Release Notes
Console 1.0.26 / Sensor 1.0.59 - September 2026
Investigations and alert triage
- Progressive search - Investigate loads results as the selected range is searched. Stop loading to review evidence, continue from the same point, or retry after a failed request.
- Clearer result scope - Search progress and retained-result exports distinguish loaded evidence from the full requested history.
- More reliable evidence links - Links from detections, alerts, API Security, and telecom views preserve the relevant sensor, event, and time context.
- HTTP evidence in Investigate - Open captured request and response content alongside process and network observations.
- Alert detail tabs - Summary, Evidence, and Activity separate the finding, original source evidence, and triage history. Attack-chain alerts link to their source chain.
- Runtime browsing - Runtime Explorer and Network views load additional results in pages and preserve position while browsing history.
- Process Tree continuity - Refreshes preserve the selected process and detail tab instead of returning to Summary.
See Investigate, Alert Inbox, and Runtime Explorer.
Detection and response
- Simpler policy navigation - Runtime Detection brings Custom Rules, Built-in Rules, and Recent Matches together. Existing imported detection rules remain available there.
- Application Restrictions - The former Guardian Profiles workflow is now named Application Restrictions under Runtime Blocks.
- Anomaly Exceptions - Expected-behavior exceptions are managed from Behavioral Analytics.
- Policy Pack retirement - The old assignment screen has been removed. Previously delivered policies are not automatically uninstalled.
- Inspect and edit custom rules - Review saved detection conditions and enforcement policies, edit them, and verify the resulting state.
- AI-assisted enforcement - Improved validation and feedback for generated policy drafts before activation.
- Activation review - A wider review dialog makes the action, targets, exceptions, and potential impact easier to inspect.
- Sensor enforcement details - Inspect configured policy YAML directly from a sensor's Enforcement tab and open Runtime Blocks to edit it.
- Learning-state guidance - Behavioral Analytics explains when scores are hidden during learning instead of presenting an unexplained empty view.
See Runtime Detection, Runtime Blocks, Application Restrictions, and Anomaly Exceptions.
API Security
- Interactive relationships - Select callers, destinations, and their observed relationships to investigate traffic in fleet-wide and Kubernetes-scoped views.
- Request and response browsing - Captured observations load in pages, with syntax-highlighted content and clearer capture details.
- Finding evidence - Risk explanations and matched-request links make it easier to find the observation behind an indicator.
- Focused evidence panels - Summary combines relationship and runtime context; Observations holds supporting capture details.
- Broader API visibility - Improved plaintext HTTP capture on nonstandard ports, HTTP/2 and gRPC evidence, and caller-address attribution.
- Extended Capture - Expand the capture controls when needed and keep collection scoped to the selected sensor.
See API Security.
Telecom visibility
- Operational workspaces - Network, Sessions, Threats, and Assurance organize telecom topology, protocols, findings, service levels, and packet capture.
- Protocol coverage - Expanded evidence includes LTE signaling, GTP control and charging, SS7, SGsAP, LCS-AP, NRPPa, E2 service models, eCPRI, RTP/SRTP metadata, H.248, and MGCP.
- Protocol inspection - Find recorded telecom observations through protocol filters in Investigate and Live Feed, and inspect supporting evidence in the relevant telecom view.
- Topology after restarts - Verified existing workload connections are shown separately from decoded protocol relationships. A connection alone does not imply a decoded SBI call.
- HTTP/2 continuity - Improved decoding across idle periods and TLS session changes, with clearer treatment of incomplete headers.
- Session and RAN evidence - Improved NGAP, UE, PFCP, and GTP-U presentation, including observation times and retained-session context.
- SBI investigations - Clearer caller, destination, operation, and response evidence in service relationships.
- Graph usability - Improved topology layouts and inspection on smaller screens.
See Telecom Overview, Supported Protocols, and TLS Visibility. Protocol support does not imply that encrypted content is available on every traffic path.
Fleet and Kubernetes
- Fleet upgrades workspace - Separate Bare metal and Kubernetes views show the staged version, readiness, rollout progress, and recent upgrade history.
