Skip to main content

Dashboard version 2.14.0

Released on November 13th

Updated over a month ago

Auto-EASM Activation

Managing protection settings for a large number of assets can be time-consuming, especially when new assets are created frequently. Auto-EASM helps simplify this workflow by automatically applying EASM protection to eligible assets as they are created.

🔩 How the setting works :

You can find this new setting in your Organization → Settings space, inside of Configurations appears a new Protection options menu.

When the setting is enabled, newly created assets are automatically assigned the protection level EASM instead of the default unprotected, provided that the organization still has available EASM credits.

This behavior applies to assets created by the members of your organization or discovered by Patrowl.

If the setting is disabled, asset protection remains fully manual.


ℹ️ Functional Rules

  • No credits available

    • If the organization has no remaining EASM credits, new assets stay unprotected.

    • If new EASM credits are added afterward, the system automatically upgrades the oldest unprotected assets to EASM.

    • During bulk imports or API batch creation, assets are assigned EASM until the credit limit is reached.

  • Protection lifecycle

    • Once an asset is set to EASM, protection cannot be disabled (standard EASM rule). When an asset is deleted, the consumed credit is freed.

    • Users may still upgrade protection to pentested.

📨 Notifications

To ensure visibility on credit usage when Auto-EASM is enabled:

  • An alert banner appears at 95% and 100% credit usage.

  • Email notifications are sent to organization admins at 95% and 100% credit consumption.


Feature Improvements

  • Assets : Bulk pentest desactivation is available again.

  • Asset groups - vulnerabilities : Bulk actions on vulnerabilities within an asset group are now supported.

  • CVE : The vendor name now appears in the product filter for clearer identification.

Design Improvements

  • Asset - IP : The IP type label has been refined from “Other” to “Other dynamic” for better consistency.

  • Tables : All empty-state messages have been reviewed and harmonized.

  • Date fields : The design of date inputs has been aligned for better visual consistency.

Bug Fixes

  • Asset - Risk insight : Removed an unnecessary asset filter from this tab.

  • Asset : The number of related domains and IPs displayed in the main information block has been corrected.

Technical Improvements

  • Upgraded Django to 4.2.26 (includes CVE-2025-64459, even though the application was not affected).

Did this answer your question?