home home
Other Sites
  • ArcticWolf.com
  • Unified Portal
  • Arctic Circle Community
  • Technical Support Knowledge Base
Request a Demo Internal Documentation
  • Aurora Endpoint Security
  • Managed Detection and Response (MDR)
  • Managed Risk
  • Managed Security Awareness (MA)
  • Incident Readiness and Response
  • Arctic Wolf Unified Portal
  • MSP Portal
  • Authentication
  • Sensors, Scanners, and Log Collectors
  • Arctic Wolf Agent
  • Onboarding Portal
  • Active Response, Log Forwarding, and Security Monitoring
  • Active Directory
  • Cloud Security Posture Management (CSPM)
  • IT Service Management (ITSM)
  • Developer and OEM
  • Product Updates
  • Additional Information about Products and Services
  • Legacy Risk Dashboard
  • Legacy Analytics
  • English
  • 日本語
  • Deutsch
  • Français
Sign In
  • Aurora Endpoint Security
  • Managed Detection and Response (MDR)
  • Managed Risk
  • Managed Security Awareness (MA)
  • Incident Readiness and Response
  • Arctic Wolf Unified Portal
  • MSP Portal
  • Authentication
  • Sensors, Scanners, and Log Collectors
  • Arctic Wolf Agent
  • Onboarding Portal
  • Active Response, Log Forwarding, and Security Monitoring
  • Active Directory
  • Cloud Security Posture Management (CSPM)
  • IT Service Management (ITSM)
  • Developer and OEM
  • Product Updates
  • Additional Information about Products and Services
  • Legacy Risk Dashboard
  • Legacy Analytics
  • English
  • 日本語
  • Deutsch
  • Français
Sign In

