Axonius Release Notes 9.0.8
Release Date: October 4th 2026
These Release Notes contain new features and enhancements added in version 9.0.8
Exposures New Features and Enhancements
The following new features and enhancements were added to Exposures:
Static Analysis: New Filtering Options to Improve Accuracy
Three new filtering options were added to Static Analysis Enrichment Settings to improve the accuracy of Security Findings generated by static analysis.
- Exclude CVEs without specific affected versions - This setting suppresses CVE matches where the NVD CPE entry carries no meaningful version constraint (e.g., a bare wildcard or only a lower version bound). This addresses the previous mass-matching that was cased across all devices running a given product regardless of their actual version. (Default: On for new customers; Off for existing customers)
- Exclude CVEs published on or before [date] - This setting allows administrators to set a publication-date cutoff to filter out aged CVEs. (Default: On for new customers. with a default date of 2015-12-31; Off for existing customers)
- Exclude devices matching this query - This setting accepts a device query and removes all matched devices from static analysis scope entirely, independent of the other two settings. (Default: no select query)
Recommended Actions: ServiceNow Support for Template Ticketing
The Recommended Actions ticket creation template flow now supports ServiceNow as a ticketing destination, in addition to the existing Jira support. Previously, Remediation Owners configured with a ServiceNow connection appeared as unmapped and required manual ticket creation. With this update, tickets can be created directly in ServiceNow using the same out-of-the-box template mechanism available for Jira, and they are automatically routed to their assigned remediation owners (if configured).
Cyber-Physical Assets – New Features and Enhancements
The following new features and enhancements were added to Cyber-Physical Assets:
Network Connection Visibility
This release introduces Network Connections, which gives you visibility into communication patterns across your IT and OT environments in two complementary views. The new Network Connections page provides a consolidated, environment-wide view of all connections between devices, letting security, IT, OT, and risk teams identify risky connections, understand traffic flows, and support network segmentation initiatives.
At the device level, a new Network Connections tab on each device's asset profile displays a visual map of that device's inbound and outbound connections, showing the protocols and ports in use, the devices on either side of each conversation, and cumulative connection counts. You can verify communication paths, spot unexpected protocols or ports, and trace unauthorized activity back to a specific device. Connection data is discovered through Network InspectorsdconnectedAN port, which passively identifies standard IT passively and industrial protocols, source and destination assets and ports, without agents, active scanning, or the collection of sensitive payload data.
Axonius Platform New Features and Enhancements
Action Center
The following new features and enhancements were added to the Action Center:
Workflows
Configurable Email Response Link Expiration
Administrators can now configure how long email response links remain valid before they expire. The default is 24 hours, with a maximum of 120 hours. This setting is available under General GUI Settings and is visible to administrators only.
Adapter Pages and Adapter Interface
The following updates were made to the common functionality across all adapters:
Adapter Interface
-
Adapter Column Views - Added two new role permissions, Column Views - View and Column Views - Add, to control access to column views in the Adapters area. The predefined Admin and Owner roles have both permissions enabled by default after the upgrade. A selected saved column view now remains selected during a normal table refresh, and is cleared only when an explicit query reset is performed.
-
Adapter Fetch History - Added a Fetch pending status for adapter connections that are queued and waiting for an available worker. The Queued At column shows when the fetch was queued, and you can use Terminate Fetch to cancel connections in either Fetch pending or Fetch started status.
System Settings
The following updates were made to various System settings:
Enterprise Password Manager
CyberArk Vault Integration - The CyberArk Vault External Password Manager now supports configuring multiple CyberArk Vault instances, each with its own domain, port, Application ID, and API Prefix settings.
HashiCorp Vault - Added support for the Active Directory / LDAP - Static Role secret engine type, enabling retrieval of the current password for an LDAP static role from HashiCorp Vault.
Network Settings: Reduced Default Parallel Workers
The default number of parallel workers used by the Network Routes enrichment process was reduced to 2 instead of 10, to lower the load placed on MongoDB during large-scale route analysis runs. This change improves system stability and reduces the risk of performance degradation in environments with high asset volume, without requiring any configuration changes from administrators. Users can still set custom values between 2 and 15, if needed.
