Axonius Release Notes 9.0.7
Release Date: September 22 2026
These Release Notes contain new features and enhancements added in version 9.0.7.
Cyber Assets New Features and Enhancements
The following new features and enhancements were added to Axonius Cyber Assets:
New Workspace: CMDB Reconciliation
Axonius presents a new CMDB Reconciliation workspace, which turns CMDB management from a manual, fragmented, high-friction endeavor into a standardized, out-of-the-box solution that:
- Automatically aggregates and validates data from multiple sources.
- Uses this data to update CMDBs and streamline related processes.
Axonius CMDB Reconciliation establishes a highly accurate source of truth, designed to complement existing CMDBs and create a seamless connection that enhances data reliability.
With CMDB Reconciliation, users can maintain a healthy, audit-ready CMDB with zero manual data entry, and ensure licensing compliance and accurate lifecycle tracking. By ensuring the CMDB reflects the current state of the network, this tool eliminates - or dramatically reduces, at least - the need for manual data validation.
Devices Page
The following new features and enhancements were added to the Devices page.
Windows Patch Tuesday - New Enrichment Fields
Axonius now enriches Windows device records with additional patch context derived from the official Microsoft Windows Update catalog. The new fields help users identify lagging devices, prioritize remediation, and enforce organizational compliance policies.
Two new fields, nested under the OS complex field, are available for Windows devices:
- OS: Windows Patch Release Type - Classifies the installed update as a Cumulative Update (CU), a non-security Preview update, or an Out-of-Band (OOB) emergency patch.
- OS: Windows Patch Release Date -The official Microsoft release date for the installed KB or build version.
The new fields are updated daily as part of the standard data enrichment process, enabling users to create queries such as "assets where patch release date is more than X days ago".
Exposures New Features and Enhancements
The following new features and enhancements were added to Exposures:
New "Earliest First Fetch Time" Asset Field
A new Earliest First Fetch Time field was added to the Vulnerability Repository and the Aggregated Security Findings pages. This field holds the earliest first-fetch timestamp across all sources or connections for each vulnerability, or in other words, the exact moment the CVE was first ever seen in the environment. This gives users a consistent reference point for how long a vulnerability has been present in their environment - down to the hour and minute.
Remediation Ownership - Destination Endpoint Becomes Optional
Destination endpoint fields in the Remediation Ownership configuration are now optional. Previously, these fields were required, which could prevent users from saving a configuration when endpoint details were not yet available. Now users can create and assign remediation owners to Security Findings without providing a destination endpoint, thus maintaining a consistent remediation accountability across their security teams.
External Exposures New Features and Enhancements
The following new features and enhancements were added to External Exposures:
Signature Mitigations Available for Device Security Findings
Network Route mapper processing now adds Signature Mitigations to CVE-type Security Findings found on device assets. The new Signature Mitigations complex field shows firewall threat profiles that mitigate a CVE on Network Routes connected to the device. Each mitigation entry includes Vendor, Firewall Rule Name, Is Enabled, Blocks, and a Firewall Rule Asset link. Axonius adds mitigations only when a firewall threat-profile signature matches a CVE reported by the device.
Cyber-Physical Assets New Features and Enhancements
The following new features and enhancements were added to Cyber-Physical Assets:
Virtual Network Inspector Management
A new Network Inspectors page is now available under Settings → System for Cyber-Physical Assets deployments. This page provides a centralized view of all Virtual Network Inspector appliances connected to your environment.
From this page you can:
- View all existing Virtual Network Inspector appliances, including their name, site, location, type, and activation status.
- Add a new appliance by providing a name, site, and location, then generating and downloading a provisioning token to deploy on the appliance.
- Re-generate a provisioning token for any appliance that is still in Pending status.
- Remove an appliance listing from the table. Removing an appliance from the table does not delete the underlying virtual machine.
- This page is visible to Cyber-Physical Assets customers only and does not appear for non-Cyber-Physical Assets deployments.
Axonius Platform New Features and Enhancements
Assets Pages
The following features were added to all assets pages:
Default View for Roles on Asset Pages
Admins can now set a default view per role for a specific Assets page. The selected view is applied automatically when a user with the relevant role opens this Assets page, thus reducing the number of steps needed to reach their preferred configuration.
Converting Custom Data to Managed Assets
Until now, custom data added manually to assets was not processed by the correlation engine, and stayed a standalone record beside the real asset. This resulted in potentially duplicated assets, as well as custom data being lost when the asset was no longer reported by adapters.
