github Asymptote-Labs/agent-beacon v1.2.0

latest releases: v1.3.29, v1.3.28, v1.3.27...
one month ago

Changelog

Features

  • 6487c03 feat(hooks): accept the endpoint settings as flags, not only as environment
  • f863898 feat(portability): compile Beacon for Windows
  • d14272b feat(release): publish Windows archives, and find the collector inside one
  • 98e1c42 feat(release): publish Windows archives, and find the collector inside one (#326)
  • 321c61b feat(release): publish the Windows MSI
  • 993a872 feat(release): publish the Windows MSI (#328)
  • 67a9ca0 feat(sandbox): assert that uninstall actually removes the endpoint
  • b5caea6 feat(sandbox): assert that uninstall actually removes the endpoint (#330)
  • 787550b feat(sandbox): dispatch Windows runs with run --provider github
  • a1bf439 feat(sandbox): run scenarios on a Windows guest via a disposable CI runner
  • eb5494d feat(windows): capture through installed hooks (#323)
  • 3170048 feat(windows): emit hook commands as one argv, and resolve the console user
  • 70b15aa feat(windows): make Windows verifiable, and make Beacon compile there (#316)
  • e048bab feat(windows): package the endpoint as an MSI
  • 2d3673e feat(windows): package the endpoint as an MSI (#327)
  • 0e1c7c4 feat(windows): resolve the system log location from one place
  • 8f66ae6 feat(windows): run the collector as a Windows service
  • d603c7a feat(windows): run the collector as a Windows service (#321)
  • dd78b4b feat(windows): the filesystem contract, and three bugs the gate found (#319)

Bug Fixes

  • f13487f fix(ci): export telemetry on a timer that fits the session
  • c2d2753 fix(ci): export telemetry on a timer that fits the session (#325)
  • 8e00e94 fix(collector): detect the Windows collector's filename instead of assuming it
  • 4ad1bb9 fix(exporter): capture PowerShell commands, not only Bash
  • 20a8f76 fix(hooks): recognize the flags form when detecting installed hooks
  • b3e345c fix(hooks): stop the hook test helper deadlocking on a full pipe
  • 3020cf3 fix(release): bound the MSI job so a hung installer cannot hold a runner
  • b15e6c7 fix(sandbox): a failed artifact copy no longer leaves a truncated file
  • e977804 fix(sandbox): assert guarded paths by identity, not by separator
  • b25035a fix(sandbox): correct four issues Cursor Bugbot found on #316
  • 3652d18 fix(sandbox): do not carry one scenario's events into the next one's verdict
  • 323ab5a fix(sandbox): keep the whole ci exec output when it fails
  • d7bd497 fix(sandbox): put Claude Code's real install directory on PATH
  • 5146be3 fix(sandbox): stop asserting a retention contract the CLI does not offer
  • 69a1d1f fix(sandbox): uninstall the endpoint a scenario installed, on providers that are the host
  • 62d4bb0 fix(threatrules): compare FIELDS.md by content, not by line-ending representation
  • f54062f fix(windows): actually keep the configuration an uninstall promises to keep
  • fa0326c fix(windows): compare encoded paths, and recognize both binary spellings
  • a2fe76f fix(windows): give SystemBaseDir a Windows value, and gate what depends on it
  • 61230e6 fix(windows): give doctor remediation that works on the platform that failed
  • 87ecf0c fix(windows): make system-mode install possible, and repair reach the right profile
  • 5821f2e fix(windows): make three checks that could not fail actually fail
  • 7bc650b fix(windows): one shared home redirect, and a collector that is findable
  • 759a197 fix(windows): quote the grant hint so it survives being pasted
  • 05d1972 fix(windows): repair four install-path defects review found
  • 4a77ad0 fix(windows): state the supervised fallback's limits wherever it is described
  • 28fa13d fix(windows): stop the endpoint before an upgrade replaces its binaries

Other

  • 2b92faf chore(ci): survey which cli/beacon packages pass on Windows
  • 78ecca1 ci(windows): widen the Windows test scope from 9 packages to 25 (#331)
  • 76fca98 ci(windows): widen the test scope from 9 packages to 25
  • f05b25f docs(sandbox): stop the contributing guide presenting itself as Linux-only
  • 280c0c9 docs(sandbox): stop the contributing guide presenting itself as Linux-only (#332)
  • 073cc89 docs(windows): document the Windows install and how to verify it
  • c95ce32 docs(windows): document the Windows install and how to verify it (#329)
  • d00baa7 probe(windows): ask which hook command forms a Windows runtime accepts
  • 047564d probe(windows): split #320 into the two halves it could be
  • 8112691 test(linux): verify the systemd query beacon-sandbox depends on
  • af3038d test(macos): assert uninstall removes the launchd job
  • 21eca34 test(macos): drop a launchd check this test cannot attribute to itself
  • 688da2e test(sandbox): make the mutation self-test capable of failing
  • 4bd429a test(windows): find out whether the collector can be an SCM service
  • 47c6bcb test(windows): gate user-mode capture now that a run has demonstrated it (#324)
  • 50f1ecd test(windows): gate user-mode capture, now that a run has demonstrated it
  • 85ad164 test(windows): scope the Windows gate to the packages this port covers
  • 43fedad test(windows): stop asserting that Windows resolves no console user
  • 88d9d56 test(windows): test retention where it is actually a contract
  • c3dc86a test(windows): test the prefix boundary, not the POSIX layout

Installation

Homebrew (macOS/Linux)

brew tap asymptote-labs/tap
brew install beacon

Manual Download

Download the appropriate archive for your platform from the assets below, extract it, and add the binary to your PATH.

Quick Start

beacon endpoint install
beacon endpoint status
beacon endpoint wazuh print-config

Threat detection rules

beacon ships with a small built-in baseline. Install the full threat-rule
pack (attached as threat-rules.tar.gz below) and scan your local telemetry:

beacon rules pull https://github.com/asymptote-labs/agent-beacon/releases/download/v1.2.0/threat-rules.tar.gz
beacon rules list
beacon scan

Don't miss a new agent-beacon release

NewReleases is sending notifications on new releases.