Changelog ZAIUX® Evo

Segui l’evoluzione di ZAIUX® Evo, scopri le ultime modifiche pubblicate e le nuove funzionalità aggiunte che lo rendono sempre più potente e versatile.

v2.20.3

2026-09-10
  • Improved some technique detection and prevention guidance in the report
  • Improved error handling for corrupted SYSTEM registry hives in SAMDump

v2.20.2

2026-09-07
  • New attack technique for obtaining Access Tokens of Azure VM managed identities
  • Optimized parallel execution of attack techniques on the same computer
  • Exploitation chain graphical improvements in report and UI

v2.20.1

2026-08-31
  • Added validation of a csv containing credentials found by external sources
  • Optimized import of computers found during network exploration phases
  • Fixed access to Partner tab for reseller users

v2.20.0

2026-08-21
  • Updated menus in the UI
  • Added multi-tenant user support for MSPs, with explicit delegation from End Users
  • Implemented Partner-specific funcionalities
  • Added demo Site for Partners

v2.19.6

2026-08-07
  • New Egress Filtering validation technique
  • Extended enumeration of groups within Entra ID tenants
  • Improved stealthiness of technique running assemblies
  • Extended target range for cloud techniques exploiting permissions on Azure resources
  • Optimized policies for authentication attempts
  • Improvements on Entra ID Health check
  • Minor graphic improvements in the report

v2.19.5

2026-07-30
  • Added validation feedback on credentials found in the Deep Web
  • Optimized Entra ID enumeration
  • New Entra ID health check test on stale devices
  • Improved harvesting of sensitive files

v2.19.4

2026-07-24
  • New Linux Privilege Escalation technique through Docker exploitation
  • Optimized RDP credential harvesting
  • Smart disablement of non-opsec-safe techniques when implants get disrupted during execution
  • Extended target range for user impersonation and lateral movement
  • Graphic fixes in the Graph View and technical report

v2.19.3

2026-07-17
  • Changed credential count logics: all exfiltrated and exposed credentials are counted once, irrespective of how many candidate internal users they may be related to
  • Fixed ordering in report chart
  • Fake computers detected as sandboxes filtered out in the UI and report results
  • Optimized commands in Kerberos ticket enumeration within Linux machines
  • Optimized exploitation of impersonated AD users to enumerate the domain
  • Improved RDP credential gathering inside the Exposed Windows Credentials technique
  • Improved naming of Entra ID Healthcheck results

v2.19.2

2026-07-14
  • Improved import of computer information after Entra ID enumeration
  • Optimized target choice for credential phishing attacks
  • Fixed parsing of default domain configuration files in Linux systems

v2.19.1

2026-07-08
  • Optimized stealthiness of the VEEAM dump technique
  • Improved impersonation policies for AD enumeration
  • Minor fixes to workgroup computer imports

v2.19.0

2026-07-01
  • Implemented Threat Actor modelling during BAS execution
  • Implemented attack profiling with possible lateral movement exclusion
  • Expanded the range of attacks available in Stealth mode

v2.18.0

2026-06-30
  • Added support for full-Entra ID and workgroup environments
  • Added technique for local network recognition
  • Added support for machine exclusions based on hostnames
  • Expanded the range of attacks available in Stealth mode
  • Improved AI-based credential correlation

v2.17.16

2026-06-10
  • Added technique Kernel AEAD Interface Local Privilege Escalation (CVE-2026-31431)
  • Added initial access vector based on Mockingjay technique
  • Minor fixes on the technical report

v2.17.15

2026-06-01
  • Added a new deploy method for windows hosts
  • Redesigned deployment area

v2.17.14

2026-05-27
  • Completely revamped Technical Report
  • Completely redesigned Dashboard area

v2.17.13

2026-05-25
  • Various UI improvements
  • Completely redesigned Partner Program area

v2.17.12

2026-05-22
  • Various UI improvements

v2.17.11

2026-05-18
  • Added technique Privileged SQL Server Access
  • Improved SQL server related techniques
  • Improved attack technique descriptions and remediation guidance in the report
  • Improved management of third party integration anomalies

