Version 3.8.6 includes:
This section describes the new features added in version 3.8.6.
The following features have been added to the Coro console:
The Activity Log Types filter list is now alphabetized.
For more information, see Activity Log.
The following features have been added to Connectors:
For customers with a configured ConnectWise PSA connector, when a Coro-originated ticket is set to “closed” status in ConnectWise, Coro now automatically closes the related ticket in the Coro ticket log.
For more information, see Integrating with ConnectWise PSA.
The following features have been added to Cloud Backup:
This release introduces a new set of views for end customers of Managed Service Providers who are subscribed to the Cloud Backup module. These new views show a record of backup and restore tasks performed, as well as the health of connected cloud apps.
For more information, see Cloud Backups.
Version 3.8.6 introduces the following additional changes:
Coro console security has been improved in the following ways:
- Admin user password strength increased
- Console inactivity timeout reduced
- Increased audit logging of console events
The MSP Global View pages have been improved in the following ways:
- Bundle breakdown panel improved with new pie chart visualizer.
For more information, see MSP workspaces overview.
Because of an external process change, customers using Coro's Azure Sentinel SIEM connector must re-establish their connections to continue using the service.
For more information, see Configuring and managing SIEM connectors.
Previously, each endpoint device scan might have resulted in Coro raising a new ticket, even if the findings were identical; Coro now consolidates findings from repeated scans of the same device into a persistent Endpoint Drive Containing Sensitive Data ticket.
Subsequent scans update the existing open ticket rather than creating a new one. Newly discovered files (since the last scan) surface at the top of the ticket, each annotated with a "last seen" timestamp.
For more information, see Ticket types for Endpoint Data Governance.
Coro now includes a dedicated filter on the Devices page to show only Protection-disabled devices. This new filter lets you quickly re-enable protection for these devices.
For more information, see Devices.
This release improves the processing rules for Unencrypted Endpoint Drive tickets to ensure admin users receive the correct number and frequency of notifications. Improvements include:
- Open and unresolved Unencrypted Endpoint Drive tickets close automatically after 10 days.
- If a ticket is marked closed, Coro does not add new detected events of the same type to it. Instead, Coro creates a new ticket for the event, which means it raises a new notification for admin users.
- When Coro detects that the drive has been re-encrypted (the issue is resolved), it automatically marks the open ticket as resolved and closes it. Coro does not add further detected events of the same type to the resolved ticket, even if an admin user manually reopens it.
- If the admin user allows no encryption, Coro closes the corresponding ticket.
For more information, see Unencrypted Endpoint Drive.
This release adds ancestry context to EDR telemetry data, so users can now view parent process IDs (PPIDs) for all listed processes.
For more information, see Telemetry.
To avoid the risk of lost email due to misconfigured mail settings, Coro now provides a seven-day grace period after a customer disconnects from the Inbound or Outbound Gateway. During this period, Coro will continue to deliver any emails received via either gateway.
Admin users can now add entries to the Email Security blocklist or allowlist based on TLD (Top-Level Domain).
For more information, see Allow or block email senders.
Admin users can now add Email Security blocklist entries based on wildcarded subdomains. For example, *.domain.com to block all subdomains (and any nested subdomains) identified at domain.com. The base domain continues to be allowed.
For more information, see Allow or block email senders.
Blocklisted IP tickets are now deprecated; from this release, detections are raised as Blocklisted Sender tickets.
For more information, see Ticket types for Email Security.
In the Security Training and Phishing Summary reports, searching for a specific user record now searches all users and not just those shown in the report.
Coro now provides improved predefined date ranges in the Date range selector for Security Training and Phishing Summary reports to better fit typical usage.