This adapter is now supported in the Agent Coverage Workspace This allows users to:
      • Track agent coverage - Identify which devices have the Ninja One (RMM) agent installed and which do not
      • Monitor agent versions - View the version of the Ninja One agent deployed on each device
      • Leverage detection rules - Use pre-built queries and dashboards to analyze agent coverage across your environment
      • Improve security posture - Ensure all critical devices have proper RMM agent coverage
  • Oracle Cloud - Added five new optional block storage endpoints: Boot Volumes, Volumes, Volume Backups, Boot Volume Backups, and Volume Group Backups.

  • OutThink

    • Added a new required "Customer ID" connection field to support updated authentication requirements. Existing OutThink adapter connections must be updated to include the new Customer ID field.
    • Improved Training Campaign and Attack Simulation data parsing for more accurate reporting.
  • Palo Alto Networks Cortex XDR - Added the option to fetch hardware information including Device Manufacturer, Model, RAM, and CPU fields.

  • Ping Federate - Added an advanced setting that allows you to filter out machine-to-machine OAuth clients from SSO applications. This setting helps users distinguish between actual SSO applications used by end users and backend API clients that only use client credentials for authentication.

  • Proofpoint's ObserveIT - Added a new "Parse endpoint location IP address as public IP" advanced setting (enabled by default) to categorize endpoint location IP addresses as public IPs.

  • Qualys Cloud Platform - Software install paths are now fetched inline from the Inventory API, replacing the previous "Fetch software install paths (CSAM API)" advanced setting, which was removed.

  • Rapid7 Insight AppSec

    • Added a new optional Modules endpoint that retrieves additional module-related fields, including Proof, Proof Description, and Module Name for vulnerability variances.
    • Added a new optional Attacks endpoint that enriches vulnerability variances with Attack Type and Attack Description fields.
  • Rubrik Security Cloud

    • Added options to enrich the following device types with additional data:
      • Virtual Machine Edge devices
      • EC2 Edge devices
  • Sectigo - Added a new configurable "Page size" advanced setting with a default of 100 (previously 200) to control the number of records fetched per page.

  • ServiceNow - Added a new "Custom HTTP Headers" connection setting with support for method and URL pattern filtering to customize HTTP request headers.

  • Snyk - Added an option to select the Vulnerable Software ingest mode: you can either ingest vulnerable software as CVEs, as Snyk Issue IDs, or both.

  • Sysdig - Secure - Added two new public API endpoints: Inventory Hosts and Runtime Results, expanding the adapter's data retrieval capabilities.

  • Tenable Vulnerability Management - Added an option to fetch cloud connectors as Accounts. The supported cloud connectors are AWS, Azure, and GCP.

  • Veeam - Added API version 1.7 support for Veeam Backup & Replication 13.

  • XM Cyber - Added a new Sensors endpoint that retrieves additional device data from the XM Cyber Sensors API.

Updated Enforcement Actions