v2.17.10

2026-05-11
  • Added BAS Event Collector for Elastic SIEM

v2.17.9

2026-05-06
  • Minor UI updates

v2.17.8

2026-04-30
  • Added more contextual information when a token is stolen from a remote process
  • Implemented user-defined proxy server and port configuration at BAS creation time

v2.17.7

2026-04-24
  • Updated deployment methods to emulate techniques used by specific APT groups
  • Added a new API endpoint for retrieving audit logs
  • Fixed a bug that prevented EDR indicators from being displayed in the attack timeline

v2.17.6

2026-04-08
  • Updated Access Token Acquisition via Browser Request technique

v2.17.5

2026-03-30
  • Added additional context for third-party integrations
  • Improved kerberoasting technique
  • fix Entra Id health checks unknown

v2.17.4

2026-03-25
  • Added CrowStrike integration
  • Added setting of the stealth mode during BAS execution

v2.17.3

2026-03-23
  • Optimized Dark Web queries for publicly-available credentials
  • Stealthier Powershell-based deployment method
  • Improved implant injection technique for some lateral movement attacks

v2.17.2

2026-03-19
  • Introduced OPSEC-safe execution mode in ZAIUX Evo, limiting available attack techniques to those with low detection risk in heavily monitored environments

v2.17.1

2026-03-11
  • Added audit log page for admin activity

v2.17.0

2026-03-05
  • New version of the Command and Control Server, with enhanced evasion capabilities
  • Improved support for Safari browser

v2.16.0

2026-03-04
  • Added AI agent to analyze folders, files, and memory dumps in order to identify and extract potential credentials
  • Added creation of additional implants for backup C2 communication and improved parallel execution of attacks

v2.15.9

2026-02-19
  • Waiting job page UI Updates

v2.15.8

2026-02-19
  • Minor improvements on Executive Report layout
  • Updated configuration tab for ZAIUX Framework integration
  • Added new technique Local Credential Extraction via VSS

v2.15.7

2026-02-13
  • Optimized Implant migration from ZAIUX Evo to ZAIUX Framework by removing command history and adding request headers

v2.15.6

2026-02-10
  • Added new technique Access Tokens from Files to retrieve cloud access tokens
  • Minor fixes

v2.15.5

2026-02-10
  • Added new Network Share Discovery technique to identify unauthorized access to network shares and sensitive files contained within them

v2.15.4

2026-02-05
  • Updated retrieval of Entra ID refresh tokens
  • Optimized LDAP queries for AD unconstrained delegations health check
  • Minor improvements in data aggregations for the Executive Dashboard

v2.15.3

2026-02-02
  • Log generation for SIEM platforms
  • Plug-and-play integration with Splunk

v2.15.2

2026-01-28
  • Added Executive Report creation to the Dashboard tab

v2.15.1

2026-01-19
  • Optimized research of public domains for exposed credentials
  • Minor attack technique description updates

v2.15.0

2025-12-29
  • added SentinelOne and Defender ATP integrations
  • minor bug fixes

v2.14.0

2025-12-17
  • Added new executive dashboard
  • New BAS scoring system
  • Minor report updates
  • Improved attack techniques descriptions

v2.13.4

2025-11-20
  • Added password spraying toggle when creating a BAS
  • Various UI improvements

v2.13.3

2025-11-19
  • Updated Powershell command to retrieve the list of old Operating Systems
  • Minor fixes

v2.13.2

2025-11-12
  • Added Windows to Linux lateral movement via clear-text SSH credentials or unprotected SSH keys
  • Enhanced cross-platform SSH session information gathering

v2.13.1

2025-11-11
  • General update of attack technique descriptions
  • Fixed management of incomplete enumeration results

v2.13.0

2025-11-07
  • Enabled Planned BAS execution through Windows services
  • Optimized management of dump files

v2.12.9

2025-10-22
  • Various UI fixes

v2.12.8

2025-10-16
  • Added ServiceNow integration

v2.12.7

2025-10-14
  • New technique Abuse Leaked Token Handle
  • Minor improvements

v2.12.6

2025-10-07
  • Various UI Fixes