Adapter and Enforcement Action Updates
New Adapters
The following new adapters were added:
-
ARCON PAM - ARCON Privileged Access Management (PAM) secures privileged accounts and provides session control, credential vaulting, and monitoring of user and service accounts. (Fetches: Users, Devices)
-
CyberArk Certificate Manager - SaaS - CyberArk Certificate Manager - SaaS is a certificate lifecycle management platform that discovers, monitors, and manages TLS/SSL certificates across networks to prevent outages and security exposures. (Fetches: Certificates, Devices, Users)
-
LinkShadow - LinkShadow is a network detection and response platform that provides network traffic analysis, behavioral analytics, threat detection, and anomaly identification across devices and users. (Fetches: Devices, Users)
-
ONESOURCE - ONESOURCE is a Thomson Reuters tax compliance platform that provides user and group administration, client management, and access control across direct and indirect tax workflows. (Fetches: Users, Groups)
-
Tencent Cloud EdgeOne - Tencent Cloud EdgeOne is an edge security acceleration platform that provides web application firewall protection, DDoS mitigation, bot management, and rate-limiting rules for internet-facing services. (Fetches: Domains & URLs, Compute Services, Load Balancers, Network/Firewall Rules)
-
Zadara zCompute - Zadara zCompute is a cloud compute platform that provides virtual machines, block and object storage, virtual networking, and machine images for building private and hybrid cloud infrastructure. (Fetches: Devices, Compute Images, Disks, Network/Firewall Rules)
Updated Adapters
The following adapters were updated:
-
A10 Control - Updated the Host Name or IP Address connection setting to require the
/api/v2suffix in the base URL. For example, enterhttps://a10control.example.com/api/v2and do not include/acapi/v1/. -
- Added support for fetching Users assets from Akamai API Security console users, including email, role, team, lock state, and registration state.
- Added the Fetch Application Settings advanced setting to retrieve application settings for console users, including whether accounts are locked and whether users have completed registration.
-
Asimily Insight - Resolved an issue where a MAC address wildcard filter included in the Assets API endpoint caused 400 errors when fetching device data.
-
- The adapter now fetches Bills as Expenses.
- Added the option to also fetch Invoices as Expenses.
-
- The adapter no longer classifies DNS records as Devices. DNS record types now map to Axonius asset types as follows: A, AAAA, and CNAME records create URLs; all other DNS record types create Network Services assets.
- The settings Devices from Domains, Devices from Subdomains, and Devices from Targets have been removed. Existing connections with any of these settings enabled are automatically upgraded to the corresponding URLs from Domains, URLs from Subdomains, or URLs from Targets setting.
-
BitSight Security Ratings - Added an option to fetch email security grades (DMARC, SPF, DKIM) for domains. When enabled, the adapter retrieves DMARC Grade, SPF Grade, and DKIM Grade data for fetched domain assets.
-
- This adapter now fetches Business Applications.
- Added the Fetch Scan Ids, Fetch SAST Results, and Fetch API Security Results advanced settings to enable optional retrieval of SAST results and API Security risks from the last completed scan for each project.
-
Cisco Catalyst Center (formerly Cisco DNA Center) - Added the option to fetch the tags assigned to each network device. When enabled, tag names in the
Category: Valueformat are added as key-value tags, and tag names without that separator are added as key-only tags. -
Cisco Identity Services Engine (ISE) - The Username and Password fields are now optional in the connection configuration. When pxGrid is enabled without credentials, the adapter collects pxGrid data, including live sessions and pxGrid endpoints. ERS-sourced devices are not fetched when credentials are not provided.
-
- Added support for:
- Fetching client devices and their associated SaaS application data
- Fetching Cisco Meraki organizations as Accounts assets
- Fetching networks and VLANs as Networks assets
- Fetching appliance NAT rules, including port forwarding, 1:1 NAT, and 1:Many NAT configurations. Each retrieved NAT rule appears as a Cisco Meraki NAT Rule Firewall asset with rule name, forwarding type, uplink details, and NAT translation data.