Aurora Endpoint Security

Aurora Endpoint Security
  • Aurora Endpoint Defense Administrator Guide
    • Release Notes
      • Aurora Endpoint Security service updates
      • Management console and platform services
        • Management console and platform services fixed issues
        • Management console and platform services known issues
      • Aurora Protect Desktop release notes
        • What's new in the Aurora Protect Agent for Windows
          • Fixed issues in the Windows agent
          • Known issues in the Windows agent
        • What's new in the Aurora Protect Desktop agent for Linux
          • Fixed issues in the Linux agent
          • Known issues in the Linux agent
        • What's new in the Aurora Protect Desktop agent for macOS
          • Fixed issues in the macOS agent
          • Known issues in the macOS agent
      • Aurora Focus release notes
        • Aurora Focus fixed issues
        • Aurora Focus known issues
      • Aurora Protect Mobile release notes
        • Aurora Protect Mobile fixed issues
        • Aurora Protect Mobile known issues
    • Using dashboards
      • Key features of Aurora Endpoint Security dashboards
      • Create a dashboard
      • Share a dashboard
    • Managing alerts across Aurora Endpoint Security services
      • How Aurora Endpoint Security groups alerts
      • View and manage aggregated alerts
        • Use the AI-powered Aurora Security Assistant to investigate alerts
        • Status changes for alerts
    • Managing users, devices, and groups
      • Manage Aurora Protect Desktop and Aurora Focus devices
      • Manage zones
      • Manage devices with the Aurora Protect Mobile app
      • Manage Aurora Protect Mobile app and Gateway users
      • View CylanceAVERT user details
      • Manage user groups
      • Configure device lifecycle management
      • View a list of applications installed on Aurora Protect Desktop devices
      • Remove a registered FIDO device for a user account
      • Discover unprotected devices
        • Enable unprotected device discovery
        • Configure your environment to view the device OS and OS version of managed unprotected devices
    • Managing threats detected by Aurora Protect Desktop
      • Manage Aurora Protect Desktop threat alerts
        • Threat indicators
      • Manage Aurora Protect Desktop script control alerts
        • Script score
      • Manage Aurora Protect Desktop external device alerts
      • Threat protection
        • Endpoint Defense score
        • Unsafe and abnormal files
        • File classification
      • Evaluate the risk level of a file
      • Using Aurora Protect Desktop reports
    • Managing safe and unsafe lists for Aurora Protect Desktop and Aurora Protect Mobile
      • Add a file to the Aurora Protect Desktop global quarantine or global safe list
      • Add a file to the Aurora Protect Desktop local quarantine or local safe list
      • Add a certificate to the Aurora Protect Desktop global safe list
      • Add an app, certificate, IP address, domain, or installer source to the Aurora Protect Mobile safe or restricted list
    • Analyzing data collected by Aurora Focus
      • Aurora Focus sensors
      • Aurora Focus optional sensors
      • Data structures that Aurora Focus uses to identify threats
      • View devices that are enabled for Aurora Focus
      • Using InstaQuery and advanced query to analyze artifact data
        • Create an InstaQuery
          • Using the InstaQuery facet breakdown
        • Create an advanced query
          • Supported EQL syntax for advanced query
          • Sample Aurora Focus EQL queries
      • View focus data
      • View and download files that Aurora Focus has retrieved
    • Using Aurora Focus to detect and respond to events
      • Create a detection rule set
        • Event responses
      • View and manage detections
      • Creating custom detection rules
        • Sample detection rule
        • Create and manage detection rules and exclusions
          • States
          • Functions
          • Field operators
          • Operands (facet value extractors)
          • Artifacts of interest
          • Paths
          • Filters
      • Create a detection exception
      • Deploy a package to collect data from devices
      • Create a package playbook to respond to events
      • Lock a device
        • Fully lock a device
        • Partially lock a device
      • Unlock a device
        • Manually unlock an endpoint device
        • Remotely unlock an endpoint device
      • Sending actions to a device
        • Start a remote response session
        • Reserved commands for remote response
    • Aurora Focus: Behavioral Detection Engine detection rules
    • Auditing administrator actions
      • View the audit log
      • Audit log information: General administration
      • Audit log information: Aurora Protect Desktop
      • Audit log information: Aurora Protect Mobile
      • Audit log information: Aurora Focus
      • Audit log information: CylanceAVERT
    • Managing logs
      • Configure BlackBerry Protect Connectivity Node logging
      • Manage logs for the Aurora Protect Desktop agent
        • Enable verbose logging on an Aurora Protect Desktop device
        • Linux logging
          • Set the logging level
          • Collect agent log files from Linux devices
    • Send events to a SIEM solution or syslog server
    • Enable access to the Endpoint Defense User API
    • Troubleshooting Aurora Endpoint Security
      • Using the Arctic Wolf Support Collection Tool
      • Using the Report a problem feature
      • Removing the BlackBerry Protect Connectivity Node software from Aurora Endpoint Security
        • Remove the BlackBerry Protect Connectivity Node software from the local server
        • Remove an BlackBerry Protect Connectivity Node instance from the Aurora Endpoint Security management console
      • Troubleshooting Aurora Protect Desktop
        • Remove the Aurora Protect Desktop agent from a device
        • Re-register a Linux agent
        • Troubleshoot update, status, and connectivity issues with Aurora Protect Desktop
        • A large number of DYLD Injection violations are reported by Linux devices
        • Time zone variances for Aurora Protect Desktop
        • Folder exclusions when using Aurora Protect Desktop with third-party security products
        • Linux driver is not loaded. Upgrade the driver package.
      • Troubleshooting Aurora Focus
        • Troubleshooting issues with the Aurora Focus agent on Linux
        • Removing the Aurora Focus agent from a device
          • Removing the Aurora Focus agent from a macOS device
    • Managing threats detected by Aurora Protect Mobile
      • View Aurora Protect Mobile alerts
      • Mobile threats detected by the Aurora Protect Mobile app
    • View mobile OS vulnerabilities
    • Monitoring network connections with Gateway
      • Viewing network activity
        • Viewing the Event Details page
    • Monitoring sensitive files with CylanceAVERT
      • CylanceAVERT events
        • View CylanceAVERT event details
      • View the file inventory to identify sensitive files
      • View partially analyzed files
      • Use the evidence locker to view exfiltration event details
    • Third-Party Software Attributions
      • Protect
      • Focus
Home ▸ Aurora Endpoint Security ▸ Aurora Endpoint Defense Administrator Guide ▸ Release Notes
Share this page
  • LinkedIn
  • X
  • Facebook
  • Email

Aurora Endpoint Security service updates

Product

Latest release

Management console and platform services

February 2026

Aurora Protect Desktop

May 2025

Aurora Focus

June 2025

Aurora Protect Mobile

October 2024

Aurora Endpoint Defense Aurora Endpoint Security Public

Last updated: March 30, 2026

Previous Release Notes Next Management console and platform services

Explore Topics

Aurora Endpoint Security Managed Detection and Response (MDR) Managed Risk Managed Security Awareness (MA) Incident Readiness and Response Arctic Wolf Unified Portal MSP Portal Authentication Sensors, Scanners, and Log Collectors Arctic Wolf Agent Onboarding Portal Active Response, Log Forwarding, and Security Monitoring Active Directory Cloud Security Posture Management (CSPM) IT Service Management (ITSM) Developer and OEM Product Updates Additional Information about Products and Services Legacy Risk Dashboard Legacy Analytics
Arctic Wolf Help Documentation
Privacy Policy
Terms of Use
Cookie Policy
Accessibility Statement
Information Security
Sustainability Statement
© 2026 Arctic Wolf Networks Inc. All Rights Reserved.