Support Center > Search Results > SecureKnowledge Details
Enterprise Endpoint Security E80.92 Windows Clients Technical Level
Solution

Table of Contents:

  • In a Nutshell
  • What's New in E80.92
  • Endpoint Security Clients Downloads
  • Standalone Clients Downloads
  • Endpoint Security Server Downloads
  • Management Console Downloads
  • Utilities/Services Downloads
  • Resolved Issues
  • Known Limitations
  • Documentation and Related SecureKnowledge Articles
  • Revision History

 Endpoint Security Homepage is now available.

Important: This version is no longer supported and is expired as of 1-Jan-2021. Follow instructions in sk171213

Notes:

  • To support SmartLog or SmartView Tracker reporting with Endpoint Security Clients for all supported servers (except R80.20), you must update the log schema. Follow instructions in sk106662.
  • Starting in E80.85, anonymized incident related data is sent to Check Point ThreatCloud, by default. To learn more see sk129753.
  • Important: Download SmartConsole with the E80.92 client to avoid "signature verification failed" messages when uploading the client to the SmartConsole.
  • The relevant links to downloads are located in the relevant section, i.e., Endpoint Security Server, Management Console, Endpoint Security Clients, Standalone Clients, Utilities/Services.
  • The relevant links to documentation are located in the "Documentation" section.
  • It is strongly recommended that you read the E80.92 Endpoint Security Client Release Notes, before installing this release.
  • This release includes all limitations of earlier releases unless explicitly shown as resolved.
  • For E80.89 releases for Mac: Refer to sk131152 - Enterprise Endpoint Security E80.89 Mac Clients.
Click Here to Show the Entire Article

In a Nutshell

Item Description Link
Managed Client E80.92 Endpoint Security Clients for Windows OS
VPN Standalone Client

E80.92 Remote Access Clients for Windows

Capsule Docs E80.92 Capsule Docs Standalone Client
Documentation E80.92 Endpoint Security Client for Windows Release Notes  

What's New in E80.92

Show / Hide this section
This release includes stability and quality fixes. It supports all features of previous releases.

New Features

  • New consolidated Reputation View in Forensics.
    This view now contains reputation, where available from Threat Cloud for all non-trusted URLs, Domains and Hashes found in the Forensics Analysis.
  • Improved and faster remediation flow in Forensics.
    We have improvements in the performance of remediation when done through a Forensics Report. This includes fixes that report the remediation status at the time of report generation more accurately.
  • Support for multiple logged-in users in Anti-Ransomware.
    We are now able to generate and monitor our honeypot detections if multiple users are logged in simultaneously.
  • Further enhancements to PowerShell obfuscation detection in Behavioral Guard.
    This results in improved detection capabilities.
  • Boot time improvements in Forensics.
    Forensic data storage now occurs well after boot. This improves the time for boot, especially on older drives and on drives with a great deal of file activity during boot.

Enhancements

  • Anti-Ransomware, Behavioral Guard and Forensics
    • Fixes an issue in Anti-Ransomware honeypot creations during a login for a new user.
    • Fixes an issue where honeypot files were not created for all users in a multi-user system.
    • Fixes an issue on Windows Server editions, where some honeypots were not created when multiple users logged in simultaneously.
    • Improves PowerShell obfuscation detection support in Behavioral Guard.
    • A new consolidated Reputation view is available in the Forensics Report that combines intelligence for all non-trusted URLs, Domains and Files in the report.
    • Improves boot performance by introducing a delay in Forensics data storage during the boot cycle.
    • Hashes for files calculated by Threat Emulation are available for visualization and reputation in the Forensics Report.
    • Extends the Forensics API with hash information so that Threat Emulation and other products always get Reputation, if available in the Forensics Report.
    • Forensics Report Tree views have a new section in Network Operations for processes that are listening on a port for a connection.
    • Processes with invalid signatures now show as suspicious events with invalid signer names available in the Forensics Report. Behavioral Guard also supports rules for invalid signatures.
    • Fixes an issue where the reputation for files that are not processes are updated correctly in the Forensics Report.
    • Fixes a very rare infinite loop that may occur, when the data in the Forensics database is corrupted.
    • Fixes the Virus Total (VT) First Seen date to be the same format as other dates in the Forensics Report.
    • Suspicious Events of a process in the Tree and Tree Time-line views of the Forensics Report now show in the order of severity.
    • Fixes a missing icon for unsigned processes in the Overview and General views of the Forensics Report.
    • Fixes an issue to make triggers on files, with IPs in their path, appear correctly in the Overview view of the Forensics Report.
    • Fixes a visualization issue, where the reputation file size appeared as zero for files with no reputation in the Forensics Report.       
  • Threat Emulation and Anti-Exploit
    • Fixes an issue in Anti-Exploit, where the protection name was not consistently displayed in the client UI and Forensics Reports.
    • Fixes an issue in Anti-Exploit with a specific build version of Internet Explorer not having VBScript God Mode protection enabled correctly.
    • Fixes a slow performance problem in Threat Emulation, when accessing files on a non-local disk.
    • Resolves an issue, where Internet Explorer can freeze when navigating to trusted sites.  
  • Full Disk Encryption 
    • Resolves an issue, where connections through Remote Desktop Protocol (RDP) to a machine with Full Disk Encryption can fail intermittently.
    • Resolves an issue, where Full Disk Encryption, enabled for UEFI BCDBOOT, sometimes experiences a boot loop. 
  • Media Encryption & Port Protection
    • Fixes an issue where Explorer flickers every second, when inserting an encrypted media.
    • Resolves an issue where the "copy" file operation is not logged in some conditions.