To address these gaps, Axonius now has a Custom Data Asset Source mechanism that coverts manually-entered data into a first-class adapter contribution. The conversion is done by a dedicated enforcement action. After conversion, custom data is:
- Ingested, normalized, and correlated exactly like data from any third-party adapter.
- Merges into a single, unified asset instead of creating duplicated assets
Moreover, because the Custom Data Asset Source has no defined retention period, users can use it to retain assets with custom data indefinitely.
Adapter and Enforcement Action Updates
New Adapters
The following new adapters were added:
-
DTS Identity - DTS Identity is an identity provider that offers user management, device inventory, multi-factor authentication, and vulnerability tracking for enterprise environments. (Fetches: Users, Devices, Aggregated Security Findings, SaaS Applications, Software)
-
HPE Alletra SAN - HPE Alletra SAN is a storage platform that provides block storage, volume provisioning, snapshots, replication, and lifecycle management for enterprise workloads. (Fetches: Devices)
-
Moody's CreditLens - Moody's CreditLens is a commercial lending and credit risk platform that helps financial institutions manage the full credit lifecycle. (Fetches: Users)
-
NetSPI Resolve - NetSPI Resolve is a penetration testing management platform that provides vulnerability findings correlation, asset tracking, and remediation risk scoring for attack surface management. (Fetches: Devices)
-
OneSpan - OneSpan Sign is an e-signature platform that provides secure digital signing, user management, and document transaction workflows. (Fetches: Users, Groups, Application Settings)
-
Radware Cloud Services - Radware Cloud Services provides cloud web application and DDoS protection (Cloud Application Protection) and cloud infrastructure protection for network and server assets (Cloud Infrastructure Protection), exposed via a REST API. (Fetches: Networks, Application Settings)
-
SOCRadar - SOCRadar is an extended threat intelligence platform that provides cyber threat intelligence, attack surface management, digital risk protection, dark web monitoring, and vulnerability intelligence for security operations. (Fetches: Devices, Networks, URLs, Certificates)
-
Spacelift - Spacelift is an infrastructure-as-code management platform that orchestrates Terraform, OpenTofu, Pulumi, and other IaC workflows with policy-based access control and CI/CD automation. (Fetches: Users, Application Settings)
-
Ubiquiti UISP - Ubiquiti UISP is a network management platform that provides centralized monitoring, configuration, and device management for wireless and wired network infrastructure. (Fetches: Devices)
-
UiPath - UiPath is a robotic process automation (RPA) platform for building, deploying, and managing software robots that automate business processes. (Fetches: Users, Application Settings)
-
WordPress Toolkit - WordPress Toolkit is a Plesk management extension that provides installation, plugin, theme, update, security hardening, and vulnerability scanning capabilities for WordPress sites. (Fetches: URLs, Aggregated Security Findings, SaaS Applications)
Updated Adapters
The following adapters were updated:
-
Amazon Web Services (AWS) - Added support for fetching Domains & URLs for aliases configured on CloudFront distributions. Each alias is linked to its CloudFront distribution, enabling CloudFront-fronted domains to be included in Internet Exposure queries.
-
AppViewX CERT - Added support for the Application Settings asset type, which now fetches authentication, access control, credential, key rotation, logging, retention, login, SMTP, SSH connection, and service account settings from AppViewX CERT.
-
Citrix ADC - The adapter now adds NAT translations to Load Balancer assets instead of creating Network Route assets for NAT rules. NAT rules that match a Load Balancer by IP address, or an SNAT source subnet, appear on that Load Balancer as NAT translations, including DNAT and SNAT mappings. The adapter no longer publishes Network Routes as a supported asset type.
Note
If you have existing queries, reports, or enforcement workflows that target Network Route assets retrieved from Citrix ADC NAT, you need to update them to use the NAT translations on Load Balancer assets.
-
Confluent - Added a new Fetch Application Settings advanced setting (default: disabled) that fetches Application Settings assets from Confluent cluster access control lists (ACLs) when enabled.
-
Cynerio - The Cynerio adapter now includes a new advanced setting that allows users to specify an upper bound for the detection date when fetching risks and vulnerabilities. This provides more granular control over the time range for risk data retrieval, complementing the existing "Fetch Risks/Vulnerabilities from X days ago" setting.
-
Datadog - Datadog host records with the
aws:lambdatag or afunctionname:tag are now classified as Serverless Function assets instead of Device assets. -
Delinea Privilege Manager (Thycotic) - Added an optional Is File setting to Delinea Vault secret references. When Delinea identifies the field as a file, Axonius retrieves the file content instead of using the field value directly.