- Added support for:
-
- Replaced the standalone Fetch Alerts as Incidents advanced setting with the Alerts as Incidents settings group, which includes a Fetch Alerts as Incidents toggle and an Alert statuses to fetch selector.
- Incident records fetched from alerts now include OS Version.
-
CrowdStrike Falcon Discover - Added the option to filter fetched vulnerabilities by status.
-
Custom Files and other file-based adapters - Added support for OAuth 2.0 client credentials authentication When selecting URL/FTP as the file source. When enabled, the adapter automatically fetches an access token before each fetch cycle and sends it as an
Authorization: Bearerheader, overriding any Authorization header configured in Additional HTTP headers. -
- Findings from this adapter are now parsed as Application Resources instead of Application Services. Existing queries, dashboards, and reports that target Application Services must be updated to target Application Resources.
- Added options to retrieve the associated usernames (Reporter and Found By) for findings.
-
Digital Ocean - Added a new Project Resources advanced setting that, when enabled under the Droplets, Load Balancers, or Kubernetes Clusters endpoint configuration, enriches assets with their DigitalOcean Project ID and Project Name.
-
Dynatrace - Added an option to fetch Application Settings, including IP allowlist, user account status, group permission, and platform-token status data.
-
- Added an option to device limit rule-event enrichment to specific Rule IDs.
- Device log enrichment now uses a seven-day lookback for both activity events and rule events.
- Enriched rule data now includes Count, First Seen, Last Seen, and Product fields, replacing the previous Ingest Time, Product, and Vendor fields.
- Enriched activity data now includes First Seen and Last Seen fields, replacing the previous Timeline field containing Ingest Time.
- The following advanced settings were removed - ensure to update any adapter configurations that used these settings:
- Maximum devices per API call
- Number of days to look back for RULE logs
- Number of days to look back for ACTIVITY logs
- Maximum logs per API call
- Maximum total events per stream
-
ExtraHop Reveal(x) 360 - Added the Fetch Kubernetes Pods as Compute Services advanced setting to classify eligible Kubernetes pods (those with an ID starting with k8s- and no IPv4 address) as Compute Services instead of Devices.
-
FlexNet Manager Suite Cloud - Added the Fetch IT Visibility Hardware Inventory for OS enrichment advanced setting (default: disabled) to retrieve IT Visibility hardware inventory data and use it to enrich device operating system information for matching devices.
-
- Added support for fetching Network/Firewalls Rules from six configurable policy sources: Internal Policies, Internal Proxy Policies, Internal Reverse Policies, Outbound Policies, Outbound Proxy Policies, and Endpoint to Endpoint Policies. Each source is disabled by default; enable the sources you want the adapter to collect.
-
- Added the option to parse GitHub scanning alerts as Security Findings. Code scanning alerts include rule information and secret scanning alerts include secret-type information.
- Updated default-branch and branch-rule fetching to use a single grouped configuration. The adapter now also skips archived, disabled, and empty repositories before default-branch processing, and records permission-denied responses by request scope to avoid repeating failed requests.
-
- Added a Fetch Users advanced setting (enabled by default) that you can disable to skip user fetch.
- Added an option to fetch packages for each project and add their details as installed software on the project asset.
- Added an option to fetch the project dependency-list components in CycloneDX SBOM format and add them as installed software on the project asset.
-
GoDaddy - Added an option to suppress fetch warnings for UNKNOWN_DOMAIN and ACCESS_DENIED domaicord responses. When enabled, the adapter logs these domain-record fetch errors at the Info level instead of as fetch warnings.
-
HarfangLab - Added an option to fetch installed application data for each agent and add it to the corresponding device.
-
HPE Aruba Networking ClearPass Policy Manager - This adapter now supports Custom Parsing.
-
IBM QRadar - Added the Do Not Use IP Address as Host Name or Asset Name advanced setting. When enabled, IP address values are excluded from device host names and asset names, and are added to the device network-interface IP addresses instead.
