11.5 Agent Release Notes

This agent release includes new features, bug fixes, and enhancements to the product. To start using them, you must update your agents to version 11.5.

Important

  • Support for version 10.10 agents ends on October 20, 2025.
  • Support for version 10.11 agents ends on January 19, 2026.
  • Starting with the 11.6 release, Android OS 10 and older will no longer be supported.

  • Starting with the 11.5 release, Agent installers will be provided as a ZIP archive containing the MSI, a configuration file, and the VC_redist installers. The MSI will no longer be tenant-specific; instead, it will require the configuration file to be passed as a parameter during installation. This change enables easier access to previous agent versions and lays the groundwork for controlled rollout of specific versions. Agent upgrades via the Deployment feature remain unaffected, and macOS/Linux agents already follow this ZIP format.

New

System Group Condition for Tool Schedules

You can now add conditional logic to tool schedules in Configure > System Configuration > Roles, so that scheduled tools run only on applicable groups.

Application Hang Detection for macOS

Application hang events on macOS can now trigger sensors in Resolve. The detection logic aligns with macOS Activity Monitor, providing consistent validation of application responsiveness for end users.

NOTE: This functionality requires Accessibility permission. If the permission is not granted, application hang events will not be collected.

New Option to Limit Database Uploads for Offline Resolve

A new setting in Database Maintenance under Configure allows you to limit database snapshot uploads to one per day. This update reduces network impact by preventing excessive uploads triggered by frequent shutdowns and logouts, such as in shared workstation scenarios.

Device Azure Join Status Is Now Collected

The agent now records how a device is joined to Azure and adds this information as a new column in the SASCFG table.

Fixed

  • The agent no longer crashes during SABATTERY inventory when the \.root\WMI namespace is inaccessible. Null pointer exceptions during WMI interaction are now handled safely. (13034)
  • Group Policy events are now consistently collected into the SAGROUP_POLICY_PROCTIMES table, even when the saved BookmarkRecordID is higher than the current Event Record ID. (12945)
  • User Defined Inventory (UDI) items targeting HKCU registry paths are now correctly written to the agent database. (13041)
  • Long-running custom views no longer block the SQLite engine. Other data collection continues uninterrupted, reducing agent restarts and fault reporting. (12583)
  • Improved Thermals collection to prevent gaps in SASYS records caused by delays in WMI calls. Thermals are now collected via a dedicated thread that sends CPU temperature data to SASYS. If the message is not received in time, a Trace 5 log entry—“Unable to receive CPU Temperature in a timely manner”—is recorded. (12738, 13262)
  • Usage collection for integrated Intel GPUs on macOS systems in SAGPU now reports accurate values. (12334)
  • The agent now tracks when data is available for views that are ready to condense. If it cannot condense the data when the view runs, it will send the data the next time views are checked and condensing is possible, ensuring timely updates to the master dataset. (13290)
  • The agent on upgraded systems now starts reliably with improved data integrity for collection extensions. (13185)
  • The agent now correctly detects the status of the Cofense Reporter add-in in Outlook. (13293)
  • The agent on non-Windows systems now automatically condenses on daily timers as expected. (13741)
  • The SysTrack Tray App Not Running sensor now reflects the current tray app state accurately in situations where the local system time was previously set to a future date. (13385)

  • Agent restart after time change now completes without generating crash dumps. (13611)
  • App records now condense correctly after the local system time was previously set to a future date. (13907)
  • Agent now runs reliably when the Ports and Ping threads operate on a shared map simultaneously. (13894)
  • The agent now collects registry keys that contain only a default value when "Include All Values" is selected in User Defined Inventory. (13340)
  • Resolved a vulnerability in the LSI agent’s user-boost interprocess communication system that could have allowed for a privilege escalation. (6371)

Changed

.NET Version Detection Beyond 4.0 for Application Dependency Tracking

The agent now uses a new method to detect the .NET version used by an application. The detected version is stored in a new column in the SAAPPINFO table. The new approach is more reliable and automatically supports future .NET versions without requiring agent updates.

Agent Version Compatibility

The following list of agents are compatible with SysTrack version 11.5.

Agent Version
11.5
11.4.x
11.3.x
11.2.x
11.1.x
11.0.x
10.12.x
10.11.x