August 18, 2026
Stronger Default Policy settings
Improvement
Updated the default policy settings to provide stronger protection out of the box. The new defaults apply to policies created from any standard template for workstations or servers, and to any policy reset to ThreatDown’s recommended settings. Existing policies are not modified.
Export AI activity
Feature
Export data directly from the AI tools and AI activity tables to CSV to pull AI usage across client sites into your own reporting. This is useful for a client review or for showing a client which AI tools are in use across their endpoints.
Features and Improvements
- Default policy settings updated. Applies only to newly created and reset policies. Existing policies are unchanged.
- Enabled by default:
- Automatic reboot when required: Workstation policies.
- Suspicious top-level domains (Browser Phishing Protection): Workstation and server policies.
- Enhance heuristics detections: Workstation and server policies.
- Enhance Hacktools detections: Workstation and server policies.
- Enhance sandbox detections: Workstation and server policies.
- Suspicious activity monitoring on servers: All Operating systems, workstation and server policies.
- Collect networking events for searching: All Operating systems, workstation and server policies.
- Disabled by default:
- Scan for rootkits (Threat Scan): Workstation and server policies.
- Enabled by default:
- Self-Protection settings moved under Tamper Protection. The Self-Protection options appear under Tamper Protection rather than Additional Protection.
- Clearer setting labels in policy configuration. The following policy settings have been renamed:
- Enable anti-malware scanning interface updated to Enable script scanning.
- Scan compressed folders updated to Scan compressed archives.
Issues Fixed
- MSP-20332: Fixed an issue where the Risk Exposure page showed a site as subscribed to Vulnerability Assessment after its trial had expired.
- MSP-20306: Fixed an issue where copying a site name from the AI activities table copied the site's identifier instead of the site name.
- MSP-20380: Fixed an issue where the Governance by category widget displayed an incorrect number of endpoints for each tool.
- MSP-20226: Fixed an issue where the hover tooltip on the Environment footprint widget's pie chart was partially cut off.