- AI Wingman
- AI-powered Windows Updates prioritization
- Block Agentic AI
- Bulk Import and Export for End-User Allowlist & Blocklist
- Heimdal Dashboard - Visual and usability refinements
- MXDR P&A Automation Emails – Top Hostname Visibility
- Configurable Secondary Location expiration interval for Login Anomaly Detection
- DNS Security Network – Threat Type search for the Standard & Latest Threats view
- Access Control for Product Modules Overview visibility at login
- Persistent isolation notification for end users
- Heimdal Dashboard – Enhanced module usage visibility
-
ROI Report section relocated to Reports & Alerts
Heimdal Dashboard
● AI Wingman
AI Wingman brings AI-powered assistance across the Heimdal security platform, supporting Heimdal’s broader vision of delivering unified, intelligent and increasingly efficient cybersecurity operations.
Built around the same core purpose of providing comprehensive protection across the digital environment, AI Wingman uses AI to help users, including MSPs managing multiple customer environments, get more value from the information, security capabilities and operational context already available within the Heimdal Dashboard.
Designed as a cross-platform intelligence layer rather than an isolated module-level capability, AI Wingman connects with Heimdal’s unified security approach by progressively extending AI-powered guidance and analysis across the product suite.
The aim is not simply to introduce AI into existing workflows, but to use it where it can reduce manual effort, accelerate decision-making and allow security teams to focus their time and expertise where they matter most.
With the 5.7.0 release, this journey begins with AI Wingman Assist and AI Wingman Triage. Assist provides contextual platform guidance, recommends relevant actions and best-practice settings, and helps users navigate and use Heimdal capabilities more effectively.
Triage uses a Multi-Agent System (MAS), where specialized AI agents work together to analyze security detections, helping users assess suspicious activity, validate incidents and determine the appropriate next steps faster.
Together, these capabilities lay the foundation for the broader AI Wingman vision, which will continue to evolve towards deeper AI-assisted and automated security operations, including Heimdal’s MXDR service.
In practical terms, the initial AI Wingman capabilities combine platform assistance through Wingman Chat with AI-powered detection analysis through AI Wingman Triage.
Wingman Chat provides contextual guidance and recommendations to help users navigate the Heimdal platform and make more effective use of its capabilities.
For the Triage component, AI Wingman analyzes detections received during the last 30 days across XTP, Ransomware Encryption Protection (REP), Next-Gen Antivirus (NGAV) and Brute Force Attack (BFA), using multiple specialized AI agents to investigate and correlate the available information.
The results are consolidated into a human-readable assessment that includes severity, confidence and recommended remediation actions, helping reduce investigation time and provide a more consistent approach to triage across the supported Heimdal detection modules.
The AI Wingman experience introduced with this release is available through two dedicated areas in the Heimdal Dashboard: Wingman Chat and Wingman Analysis.
Wingman Chat
Wingman Chat provides an AI-powered conversational interface within the Heimdal Dashboard, serving as the primary interaction point for AI Wingman Assist.
Through a familiar chat-based experience, Heimdal Dashboard users can access module-specific security summaries and guidance, while also connecting with Triage capabilities by initiating full Wingman analyses and accessing previous analysis history.
Wingman Chat can be accessed using the dedicated AI Wingman icon located in the top-right area of the Heimdal Dashboard, next to Network Settings.
Users can request module-specific summaries for supported detections directly from the relevant product grid or from TAC -> Action Center by selecting the Wingman option available for the detection.
For Heimdal users operating at Corporate customer level, module-specific summaries are available for XTP, Ransomware Encryption Protection (REP), Next-Gen Antivirus (NGAV) and Brute Force Attack (BFA), depending on the enabled licensing options.
At reseller user level, Wingman Chat provides access to Analysis History when the TAC license is enabled.
Example of accessing AI Wingman from the REP Endpoint Detections grid
Example of accessing AI Wingman from the TAC Action Center, REP notifications
When a Corporate customer is impersonated, Wingman Chat provides access to the following options:
- View module-specific summaries for XTP, REP, NGAV and BFA. Chat history and generated summaries are preserved for the duration of the current session.
- Start Full Analysis, which redirects the user to the Wingman Analysis Details page.
- Analysis History, which redirects the user to the Wingman Analysis page.