-
- Added a new opt-in Incidents endpoint that enriches Devices with incident details, including Incident Number, Summary, Status, and Owner. Users can also filter retrieved incidents by status.
-
Jamf Pro - Added an option to fetch the full details for every Jamf restricted software record and create a Software asset for it, even when it is not installed on a device.
-
Kenna Security Platform - Added the option to parse Kenna URL assets as Domain & URL entities rather than Devices.
-
- Added additional certificate fields to fetched certificate assets, including key type, key size, signing algorithm, thumbprint, certificate authority details, template details, key usage, detailed key usage, extended key usages, subject alternative name elements, and metadata.
- Added an option to control user fetch via advanced setting.
-
ManageEngine Mobile Device Management - Updated the adapter metadata to include Software and SaaS Applications as supported asset types.
-
- Added the Group field to URL assets.
- Added the option to fetch User Defined Fields (customer-defined fields) for each domain and add them to URL assets. This setting requires an API Key for the MarkMonitor V2 API.
- Added the option to fetch Last Domain Note (the most recent domain note) for each domain and add it to URL assets. This setting requires an API Key for the MarkMonitor V2 API.
-
Microsoft Active Directory (AD)
- Added the option to fetch Certificate Template metadata as Certificate assets.
- Replaced the numeric MSDS Supported Encryption Types field with the Supported Encryption Types field, which returns a list of enabled encryption algorithm names. Queries referencing MSDS Supported Encryption Types must be updated to use Supported Encryption Types.
-
Microsoft Dynamics 365 - Added support for fetching Application Settings assets from the Dataverse Organization data source. The adapter now collects auditing, inactivity timeout, IP-based firewall, file upload, and content security policy settings for the environment.
-
Microsoft Entra ID (formerly Azure Active Directory) and Microsoft Intune
- Redesigned the Last Sign-In fetch settings by separating the Fetch users Last Sign-In toggle from the collection options, and separating the When to fetch option (Normal Fetch or Background Fetch) and Sign-in types to include option.
- Added support for fetching Service Principal sign-in timestamps.
-
Microsoft Intune - Added the option to fetch Application Settings assets, including tenant-wide Intune settings and device enrollment configurations.
-
Microsoft Power BI - Added an option to fetch Applications Settings advanced setting via advanced settings.
-
Microsoft Power Platform - This adapter now fetches Application Settings (via advanced setting). When enable, the adapter collects the following information for Microsoft Power LastmSign-In fetchenvironment protection, security group, retention, IP-based storage access signature, C, and separating the e policy settings.
-
Microsoft Teams - Added the option fetch Application Settings ass organization-wide Teafetching Sand perPuser Teams confi timestamps.
-
Moody's CreditLens - Added support for fetching Application Settings.
-
Odoo - Added support for fetching Tickets based on a predefined Helpdesk Ticket Model Name.
-
oVirt - Added options to fetch datacenters, clusters, and networks.
-
PingID Enterprise - Added an option to fetch MFA Registrations as Device Assets.
-
ReliaQuest GreyMatter - The adapter now provides advanced controls for its Assets and Incidents data retrieval. For example, you can set it to fetch Incidents and not fetch Devices.
-
Samsung Knox - Added an option to authenticate with an API Token instead of Client ID and Client Secret.
-
SEL Blueframe - Added a Login Authentication option to the connection settings, enabling the adapter to authenticate using a short-lived bearer token returned by a login request instead of sending basic credentials directly.
-
Snowflake Data Warehouse - The adapter now supports incremental fetch for updated rows in a configured table or view. Configure the timestamp column and enable incremental fetch in the advanced settings to retrieve rows updated since the previous incremental run.
-
SQL Server - This adapter now fetches Serverless Functions, Containers, and Compute Images. These asset types are also supported in the adapter's Custom Parsing.
-
Tenable Vulnerability Management - The Foreground Vulnerability Export Advanced Settings advanced setting was removed from the adapter configuration.
-
Viptela (Cisco) SD-WAN - Added an option to fetch interface data - MAC addresses, interface IP addresses, and public IP addresses - and add them to the network interfaces of existing Cisco SD-WAN device assets.