-
DocuSign - Added support for collecting data from every account in a DocuSign organization. Now, when connecting the adapter, users can select between Single Account and All Organization Accounts. When All Organization Accounts is selected, a new Organization ID field identifies the organization whose accounts will be discovered and collected.
-
-
Added the Devices API Version connection setting, which allows selecting the Druva Devices API version used to retrieve devices. The adapter defaults to version 1; select version 2 to use the updated API for device retrieval.
-
Added Application Settings support for the adapter. The adapter now fetches administrator roles and statuses from the Druva administrators API, and evaluates whether Druva audit events are available, creating Application Settings assets.
Note: To retrieve administrator role and status settings, enable the administrator management APIs in the Druva Console under Settings > Enable admin APIs.
-
-
Dynatrace - Added support for the
fortinet:fortigateentity type. When included in the list of entity types to fetch, the adapter mapsfortinet:fortigateentities to Devices in Axonius. -
EasyDNS - Added options to enrich Domain Lists with Domain Details and DNS Records.
-
- Added an option to fetch Chrome Profile management data, which is Chrome profile affiliation state data for users, including profile permanent ID, user email, affiliation state, last activity time, and last policy fetch time.
- Added a Has Affiliated Chrome Profile field that indicates whether a user has a Chrome profile with the AFFILIATED_CLOUD_MANAGED affiliation state.
-
HPE Aruba Networking Central - Added the option to fetch switch port 802.1x/NAC configuration for each Switch device by enabling the new Fetch Switch Port NAC/802.1x Status advanced setting. When enabled, Switch device records include Switch Ports information such as Port Name, Description, Admin Enabled, 802.1x/NAC Enabled, and Access VLAN.
-
HPE Nimble SAN - The HPE SAN adapter has been renamed from HPE SAN to HPE Nimble SAN.
-
IBM Maximo - Added support for fetching Application Settings assets from IBM Maximo Application Suite, including certificate, session, sign-on, password-policy, and SMTP configuration.
-
Illumio Core - Added support for fetching Application Settings assets, including security, authentication, firewall, organization, event, report, SAML configuration, trusted proxy IP, and workload settings.
-
Mashery (Boomi Cloud API Management) - Added an option to fetch Application Settings. When enabled, the adapter collects portal member area status, service OAuth settings, and package API key and shared-secret lengths from the Mashery portal members, services, and packages endpoints.
-
- Added the option to enable Application Settings collection using the new Fetch Application Settings setting. When enabled, the adapter collects User State for Mindtickle users.
- Added the optional Asset Hub API Base URL (API3) setting. When configured alongside Fetch Application Settings, the adapter also collects Asset Sharing Type and Asset Expiry Time for published Asset Hub assets.
-
Microsoft Power BI - Added the option to fetch tenant-wide inventory using read-only admin APIs. When enabled, the adapter authenticates as a service principal to collect workspaces, users, and dataflows from all workspaces across the tenant, using the Power BI read-only admin API instead of delegated authentication.
-
NodeZero - Added an option to fetch weakness statuses, which retrieves the current NodeZero Vulnerability Management Hub status for each weakness.
-
NS1 - Added the option to map NS1 DNS records to the Domains & URLs module instead of the Network Services module using the new Parse DNS records as Domains & URLs advanced setting.
-
Oracle Identity Cloud Service (IDCS) - Added a new Fetch Applications Settings advanced setting that fetches Application Settings assets from Oracle IDCS, including application roles, adaptive access settings, authentication factor settings, application-role search results, application configuration, and SDK authentication settings.
-
Palo Alto Networks Strata Cloud Manager
- Added support for ION (SD-WAN) devices. Enable the ION Elements setting in Endpoints Config to retrieve ION devices, including device name, model, serial number, and software version.
- Added the ION Interface Status setting in Endpoints Config to retrieve interface status data for ION devices. Both settings are disabled by default.
-
Panorays - Added the Fetch company assets only advanced setting. When enabled, the adapter skips all supplier endpoints and fetches only company assets, which helps organizations with large supplier volumes avoid hitting API rate limits.
-
- Added the URL Path Prefix connection setting to support phpIPAM instances hosted at a custom URL path, and the App Token connection setting to allow authentication using a phpIPAM application token instead of a username and password.