Note: Start Full Analysis and Analysis History are available when the TAC license is enabled.
When no customer is impersonated (reseller user level), Wingman Chat provides access to Analysis History when the TAC licensing option is enabled, redirecting the user to the Wingman Analysis page.
Wingman Analysis
Wingman Analysis provides the AI-powered assessment of security detections, together with recommended actions that can be taken based on the analysis, such as excluding a detection or adding it to the allowlist. The capability is available under Threat - hunting & Action Center and requires an active TAC license.
For Reseller users impersonating a Corporate customer, the Wingman Analysis view displays only the analyses associated with the selected customer, keeping the investigation context specific to that environment.
Wingman Analysis is available from the left-hand Dashboard menu under Products -> Threat - hunting & Action Center -> Wingman Analysis. The Wingman Analysis overview provides a centralized view of the AI analyses performed across customer environments.
For each analysis, the grid displays the customer, analysis date and status, duration, number of analyzed alerts and AI agents involved, together with the resulting Verdict and Severity.
Users can search analyses by Customer ID or Customer Name, filter the results by Verdict and Severity, and select the relevant region. Each completed analysis can be opened to access its detailed assessment, while users with the required permissions can also delete existing analyses.
A new assessment can be initiated directly from the Wingman Analysis view using the New Analysis option. When no Corporate customer is impersonated, the Dashboard user can select the customer for which the analysis should be performed.
When working within an impersonated Corporate customer, the analysis is automatically started in the context of that customer.
Opening an analysis displays the Wingman Analysis Details page, including a visual representation of the Multi-Agent System (MAS) workflow used to investigate the detection. Depending on the available detection data, dedicated XTP, REP, NGAV and BFA Specialist Agents analyze the relevant security information.
The findings produced by the Specialist Agents are then cross-correlated by the Correlation Agent and consolidated by the Orchestrator Agent into a single, human-readable assessment. The resulting analysis includes the Verdict, Severity, Confidence level and recommended remediation actions, providing users with both the outcome of the investigation and actionable guidance on how to proceed.
Users can also provide feedback on the assessments produced by the individual Specialist Agents and the Orchestrator Agent, including corrections to the assigned Severity and Verdict and an optional analyst note.
Specialist Agents
Wingman Analysis uses dedicated Specialist Agents for each supported detection source, with each AI agent applying analysis tailored to the security information available from that module:
- XTP Specialist Agent analyzes XTP detections from the last 30 days, correlating information such as executed tools, file paths, command-line activity, execution context, prevalence and available threat intelligence to identify suspicious or malicious behavior and assess the associated risk.
- REP Specialist Agent analyzes file reputation and execution behavior, including provenance, signatures, runtime activity, malware-related indicators, detection results and prevention outcomes, to assess the likelihood of malicious activity.
- NGAV Specialist Agent analyzes endpoint malware detections, considering executable characteristics, execution paths, prevalence, propagation patterns, threat intelligence and antivirus response actions to validate detections and assess their potential impact.
- BFA Specialist Agent analyzes authentication-related activity, including failed and successful login events, source IP intelligence, attack frequency, targeted accounts and geographic indicators, to identify brute-force activity and assess the likelihood of account compromise.
Each Specialist Agent produces its own assessment based on the evidence available to it, including a Status, Severity and Confidence level, together with a Summary explaining the most relevant findings and the factors behind the assessment.
Individual Detection Assessments provide further context for the detections analyzed by the Specialist Agent, including the supporting Findings and Recommended Actions. Evidence References identify the information and external references supporting the assessment, while Missing Evidence highlights information that was not available during the investigation but could help increase confidence in the analysis.
Correlation Agent
The Correlation Agent builds on Heimdal’s unified security approach by analyzing the findings produced by the Specialist Agents across the supported security modules, determining how detections relate to one another.
It identifies shared indicators and attack patterns, correlates events across modules and reconstructs attack timelines to determine whether separate detections form part of the same attack chain, represent independent incidents or are unrelated.
The resulting Correlation Assessment describes the identified Relationship, its Strength and the agent’s Confidence in the correlation. Where the combined evidence indicates a higher level of risk than the individual Specialist Agent assessments alone, the analysis can also indicate that the overall Severity should be escalated.
