Skip to content

Commit ea136d1

Browse files
authored
Merge branch 'main' into main
2 parents afb62b4 + 1c7a2a9 commit ea136d1

File tree

1 file changed

+24
-4
lines changed

1 file changed

+24
-4
lines changed

defender-endpoint/linux-whatsnew.md

Lines changed: 24 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: deniseb
66
author: denisebmsft
77
ms.reviewer: kumasumit, gopkr
88
ms.localizationpriority: medium
9-
ms.date: 10/11/2024
9+
ms.date: 10/14/2024
1010
manager: deniseb
1111
audience: ITPro
1212
ms.collection:
@@ -34,16 +34,36 @@ This article is updated frequently to let you know what's new in the latest rele
3434
- [What's new in Defender for Endpoint on iOS](ios-whatsnew.md)
3535

3636
> [!IMPORTANT]
37-
> Starting with version `101.2408.0000`, Microsoft defender for Endpoint for Linux no longer supports the Auditd event provider. We're transitioning completely to the more efficient eBPF technology. This change allows for better performance, reduced resource consumption, and overall improved stability. eBPF support has been available since August 2023 and is fully integrated into all updates of Defender for Endpoint on Linux (version `101.23082.0006` and later). We strongly encourage you to adopt the eBPF build, as it provides significant enhancements over Auditd. If eBPF is not supported on your machines, or if there are specific requirements to remain on Auditd, you have the following options:
37+
> Starting with version `101.2408.0004`, Defender for Endpoint on Linux no longer supports the `Auditd` event provider. We're transitioning completely to the more efficient eBPF technology. This change allows for better performance, reduced resource consumption, and overall improved stability. eBPF support has been available since August 2023, and is fully integrated into all updates of Defender for Endpoint on Linux (version `101.23082.0006` and later). We strongly encourage you to adopt the eBPF build, as it provides significant enhancements over Auditd. If eBPF is not supported on your machines, or if there are specific requirements to remain on Auditd, you have the following options:
3838
>
39-
> 1. Continue to use Defender for Endpoint on Linux build `101.24072.0000` with Auditd. This build will continue to be supported for several months, so you have time to plan and execute your migration to eBPF.
39+
> 1. Continue to use Defender for Endpoint on Linux build `101.24072.0000` with Auditd. This build will continue to be supported for several months, so you have time to plan and execute your migration to eBPF.
4040
>
41-
> 2. If you are on versions later than `101.24072.0000`, Defender for Endpoint on Linux relies on `netlink` as a backup supplementary event provider. In the event of a fallback, all process operations continue to flow seamlessly.
41+
> 2. If you are on versions later than `101.24072.0000`, Defender for Endpoint on Linux relies on `netlink` as a backup supplementary event provider. In the event of a fallback, all process operations continue to flow seamlessly.
4242
>
4343
> Review your current Defender for Endpoint on Linux deployment, and begin planning your migration to the eBPF-supported build. For more information on eBPF and how it works, see [Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux](/defender-endpoint/linux-support-ebpf).
4444
>
4545
> If you have any concerns or need assistance during this transition, contact support.
4646
47+
<details>
48+
<summary> Oct-2024 (Build: 101.24082.0004 | Release version: 30.124082.0004.0)</summary>
49+
50+
## Sept-2024 Build: 101.24082.0004 | Release version: 30.124082.0004.0
51+
52+
&ensp;Released: **October 15, 2024**<br/>
53+
&ensp;Published: **October 15, 2024**<br/>
54+
&ensp;Build: **101.24082.0004**<br/>
55+
&ensp;Release version: **30.124082.0004**<br/>
56+
&ensp;Engine version: **1.1.24080.9**<br/>
57+
&ensp;Signature version: **1.417.659.0**<br/>
58+
59+
**What's new**
60+
61+
- Starting this version, Defender for Endpoint on Linux no longer supports `AuditD` as a supplementary event provider. For improved stability and performance, we have completely transitioned to eBPF. If you disable eBPF, or in the event eBPF is not supported on any specific kernel, Defender for Endpoint on Linux automatically switches back to Netlink as a fallback supplementary event provider. Netlink provides reduced functionality and tracks only process-related events. In this case, all process operations continue to flow seamlessly, but you could miss specific file and socket-related events that eBPF would otherwise capture. For more details, see [Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux](linux-support-ebpf.md). If you have any concerns or need assistance during this transition, contact support.
62+
- Stability and performance improvements
63+
- Other bug fixes
64+
65+
</details>
66+
4767
<details>
4868
<summary> Sept-2024 (Build: 101.24072.0001 | Release version: 30.124072.0001.0)</summary>
4969

0 commit comments

Comments
 (0)