- Added support for custom parsing of device data, which allows defining how specific fields from the raw data are parsed into existing or new fields.
-
Platform - Added a Normalized Cloud Provider field for users and other assets that automatically derives a standard cloud provider value from the Cloud Provider field, providing consistent provider values across queries and reports.
-
Proxmox Virtual Environment (VE) - Added the Enable Custom Parsing advanced setting to allow defining how specific fields from the raw data are parsed into existing or new fields for device data.
-
Qualys Cloud Platform - Added support for fetching Application Settings assets, including the account-level status of the restricted IPs feature.
-
- The Sectigo adapter now retrieves SSL certificates through the v2 API by default.
- Added the Fetch certificate deployment locations advanced setting. When enabled, the adapter fetches deployment locations for each SSL certificate, including the Location ID, Location Type, Location Name, and Location Details. This option requires the SSL v2 API and adds one additional request per certificate.
- Added the Use legacy SSL certificates API (v1) advanced setting. When enabled, the adapter fetches SSL certificates from the legacy
/api/ssl/v1endpoints instead of/api/ssl/v2. Deployment location data is unavailable when this option is enabled.
-
SentinelOne - Added a configurable maximum device control events per agent setting. This limits the number of device control events ingested per agent and prevents document size errors for agents that generate a high volume of events.
-
ServiceNow - Removed the Do not fetch devices without IP address, MAC address and serial number advanced setting. If this setting was previously enabled, Axonius automatically converts it to an equivalent device ingestion rule during the upgrade.
-
SonarQube Server - Added the Users advanced setting (enabled by default) to allow the users fetch to be enabled or disabled independently.
-
- This adapter now fetched Network assets.
- Added support for the Networks asset type in fetch-schema mappings, enabling the adapter to create Networks assets from configured Splunk search macros and reports.
-
SQL Server - Added support for fetching Roles as assets. The fetched Roles data includes server-level and database-level roles with their permissions, database permissions (permission name, scope, and state), and additional Users data such as server admin roles and database admin roles.
-
TRIMEDX - Added support for the Client Inventory (v5) API in addition to the existing MDSP Inventory API. The new Inventory API Version connection setting lets you select the inventory API the adapter uses; existing connections default to MDSP Inventory and are not affected. When Client Inventory (v5) is selected, the adapter uses the
openid,client.inventory.read, andclient.workorder.readOAuth scopes. -
Upwind - The adapter now fetches the following Azure resources as Axonius asset types:
Azure Resource Axonius Asset Type Azure Virtual Machine Devices Azure AKS Cluster Compute Services Azure SQL Server, Azure MySQL Flexible Server, Azure PostgreSQL Flexible Server, Databases Azure Container App Containers Azure API Management Service, Azure Databricks Workspace, Azure Machine Learning Workspace Application Services Azure role definitions Security Roles Azure storage accounts Accounts -
- Added support for Veeam Backup & Replication API version 1.3-rev2.
- Added the Fetch only Virtual Machine objects advanced setting. When enabled, the adapter fetches only Virtual Machine objects from Veeam backup jobs and skips container objects, such as clusters, folders, and resource pools.
-
VulnDB Enrichment - Added support for the Flashpoint Ignite API as an alternative to the legacy VulnDB API. When Flashpoint Ignite API is selected, the adapter enriches vulnerabilities with Flashpoint data, including Flashpoint ID, EPSS Score, Ransomware Score, and Affected Products.
-
Workday - Added an option to skip user fetch to allow the adapter to fetch only device assets from the custom report.
-
Wiz - Added an option to fetch security subcategory details for cloud configuration findings.
-
- Added support for fetching Zendesk IT Asset Management (ITAM) assets as Devices.
- Enhanced the adapter's advanced settings for controlling real-time Ticket Created and Ticket Updated events for tickets created or updated outside Axonius Enforcement Actions. Now you can emit such events, or add a Zendesk search query that limits the non-Axonius tickets that generate each event.
-
Zscaler Client Connector - Added optional Cloud Name and Tenant ID connection settings when authenticating with OneAPI (OAuth), to support cases when the ZIdentity organization is linked to Zscaler Client Connector tenants on more than one Zscaler cloud.
New Enforcement Actions
The following Enforcement Actions were added:
- Axonius - Convert Custom Data to Managed Asset - Converts custom data (manually entered by the user) into managed asset data.
-
Sectigo - Delete SSL Certificate - Deletes an SSL certificate for assets returned by the selected query or assets selected on the relevant asset page.