-
VMWare ESXi and vSphere - The Fetch Users And Local Accounts advanced setting was split into two separate settings: Fetch Users and Fetch Local Accounts.
-
Wiz Reports - This adapter was removed from the system and is no longer available. Use the Wiz adapter instead, as it supports all capabilities.
-
- Added options to parse Zimperium Tracking ID 1 and 2 to the either device's IMEI or Serial Number.
-
- The adapter now parses Nanolog Streaming Service (NSS) logs to identify browsed applications by root domain and creates inferred SaaS application records from the results.
- User records now include browsed applications identified from NSS logs, along with a Detection Confidence Score.
- Inferred SaaS applications include URLs and a Detection Confidence Score field.
New Enforcement Actions
The following Enforcement Actions were added:
-
HPE Aruba Networking ClearPass Policy Manager - Update custom attributes on MAC addresses - Sets a custom attribute and value on the MAC addresses for selected assets in ClearPass. Optionally creates or updates a ClearPass role-mapping policy that associates the attribute value with an Aruba role.
-
IONIX - Add FQDNs To Inventory - Submits fully qualified domain name (FQDN) values from selected assets to the IONIX inventory. Configure the Source Field to specify which asset field holds the FQDN to submit, and use stored credentials from an IONIX adapter connection or provide connection details directly.
-
Sectigo - Enroll SSL Certificate - Enrolls an SSL certificate for the Sectigo organization associated with each selected certificate asset using a provided Certificate Signing Request (CSR).
-
Sectigo - Enroll SSL Certificate with Key Generation - Enrolls an SSL certificate with server-side key generation for the Sectigo organization associated with each selected certificate asset.
-
Sectigo - Import SSL Certificates - Imports an existing SSL certificate into Sectigo for the organization associated with each selected certificate asset.
Updated Enforcement Actions
The following Enforcement Actions were updated:
-
Google Big Query - Send to Table - Added the Use stored credentials from Google BigQuery connection parameter, which lets you select a saved Google BigQuery adapter connection to use its saved credentials.
-
IFS Assyst CMDB - Create Item - Added the shared connection fields to the enforcement action configuration, allowing you to provide connection information when configuring the action.
-
IFS Assyst CMDB - Update Item - Added the shared connection fields to the enforcement action configuration, allowing you to provide connection information when configuring the action.
-
Ivanti Neurons for ITSM - Create Incident per Asset - Updated the action to use field rows and template placeholders for building Incident values. The Map Axonius Fields to Required Ivanti Neurons ITSM Incident Fields and Map Axonius Fields to Additional Ivanti Neurons ITSM Incident Fields settings have been replaced by Required Incident Fields, Additional Fields, and Map Axonius Fields to Template Placeholders. Existing configurations using the removed settings must be updated before running the action.
-
Ivanti Neurons for ITSM - Create Service Request per Asset - Added support for template placeholders in the Subject and Symptom fields, along with two new optional settings: Service Request Parameters for adding tenant-specific parameter RecIDs and values, and Additional Service Request Fields for adding extra top-level Service Request fields.
-
Jira Software - Update Tickets - Updated the ticket-status input parameter to Transition/Status ID, which now accepts a numeric Jira transition ID. Update existing action configurations to provide a numeric transition ID instead of a status name.
-
Palo Alto Cortex XSOAR - Create Incident - Updated the Create Incident action to present supported incident fields and custom fields as dropdown choices when configuring field mappings, replacing free-text entry to reduce configuration errors.
-
PDQ Connect - Deploy Package - Corrected the adapter name displayed in the stored-credentials connection setting so it now correctly reads "Use stored credentials from PDQ Connect adapter."
Fixed Bugs
Authentication & Connectivity
-
Bindplane - Added a Project ID connection setting for Bindplane Cloud (app.bindplane.com) connections. The adapter now sends this value as the X-Bindplane-Account-ID request header, which is required to authenticate with Bindplane Cloud. Leave the setting empty for on-premise deployments.
-
BMC Atrium CMDB - Fixed the Create or Update Asset enforcement action so that create and update operations work correctly when the adapter is configured to use the AR System API type.
