BeyondTrust Discovery Agent 25.1.0.1704 release notes
3 days ago
Expected release date: June 3, 2025
Requirements:
- There is a product dependency on having the .NET 8 Hosting package installed.
- OAuth authorization is dependent on having BI version 24.2.0.
- The new Central Policy message to retrieve all scheduled scans is dependent on BI version 24.3.0 and later.
- A reboot of the system may be required.
New features and enhancements:
- Added support for reporting Windows Server 2025.
- Enabled multiple SSH channels for Posix targets only.
- Improved scanning credential selection by eliminating credentials which don't apply to the target.
- Improved performance by moving DCOM Enumeration to the remote agent extension.
- Added a retry when checking to see if the RPC service is running when executing a BTDiscovery.cmd client command.
- Added a runtime option to allow for additional ports in the port scan.
- Added support for Check Point network devices.
- Improved scan results by not enumerating Domain Users in groups when the job setting for EnumerateDomainUsers is disabled.
Issues resolved:
- Resolved an remote command timeout issue by sending the command timeout to the remote agent when starting a new session.
- Resolved a bug when using SUDO elevation when the "-k" option is not supported.
- Resolved a parsing bug which caused Linux Scheduled Task enumeration to fail.
- Resolved the password expired value so that it reports "not expired" when no data is found.
- Resolved the IPv6 connection strings for Oracle, MongoDB, Terradata, and MySQL
- Resolved a bug in the handling of MySQL data which resulted in a failure in event processing.
- Resolved bug where the debug log level was not working for the Remote Agent service.
- Resolved false positive on SSH and MongoDB credential access which was incorrectly reporting the credential access succeeded.
- Resolved a condition in which a nonexistent MSSQL instance was reported.
- Resolved a bug in which the SSH connection timeout runtime option was not being used causing early timeouts.
- Resolved a bug where targets were incorrectly identified as DCs.
Notes:
- SSH Session encryption using the SHA1 cipher is deprecated. SHA256 or higher should be used.
- Support for Windows 8 and Server 2012 as a scanner host is deprecated.
- This release is available by download from the BeyondTrust Client Portal.
- Deprecate DSA encryption as an SSH authentication cipher.
- The MD5 signature is: 38b53b4d08f551dc05175921b5233f8d
- The SHA-1 signature is: 1a5fb5bdca31e87e66136b2294a8c79bea8eeb64
- The SHA256 signature is: 31d291cd493d097d0db2c04804407cf77da485025ae8695ef2b9162870cf40f0