-
Sectigo - Generate SSL Private Key Download Link - Generates a download link for an SSL certificate private key for assets returned by the selected query or assets selected on the relevant asset page.
-
Sectigo - Replace SSL Certificate - Submits a replacement request for an SSL certificate for assets returned by the selected query or assets selected on the relevant asset page.
-
Sectigo - Update SSL Certificate Details - Updates details for an SSL certificate for assets returned by the selected query or assets selected on the relevant asset page.
Updated Enforcement Actions
The following Enforcement Actions were updated:
-
Cherwell - Update Incidents - Renamed from "Cherwell - Update Tickets" to "Cherwell - Update Incidents" to align with Cherwell's official incident terminology.
-
Deactivate Mimecast Incydr Agent - Renamed from Deactivate Code42 Agent to Deactivate Mimecast Incydr Agent to reflect the Mimecast Incydr rebranding.
-
Freshservice - Create Service Request per Asset
- Added a Custom Field Description Key parameter that specifies the custom field key to use for a description value in the
custom_fieldsJSON payload. - Added a Custom Field Description Message parameter that specifies the description message to place in the custom field, with support for Dynamic Values.
- Added a Custom Field Description Key parameter that specifies the custom field key to use for a description value in the
-
Google Workspace - delete extension - Added the option to run the action on entities that do not originate from Google MDM by providing a user email or ID through Dynamic Values. When no value is provided, the action continues to use the matching Google MDM entity's user remote ID for entities from Google MDM.
-
Microsoft AD - Create users - Added a field-mapping configuration that lets you map Axonius fields to Active Directory attributes when creating users, providing the same field-mapping capability available in other Axonius enforcement actions.
-
SharePoint - Send CSV - Added a Remove adapter prefix from CSV column headers option (default: disabled) that removes the adapter-name prefix from each CSV column header when the action exports a CSV file to SharePoint.
-
Tenable Vulnerability Management - Add or Remove Tags to/from Assets - This action now supports configuring a gateway thorugh which to connect to perform the action.
Removed Enforcement Actions
The following enforcement actions have been removed from the Action Library and are no longer available for selection in the Axonius Enforcement Center:
-
Axonius BACnet Scanner - Scan Device - This enforcement action has been removed from the Axonius GUI and action registry and is no longer available for selection in the Action Library.
-
Axonius Modbus Scanner - Scan Device - This enforcement action has been removed from the Axonius GUI and action registry and is no longer available for selection in the Action Library..
Fixed Bugs
The following bugs were fixed:
Authentication & Connectivity
-
AKIPS - Added support for username and password authentication to allow connections to AKIPS instances that require a user name in addition to a password.
-
Azure Email Server - Fixed an issue where client secrets stored in a CyberArk vault were not resolved before Azure email authentication, causing email sending to fail when credentials were managed by a password manager.
-
BeyondTrust Remote Support (Bomgar) - Fixed an issue where the Bomgar enforcement action was failing due to an incorrectly constructed API URL that included an extra trailing slash, causing enforcement actions to report success in Axonius without completing the action in BeyondTrust Remote Support.
-
DocuSign - Fixed a DocuSign organization account discovery and user permission requests so Management API paths use the DocuSign Admin API host rather than the configured OAuth or account host. The adapter now obtains organization account IDs from the organizations response and resolves their base URIs through the OAuth userinfo response.
-
EasyDNS - Fixed connection failures caused by trailing slashes in the configured domain name, and added rate limiting of one request every three seconds with a three-second wait after HTTP 420 rate-limit responses to prevent additional connection failures caused by API rate limits.
-
Forward Networks - Updated the adapter to correctly pass the client ID from the connection configuration when establishing a Forward Networks connection.
-
Google Workspace (G Suite) - Updated the Google MDM login flow to use a current browser user-agent and added a fallback email-field locator, resolving login failures caused by changes to the Google sign-in page.
-
IP Fabric - Added support for IP Fabric API v8.0, which uses an unversioned API path, resolving HTTP 404 connection failures for customers running IP Fabric v8.0 or later.
-
Keeper Enterprise Password Vault
- Fixed connection errors caused by API requests being sent with an incorrect Content-Type format. The adapter now sends all requests as JSON, resolving 400 Bad Request errors when connecting to the Keeper API.
- Fixed connection failures caused by the Keeper API rejecting the adapter's client version. Updated the Keeper SDK dependencies to meet the minimum version requirement enforced by Keeper Security's API.
