Octowatch Update: 09/15/2025

Good day! Today we have released an update.

What’s new:

  1. Integration with AI: Automatic categorization of user activities (websites, applications) using AI. Automatic recognition of suspicious user actions using AI (keystrokes, clipboard, search queries).
  2. Speech recognition in audio recordings using Whisper (a free open-source engine). Available only in the local version.
  3. Interception of POST/GET HTTP requests (web forms in x-www-form-urlencoded and multipart/form-data formats).
  4. Collection of information about Wi-Fi connections and Ethernet connections.
  5. Collection of information on traffic usage.
  6. Changes in screenshot collection and display, as well as a quick view window.
  7. Collection of information about the PC’s serial number, saving additional information about the computer along with images, as well as many changes related to software localization.
  8. Optimization of Grabber’s operational algorithms.
  9. Improvements in traffic filtering:
    • OpenSSL has been updated to version 3.5.1.
    • Accelerated automatic addition of SSL exceptions when the client process reports issues with the generated certificate.
    • Fixed problems with the re-initialization of OpenSSL.
    • Fixed IPv6 address conversion to string representation.
    • Added ARM64 configurations for components and dependencies.
    • Libraries updated: Brotli → 1.1.0, Zstd → 1.5.7, Zlib → 1.3.1.
    • Fixed errors in the proxy filter, including parsing HTTPS proxy responses and handling large HTTPS proxied requests.
    • Multiple issues and vulnerabilities in HTTP and HTTP/2 filters have been addressed:
    • Fixed handling of large header fields and splitting large headers;
    • Fixed window size accounting (flow control);
    • Optimized usage of the “end of stream” flag and eliminated memory leaks;
    • Fixed issues with header part flags and reordering of stream identifiers;
    • Fixed handling of content-length in various scenarios (including cases with injected content and cases without content-length or chunked);
    • Added support for early hints headers (HTTP/2 Early Hints, code 103);
    • Added support for HTTP/2 (FT_HTTP2) and updated usage examples.
    • Added support for zstd compression algorithm for HTTP content; improved filtering of HTTP responses combined with WebSocket data.
    • Fixed issues with WebSocket protocol; read-only mode packets are correctly indicated for subsequent filters.
    • Fixed filtering of SOCKS4/SOCKS responses and behavior in the proxy filter.
    • Fixed handling of streams with temporary files and other data stream issues.
    • Fixed errors in uncompression procedures.
    • Fixed issues with incorrect public keys used by some web servers; corrected storage of SSL certificates.
    • SSL filter behavior and compatibility:
    • The SSL filter uses a list of curves from the original TLS handshake for compatibility;
    • The SSL filter skips filtering for TLS_ANY_VERSION to avoid blocking data transmission.
    • Domain certificates are removed and regenerated upon each initialization of filters (by default).
    • Legacy Unsafe Renegotiation mode for TLS is enabled by default.
    • Fixed TLS version selection for local traffic between clients and proxy.
    • Fixed compatibility with certain FTP clients at the TLS filtering level.
    • Optimized the procedure for importing root certificates into stores (including Mozilla);
    • Numerous minor fixes and security enhancements have been made.

⚠ Update procedure: ⚠

Local version:

  • Update the Server (over the existing one) by downloading the updated distribution from the personal account: https://octowatchdlp.com/account/
  • Update the Viewer by obtaining the updated distribution from the OctoWatch Admin Console.
  • Wait for automatic updates of the Grabbers (within 1-2 days from the Server update in step 1).
  • Update the Recognition Server.

Cloud version:

  • Update the Viewer by downloading its distribution from the personal account: https://octowatchdlp.com/account/
  • Wait for automatic updates of the Grabbers (within 1-2 days from the publication of this message).

Enabling new options and settings:

Local version: Specify AI connection settings (ChatGPT via proxy/DeepSeek) in the AI Integration tab in the Admin Console.

All versions: Enable AI integration options in the Notifications Sending tab in the Account Settings window.

All versions: Enable options: Network interfaces, Wi-Fi networks, Web forms (check for keywords in the Parameters window) in the User/Group Settings Profile.

All versions: Enable Traffic Accounting option in the Computer Settings Profile.

Ready to monitor Windows endpoints?

Start Free TrialContact

Leave a Reply

Your email address will not be published. Required fields are marked *