-
Checkmarx SAST - Fixed incorrect OAuth credentials used for OData API authentication, where the adapter was using SCA-specific scope, client ID, and client secret values instead of the required SAST OData credentials, which prevented the OData connection from establishing.
-
CrowdStrike Falcon - Fixed an issue where SaaS application fetching failed for adapters configured with non-US-1 API domains because the scraper was navigating to the US-1 Falcon console. The adapter now derives the correct region-specific Falcon console URL from the configured API domain.
-
Data Theorem - Fixed an issue where the adapter returned a 404 error when using a base domain without an endpoint path; the API request URL now includes the required endpoint suffix automatically, and a migration normalizes existing connections that previously required the suffix to be entered manually.
-
EasyDNS - Fixed an issue where authentication failed by adding a required API Key Name connection setting that works with the existing API Token to authenticate to EasyDNS.
-
F5 LBaaS LB Farms - Fixed an authentication error that prevented the adapter from fetching data. The adapter now sends credentials as a JSON request body and refreshes the access token before it expires, ensuring fetches complete successfully.
-
Fortinet FortiNDR Cloud - Fixed a connection failure caused by the configured account UUID not being included in device requests. The adapter now correctly forwards the account UUID when making device data requests.
-
GitHub - Improved handling of HTTP 403 permission errors by tracking failed request scopes and skipping repeated requests for any scope that returned a permission-denied response. The adapter now also correctly distinguishes exhausted rate-limit retries from permission-denied responses.
-
Nameshield - Fixed an issue where the token revocation request was not executed after fetch operations and connection tests, causing the adapter to fail after multiple fetches due to stale tokens.
-
OpenText Service Management (SMAX) - Fixed an issue where the adapter failed to connect because the configured tenant ID was not included as a required parameter in authentication requests.
-
Snowflake Data Warehouse - Fixed an issue where JWT session tokens expired during long-running fetches, causing authentication failures. Tokens are now refreshed five minutes before expiry, preventing 401 errors mid-fetch.
Data Accuracy
-
CrowdStrike Falcon - Fixed GCP Cloud Run service assets to populate the Compute Service Name field with the hostname value and set the Asset Type to GCP Cloud Run Service, enabling accurate correlation between CrowdStrike and other adapters.
-
EfficientIP SOLIDserver DDI - Fixed an issue where blank values in the TCCC Location subnet class parameter incorrectly populated the network asset's location field, causing inaccurate query results when filtering by that field.
-
Elasticsearch - Fixed incorrect device correlation caused by conflicting hardware serials in aggregated data. The adapter now uses the document-level hardware serial as a fallback when aggregated serials conflict, preventing devices from being incorrectly merged.
-
Empirical Security Enrichment - Fixed an issue where this adapter displayed Devices as its asset type in the Axonius UI; it now correctly shows Vulnerabilities and Discovered SaaS Applications.
-
Figure OS - Fixed an issue where the OS Release Date field displayed the base major version release date instead of the actual release date of the installed iOS patch version, causing devices running iOS 26 patch versions (such as 26.5 and 26.5.1) to report inaccurate OS release dates.
-
GitLab - Fixed an issue where GitLab repository assets appeared as duplicate or sparse entries in the asset inventory. The adapter now sets the correct remote ID on repository application resource assets, allowing user-embedded project references to resolve accurately.
-
Google Threat Intelligence Vulnerability Intelligence - Fixed an issue where this adapter displayed Devices as its asset type in the Axonius UI; it now correctly shows Aggregated Security Findings and SaaS Applications.
-
Group-IB Threat Intelligence CVE Enrichment - Fixed an issue where this adapter displayed Devices as its asset type in the Axonius UI; it now correctly shows Aggregated Security Findings and SaaS Applications.
-
Microsoft Endpoint Configuration Manager (MECM) (formerly SCCM) - Fixed an issue where the adapter reported a failed connection status even after successfully fetching assets.
