Changelog ZAIUX® Evo
Segui l’evoluzione di ZAIUX® Evo, scopri le ultime modifiche pubblicate e le nuove funzionalità aggiunte che lo rendono sempre più potente e versatile.
v2.20.3
2026-09-10
- Improved some technique detection and prevention guidance in the report
- Improved error handling for corrupted SYSTEM registry hives in SAMDump
v2.20.2
2026-09-07
- New attack technique for obtaining Access Tokens of Azure VM managed identities
- Optimized parallel execution of attack techniques on the same computer
- Exploitation chain graphical improvements in report and UI
v2.20.1
2026-08-31
- Added validation of a csv containing credentials found by external sources
- Optimized import of computers found during network exploration phases
- Fixed access to Partner tab for reseller users
v2.20.0
2026-08-21
- Updated menus in the UI
- Added multi-tenant user support for MSPs, with explicit delegation from End Users
- Implemented Partner-specific funcionalities
- Added demo Site for Partners
v2.19.6
2026-08-07
- New Egress Filtering validation technique
- Extended enumeration of groups within Entra ID tenants
- Improved stealthiness of technique running assemblies
- Extended target range for cloud techniques exploiting permissions on Azure resources
- Optimized policies for authentication attempts
- Improvements on Entra ID Health check
- Minor graphic improvements in the report
v2.19.5
2026-07-30
- Added validation feedback on credentials found in the Deep Web
- Optimized Entra ID enumeration
- New Entra ID health check test on stale devices
- Improved harvesting of sensitive files
v2.19.4
2026-07-24
- New Linux Privilege Escalation technique through Docker exploitation
- Optimized RDP credential harvesting
- Smart disablement of non-opsec-safe techniques when implants get disrupted during execution
- Extended target range for user impersonation and lateral movement
- Graphic fixes in the Graph View and technical report
v2.19.3
2026-07-17
- Changed credential count logics: all exfiltrated and exposed credentials are counted once, irrespective of how many candidate internal users they may be related to
- Fixed ordering in report chart
- Fake computers detected as sandboxes filtered out in the UI and report results
- Optimized commands in Kerberos ticket enumeration within Linux machines
- Optimized exploitation of impersonated AD users to enumerate the domain
- Improved RDP credential gathering inside the Exposed Windows Credentials technique
- Improved naming of Entra ID Healthcheck results
v2.19.2
2026-07-14
- Improved import of computer information after Entra ID enumeration
- Optimized target choice for credential phishing attacks
- Fixed parsing of default domain configuration files in Linux systems
v2.19.1
2026-07-08
- Optimized stealthiness of the VEEAM dump technique
- Improved impersonation policies for AD enumeration
- Minor fixes to workgroup computer imports
v2.19.0
2026-07-01
- Implemented Threat Actor modelling during BAS execution
- Implemented attack profiling with possible lateral movement exclusion
- Expanded the range of attacks available in Stealth mode
v2.18.0
2026-06-30
- Added support for full-Entra ID and workgroup environments
- Added technique for local network recognition
- Added support for machine exclusions based on hostnames
- Expanded the range of attacks available in Stealth mode
- Improved AI-based credential correlation
v2.17.16
2026-06-10
- Added technique Kernel AEAD Interface Local Privilege Escalation (CVE-2026-31431)
- Added initial access vector based on Mockingjay technique
- Minor fixes on the technical report
v2.17.15
2026-06-01
- Added a new deploy method for windows hosts
- Redesigned deployment area
v2.17.14
2026-05-27
- Completely revamped Technical Report
- Completely redesigned Dashboard area
v2.17.13
2026-05-25
- Various UI improvements
- Completely redesigned Partner Program area
v2.17.12
2026-05-22
- Various UI improvements
v2.17.11
2026-05-18
- Added technique Privileged SQL Server Access
- Improved SQL server related techniques
