Netwrix Endpoint Protector Client Version 2608

This release strengthens EPP’s tamper resistance across all platforms and delivers a comprehensive redesign of the eDiscovery module. It also broadens AI application monitoring to keep pace with fast-moving tools like Comet, Claude Cowork/Code, and Atlassian Rovo, and delivers a wide set of new national ID and PII detection patterns for global compliance coverage.

Updated versions of components provided with this release:

Windows Client: 2608.1.1.3
Mac Client: 2608.2.1.3
Linux Client: 2608.3.1.1
Browser print plugin: (not changed)
Outlook add-in: (not changed)
Enforced Encryption: 2608.4.1.0

Want the full details? Click the link below!

What’s New in Endpoint Protector Client Version 2608

General

Hardened Tamper Protection Across Windows, macOS, and Linux

This release closes several avenues attackers or unauthorized local users could use to disable or interfere with the EPP Client, giving security teams stronger assurance that protection stays active even under active tampering attempts. On Windows, EPP processes are now hardened against termination via WMI/CIM-based commands, and access control lists now restrict who can modify EPP’s installation folders, files, and services. macOS gains equivalent ACL- and permission-based hardening for EPP-owned resources, while Linux now detects and reports tampering attempts made through native systemctl commands (stop, disable, kill, mask) as security events on the EPP Server. Improved Tamper Protection hardening was first introduced in the 1st Hotfix of Client version 2605; this release extends that protection with the additional platform coverage described above.

Post-Quantum Cryptography for Client-Server Communication

Starting with the 2608 Client and Server release, Endpoint Protector supports Post-Quantum Cryptography (PQC) encryption for Client-to-Server communication, using hybrid key exchange ciphers in line with NIST-recommended standards. This prepares customer environments for long-term cryptographic resilience while maintaining backward compatibility with TLS 1.2/1.3.

No action is needed to enable PQC. Endpoint Protector negotiates it transparently and automatically as the highest available encryption option when both the Client and the Server are on version 2608.x.x.x or later. If either side runs an older version, Endpoint Protector falls back to the highest TLS version both sides support.

SCAP Level 1 Compliance for Linux Deployments

The Linux Client has been updated to align with SCAP (Security Content Automation Protocol) Level 1 requirements, making EPP easier to deploy in security-conscious and regulated environments. Improvements include moving keyboard monitoring from the notifier into the service (removing the need to add users to the “input” group), eliminating use of /tmp for EPP processes, and adding an option to disable printer monitoring entirely at install time.

Streamlined Client Upgrade Diagnostics

Troubleshooting failed client upgrades is now faster and less disruptive. Administrators can remotely collect diagnostic logs directly from endpoints that failed an upgrade — individually or in bulk — and review a specific failure code or stage indicator (such as download, install, validation, or communication failure) for each failed endpoint from the Client Upgrade Job details. Debug logs now also use size-limited rotation with configurable retention, plus standardized log storage locations across Windows, macOS, and Linux, so troubleshooting stays consistent no matter the platform.

Other Improvements

  • The EPP Client Notifier now supports the Ukrainian language.
  • The EPP Client Notifier now supports the Italian language. To be configured via Server, Requires EPP Server 2610 or later.
  • Windows now blocks the x64 EPP Client installer from being run on ARM-based devices, preventing an incompatible installer from leaving an endpoint partially protected.

macOS 27 (Golden Gate) Beta Compatibility

This release of the EPP Client has been validated against the macOS 27 “Golden Gate” beta.

Apple’s permission-handling changes in this beta mean end users may now need to manually approve the Bluetooth permission prompt after installing the Client. This is a known, industry-wide macOS 27 behavior change affecting security and monitoring software generally, not an EPP-specific issue. We’re actively working on a solution to restore silent, MDM-enforced approval of this permission and will share an update in a future release.


Device Control

Expanded Device Control Coverage

Device Control continues to close platform gaps and add finer-grained control over peripherals:

  • macOS and Linux now support audio input/output device control, aligned with existing Windows Audio Card capabilities
  • Linux adds support for covered biometric devices
  • macOS now correctly identifies VIVO and OPPO Android phones as mobile devices for policy enforcement

Other Improvements

  • Offline Temporary Password (OTP) handling on the Client now recognizes the final “Revoked” status across Device Control, CAP, and File Transfer Limit policies. Requires EPP Server 2608 or later.