A Correlation Summary explains the main relationships and conclusions, while the Attack Narrative reconstructs the sequence of events from the correlated evidence to provide a clearer view of how the activity developed. Supporting Signals highlight evidence reinforcing the correlation, while Contradicting Signals identify evidence that challenges it and helps avoid incorrectly connecting unrelated activity.
Missing Evidence highlights additional information that could help confirm or refute the correlation assessment.
Orchestrator Agent
The Orchestrator Agent represents the final decision-making stage of the Wingman Analysis workflow. It evaluates and consolidates the findings produced by the Specialist Agents together with the results of the Correlation Agent to provide a unified view of the investigated incident through a single, human-readable assessment, rather than requiring users to interpret findings from individual security modules separately.
The final assessment provides an Overall Status, Final Severity and Confidence level based on the available evidence and the identified correlations. The Threat Summary provides a concise overview of the incident and the main factors influencing the final verdict, while the Customer Narrative brings together the investigation timeline, correlated events and relevant context into a detailed, human-readable explanation of the incident and the reasoning behind the assessment.
Where analyst validation is required, the assessment also indicates that human review is needed and explains the factors behind that recommendation.
Module Synthesis provides a consolidated view of how the individual Specialist Agents contributed to the final assessment, including their key findings and risk contribution. Based on the complete analysis, Next Best Actions provides prioritized investigation, remediation and response recommendations according to their urgency and potential impact reduction.
The complete Orchestrator assessment can also be exported as a PDF report, providing a portable summary of the analysis, key findings and final verdict.
Together, these capabilities help streamline security investigation and triage by bringing detection analysis, correlation and actionable guidance into a unified AI-powered workflow, reducing manual effort and enabling security teams to reach informed decisions faster.
Heimdal Patch & Asset Management
● Operating System Updates – AI-powered Windows Updates prioritization
Keeping Windows environments protected is not only about deploying updates, but also about ensuring that the most important updates are addressed first. AI-powered Windows Updates installation sequencing adds an intelligent layer to the update process by automatically determining the recommended installation order for eligible Windows updates based on their importance and urgency, regardless of the configured update source.
By automatically prioritizing the updates available for deployment, AI Wingman helps organizations address critical updates sooner, make more effective use of maintenance windows and reduce the manual effort required from IT administrators, freeing up valuable time for higher-value activities.
AI Wingman sequencing does not change which updates are approved or eligible for installation; it determines the order in which those updates are installed.
AI Wingman sequencing is applied only after the existing OS Updates Endpoint Settings (Group Policy)
and filters have been evaluated (such as update categories, reboot and scheduling settings, etc.).
Once the eligible updates have been determined, AI Wingman analyzes factors such as update category, severity, associated CVEs, CVSS scores and overall security impact to assign a priority to each update.
Eligible updates are then installed according to the assigned priority, while the priority information is reported back to the Heimdal Dashboard, providing administrators with additional visibility and reporting capabilities.
Wingman Sequencing can be enabled for Windows devices under Endpoint Settings -> Windows GPs -> Patch & Assets -> Operating System Updates, Install Settings area. The new checkbox includes an information tooltip summarizing the AI-powered prioritization behavior.
AI Wingman assigns each eligible Windows Update one of three priority levels, which determines its position in the installation sequence:
- NOW: critical or urgent updates, prioritized for installation first.
- SOON: important updates that should be addressed promptly, following NOW-priority updates.
- LATER: lower-risk or less urgent updates, installed after higher-priority updates.
The assigned priority is displayed in the new Wingman Priority column across the relevant Heimdal Dashboard views, including:
- OS Updates -> Per Update visualization from Installed, Pending and Available views;
- Stats views (selecting/ clicking an Update) for Installed, Pending and Available updates;
- Client Specifics (selecting/ clicking a Hostname), OS Updates related sub views;
- OS Updates Compliance views;
- Operating System Update Details modal.
Note: Wingman priorities are assessed periodically. If an eligible update has not yet received a priority when it is processed by the Heimdal Agent, it is placed last in the installation sequence.
The Wingman Priority column can also be sorted across all supported views, allowing IT administrators to quickly bring higher or lower-priority updates into focus. The relevant CSV exports have also been updated to include the Wingman Priority information, supporting enhanced reporting and further analysis of update priorities.
