[Fix] Fixed an issue where enabling auto-update or the credential capture setting in a policy update did not take effect unless the set of active services also changed in the same push.
[New] Added a rate limit detector to SMB authentication attempts: a brute-force run against the SMB decoy is now collapsed into a single BruteForce event.
[Improvement] Automatic Windows OS deception feature no longer misreads a disabled service’s leftover template or banner.
[Fix] Fixed port scan false positives when a service port was already in use (e.g. another process already holding it, common in container deployments).