Content Aware Protection & Deep Packet Inspection

Expanded AI Application Monitoring

As employees increasingly turn to AI-powered browsers, coding assistants, and collaboration tools, Content-Aware Protection keeps pace to prevent sensitive data from leaving through these new channels. This release adds monitoring and control for:

  • The Comet AI web browser on macOS and Windows
  • Claude Cowork and Claude Code (available with the Claude Enterprise licensing model), blocking file and text transfers that violate policy
  • Atlassian Rovo AI inside Jira and Confluence web apps.
  • TimelyGPT, as a web application accessed through common browsers
  • Cursor, as a desktop application

Expanded PII & National ID Detection Coverage

EPP’s DLP content detection engine adds a wide set of new, checksum-validated identity and financial patterns, helping global organizations meet data protection requirements in additional regions without waiting on custom pattern configuration. New patterns include:

  • The Mexican Electoral Registry number (INE) and Federal Taxpayer Registry (RFC)
  • UAE passport numbers
  • French Social Security Numbers written with standard spacing between digit groups, matching real-world document formatting
  • Prostir debit cards, Ukraine’s national payment scheme

Expanded Network Share Visibility for Linux

The Linux Client can now monitor file activity — opens, reads, writes, renames, and deletes — on NFS-mounted network shares using the existing fanotify infrastructure, giving administrators the same visibility into network file activity already available for local files. This release delivers verified support for NFSv4 mounts, with detection dynamically tracking shares as they’re mounted or unmounted.

More Accurate Detection in Spreadsheet Files

DLP scanning of Excel files is now more reliable when large numbers such as phone numbers or tax IDs are stored internally in scientific notation, ensuring pattern matching correctly identifies sensitive numeric data regardless of how Excel represents it under the hood.

New File Type Support for Engineering Files

CAP and eDiscovery policies now recognize Altium Designer file formats, extending sensitive-data protection to proprietary circuit board and schematic designs:

  • .PcbDoc
  • .SchDoc
  • .PrjPcb
  • Other associated Altium Designer extensions

Expanded CAP Coverage Applications

Content-Aware Protection now covers additional business applications where file exfiltration risk is high:

  • Jira and Confluence desktop and web apps, now monitored and controlled as CAP exit points
  • VMware Workstation on Linux, now a fully supported CAP exit point with complete DPI-based policy enforcement, matching the coverage already available for web browsers

Enhanced Print Activity Monitoring for macOS

macOS File Tracing has been extended to cover printing events, giving administrators the same level of print activity visibility for print jobs already available on other platforms.

Other Improvements

  • Deep Packet Inspection can now be configured to ignore traffic on point-to-point interfaces, which are commonly used by VPN clients. This resolves connection timeouts on Linux endpoints where a VPN solution and DPI interfere with one another. Requires EPP Server 2610 or later.

eDiscovery

eDiscovery Redesign: Version 2608 delivers a comprehensive redesign of the eDiscovery module — Endpoint Protector’s data-at-rest scanning capability — giving organizations more control over how they discover, analyze, and remediate sensitive data residing on endpoints. On the Client side, this redesign brings:

  • User-initiated scans — end users can now start a data-at-rest scan directly from the EPP agent on their own endpoint, rather than waiting for a server-scheduled scan
  • Resource-aware scan execution — scans can automatically pause based on battery level, CPU usage, or active user activity, minimizing disruption to the end user’s device
  • Removable devices as scan targets — data-at-rest discovery now extends beyond fixed storage to removable devices (USB drives, external storage) attached to the endpoint
  • Configurable local scan retention — administrators can control how many user-initiated scan results (by count or days) are retained on the endpoint before rollover, and whether that scan event data is sent to the server; sending is off by default to avoid generating excessive log traffic
  • Policy-level Contextual Detection Rules — contextual detection is now configured per eDiscovery policy rather than as a single global setting, improving the granularity of what each scan actually looks for and the context it’s evaluated in
  • Expanded policy capacity — the number of supported eDiscovery policies has been increased to 40

The eDiscovery redesign requires EPP Server 2608 or later. With older EPP Server versions, the Client’s eDiscovery module continues to operate in its previous mode. The full policy management, scheduling, and reporting capabilities introduced with the redesign are covered in the EPP Server release notes.


eDiscovery tab in EPP Notifier for User Initiated scans


eDiscovery result tab in EPP Notifier for User Initiated scans


Bug Fixes and Miscellaneous Updates

The following table contains a comprehensive list of updates and fixes introduced in this version:

Component Description Case # Escalation #
Security **Updated Component: OpenSSL library** — EPP uses latest version with upstream security fixes. 437978
Security **Updated Component: WolfSSL library** — Enforced Encryption uses latest version with upstream security fixes. 445103
Security **Files exposed under Tamper Protection** — Fixed an issue on Windows where, with Tamper Protection enabled, two internal configuration files could be read by unauthorized processes. File access permissions have been tightened to prevent this exposure. 440887
General **False “Forced Uninstall” log on Linux startup** — Fixed an issue where Linux endpoints generated a “Forced Uninstall” log entry every time the machine started, even though no uninstall was attempted. 320083
General **Collect Diagnostics action not returning data** — Fixed an issue where running “Collect Diagnostics” from the server did not return a diagnostic artifact, leaving the Diagnostic Data table empty. 438317
General **Client sending empty log packets** — Fixed an issue where the client periodically sent empty log packages to the server, creating unnecessary log traffic. 442256
General **Client configuration could be lost after an unexpected shutdown** — Improved reliability on macOS and Linux so the client’s local settings file can no longer be left empty if the client process is terminated while saving, which previously could cause the client to lose its server connection details. 445461 00481291
General **Leftover files after uninstalling on macOS** — Fixed an issue where uninstalling the client on macOS left behind two application support folders instead of removing them completely. 451175
General **File Shadows not delivered to FTP repository** — Fixed an issue where shadow copies of blocked files were not sent to the File Shadows Repository when it was configured to use an FTP connection. 452018
General **File shadows missing for file move events on Linux** — Fixed an issue where moving a file to a removable device or network share generated a File Copy event without an accompanying shadow copy. 390728
General **Linux install certificate script failed to detect domain-style home paths** — Fixed an issue where the Linux DPI certificate installer did not correctly detect a user’s home path when the path included a domain name (e.g. `/home/infra@domain`). 447476 00481378
DC **Device lockdown option not enforced on macOS Sonoma** — Fixed an issue on macOS Sonoma where enabling “lockdown all endpoints” and clearing exclusions in the Device Control dashboard did not actually block the excluded device types (Wi-Fi, Bluetooth, keyboard, etc.). 319869
DC **Bluetooth mouse/keyboard remained usable after being denied** — Fixed an issue on Linux where a Bluetooth mouse or keyboard set to Deny was blocked only briefly, then resumed working with erratic behavior. 437232
DC **Third-party virtual drives could crash on startup** — Fixed an issue where certain virtual drive software (e.g., Box Drive) was incorrectly identified as an unknown storage device, causing it to crash on launch when unknown devices were set to Deny. 442287 00480242, 00481321
DC **Specific virtual drives could be blocked by “Unknown Devices” policies** — Improved device identification so administrators can exclude specific third-party virtual drives from Device Control enforcement at the driver level, without needing to broadly allow all unknown devices. 442754 00466821
DC **Advanced Printer and MTP Scanning not working correctly on Windows ARM64** — Fixed an issue where the Advanced Printer and MTP Scanning feature did not interoperate correctly with x64 and x86 processes running under WoW64 emulation on ARM64 Windows devices. 426297
DC **Trusted Device content readable outside EasyLock on macOS** — Fixed an issue where files on a TD1/TD1+ device could be listed and copied via Finder or Terminal on macOS, bypassing EasyLock. macOS now matches the full-block behavior already applied on Windows. 452102 00477749
DC **Built-in webcam not blocked on macOS** — Fixed an issue on macOS where denying the Webcam device right did not stop the built-in camera; on affected Macs, the built-in camera is handled by a separate system component that was not covered by the existing camera-blocking logic. 452353 00482087
CAP **DLP engine could crash loading a large custom dictionary** — Fixed a crash that could occur when the DLP engine loaded a large custom dictionary file. 437988
CAP **DLP engine could crash reporting threats on a network share** — Fixed a crash that could occur when threat events were reported for files detected on a network share. 438145
CAP **Duplicate remediation prompts for network share transfers** — Fixed an issue on macOS where the user remediation pop-up for a Block & Remediate policy could appear twice for a single file transfer to a network share, with the event logged multiple times. 320086
CAP **CAP scanning direction dependent on File Tracing settings (Linux)** — Fixed an issue on Linux where Content Aware Protection scanning of removable-device transfers was incorrectly affected by the File Tracing direction setting, letting some monitored transfers through undetected. 341792
CAP **CAP scanning to removable devices required File Tracing (Linux)** — Fixed an issue on Linux where Content Aware Protection policies for removable devices were enforced only when File Tracing was also enabled, letting transfers bypass detection otherwise. 347533
CAP **Sensitive DOCX files could bypass network share protection via “Save As”** — Fixed an issue where using “Save As” to copy a DOCX file with sensitive content to a network share could bypass Content Aware Protection, even though the transfer was logged as blocked. 398611 00452594
CAP **SBF files not always recognized by content detection** — Fixed an edge case where certain .sbf files were not correctly identified, allowing them to bypass Content Aware Protection policies restricting this file type. 426543 00473674