    Endpoint Security Clients Downloads

    Show / Hide this section
    Important:
      • Starting from E80.85, SandBlast Agent improves coverage of malicious threats by sending anonymized Incident related data to the Check Point Threat Cloud. This feature is turned on by default. For more information, including how to disable this feature, refer to sk129753.

    • To support SmartLog or SmartView Tracker reporting with Endpoint Security Clients for all supported servers (except R80.20), you must update the log schema. Follow instructions in sk106662.

    Endpoint Security E80.92 Clients

    Platform Package Description Link
    Windows E80.92 Endpoint Security Clients for Windows OS (Recommended) A zip file that contains all package permutations listed below.
    E80.92 Complete Endpoint Security Client for 32 bit systems
    A package for 32bit devices that includes Endpoint Complete package:
    • Desktop FW and Application Control
    • Anti-Malware
    • Forensics and Anti-Ransomware
    • URL Filtering
    • Anti-Bot
    • Threat Emulation
    • Media Encryption and Port Protection
    • Full Disk Encryption
    • Compliance
    • Remote Access VPN
    • Capsule Docs 
    E80.92 Complete Endpoint Security Client for 64 bit systems
    A package for 64bit devices that includes Endpoint Complete package:
    • Desktop FW and Application Control
    • Anti-Malware
    • Forensics and Anti-Ransomware
    • URL Filtering
    • Anti-Bot
    • Threat Emulation
    • Media Encryption and Port Protection
    • Full Disk Encryption
    • Compliance
    • Remote Access VPN
    • Capsule Docs 
    E80.92 Complete Endpoint Security Client without Anti-Malware for 32 bit systems
    A package for 32bit devices that includes Endpoint Complete package with the exception of Anti-Malware:
    • Desktop FW and Application Control
    • Forensics and Anti-Ransomware
    • URL Filtering
    • Anti-Bot
    • Threat Emulation
    • Media Encryption and Port Protection
    • Full Disk Encryption
    • Compliance
    • Remote Access VPN
    • Capsule Docs 
    E80.92 Complete Endpoint Security Client without Anti-Malware for 64 bit systems
    A package for 64bit devices that includes Endpoint Complete package with the exception of Anti-Malware:
    • Desktop FW and Application Control
    • Forensics and Anti-Ransomware
    • URL Filtering
    • Anti-Bot
    • Threat Emulation
    • Media Encryption and Port Protection
    • Full Disk Encryption
    • Compliance
    • Remote Access VPN
    • Capsule Docs 
    E80.92 SandBlast Agent Client for 32 bit systems
    SandBlast Agent package for 32bit devices:
    • Forensics and Anti-Ransomware
    • Anti-Bot
    • Threat Emulation
    E80.92 SandBlast Agent Client for 64 bit systems
    SandBlast Agent package for 64bit devices:
    • Forensics and Anti-Ransomware
    • Anti-Bot
    • Threat Emulation
    E80.92 Full Disk Encryption and Media Encryption and Port Protection client for 32 bit systems Full Disk Encryption and Media Encryption and Port Protection package for 32 bit systems
    E80.92 Full Disk Encryption and Media Encryption and Port Protection client for 64 bit systems Full Disk Encryption and Media Encryption and Port Protection package for 64 bit systems 
    E80.92 Initial client Initial client is a very thin client without any blade used for software deployment purposes.

    Standalone Clients Downloads

    Show / Hide this section
    Note: These Standalone clients do not require Endpoint Security Server installation as part of their deployment.

    E80.92 Standalone Clients

    Platform Package Description Link
    Windows E80.92 Remote Access Clients for Windows Remote Access VPN Client for SmartConsole-managed clients
    E80.92 Remote Access VPN Clients - Automatic Upgrade file Remote Access VPN Client for automatic upgrade through the gateway. For SmartConsole-managed clients only.
    E80.92 Remote Access VPN Clients for ATM Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface.
    E80.92 Remote Access VPN Clients for ATM - Automatic Upgrade file Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface for automatic upgrade through the gateway. For SmartConsole-managed clients only.
    E80.92 Capsule Docs Standalone Client Capsule Docs package for environments that are managed by Capsule Docs Cloud Service.  
    Capsule Docs PC Viewer Check Point Capsule Docs Viewer is a stand-alone client that lets you view documents that were protected through Capsule Docs. Get from: Capsule Docs Portal

    Endpoint Security Server Downloads

    Show / Hide this section

    Note: In order to download some of the packages you will need to have a Software Subscription or Active Support plan.