-
Let's Encrypt - Fixed an issue where the Let's Encrypt adapter failed to connect when multiple contact details were entered in the User Contact Details setting. The adapter now accepts multiple comma-separated entries in the User Contact Details field.
-
Lenovo Device Orchestration - Updated the adapter to use the current Lenovo Device Orchestration API service paths.
-
Platform - Fixed an issue where the gateway installer API endpoint returned a 500 Internal Server Error instead of a 403 Forbidden response when a user lacked the required gateway management permission.
-
Resolver - Updated the Users fetch endpoint to use the current API path, resolving HTTP 410 errors that prevented user data from being fetched after Resolver deprecated the previous endpoint.
-
Seismic - Fixed an incorrect authentication URL that caused HTTP 404 errors during connection. The adapter now uses Seismic's correct service endpoints internally, and the Host Name or IP Address connection setting was renamed
Domain. -
Snow Atlas - Fixed token refresh timing so that the adapter refreshes authentication tokens before they expire, preventing fetch failures on long-running data retrievals. The adapter now also retries requests that receive a 401 Unauthorized response.
-
Tenable Vulnerability Management - Add or Remove Tags to/from Assets - Added a tunnel option to the enforcement action, allowing asset-tagging operations to run through a configured tunnel for environments that require one, such as FedRAMP deployments.
Data Accuracy
-
Activity Log - Fixed the Activity Log filter applied when clicking a value in the Last Connection Update column in the Adapter Fetch History page, so that the Edit Connection And Fetch action type is now included in the results.
-
BeyondTrust Remote Support (Bomgar) - Added an advanced setting to use the device hostname or IP address as the asset name instead of the generic display name assigned in BeyondTrust, improving asset identification accuracy.
-
CrowdStrike Falcon - Added a new advanced setting, Always parse GCP Cloud Run as Compute Service, which, when enabled, classifies assets with a Service Provider value of GOOGLE_CLOUDRUN as Compute Services so they correlate correctly with the same assets reported by other cloud adapters.
-
CVE Enrichment - Fixed an issue where security findings could be missing a risk score by ensuring CVE enrichment runs after all post-correlation processing has completed.
-
Elisity - Fixed an issue where Elisity devices were being incorrectly correlated with unrelated assets because the hostname was not included in the device ID.
-
Gong - Removed the Calls - Is Private application setting and its associated data retrieval endpoint, which was incorrectly reporting a large volume of configuration values that did not accurately reflect individual user settings.
-
Microsoft Azure - Fixed an issue where Azure network interfaces associated with private endpoints (without an associated virtual machine) were incorrectly classified as virtual devices, causing them to appear in server-type device queries.
-
Microsoft Defender for Endpoint (Microsoft Defender ATP) - Fixed cloud ID assignment for AWS and GCP devices by parsing cloud resource names to extract the correct cloud identifier, improving asset correlation.
-
Orca Cloud Visibility Platform - Fixed an issue where AWS S3 bucket assets were not being correctly classified, which prevented them from correlating properly with other asset sources.
-
Qualys Cloud Platform - Fixed the Vulnerability Port field, which was always empty despite port data being available in Qualys for the detected vulnerabilities.
-
Rapid7 Nexpose and InsightVM - Updated host-name parsing to return the short host name rather than the full DNS FQDN, improving host-name correlation with other data sources.
-
Rubrik Security Cloud - Fixed an issue where NAS mount points were incorrectly parsed as individual device entities, causing asset correlation issues.
-
runZero - Reclassified the runZero adapter as a scanner adapter to improve asset correlation with other scanner adapters such as Shodan and Tenable.
-
ServiceNow - Fixed an issue where the FQDN field was not updated correctly when the primary fqdn field was empty. The adapter now falls back to the
u_fqdnfield when the primary fqdn field is unavailable. -
Shodan - Fixed an issue where the Data Blob field was populated with HTTP 400 error responses instead of the actual API response data.
-
Tenable Cloud Security - Corrected cloud ID parsing to use the cloud resource ARN as the primary source, with the resource ID as a fallback, improving asset correlation across cloud providers.
-
Tenable Vulnerability Management - Fixed an issue where conflicting agent version values were reported when a merged device included both a Tenable.io agent version from core data and a Nessus Agent version from CPE scan data.
-
Tenable.sc (SecurityCenter) - Fixed the Add IPs to Scan and Launch Scan enforcement actions, which were incorrectly reporting failures even when the operations in Tenable.sc completed successfully.