- Managed Kubernetes updates - Set up a cluster-local controller for Console-requested releases, or use the Helm, Flux, and Argo CD workflows.
- Clearer update results - Improved recovery and version reporting for VM, bare-metal, and Kubernetes upgrades.
- Large-fleet selection - Search and page through sensors while retaining selections, then review the target count before confirming.
- Kubernetes inventory - More consistent workload, pod, node, image, connectivity, and security results, with partial collection distinguished from confirmed empty results.
- Deployment-aware details - Kubernetes-only evidence is hidden on non-Kubernetes hosts. Temperature metrics appear only when the host provides them.
- Sensor efficiency - Reduced repeated work during startup and high-volume HTTP/TLS observation.
See Fleet Management, Upgrading Sensors, and Kubernetes Security.
Integrations and reporting
- Microsoft Sentinel - Added Logs Ingestion configuration alongside Legacy Data Collector.
- Notification delivery - Improved provider-specific delivery, transient-failure retries, and delivery-log feedback for notifications and SIEM alerts.
- Data Lake - S3-compatible and Azure Blob destinations archive received sensor payloads, including inventories and captured API evidence. Delivery status identifies pending work and the last uploaded object.
- Compliance evidence - Clearer evidence-check labels distinguish assessed results from missing evidence. Reports do not present absent telemetry as proof of compliance.
- Audit Log - Expanded categories, search, actor attribution, and filtered CSV exports make administrative changes easier to review.
- API integrations - Improved API-key permissions, request validation, pagination, and revocation handling.
- Analytics - Clearer query controls, result paging, and exports that identify the loaded result scope.
See SIEM Integration, Notifications, Data Lake, Compliance, Audit Log, and API Keys.
Appearance and documentation
- Appearance settings - Choose from the expanded theme catalog, three font options, text sizes, left or right sidebar placement, and preferred detail-panel widths.
- Consistent controls - Improved theme handling for dropdowns, right-sidebar resizing, and expandable evidence panels.
- User guides - Added Appearance, Analytics, and Data Lake guides, and updated navigation and instructions across the Console documentation.
See Appearance and Analytics.
Console 1.0.19 / Sensor 1.0.45 - August 2026
Security workspaces
- API Security workspace - API visibility is now organized into Overview, Inventory, Threats, and Controls across fleet, Kubernetes, container, host, process, and external scopes. The evidence panel connects requests, responses, findings, runtime identity, relationships, Call Trace, and Visibility Health.
- AI and MCP lens - Operators can focus API investigation on AI gateways, model APIs, MCP clients, and MCP servers without creating a separate inventory.
- DNS Activity - Network View now provides process-attributed DNS requests, resolver responses, record answers, coverage state, and inferred subsequent connections with server-side search and pagination.
- Execution-aware Process Tree - Interpreted scripts and modules are searchable independently from their interpreter, recent executions are separated from live processes, and actions require a verifiable live process identity.
Telecom
- Bounded Telco Capture - Operators can run per-sensor Diagnostic, Control-plane, or Deep captures and download finalized PCAPNG evidence with protocol and observed TLS plaintext records.
- Evidence reliability - Telecom views distinguish Observed, Not observed, Unsupported, Lost, Stale, and Unavailable states and preserve the selected network and sensor provenance in evidence pivots.
- Topology and session continuity - 5G topology, NGAP UE context, PFCP sessions, GTP-U tunnels, and O-RAN peers retain bounded recent evidence across normal reporting cycles.
Operations and integrations
- Managed sensor upgrades - VM and bare-metal upgrade plans are restart-safe and show creation time, eligibility, progress, and terminal state. Kubernetes remains Helm-managed with legacy value migration guidance.
- Authentication - OIDC configuration and sign-in handling were validated for Okta, Microsoft Entra ID, Google Workspace, and generic providers, including local MFA, linked accounts, SSO-only recovery, and remembered local sessions.
