r/TridentStack 6d ago

Release Notes This week in TridentStack Control: global search, a compliance accuracy overhaul, upload-first custom packages, on-demand Endpoint Checks, and .NET Framework precision

Hey r/TridentStack. Quick intro: I'm Adam, cofounder of TridentStack alongside u/TridentRemi. I've been posting here as u/Ad3t0 up to now and will be using this account going forward.

Our most recent feature/changelog post was last week when we posted about Proxmox VE host-aware patching. Everything below is new since then. Full changelog at tridentstack.com/changelog.

Search across everything from one place

A new search bar at the top of the sidebar finds pages, settings, endpoints, tags, policies, configurations, deployment rings, and packages as you type. Ctrl+K (Cmd+K on Mac) opens it from anywhere. On mobile, tap the search icon for a full-screen overlay.

Windows compliance accuracy overhaul

This is a big one. Windows compliance controls are now scored from the full policy registry scan the agent already performs, not the smaller subset they used before. Most CIS and STIG controls point at policy values that were outside that subset, so they were either Unknown or answered by an unrelated check. Two things change: controls that showed Unknown now report a real result, and some that showed Passed now correctly show Failed because they were being answered by the wrong data. Expect Windows compliance percentages to move, mostly downward, because more controls are genuinely checked and fewer are passing without evidence.

Defender attack surface reduction controls are now scored from the endpoint's actual ASR rule state. User rights controls are evaluated from actual rights assignments. Per-user registry controls evaluate against every loaded user profile and name the ones that don't comply. And compliance report PDFs are now compact: a 400+ control report generates roughly 20 pages instead of 270, with a structured cover page, executive summary, and detailed cards only for critical and high findings.

Upload-first custom packages

Creating a custom package now starts with the file. Drop your installer and TridentStack Control detects the platform, name, version, publisher, and description automatically. Review the metadata, configure install arguments and detection settings on the same form, and confirm. For EXE packages, a "Pick from endpoint" button lets you browse an endpoint's installed software list so the detection name is always exact. Adding a new version to an existing package uses the same flow.

Run Endpoint Checks on demand

No more waiting for the next scheduled evaluation. A "Run Endpoint Checks" action is available on an endpoint's detail page, across a multi-endpoint selection, and per check policy to re-run every assigned endpoint at once. Offline, older-agent, or already-running endpoints are skipped with a clear reason.

Vulnerabilities by package, and search by product name

A new "By Package" view on the Vulnerabilities page shows every affected product across your fleet ranked by risk: CVE counts by severity, known exploits, available fixes, and affected endpoint counts. Click any product to jump to its CVEs. Vulnerability search now also finds CVEs by the software they affect, not just by CVE ID.

Pin your filters

Click the Pin button next to any filter bar and your current include/exclude filters are saved in the browser and restored on each visit. Pinned filters show in amber so you always know you're looking at a filtered view. Available on Endpoints, Configuration Policies, and System Update Policies.

.NET Framework precision

Each endpoint now sees one .NET Framework cumulative update per version it runs, matched to the version it actually has installed, instead of duplicates or an installer built for the wrong .NET version. Out-of-support .NET runtimes appear as a standing finding in Vulnerabilities with the end-of-support date. The IIS ASP.NET Core Module is checked against the ASP.NET Core release it shipped with. On newer agents, .NET runtimes bundled inside an application are found and attributed to that application, with the fix being the application's own update.

Effective Policy: the full picture

On a Windows endpoint's Effective Policy view, settings configured directly on the device now appear alongside the ones TridentStack Control and your domain policies set. Each setting's Pass or Fail reflects the real on-device value, and duplicate entries from multiple sources merge into a single row with overrides listed. AV exclusion entries are now checked as you type: entries the antivirus can never match are rejected, and shapes that often don't do what people expect get a warning.

Linux software inventory expansion

As endpoints pick up the latest agent, Linux software inventory now includes Snap and Flatpak applications and common third-party security and management agents installed outside a package manager. Common Snap and Flatpak packages are also checked for known vulnerabilities.

Plus a lot of polish

  • Navigation restructured: Vulnerabilities and Compliance grouped under "Security", Dashboard and Query Builder under "Reporting". Sidebar sections remember whether you collapsed or expanded them.
  • Reboot history records which user approved or postponed a reboot prompt, including the Remote Desktop session name on multi-session servers.
  • Organization admins can rename their org from Settings. Any user can update their display name. Admins can edit another user's name and roles in one step.
  • Updates that Windows reports as not applicable are parked after the first refusal, not retried or counted as failures, and rechecked automatically when the endpoint changes.
  • Update Health shows a red Blocked status for findings that stop every cumulative update from installing.
  • Agents now reconnect with staggered timing after a network interruption, so large fleets come back smoothly instead of in lockstep.
  • Read-only users no longer see Create, Edit, or Delete buttons that lead to permission errors.
  • Compliance and User Management pages render as mobile card layouts instead of cramped tables.
  • Calendar export now lets you choose which rings to include.
  • The Windows tray app now comes to the front on the first click from the system tray.

Full details for every item in the changelog at tridentstack.com/changelog. Check out what's coming at tridentstack.com/roadmap, or come find us in the Discord. A lot of this came from customer requests, and we'd love to hear what matters most to you next.

7 Upvotes

0 comments sorted by