-
Nexthink Query Language (NQL) - Fixed the Is Virtual Machine field to correctly identify virtual machines that are not virtual desktops. The adapter now evaluates hardware type and hardware model values in addition to the virtual-desktop flag, so Azure VMs, Hyper-V guests, and other non-VDI virtual machines are accurately classified.
-
Orca Cloud Visibility Platform
- Fixed an issue where load balancer assets were not correlating with AWS because AWS ARN values were not being parsed from the unique field data.
- Fixed an issue where database assets were not correlating correctly because cloud ID values were not being parsed from the unique field data.
-
OS Enrichment - Fixed an issue where the OS: CUs Behind Latest field displayed 0 for Windows devices reporting a patch number not present in the enrichment data. The field now correctly shows no value when the patch cannot be matched in the enrichment data.
-
Proofpoint Endpoint DLP - Added an option to parse the Alias Field as the Device's Serial Number.
-
ServiceNow - Fixed an issue in the Update Assets enforcement action where fields from two different adapters sharing the same field name (for example, a "status" field from both Oomnitza and Absolute) were incorrectly merged, causing both mapped ServiceNow fields to receive a combined value instead of each adapter's individual value.
-
Threat Connect - Fixed an issue where this adapter displayed Devices as its asset type in the Axonius UI; it now correctly shows Aggregated Security Findings and SaaS Applications..
-
VulnDB Enrichment - Fixed an issue where this adapter displayed Devices as its asset type in the Axonius UI; it now correctly shows Aggregated Security Findings and SaaS Applications.
-
Workday - Fixed an issue where back-dated hire and termination transactions were not captured because the worker query filtered by effective date instead of updated date.
Data Completeness
-
Akamai CDN Cloud - Fixed GTM domain enrichment requests to include the required versioned API Accept header, preventing 406 errors for domains that use GTM features introduced after the default API version. Domain detail enrichment now completes successfully for all GTM domain configurations.
-
BigFix - Fixed an issue where device processing stopped and returned no assets when a common device data queue item was dropped due to exceeding the queue size limit.
-
Bishop Fox - Fixed the adapter to populate the aggregated Open Ports field with the port values fetched for each asset.
-
Cato Networks - Fixed an issue where SDP/ZTNA devices with a null device-level last-connected timestamp were excluded from Axonius by the "Ignore devices not seen in last X hours" setting. The adapter now uses the associated user's last-connected timestamp as a fallback, ensuring these devices are retained.
-
- Added an option to fetch Child CID Policies for multi-tenant Flight Control deployments. When enabled, the adapter retrieves policy details for devices associated with child CIDs, which were previously unavailable when fetching from a parent CID scope.
- Added an option to select the alert statuses fo fetch when fetching alerts as Incidents.
-
Dynamics CMDB (Helpdesk) - Fixed an issue where device fetch failures (such as HTTP 504 gateway errors) were silently suppressed, causing the adapter to report a successful fetch with 0 devices and no visible error in the UI.
-
Edgescan Fullstack Vulnerability Management - Fixed an issue where block assets containing multiple hosts were returned as a single device record, causing individual host devices to be missing from Axonius. The adapter now fetches individual host records and creates a separate device for each host, including its individual IP address, hostname, and OS data.
-
Forward Networks - Added the option to specify a custom NQE query for STIG compliance checks, resolving an issue where the built-in STIG query caused fetch timeouts that prevented devices from being returned.
-
HTTP Server - Send to Webhook - Fixed an issue where relationship fields selected in the action's view were not included in the entity data sent to the webhook.
-
ManageEngine Mobile Device Management - Added an option to fetch installed applications for each device and populate the device's Installed Software field.
-
Palo Alto Networks Cortex Xpanse - Fixed an issue where alerts failed to fetch because pagination parameters were not nested inside the required
request_datafield in API requests. -
Phosphorus - Fixed an issue where Aggregated Security Findings were not being fetched due to a CVE severity parsing error. The adapter now correctly processes CVE severity values during fetch.
-
Rapid7 Bulk Export - Fixed HTTP 415 errors that prevented vulnerability, policy, and remediation data from being fetched. The adapter now sends the required JSON request body with GraphQL export requests.
