-
Collaboration Protection Changelog
This changelog provides updates for WithSecure™ Elements Collaboration Protection, which safeguards cloud-based collaboration platforms such as Microsoft 365. It includes the latest improvements, feature updates, and fixes related to email and collaboration security, helping organizations defend against phishing, malware,…
-
Identity Security Changelog
This changelog provides updates specifically for the Identity Security component of WithSecure™ Elements Extended Detection and Response (XDR) . It includes the latest improvements, new features, and fixes related to identity-based threat detection, user behavior analytics, and identity protection capabilities within the…
-
Agent for Windows and Server Changelog
This changelog provides updates for the WithSecure™ Elements Agent for Windows and Server, covering both workstation and server environments. It includes the latest improvements, security enhancements, feature updates, and fixes to ensure optimal protection, performance, and compatibility across Windows-based systems.
-
Agent for Mobile Changelog
This changelog provides updates for the WithSecure™ Elements Agent for Mobile, covering both iOS and Android platforms. It includes the latest improvements, feature enhancements, and fixes that strengthen mobile device protection, improve performance, and ensure compatibility with the latest operating system versions.
-
Agent for Mac Changelog
This changelog provides updates for the WithSecure™ Elements Agent for Mac, detailing the latest improvements, feature enhancements, and fixes for macOS endpoints. It covers changes to protection capabilities, performance optimizations, and compatibility updates to ensure reliable and secure operation on Apple devices.
-
Endpoint Security Portal (formerly Endpoint Protection Portal) Changelog
This changelog provides updates for the WithSecure™ Elements Endpoint Security Portal (formerly Endpoint Protection Portal), the central interface for managing endpoint protection across your organization. It includes the latest enhancements, usability improvements, and fixes related to the portal’s functionality, user…
-
Endpoint Security (formerly Endpoint Detection and Response) Changelog
This changelog provides updates for WithSecure™ Elements Endpoint Security, previously known as Endpoint Detection and Response (EDR). It includes the latest improvements, feature enhancements, and fixes related to endpoint protection, detection, and response capabilities. These updates help organizations strengthen their…
-
Vulnerability Management Web Scan Changelog
This changelog provides updates for the Web Scan component of WithSecure™ Elements Vulnerability Management. It includes the latest improvements, fixes, and new features related to scanning and assessing the security of web applications and services, helping organizations identify vulnerabilities in their online assets.…
-
Vulnerability Management Discovery Scan Changelog
This changelog highlights updates for the Discovery Scan component of WithSecure™ Elements Vulnerability Management. It includes the latest improvements, fixes, and feature enhancements related to asset discovery and network visibility, helping organizations identify unmanaged or unknown devices in their environments. For…
-
Vulnerability Management Scan Node Agent Changelog
This changelog provides updates for the Scan Node Agent component of WithSecure™ Elements Vulnerability Management. It includes the latest enhancements, fixes, and performance improvements related to the scan node agent, which is responsible for executing vulnerability scans within customer environments. For updates on…
-
Vulnerability Management System Scan Changelog
This changelog focuses on updates related to the System Scan component of WithSecure™ Elements Vulnerability Management. It includes the latest changes, improvements, and fixes affecting how system scans are performed, managed, and reported within the solution. For updates related to the portal interface or other…
-
Vulnerability Management Portal Changelog
This changelog provides updates specifically for the portal interface of WithSecure™ Elements Vulnerability Management. It includes the latest improvements, feature enhancements, and fixes related to the user experience, dashboard functionality, and overall usability of the portal. For updates related to other components…
-
Exposure Management for Cloud Changelog
This changelog is dedicated exclusively to updates for the Cloud component of WithSecure™ Elements Exposure Management. It includes the latest improvements, fixes, and new features specific to the cloud-based capabilities of the solution. Note: For updates related to Exposure Management for Business and the Frontline…
-
Exposure Management (including XM for Business and XM Frontline Add-on) Changelog
This is the primary changelog for WithSecure™ Elements Exposure Management, covering all updates related to: Exposure Management for Business Exposure Management Frontline Add-on It provides the latest enhancements, fixes, and feature updates for these components of the Exposure Management solution. Note: This changelog…
-
Improve 'Analysis'-tab; Formatting/Markdown support
Hi, As of now, the 'Analysis'-tab for BCD alerts is quite lack-luster. The idea behind the existing functionality is quite good actually, but not when it comes to using and reading it, it could be a lot better and more human friendly. It's just a long text line. It's not even a text box, since everything gets truncated…
-
Flexible Restart Deferral Options After Application Updates
We are using WithSecure, and after updates of certain third-party applications, our clients frequently receive a system prompt indicating that a restart is required (see attached example). Currently, users can only choose between restarting immediately or postponing the restart without specifying a timeframe. This often…
-
[Insight] How to Spot Gaps in Your Incident Response Plan
Even mature organizations miss key elements in their response strategy. Here’s how to identify and fix them: 1. No Clear Escalation Path Who gets called first? Who makes decisions? 🛠 Use WithSecure’s Incident Readiness Framework to build a clear escalation tree. 2. Lack of Containment Procedures Can you isolate a device or…
-
[Insight] 3 Questions to Ask Before Enabling Automated Actions in WithSecure Elements
Automated Actions can supercharge your response time — but only if configured wisely. Ask yourself: 1. Do I Trust the Detection Source? Automating based on low-confidence detections can lead to false positives. 🛠 Use Broad Context Detection to ensure high-quality triggers. 2. Is My Response Proportionate? Isolating a…
-
Windows 10 "ESU" devices ?