CAP **Outlook attachment policy also matched email body content** — Fixed an issue where a Content Aware Protection policy scoped to Outlook attachments could still block an email based on content found in the message body rather than the attachment. 432088 00475228
CAP **Print jobs sometimes evaluated against the wrong document** — Fixed an issue where, in certain printing scenarios, the client could attempt to scan a temporary print file that no longer existed on disk, so the print job was not properly evaluated against content policies. 433789 00475104
CAP **Sensitive image files not blocked when “report all sensitive data” enabled** — Fixed an issue where enabling “Ignore thresholds (report all sensitive data)” caused image files that should have been blocked by file location, filename, or size rules to be allowed through instead. 437668
CAP **False content alerts triggered by Chrome Translate** — Fixed an issue where using Chrome’s built-in translate feature could trigger false-positive gzip file detections when Chrome monitoring and DPI were enabled. 437698
CAP **Policy conditions using multiple custom dictionaries did not trigger correctly** — Fixed an issue where a file was not blocked if a matched word belonged to more than one custom dictionary and the policy used logical conditions referencing those dictionaries. 437734 00474838
CAP **Google Photos uploads not blocked** — Fixed an issue where image uploads to Google Photos were not blocked by Content Aware Protection policies denying graphic file types on browser exit points. 437861 00477061
CAP **Sensitive clipboard content could remain visible in remote sessions** — Fixed an issue where blocking a clipboard copy/paste in AnyDesk cleared the content locally but not on the remote machine, leaving it accessible there. 438599 00477984
CAP **Shadow copies not created for large blocked files** — Fixed an issue where shadow copies were not consistently generated for blocked files, most often affecting files larger than 10 MB transferred via Teams or USB. 439926 00450675
CAP **Downloaded Teams screenshots occasionally removed** — Fixed an issue on macOS where screenshots downloaded from Microsoft Teams could be intermittently and silently removed from the Downloads folder while OCR-based content scanning was active. 442103 00480316
CAP **Non-JPEG image uploads to M365 Copilot not monitored** — Fixed an issue where the client only inspected JPEG image attachments uploaded to Microsoft 365 Copilot; other common image formats (PNG, BMP, GIF) were not monitored. 444447
CAP **OCR-enabled policies could delete newly created image files** — Fixed an issue where, with OCR content scanning enabled, newly saved image files such as screenshots could be deleted shortly after creation, even under Report Only policies. 444725 00481321
CAP **First message in Google AI Mode not inspected** — Fixed an issue where the first text message sent in a new Google AI Mode session was not inspected for monitored content. 447532
CAP **Paste restrictions not enforced in ChatGPT desktop app** — Fixed an issue where clipboard paste restrictions configured in a Content Aware Protection policy were not enforced when pasting into the ChatGPT Windows app. 450844
CAP **Fasoo DRM-encrypted files not detected** — Improved file type detection to recognize Fasoo DRM-encrypted documents, which were previously classified as a generic file type and could bypass policies restricting this format. 451642 00483864
CAP **Printer name missing from CAP report on Mac** — Print events on macOS did not include the printer name in the CAP report; the report showed a generic “Printer” or “Network Printer” label instead. 452007 00484573
CAP Large numeric IDs in XLSX files not detected by content policies — Fixed an issue where numbers such as phone numbers, tax IDs, and IBANs stored in Excel’s scientific notation (e.g. 9.8767112233E9) were not matched by DLP pattern detection, allowing them to bypass Content Aware Protection policies. 440915 00479486
DPI **Slow or failed website loading with DPI enabled on macOS** — Fixed an issue on macOS where enabling Deep Packet Inspection could cause certain websites to load very slowly or fail to load, caused by an excessive number of concurrent inspection connections. 423981 00468494
DPI **DPI inspection process could crash** — Fixed a crash in the client’s SSL inspection component caused by an internal memory-handling error. 438981
DPI **Large file uploads could stall when DPI scanning is enabled** — Fixed an issue where uploading files larger than the initial HTTP/2 flow-control window while DPI content scanning was enabled could cause the upload to hang and eventually fail. 439906 00479286
DPI **Google Meet calls dropped when DPI enabled** — Fixed an issue where Google Meet and other WebRTC-based apps could drop calls after about a minute when Deep Packet Inspection was enabled. 444654 00483630, 00480760
DPI **External sites unreachable with DPI enabled while on GlobalProtect VPN** — Fixed an issue where several external sites, including Outlook, Azure DevOps, Grok, and Copilot, became unreachable when a policy had DPI enabled while connected to GlobalProtect VPN. 451184
DPI **Stale IPv6 connectivity status on macOS after network changes** — Fixed an issue where the Transparent Proxy network extension on macOS did not re-evaluate IPv6 connectivity when the network configuration changed (Wi-Fi/Ethernet connect/disconnect, VPN connect/disconnect, interface changes), which could route browser and app connections to IPv6 destinations based on stale connectivity information. 452053 00479286
DPI DPI could block access to GitHub and Azure DevOps — Fixed an issue where enabling Deep Packet Inspection could prevent connections to github.com and dev.azure.com from completing in the browser. 452165

