Skip to content
What's New

Release Notes

What changed in the Kraitos AIDR agent and dashboard, newest first. Agents update automatically.

  1. Agent: maintenance update

    Maintenance release. No functional change for customers; it hardens the release pipeline behind automatic updates. Devices update on their own.

  2. Agent: macOS stability fix

    Fixes agent stability on macOS.

    • macOS crash loop fixed. Mac agents updated on 23 September crashed at the first YARA scan and restarted in a loop for about 13 hours; the fix shipped the same day. It corrects the binary's code-signing entitlements so the new YARA engine can run under macOS Hardened Runtime. Windows and Linux were not affected.
    • What to do. Nothing. Automatic update delivers the fix to Mac devices. With this release the new detection engine runs on every supported platform.
  3. Dashboard: threat triage, device events, AI Sessions

    • Threats: bulk triage. Select detections individually, by rule group, or all matching the current filter, then resolve them or mark them false positive in one action. Every status change records who made it.
    • Threats: Monitor. Flag a detection to keep watching it, with a note, without changing its status. Filter to monitored detections on the Threats page.
    • Device events. The device page's Events tab separates activity from system health, filters by event type with counts, collapses repeated heartbeats, and opens a detail drawer for each event and each detected AI tool, with a link to the related detection.
    • AI Sessions. Sessions are grouped by device, user, and day, with the opening prompt, repo, branch, model, risk, cost, and duration on each row and subagents nested under their parent. Replay renders each turn by role, shows tool calls as code or diffs, and loads earlier turns on demand. Session costs that displayed as $0.00 in some views are fixed, and per-model pricing was corrected.
    • Overview. The Cost by User chart populates, AI Tool Distribution is split into Installed and Network, and widgets link to the data they summarise.
    • Malware samples. Sample detail, lookup, and false-positive actions work for every role (previously they failed with a permission error), and each sample links to a VirusTotal search for its hash.
    • Agent fixes. The same day's agent update fixes a DLP false positive on SWIFT/BIC codes and corrects subagent sessions that were attributed to root instead of the signed-in user.
  4. Agent: new YARA detection engine

    • New YARA engine. YARA scanning now runs on yara-x with a compiled rule bundle, on macOS, Windows, and Linux. On macOS this release was unstable for about 13 hours; see the macOS stability fix above.
    • Fewer false positives. Signed, trusted software no longer raises alerts; repeated hits on one file are collapsed into a single detection; and low-confidence matches are recorded as observations, which stay out of the default Threats view until you turn them on. Existing tenants received the curated rule blocklist automatically.
    • Threats page. “By rule” defaults to open detections, each rule group shows a severity breakdown, and the Quarantined tile reads from the server total.
  5. Platform: monthly billing

    • Billing. Self-serve plans are billed monthly, in advance, for the endpoints active on your billing date, with a 5-endpoint minimum on Team and Business. Annual terms are Enterprise agreements.
  6. Agent: quick scans, upload tooling, memory

    • Quick scans cover home directories. Scheduled quick scans now include user home directories. Earlier releases did not include them in quick scans.
    • Failed-upload tooling. New kraitos-agent dlq commands let administrators inspect, replay, or retire events that failed to upload.
    • Predictable memory. The agent now sets a default memory limit for its runtime to keep resident memory predictable.
  7. Platform: single sign-on, MFA, SCIM, onboarding

    • SSO, MFA, and SCIM on every plan. Sign in with Microsoft Entra ID, Okta, or Google Workspace via OpenID Connect; enforce MFA with passkeys, TOTP, or recovery codes; provision and deprovision users with SCIM 2.0.
    • Onboarding tour and contextual help. New users get a short guided tour on first sign-in, and a help menu in the sidebar links each dashboard page to its documentation.
  8. Agent and platform: enrollment codes, Windows MSI

    • Enrollment codes. Enroll a device with a short code from the dashboard (kraitos-agent enroll --code) instead of a long token.
    • Windows MSI. A signed MSI installer is available for download from the dashboard.

See Kraitos AIDR in Action

Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.

[email protected]kraitos.io