- Improved attack technique descriptions and remediation guidance in the report
- Improved management of third party integration anomalies
v2.17.10
2026-05-11
- Added BAS Event Collector for Elastic SIEM
v2.17.9
2026-05-06
- Minor UI updates
v2.17.8
2026-04-30
- Added more contextual information when a token is stolen from a remote process
- Implemented user-defined proxy server and port configuration at BAS creation time
v2.17.7
2026-04-24
- Updated deployment methods to emulate techniques used by specific APT groups
- Added a new API endpoint for retrieving audit logs
- Fixed a bug that prevented EDR indicators from being displayed in the attack timeline
v2.17.6
2026-04-08
- Updated Access Token Acquisition via Browser Request technique
v2.17.5
2026-03-30
- Added additional context for third-party integrations
- Improved kerberoasting technique
- fix Entra Id health checks unknown
v2.17.4
2026-03-25
- Added CrowStrike integration
- Added setting of the stealth mode during BAS execution
v2.17.3
2026-03-23
- Optimized Dark Web queries for publicly-available credentials
- Stealthier Powershell-based deployment method
- Improved implant injection technique for some lateral movement attacks
v2.17.2
2026-03-19
- Introduced OPSEC-safe execution mode in ZAIUX Evo, limiting available attack techniques to those with low detection risk in heavily monitored environments
v2.17.1
2026-03-11
- Added audit log page for admin activity
v2.17.0
2026-03-05
- New version of the Command and Control Server, with enhanced evasion capabilities
- Improved support for Safari browser
v2.16.0
2026-03-04
- Added AI agent to analyze folders, files, and memory dumps in order to identify and extract potential credentials
- Added creation of additional implants for backup C2 communication and improved parallel execution of attacks
v2.15.9
2026-02-19
- Waiting job page UI Updates
v2.15.8
2026-02-19
- Minor improvements on Executive Report layout
- Updated configuration tab for ZAIUX Framework integration
- Added new technique Local Credential Extraction via VSS
v2.15.7
2026-02-13
- Optimized Implant migration from ZAIUX Evo to ZAIUX Framework by removing command history and adding request headers
v2.15.6
2026-02-10
- Added new technique Access Tokens from Files to retrieve cloud access tokens
- Minor fixes
v2.15.5
2026-02-10
- Added new Network Share Discovery technique to identify unauthorized access to network shares and sensitive files contained within them
v2.15.4
2026-02-05
- Updated retrieval of Entra ID refresh tokens
- Optimized LDAP queries for AD unconstrained delegations health check
- Minor improvements in data aggregations for the Executive Dashboard
v2.15.3
2026-02-02
- Log generation for SIEM platforms
- Plug-and-play integration with Splunk
v2.15.2
2026-01-28
- Added Executive Report creation to the Dashboard tab
v2.15.1
2026-01-19
- Optimized research of public domains for exposed credentials
- Minor attack technique description updates
v2.15.0
2025-12-29
- added SentinelOne and Defender ATP integrations
- minor bug fixes
v2.14.0
2025-12-17
- Added new executive dashboard
- New BAS scoring system
- Minor report updates
- Improved attack techniques descriptions
v2.13.4
2025-11-20
- Added password spraying toggle when creating a BAS
- Various UI improvements
v2.13.3
2025-11-19
- Updated Powershell command to retrieve the list of old Operating Systems
- Minor fixes
v2.13.2
2025-11-12
- Added Windows to Linux lateral movement via clear-text SSH credentials or unprotected SSH keys
- Enhanced cross-platform SSH session information gathering
v2.13.1
2025-11-11
- General update of attack technique descriptions
- Fixed management of incomplete enumeration results
v2.13.0
2025-11-07
- Enabled Planned BAS execution through Windows services
- Optimized management of dump files
v2.12.9
2025-10-22
- Various UI fixes
v2.12.8
2025-10-16
- Added ServiceNow integration
v2.12.7
2025-10-14
- New technique Abuse Leaked Token Handle
- Minor improvements
v2.12.6
2025-10-07
- Various UI Fixes