Documentation › Release notes
Every change to the probe, the portal and the reports. Anything that changes what a check means, or what a report says, is listed here.
The first Linux probe, for Ubuntu 22.04, 24.04 and 26.04 LTS and Debian 12 and 13. It reports the same controls as Windows, read the Linux way: antivirus, firewall, disk encryption, ssh and account settings, password policy, screen lock on desktops, and failed services. Checks that cannot apply say so, with the reason. Update age is days since the oldest waiting security update was released, dated by the portal from Ubuntu's and Debian's security notices and judged against the same 14 days. It installs from probe-linux.tar.gz on Add a machine, and updates itself with signed releases when automatic updates are on.
The probe now installs under BOBcloud Monitor names: C:\Program Files\BOBcloud\Monitor, C:\ProgramData\BOBcloud\Monitor, the scheduled task \BOBcloud\Monitor Probe and the registry key HKLM\SOFTWARE\BOBcloud\Monitor. Probes from before 0.8.0 are not offered automatic updates: reinstall them once with the current download, after uninstalling the earlier probe (the installer's -Uninstall removes both old and new names). From then on, later versions follow automatically where updates are switched on.
A check that cannot apply to a machine now shows as not applicable, with the reason, instead of as unknown. It is never counted as a pass, never scored as healthy and never offered for silencing, and no "resolved" email is sent when a failing check becomes not applicable.
No functional change. This is the first release delivered by automatic update: machines on 0.7.6 with updates switched on verify the signature, install it, check themselves and report the result, which shows beside each machine on the Updates page.
The first probe that pins our update-signing key, so it will only ever accept an update we have signed. Every check now has a time limit: a check that stalls, such as a hung Windows Update search, reports as unknown with "timed out" and the rest of the run still arrives. The installer now says when a machine has been approved automatically.
Automatic updates reach an estate in stages; the time between stages is now a setting on the Updates page rather than fixed. The Devices page shows the probe version each machine last reported, and flags any that are behind.
Adds a -Diagnostics switch that writes a redacted file a technician can send to support, and a header at the top of the probe log showing version, start time and how it was run.
Scheduled-task results are counted against the task list so a missing result is visible. A reading too large to store is now recorded as dropped rather than disappearing without trace.
The probe sends every scheduled-task result code as it reads it, and the server decides which codes count as failures. Changing that list no longer needs a new probe on every machine.
New checks: screen lock on signed-in profiles, local password and lockout policy, and secure configuration (SMBv1, remote desktop with network-level authentication, UAC and autorun). Disk encryption is read and reported.
A pack now runs between two dates and lists every change of result in between, rather than the state on the day it was produced. Silenced findings stay in the pack with their reason.
Each machine reports its hardware and installed software. Inventory is reported, not graded, and is kept out of evidence packs.
The baseline probe: update age against the fourteen-day window, supported Windows version, antivirus, firewall, update settings, local administrators and the guest account, reported hourly over outbound HTTPS.