-
ThousandEyes - Fixed device correlation by adding the serial number to Enterprise Agent device identifiers to improve differentiation between similar agents.
-
Tufin SecureTrack - Fixed device identification to use a stable ID format based on the device name and UID, preventing duplicate device records from being created on successive fetches and allowing the automatic cleanup job to correctly remove stale assets.
-
Vicarius - Fixed an issue where the Publisher field for installed software was incorrectly populated due to an erroneous field mapping. The publisher field mapping has been removed, and installed software entries now correctly reflect only the available name and vendor data.
Data Completeness
-
- Fixed an issue where the adapter stopped fetching device assets after the Certero API rejected a query parameter that the adapter was sending. Existing connections now fetch devices successfully without any configuration changes.
-
Cisco Identity Services Engine (ISE) - Extended the maximum session lookback from 30 to 90 days and enabled endpoint data enrichment for devices without recent sessions. Added support for parsing additional fields, including authentication timestamps, endpoint policy, identity rules, protocol, TLS cipher and version, and SSID.
-
Cribl - Fixed an issue where the adapter's default API path prefix was not saved to the connection configuration, causing the adapter to construct invalid request URLs that resulted in fetches completing with zero assets.
-
- Fixed vulnerability query filters to correctly format list values as valid FQL list literals. Previously, filters using list-type values returned no results regardless of the filter content specified.
- Fixed the Fetch online devices only advanced setting, which was not being applied during device fetches. The adapter now correctly passes this configuration to the CrowdStrike client, filtering devices to online-only when the setting is enabled.
-
CrowdStrike Falcon Discover - Fixed an asset count mismatch where the adapter returned fewer unmanaged devices than reported in the CrowdStrike console. The adapter now uses the combined hosts API to retrieve device data, providing a complete and consistent result set.
-
Custom Files - Fixed an issue where CSV files configured with the Licenses file type were incorrectly processed as device data, resulting in zero license entities being created.
-
CyberArk Endpoint Privilege Manager - Fixed an issue where customers who had not yet migrated to the CyberArk Endpoints (Beta) page received significantly fewer devices than expected. Added a Use legacy computers endpoint (GET /Computers) advanced setting that allows the adapter to fetch computer data through the legacy endpoint instead of the default endpoint search request.
-
CyberArk Privilege Cloud - Fixed a pagination issue that prevented the adapter from retrieving Safes beyond the first page of results.
-
Denodo - Fixed an issue where the Denodo adapter stopped fetching assets after a previous patch was applied, causing all Denodo connections to return zero assets during discovery.
-
Imperva WAF Cloud - Fixed pagination for the site-domains endpoint so that the adapter retrieves all domain records instead of stopping at the default page limit of 50 results per request.
-
IONIX (formerly Cyberpion) - Added a clarification to the Fetch IP Assets as Devices advanced setting, stating that enabling this setting is required for IONIX IP-asset CVEs to be available in Aggregated Security Findings.
-
JFrog Xray - Updated the enforcement action integration to use a shared engine configuration, improving the reliability of enforcement action operations for JFrog Xray.
-
mPro3 - Fixed pagination handling to correctly process paginated API responses and align device counts with expected results during data fetching.
-
New Relic - Fixed an issue where Windows service data from New Relic was not being used to enrich host records. Updated the Windows service GraphQL query to use the supported entity search syntax so the adapter can correctly retrieve and apply Windows service enrichment data.
-
Okta - added an option to fetch full user profiles for device users, which retrieves complete Okta user profiles for users associated with devices.
-
Qualys Cloud Platform - Added a new Host-Dependent (Confirmed or Potential) option to the list of Detections Allowed Types, to include detections whose type is Vulnerability or Potential Vulnerability when filtering allowed detection types.
-
ServiceNow - Fixed an issue where specific dotwalked fields could not be retrieved alongside all table fields. The Fields to fetch advanced setting now supports
*as an entry to fetch all table fields together with any listed dotwalked fields. -
Sweet Security - Fixed an issue where the Sweet Security adapter fetched no assets due to processing report downloads as NDJSON instead of the correct gzip-compressed CSV format.
-
Tanium Client Status - Fixed the Tanium Client Status - Create Action enforcement action's computer group deletion step to retrieve the complete list of computer groups and filter by name prefix before deletion, replacing a workaround that sent requests to an incorrect API endpoint and caused the action to abort.
-
TeamDynamix - Fixed an issue where custom attribute values could not be set when creating or updating assets in TeamDynamix. The Create/Update Asset enforcement action now supports mapping Axonius fields to TeamDynamix custom attributes when creating or updating assets.