How to identify Windows 10 devices which have ESU activated ? Should such devices still being shown with OS End of Life = Yes ? Regards, aj
-
unable to create suppression rule
Hi all, we are receiving alerts for the below script but when we close it it does not create a rule. C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -NonInteractive -Command "[Console]::OutputEncoding = [System.Text.Encoding]::UTF8;" " Get-LocalUser | ForEach-Object { $userName = $_.Name $output = net…
-
Vulnerability network scans stuck in queued
All vulnerability network scans are stuck in a Queued state and do not start, although Discovery scans are running successfully. Network scans remain permanently queued with no progress. Has anyone encountered this before or have suggestions on where to begin troubleshooting? Steps already taken: Confirmed that all scan…
-
[Insight] Why RDP May Fail When Application Control Is Active
If Remote Desktop Protocol (RDP) stops working on Windows Server 2022, the culprit might be Application Control. What’s Happening? Application Control rules may block RDP-related processes or services, especially if set too restrictively. What You Can Do: Review your Application Control rules Add exclusions for RDP-related…
-
What's New in Elements
We want our users to have the most up-to-date information, and the What's New page is the perfect way to stay informed about the latest updates and enhancements to Elements. Here you will find links to the monthly What's New in Elements. If you would like to be notified whenever we update our What's New in Elements,…
-
System Maintenance: XDR-related updates - 24th November 2025
We will be performing some system maintenance on our WithSecure Elements backend systems on 24th November 2025, at 8.00 UTC. Read the full article here: https://community.withsecure.com/en/kb/articles/32707-system-maintenance-xdr-related-updates-24th-november-2025
-
Exciting New Release: Identity Inventory for XDR!
We are happy to announce a new capability for WithSecure™ Elements: Identity Inventory. This functionality will benefit customers of both WithSecure Elements Identity Security for Entra ID, and WithSecure Elements XDR Cloud Security for Azure Read the full article here:…
-
[Insight] Troubleshooting Performance Issues with WithSecure Endpoint Products
Experiencing slow systems or high CPU usage after installing WithSecure endpoint protection? You’re not alone — and there are solutions. 🔍 Common Causes: Misconfigured Application Control Active Web Traffic Scanning Ongoing Scheduled Scans Connectivity issues to Security Cloud 🛠 Use the built-in WithSecure Connectivity…
-
Grafana Infinity plugin – 500 error when querying BCD data from WithSecure API
Hi everyone, I’m trying to pull BCD metrics into Grafana, but my query always returns a 500 error, no matter what parameters I use. For other modules — like Collaboration Protection and EPP — everything works fine, but data retrieval specifically for BCD doesn’t work at all. I’ve already tried specifying my organizationId,…
-
[Insight] Did You Know? WithSecure Elements Can Isolate Infected Devices Remotely
Containment is critical — and WithSecure makes it fast and easy. Why Remote Isolation Matters: Stops lateral movement instantly Buys time for investigation Minimizes business disruption 🛠 Learn how to isolate devices remotely using WithSecure Elements. 📌 Speed is everything in incident response — and remote isolation gives…
-
application control blocks adobe reader background tasks
Hi there, the application control logs following blocking action: Die Anwendungssteuerung hat die Installation einer Anwendung verhindert. Regelname: Default block rule Regel-ID: 00000000000000000000000000000000 MSI: C:\WINDOWS\system32{AC76BA86-1031-1033-7760-BC15014EA700} Name des Unterzeichners: Übergeordneter Pfad:…
-
[Insight] 3 Ways to Detect Insider Threats Without Invading Privacy
Insider threats are tricky — but you can spot them without overstepping boundaries. 1. Monitor for Unusual Access Patterns Accessing sensitive files outside normal hours or from unusual locations can be a red flag. 🛠 WithSecure Elements tracks user behavior anomalies — see how. 2. Watch for Data Movement Large file…