Skip to content

Release Notes

Version 1.5.0

Minor Changes

  • [New] Introduced advanced SMB deception service: The decoy now provides an in-memory SMB share with Net-NTLM hash interception capabilities. The service identifies coercion attempts (PetitPotam, etc..), detects SMB relay techniques, and fingerprints incoming sessions to distinguish attacker tooling such as Impacket, NetExec, smbclient, macOS clients, and Windows hosts.
  • [New] Added OS deception through TCP/IP fingerprint emulation: The decoy now dynamically crafts and modifies low-level network responses to reproduce the TCP/IP fingerprint of a chosen operating system, improving deception against fingerprinting tools such as Nmap.
  • [Fix] Improved sandbox reliability.