-
Tenable Identity Exposure (formerly Tenable.ad) - Resolved missing data in Security Findings by removing fixed pagination limits from an endpoint configuration, allowing the adapter to retrieve complete results.
-
Tenable.sc (SecurityCenter) - Fixed the Launch Scan enforcement action by correcting the method call used to retrieve the adapter unique name, restoring proper scan execution.
-
ThreatLocker - Fixed an issue where only a single IP address was being fetched per device by adding a new network data endpoint, now providing all device IP addresses for improved correlation.
-
watchTowr - Fixed a pagination issue in the IP addresses endpoint where fetches would stall on the second page and time out, resulting in incomplete or missing IP address data.
-
Wiz - Improved the reliability of vulnerability report downloads by adding retry logic that restarts a failed download from the beginning with a refreshed report URL, preventing intermittent stream failures from causing the fetch to abort without data.
Parsing
-
Bishop Fox - Fixed an issue where IP addresses and port values were not being parsed correctly for some device subtypes. The adapter now reads IP addresses from the supported IP address fields and correctly handles port values returned as lists.
-
CipherTrust Manager - Fixed the Certificate Valid Until field not populating by adding the correct date format parser for CipherTrust timestamps.
-
Claroty xDome - Fixed OS parsing for devices that report a slash-separated list of possible OS versions, so they are no longer incorrectly classified as Windows Server when the specific OS version cannot be determined.
-
IBM QRadar - Fixed asset name parsing to extract only the hostname portion from names that included a "Log Source @" prefix, resolving asset correlation issues caused by incorrect asset names.
-
One Identity Safeguard - Fixed an issue where IP addresses in the Network Address field were not being parsed into device network interfaces, which prevented device correlation across asset sources.
-
PDQ Inventory - Fixed an issue where the adapter only parsed the first result from custom SQL query rows when an asset had multiple matching entries.
-
Platform - Fixed query builder input handling to normalize line breaks and surrounding whitespace before applying special-character escaping, resolving "could not create filter" errors that occurred when query field values contained certain formatting characters.
-
Qualys Cloud Platform - Fixed streaming parsing of PCRS posture data so that nested evidence objects are correctly retained and populated, resolving missing evidence field data.
-
runZero - Fixed an issue where Common Weakness Enumeration (CWE) identifiers were not being parsed correctly when multiple CWEs were returned on a single line with space or comma delimiters.
Performance
-
Amazon Web Services (AWS) - Fixed AWS Organizations account enumeration failures caused by rate limits in large organizations. The adapter now uses adaptive retry mode and builds account-parent mappings more efficiently to reduce the number of Organizations API calls, preserving accounts already collected if enumeration is interrupted.
-
Cisco Identity Services Engine (ISE) - Replaced the single ERS enrichment setting with four separate advanced settings that provide granular control over authentication status enrichment and session data collection level for Endpoint devices, preventing excessively long fetch durations on large ISE deployments.
-
FireMon Asset Manager - Fixed a memory exhaustion issue that caused out-of-memory failures during firewall rule retrieval by summarizing large address ranges as CIDR blocks instead of expanding each individual IP address. The adapter also now falls back to per-device rule queries when domain-wide retrieval reaches its result limit.
-
FortiManager - Resolved long fetch times by batching per-device enrichment requests and applying bounded timeouts and concurrency limits for managed device relay requests.
-
Microsoft Defender for Endpoint for GCC - Updated device data collection to stage software inventory and vulnerability records in local database storage before enriching device results, reducing memory usage during large fetches and preventing out-of-memory failures.
-
Microsoft Endpoint Configuration Manager (MECM) (formerly SCCM) - Improved the reliability of SharePoint data uploads by simplifying the file-upload chunk handling and removing unused retry and backoff logic.
-
Microsoft Intune - Fixed high API call volume for compliance policy settings by marking the compliance policy settings endpoint as cacheable, reducing redundant requests during fetches.
-
Platform - Fixed an issue where volatile adapter data files were not deleted after a fetch completed, causing nodes to accumulate disk space unnecessarily over time.
-
Qualys Cloud Platform - Corrected the PCRS policy list endpoint API version to eliminate unnecessary failed requests that were occurring on every adapter cycle.
-
SharePoint - Resolved upload failures caused by transient 503 errors by adding retry logic with exponential backoff to SharePoint enforcement action chunk uploads.