    The packages provided below are Legacy CLI packages (not CPUSE packages).
     

    R77.30.03

    Clean installation and In-Place Upgrade

    • Before installing the hotfixes, you need R77.30 to be installed and to update CPUSE (sk92449) to the latest build.
    • You must install the R77.30 Jumbo Hotfix for Endpoint Security Server before you install the Endpoint Security Server Package for Gaia OS.
    Order of Installation Package Link
    1 R77.30 Jumbo Hotfix for Endpoint Security Server (TGZ)
    2 R77.30.03 Endpoint Security Server Package for Gaia OS (TGZ)

    R80.20

     

    Endpoint Security Server Package Link
    R80.20 Endpoint Security Server R80.20  (ISO)

    Management Console Downloads

    Show / Hide this section

    Management Console for Endpoint Security Server

    The SmartConsole for Endpoint Security Server allows the Administrator to connect to the Endpoint Security Server and to manage the new Endpoint Security Software Blades.

    Latest Versions

    Endpoint Security Server Package Link
    R77.30.03 SmartConsole for Endpoint Security Server R77.30.03 / E80.92 (EXE)
    R80.20 SmartConsole for Endpoint Security Server R80.20 sk137593

    Previous Versions

    Endpoint Security Server Package Link
    R77.30 SmartConsole for Endpoint Security Server R77.30 / E80.90 / E80.92  (EXE)
    R80.10 SmartConsole for Endpoint Security Server R80.10 / E80.90 / E80.92 (EXE)
    R77.30 EP6.5 SmartConsole for Endpoint Security Server R77.30 EP6.5 / E80.92 (EXE)
    R77.20 EP6.2 SmartConsole for Endpoint Security Server R77.20 EP6.2 / E80.92 (EXE)

    Utilities/Services Downloads

    Show / Hide this section
    Utilities

    Platform Package Description Link
    Windows SandBlast Agent Remediation Manager for Administrators

    The administrator utility contains the capabilities of the end-user utility plus these additional features:

    • Quarantine - Send files to quarantine. 
    • Delete - Use the SandBlast Agent remediation service to delete a file. 
    • Import - Import a quarantined file from a different computer or location. Get the administrator utility from the release homepage
    Capsule Docs Bulk Protection Services for Windows-based Servers and Workstations Capsule Docs Bulk Protection lets you manage file protection settings based on file locations and properties. 
    R77.30 DLP Gateway HF for Content-aware Capsule Docs protection (Mail attachments / Network locations)  

    For more information about Capsule Docs Bulk Protection, refer to Capsule Docs Bulk Protection Services Reference Guide.

    Full Disk Encryption Offline Management Tool

    Platform Package Description Link
    Windows Full Disk Encryption Offline Management Tool The Endpoint Offline Management Tool lets administrators manage offline mode users and give them password recovery and disk recovery.
    Windows Full Disk Encryption Offline Management Tool (Japanese) The Endpoint Offline Management Tool lets administrators manage offline mode users and give them password recovery and disk recovery.

    Resolved Issues

    Show / Hide this section
    Issue ID Description
    CDOC-559

    Capsule Docs does not support Acrobat Reader DC v2019.

    AHTP-10267 Windows stuck at loading screen after installing Windows updates with Endpoint Security Client installed.
    Refer to sk143573

    Known Limitations

    Show / Hide this section
    Issue ID Description
    CDOC-734

    "Ask" function on Screen Capture permission does not apply when using a Snipping Tool.

    EPS-20568 Anti-Malware signatures database sometimes fails to update. Fixed in E80.95.
    Show / Hide this section      
    Document
    Endpoint Security Server
    R77.30.03 Management Endpoint Security Release Notes 
    R77.30.03 Endpoint Security Management Administration Guide
    R80.20 Release Notes
    Endpoint Security Clients
    E80.85 and higher Endpoint Security Client for Windows User Guide
    E80.92 Endpoint Security Client for Windows Release Notes
    Remote Access VPN Clients
    E80.92 Remote Access Clients for Windows Release Notes
    E80.72 and higher Remote Access Clients for Windows Administration Guide
    Capsule Docs Client
    E80.72 and higher Capsule Docs Plugin User Guide
    Check Point Capsule Docs Viewer User Guide: Get from: Capsule Docs Portal
    Capsule Docs Bulk Protection Services
    Capsule Docs Bulk Protection Guide

    Revision History

    Show / Hide this section
    Date Description
    15 July 2019  Link to Release map was replaced 
    14 May 2019 Added AHTP-10267 to Resolved Issues 
    14 Feb 2019 First release of this document
    This solution is about products that are no longer supported and it will not be updated

    Give us Feedback
    Please rate this document
    [1=Worst,5=Best]
    Comment