Known Limitations

Component Description Case # Escalation #
General In newer Linux distributions, the default snap application for file access events in xdg Desktop portals is not supported by the EPP Client. EPP-8735 EPPSUPPORT-3198
General Windows XP, Windows 7, Windows 8, early Windows 10 builds, and Windows Server 2016/2019 no longer supported as of EPP client version 5.9.4.1. 438053
DC Despite denying Bluetooth, Webcam, and iPhone access on macOS, Continuity Camera continues functioning in Slack, Zoom, FaceTime, and Photo Booth. EPP-8781, EPP-6826
CAP On Linux environments using the Wayland protocol by default, paste control is constrained due to Wayland’s inability to detect the focused window. EPP-8510
CAP File Shadow downloads from AWS S3 buckets with concurrent File Tracing and CAP may result in inconsistent behavior. 320213, EPP-9023
CAP AI interaction monitoring does not extend to meta.ai when accessed within Facebook, Messenger, or WhatsApp due to encryption dependencies. 410799
CAP On macOS, files containing confidential content are not blocked when uploaded through the Cursor application’s “New Agent” feature, even when a CAP policy with DPI enabled is monitoring Cursor. A fix is targeted for a future release. 453228
General On macOS 27 “Golden Gate”, both a fresh EPP Client install and an upgrade of an existing install trigger a Bluetooth permission pop-up that requires manual end-user approval; the previous silent pre-approval method is no longer available under macOS 27. A fix restoring silent, MDM-enforced approval is in progress for a future release. 451042

Deprecated

Component Description Case #
CAP Contextual Detection under System Parameters has been discontinued and replaced by Context Detection Rules in CAP Policies. EPP-8941

Upcoming Deprecations

Component Description Case # Targeted Release
General The File Shadow Maintenance feature for listing and managing File Shadows on the EPP Server will be discontinued in a future release. TBD

Need help with this update?

There are many different ways to get help with our products!

Situation Action
If you feel the product is broken and not working as intended… Contact Support
If you have a question you’d like to ask other experts… Create a discussion in the community: Endpoint Protector > Discussions & Questions
If you have a feature request… Let our product team know directly: Endpoint Protector > Ideas
If you have something cool to show… Show everyone what you built: Endpoint Protector > Show & Tell

What are your thoughts?

We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!

2 Likes

I’m glad to see that the improved 2608 client has been released with several enhancements.

By any chance, is there also a 2608 server version planned for release?

1 Like

Could you please confirm the planned release date and time for EPP Server version 2608?

Hi @jwkim, @Krutik,

Thanks for asking. I have good news — we plan to announce more details about the 2608 Server release in the coming days.

Please stay tuned and follow the Netwrix Community for further updates.

BR, Krzysiek

1 Like

Hi,

could you please share the most recent installation instructions for EPP Client 20608.2.1.3 (macOS) when deployed via Jamf Pro?

Thank you,

Bernhard

Hi @bernhard.schandl,

Thank you for raising this.
The Jamf guide is provided on a best-effort basis, as third-party tools may change their behavior, UI, or configuration options over time. That said, I’m happy to confirm that we are already working on an update to this documentation, and we expect to publish the refreshed version soon.

Please stay tuned for the updated guide.
BR, Krzysiek

Hi @jwkim, @Krutik,

I’m happy to announce that EPP Server 2608 goes live today:
https://community.netwrix.com/t/netwrix-endpoint-protector-server-2608-0-1-0/140427

BR, Krzysiek

1 Like

Kindly provide the scheduled date and time for the EPP server upgrade activity for the Asia region. We have still not received any update from your end.

As per the maintenance notification/article, the scheduled maintenance time was 1 September 2026 at 12:00 PM UTC.Please provide the current status of the upgrade activity and confirm the expected timeline for service restoration.