- Alerting and SIEM - Slack, Discord, Teams, PagerDuty, OpsGenie, TheHive, generic webhooks, Splunk, Sentinel, Elasticsearch, QRadar, Observe, Huntress, Sumo Logic, and Syslog use destination-specific credentials and payload contracts.
- Runtime Blocks - Policy validation, sensor scope, exceptions, delivery outcomes, impact evidence, and blocked-versus-terminated analytics are reported explicitly.
- Live Feed and Investigate - High-volume live rendering, historical pagination, exact cross-sensor event identity, session timelines, ancestry, and AI-generated pivots remain bounded and preserve the selected scope.
Platform
- Telovix eBPF engine 1.7.1 - Sensor packages include engine 1.7.1 with policy compatibility updates and runtime reliability fixes.
1.2.0 - June 2026
Console ingestion and performance
Split-plane ingestion endpoints - The Console now processes sensor event batches and inventory reports on separate dedicated paths, improving throughput and reducing heartbeat payload size. Both use the same mTLS authentication as the heartbeat.
zstd compression on ClickHouse event inserts - The Console now compresses event batches with zstd (level 1) before writing to ClickHouse when Redpanda is not active. ClickHouse decompresses natively on the HTTP layer. Typical telecom sensor batches of 200 events compress from ~150 KB to ~8 KB, reducing Console-to-ClickHouse traffic by approximately 18x.
Inventory delta suppression - The Console now tracks a per-sensor hash of each inventory type (active connections, process list, listening services, container images, Kubernetes policies/services/workloads/ingresses, UDP listeners). An incoming inventory payload is only written to PostgreSQL when its hash differs from the previously stored value. Unchanged inventory across heartbeat cycles no longer produces redundant DB writes.
1.1.0 - May 2026
New features
Sensor IPv4/IPv6 addresses - The sensor now collects and reports the host's active IPv4 and IPv6 interface addresses. Addresses are displayed on the sensor detail page in Sensors and are available in the sensor summary API response.
Real-time process viewer (Telovix Top) - The Runtime Inspector now includes a live process viewer showing CPU percentage, memory usage, and user for all active processes on the sensor host. Updates on every heartbeat cycle.
User Tracking dashboard - A new dashboard widget shows active user sessions, shell activity, and privilege change events aggregated across the fleet. Useful for quickly identifying interactive access during incident response.
Fingerprint-to-policy promotion workflow - The behavioral fingerprint view now includes a guided workflow to promote an approved baseline directly into a Guardian Profile policy. Reduces the manual steps from observing a binary to protecting it.
Improvements
Kubernetes view rebuilt - The Kubernetes section has been rewritten with a new tab layout: Pods, Workloads, Services, Images, Network Policies, and Admission Decisions. All six tabs support CSV and JSON export. The Workloads tab shows rollout status for Deployments, StatefulSets, and DaemonSets.
Kubernetes cross-resource navigation - A global namespace selector now scopes all Kubernetes tabs simultaneously. The Service tab resolves Pod topology via label selector matching. Investigation links are preserved in the URL for sharing.
Dashboard Kubernetes widget - The K8s widget on the main dashboard now shows real cluster data: running pod count, unhealthy pod count, and a mini workload health breakdown sourced from sensor heartbeats.
Kubernetes YAML export - YAML export is now available for all Kubernetes resource types: Pod, Service, Deployment, StatefulSet, and DaemonSet. The export panel is accessible from any resource row in the Kubernetes view.
Runtime Inspector expanded - The Runtime Inspector now includes System, Listening, and Container tabs alongside the existing Process and Network tabs. The Red Flags tab surfaces unusual process activity without requiring a custom rule.
Simple/Advanced search - The event search bar now switches between Simple mode (keyword search across message and executable) and Advanced mode (structured field filters). Both modes support saved searches.
Loading and empty states - Skeleton rows, progress bars, and empty state messages have been added across all major Console views. Pages no longer show blank content while data loads.
Auto-refresh interval - The Kubernetes view now includes a configurable auto-refresh interval selector. Options range from 10 seconds to 5 minutes.
