Release Notes
Stay up to date with the latest features, improvements, and fixes in TrapEye.
Version 1.6.2
Section titled “Version 1.6.2”Release Date: 17 Jul 2026
[FIX] Fixed an issue where enabling auto-update or the credential capture setting in a policy update did not take effect unless the set of active services also changed in the same push.
Version 1.6.1
Section titled “Version 1.6.1”Release Date: 16 Jul 2026
[FIX] Fixed a gap in the port scan detector. Some scans targeting the new SMB service were not being detected.
[IMPROVEMENT] Improved the SSH and HTTP server implementations.
[IMPROVEMENT] Kept the virtual machine base image current with the latest Debian point release.
Version 1.6.0
Section titled “Version 1.6.0”Release Date: 16 Jul 2026
[NEW] Added generic device settings to policies: Auto-update, credential capture settings, and OS deception mode selection (Automatic / Manual).
[NEW] The platform now displays the deployment type directly in the interface, distinguishing between virtual machine and container-based deployments.
[IMPROVEMENT] Improved agent resilience with recovery fallback service that automatically takes over when the main agent executable fails to start after an update.
Version 1.5.0
Section titled “Version 1.5.0”Release Date: 2 Jul 2026
[NEW] Introduced advanced SMB deception service: The decoy now provides an in-memory SMB share with Net-NTLM hash interception capabilities. The service identifies coercion attempts (PetitPotam, etc..), detects SMB relay techniques, and fingerprints incoming sessions to distinguish attacker tooling such as Impacket, NetExec, smbclient, macOS clients, and Windows hosts.
[NEW] Added OS deception through TCP/IP fingerprint emulation: The decoy now dynamically crafts and modifies low-level network responses to reproduce the TCP/IP fingerprint of a chosen operating system, improving deception against fingerprinting tools such as Nmap.
[FIX] Improved sandbox reliability.
Version 1.4.1
Section titled “Version 1.4.1”Release Date: 10 Jun 2026
[FIX] Improved performance of the decoy and several minor bug fixes.
Version 1.4.0
Section titled “Version 1.4.0”Release Date: 06 Jun 2026
[NEW] 10+ Canary types are now available in the Anantis TrapEye platform.
[IMPROVEMENT] Performance improvements on the TrapEye decoy.
[IMPROVEMENT] TrapEye Logs are now batched and saved in memory when sending fails, like alert ingestion.
[IMPROVEMENT] SSH text header upon login is no longer hardcoded.
[IMPROVEMENT] Added default network configuration with DHCP support for new interfaces.
[FIX] Fixed an issue where service restart was not properly handled when the decoy IP address was changed.
[FIX] Fixed FTP subdirectory listing issues
Version 1.3.0
Section titled “Version 1.3.0”Release Date: 08 May 2026
[NEW] New AI-powered filesystem generation for the file server.
[NEW] License management dashboard directly on the web interface for a better user experience.
[IMPROVEMENT] SSH keypair generation is now performed at each agent startup.
[IMPROVEMENT] Improved gRPC event batching.
[IMPROVEMENT] Dynamic hostname generation with wildcard support.
[FIX] Brute-force detection now includes port details.
Version 1.2.4
Section titled “Version 1.2.4”Release Date: 01 April 2026
[IMPROVEMENT] The agent now periodically checks for a dynamically assigned IPv4 address on the network interface. When an IPv4 address becomes available while operating over IPv6 at startup, the agent will automatically switch to IPv4.
Version 1.2.3
Section titled “Version 1.2.3”Release Date: 16 March 2026
[FIX] Fixed incorrect logging of ipinfo requests
Version 1.2.2
Section titled “Version 1.2.2”Release Date: 19 February 2026
[FIX] Fixed incomplete port scan detection for TCP-FIN terminated connections
Version 1.2.1
Section titled “Version 1.2.1”Release Date: 12 February 2026
[FIX] Fixed an issue where the new services Modbus and Telnet did not properly detect network scans
Version 1.2.0
Section titled “Version 1.2.0”Release Date: 08 February 2026
[NEW] Added new Modbus service
[NEW] Added new Telnet service
[NEW] Added new HTTP template for Siemens S7-1200
[IMPROVEMENT] Dynamic hostname generation instead of hardcoded values