-
Rapid7 InsightVM - Added an option to parse Security Finding software names from ID. When enabled, the adapter parses the portion of a security finding ID before
-cveas the software name, replacing hyphens with spaces. This restores software name data for Security Findings that do not include a separate software name field. -
Tenable Cloud Security - Fixed an issue where Azure SQL Server databases were not being fetched due to a conflicting field type in the GraphQL query. The adapter now uses an alias to resolve the field type conflict and fetch database records correctly.
-
Tenable Vulnerability Management - Fixed a compliance enrichment issue where duplicate field values were stored during enrichment, causing device BSON documents to grow beyond the 16 MB MongoDB limit and preventing vulnerability data from being saved for affected devices.
Parsing
-
Black Kite V2 - Fixed an issue where tags associated with Black Kite V2 findings were not being parsed from API responses, causing the Tags field to return null values and preventing tags from appearing as filter options in the Query Wizard.
-
F5 BIG-IQ Centralized Management - Fixed an issue where the Last Modified field on load balancer assets was incorrectly populated with the Last Seen timestamp. The adapter now correctly assigns the last-update time to the Last Modified field.
-
Island - Fixed an issue where IP and MAC addresses were not parsed for certain Windows devices that present network data in an alternate format, causing these assets to correlate only by hostname.
-
- Fixed OS version strings with trailing .0 segments being incorrectly truncated during parsing. For example, version 27.0 was displayed as 27 and 26.6.0 as 26.6. OS versions are now displayed with their full precision as provided by the Jamf API.
- Fixed the remote management status field not being populated when the Jamf API returns the value as a boolean. The adapter now correctly parses both boolean and object-form remote management data.
- Fixed inconsistent location data where sub-fields such as username and real name were sometimes returned as an array and sometimes as a string. The adapter now normalizes list-valued location data to ensure consistent field values.
-
Jira Service Management (Service Desk) - Fixed two issues in the Jira Service Management - Create Ticket enforcement action: labels entered with spaces after commas (for example, "TVM, audit") now work correctly and are trimmed automatically, and the split-by-field option now works correctly when the selected field name contains special characters such as colons or spaces.
-
- Fixed installed software data to appear correctly in the Software module by refactoring the installed software parsing to map software attributes (name, version, publisher, and software type) directly in the adapter structure.
- Fixed an issue where LAN and WLAN MAC addresses from Wi-Fi configuration data were not parsed into network interface records, affecting device correlation.
-
Nutanix Prism Central - Fixed an error in the Associate Categories enforcement action caused by incorrectly formatted OData string literals in the category key lookup filter, which resulted in 400 Bad Request errors. The action now correctly formats and escapes category keys in the filter query.
-
Rockwell FactoryTalk AssetCentre - Fixed incorrect data parsing in the Rockwell FactoryTalk AssetCentre adapter.
-
Tanium Asset - Fixed corrupted dynamic list field schemas so that nested object fields (such as database information) are correctly parsed and displayed instead of appearing as empty colon-separated entries.
-
Windows OS Version Parsing - Fixed an issue where the "OS: CUs Behind Latest" field was not populated for Windows devices whose OS version string contains only three parts (for example, "windows 11 pro 10.0 (26200)"). The fix adds a fallback that uses the device's numeric patch or build value when the dotted OS version does not include a fourth component.
Performance
-
Microsoft AD - Add or Update LDAP Attributes of Assets - Fixed an issue where enforcement actions running against large numbers of user assets failed with an "Orphaned Scheduled task" error. The action now uses optimized entity data projection and chunk sizes to stay within processing limits for large operations.
-
Microsoft Entra ID (formerly Azure Active Directory) and Microsoft Intune
- Improved Azure AD group member fetch performance for large tenants by parallelizing member count retrieval and distributing group fetch work concurrently, significantly reducing fetch times that could previously exceed 20 hours.
- Improved the retrieval of user authentication methods by processing user batches concurrently across multiple threads. This prevents the per-user authentication method fetch from timing out in large tenants, ensuring that all registered authentication methods are returned.