Kubernetes pod identity in events - Runtime events from Kubernetes pods now include pod name, namespace, workload type, and workload name. These fields are shown in event detail views and are filterable in the Events search.
Kubernetes cluster metadata header - The Kubernetes view now shows a cluster metadata header with cluster name, node count, and namespace count sourced from the latest sensor heartbeats.
Helm upgrade guidance - The sensor detail page for Kubernetes-deployed sensors now shows the exact
helm upgradecommand needed to update that sensor, pre-filled with the current values.
Bug fixes
- Fixed: missing event kinds in the heartbeat event kind whitelist caused some event types to be silently dropped before delivery to the Console.
- Fixed: sensor health state flickered between
watchandhealthywhen heartbeats arrived at the boundary of the stale threshold. The degraded window now uses a helper that smooths the transition. - Fixed: Pod YAML export fell back to incorrect data when
container_imageswas empty; it now correctly falls back to sensor event history. - Fixed: Kubernetes topology viewport position was lost during background data refreshes. Position is now preserved.
- Fixed: loading states were missing on several Kubernetes tabs, causing blank content to show briefly on page load.
- Fixed: YAML export for workloads fell back to sensor events correctly but showed stale data on refresh. Now invalidates and reloads on tab activation.
- Fixed: ApexCharts
Element not founderror when navigating directly to a tab URL that includes chart components. - Fixed:
nc -zv localhostcommands in shell sessions were incorrectly scored as suspicious. Port health checks using netcat are now recognized as a known-good pattern and scored accordingly. - Fixed: SSH root shell sessions with no commands executed were scored at full severity. Empty shell sessions now receive a 0.25 discount factor.
- Fixed: Duplicate shell sessions from the same PID were shown in the Sessions view after sensor restart.
- Fixed: Sensors enrolled from multiple Kubernetes clusters could create duplicate records when the cluster name was null. Deduplication now uses
node_nameandcluster_nametogether. - Fixed: Session expired message was shown on the wrong login page in multi-tenant Portal setups.
- Fixed: Global 401 redirect now triggers the session-expired banner correctly across all Console views.
- Fixed: VField component rendering errors with VTextarea and VInput in certain layouts.
- Fixed: Teleport and Transition component crash when alert inbox mounted with null vnode.
1.0.0 - April 2026
Initial general availability release of Telovix Console and Sensor.
Console
- Fleet management with per-sensor health state, trust health, enforcement state, and policy pack assignment
- Alert Inbox with rule-based detection, severity classification, MITRE ATT&CK mapping, and AI-assisted triage
- Behavioral Analytics with per-binary process baselines, anomaly scoring, and suppression rules
- Attack Chain detection with seven built-in multi-stage patterns and 30-minute correlation windows
- Investigations for multi-alert case management with timeline, notes, and evidence linking
- Compliance reports for CIS Controls v8, NIS2 Directive, 3GPP TS 33.117, O-RAN WG11, and NIS2 Telecom
- Kubernetes Security view with pod inventory, security posture findings, admission webhook, and network policy visualization
- SBOM scanning via bundled scanner with CycloneDX export and private registry credential management
- Runtime Inspector for live process, network, and container snapshots from sensor heartbeats
- Process Tree and Investigate view with fleet correlation, behavioral fingerprints, and shell session history
- AI Assistant with 44 structured tools covering fleet, events, anomalies, compliance, Kubernetes, and telecom data
- SIEM forwarding to Splunk, Microsoft Sentinel, Elasticsearch, QRadar, Observe, Huntress, Sumo Logic, and Syslog
- Webhook notifications with Slack, Discord, Microsoft Teams, PagerDuty, OpsGenie, and TheHive formatting
- SSO via OpenID Connect (OIDC) with support for Microsoft Entra ID, Okta, and Google Workspace
- Role-based access control with five roles: admin, operator, sensor_owner, analyst, and viewer
- API keys with HMAC-SHA256 signed requests and per-key scope control
- Audit log with 51 action types, family-based filtering, CSV/JSON export, and compliance control coverage
- Red team exercises for O-RAN WG11 threat validation with 10 exercise types and detection latency measurement
- Sensor upgrade plans with rolling, canary, and immediate strategies
- Enrollment token management with one-time, cluster, and re-enrollment token types
- Federation support with standalone, regional, and central Console roles
- License validation offline using Ed25519 signature verification
Sensor
- eBPF event collection via embedded engine with no kernel module and no kernel patches required
- Supports Linux x86-64 and ARM64, kernel 5.4 or later, BTF required
- Standard flavor: process execution, network connections, file integrity monitoring, privilege changes, DNS, BPF tamper detection, kernel module monitoring
- Telecom flavor: all standard capabilities plus NGAP, PFCP, GTP-U, F1AP, E1AP, XnAP, E2AP, SCTP, Diameter, RADIUS, SIP, SBI/HTTP2, NAS5G, and M3UA protocol parsing
- Telecom flavor: 24 NF role types detected automatically from port binding, process name, binary path, and gRPC service signals
- Telecom flavor: per-NF SLO monitoring with breach detection, MTTR tracking, and suppression
- Telecom flavor: O-RAN WG11 checks for E2 peer verification, O1 management interface, O2 infrastructure, xApp/rApp security, CU/DU boundary, timing integrity, and management plane access
- Telecom flavor: TLS uprobe coverage for OpenSSL, GnuTLS, Go TLS, and BoringSSL with SBI compliance enforcement
- Telecom flavor: GTP-U visibility gap detection for AF_XDP, VFIO, and DPDK kernel bypass
- Policy pack delivery with Ed25519 signature verification per policy file
- Guardian Profiles with observe, audit, and enforce modes
- Custom detection rules via TracingPolicy YAML with kprobe, LSM hook, and uprobe support
- Enforcement rules with Signal (SIGKILL) and Override (kernel deny) action types
- Behavioral baselines from 14 days of event history with per-binary anomaly scoring
- On-disk event spool with 100,000-event buffer and automatic drain on reconnect
- mTLS enrollment with per-sensor client certificates, 30-day TTL, automatic proactive renewal
- Kubernetes DaemonSet deployment via Helm chart with init container, BPF map pin cleanup, and token rotation support
- Sensor upgrade managed from the Console with version staging, rollout plans, and canary wave support
Policy packs
o-du-baseline-observe- O-RAN Distributed Unit baseline observationo-du-fronthaul-observe- O-DU fronthaul interface activity monitoringo-du-process-guard- O-DU execution path guard (enforcement-capable)o-cu-baseline-observe- O-RAN Central Unit baseline observationo-cu-core-signaling-observe- NGAP, F1-AP, and E1-AP signaling handler monitoringo-cu-ims-session-observe- IMS session activity on O-CU nodeso-cu-signaling-observe- O-CU signaling interface coverageo-cloud-baseline-observe- O-Cloud host baseline coverageo-cloud-core-observe- GTP user-plane, PFCP, and 5G Core control-plane monitoringo-cloud-integrity-guard- O-Cloud mutable path execution guard (enforcement-capable)o-cloud-interconnect-observe- O-Cloud interconnect and transport coverageo-cloud-runtime-drift-observe- Runtime drift detection: unexpected launches, novel connections, integrity indicatorsgeneric-linux-observe- General-purpose Linux baseline (development tier)
Upgrade notes
1.0.0 to 1.1.0
The Console and Sensor binaries are independently upgradeable. Sensors running 1.0.x continue to function with a 1.1.x Console; the new IPv4/IPv6 fields are populated automatically once sensors upgrade.
Telovix self-hosted: Update the Console binary using Settings > Updates or by replacing the binary and restarting the service. Stage new sensor binaries under sensor-binaries/ before creating an upgrade plan. See Upgrading Sensors for the full procedure.
Telovix Cloud: The Console is updated automatically. Sensor upgrades are coordinated by your Telovix Cloud administrator or triggered through the Console upgrade plans workflow.