Heimdal Privileges & App. Control
● App Control – Block Agentic AI
As Agentic AI applications continue to become more prevalent across enterprise IT environments, Application Control has been enhanced with the new Block Agentic AI Products capability, giving administrators greater visibility and control over Agentic AI software and helping limit the use of unauthorized AI tools that could expose sensitive or confidential organizational data.
The new functionality allows administrators to automatically block processes associated with predefined Agentic AI applications, while retaining the flexibility to configure individual exceptions.
The predefined Agentic AI application list is centrally maintained by Heimdal, allowing coverage to evolve as new applications and associated publisher and certificate information are identified.
The Block Agentic AI Products checkbox is available for Windows devices under Endpoint Settings -> Privileges & App Control -> App Control -> Rules. The App Control module must be enabled, with Rule Enforcement set to Enabled or Reporting mode and Default file action set to Allow.
Once enabled, the corresponding Application Control block rules are automatically created for processes associated with the predefined Agentic AI applications, using publisher and trusted code-signing certificate information for identification.
When Block Agentic AI Products is enabled, the full software list can be expanded to display the predefined Agentic AI software together with the associated publisher and trusted code-signing certificate information.
By default, all listed software is included in the blocking scope.
IT administrators can create individual Allow exceptions using the + action or select multiple applications and use Select what action to take -> Allow to configure exceptions in bulk. The list can be searched by software name, publisher, or certificate hash, making it easier to identify and manage specific Agentic AI applications.
When a process is blocked through Block Agentic AI Products, the standard Application Control end-user notification is displayed on the endpoint, including the full path of the intercepted process. Applications configured as Allow exceptions are excluded from the Agentic AI blocking mechanism and continue through the regular Application Control rule evaluation flow.
Blocked executions are identified by the new Blocked by Agentic AI status, available in both the Standard and Raw Application Control views, as well as under Device Info. When Reporting mode is used, the corresponding executions are additionally marked with the R indicator, consistent with the existing Application Control reporting behavior.
A dedicated Matching Blocked by Agentic AI filtering option has also been introduced, making it easier to isolate and review executions associated with this functionality.
Heimdal Email Protection
● Bulk Import and Export for End-User Allowlist & Blocklist
The End-User Allowlist & Blocklist functionality has been enhanced with CSV import and export capabilities, allowing administrators to bulk manage mailbox-specific Allowlist and Blocklist rules. Multiple rules can now be imported from a CSV file, while existing rules can be exported and reused for subsequent imports.
The new functionality is available under Allowlist, Blocklist & Greylist -> End-User Allowlist & Blocklist.
A sample CSV file is also available directly from the information tooltip to help prepare files in the supported format.
Note: for imports, the first four fields are required, in this order: Mailbox, Domain/Address/Subject, Type and Category.
The exported CSV includes the Mailbox, Domain/Address/Subject, Type, Category, Action and Timestamp for each rule and can be reused directly for subsequent imports without changing its column structure.
Entries are validated during import, with valid rules being added even when other entries in the same file are invalid. Entries can be excluded if they are malformed, duplicates, associated with a mailbox outside the selected domain, conflict with an existing rule, or would create conflicting Allowlist and Blocklist rules.
Once processed, the Dashboard displays the import result, including the number of entries successfully imported or excluded. Successful and partially successful imports are saved automatically, without requiring Save Changes.
Note: a maximum of 10,000 End-User rules across the Allowlist and Blocklist is supported. If an import would cause this limit to be exceeded, the entire import is rejected and no entries from the CSV file are added.
Other improvements & fixes:
● Heimdal Dashboard - Visual and usability refinements
We've introduced a series of visual refinements across the Heimdal Dashboard to deliver a more consistent and polished user experience. These updates include improvements to interface elements, layouts and overall visual alignment.
Building on the Basic and Advanced configuration modes introduced with version 5.6.0, Endpoint and Network Settings have also received further usability refinements, including clearer feature and functionality naming, more concise and informative tooltips, and adjustments to selected default configuration values.
Together, these changes provide additional clarity around the available settings, making them easier to understand and use while further refining the overall configuration experience.
● MXDR P&A Automation Emails – Top Hostname Visibility
The existing MXDR Patch & Asset Management email automation has been enhanced with a Top 5 Hostnames table, providing greater visibility into the endpoints associated with available and pending OS Updates and outdated 3rd-party applications.
Hostnames are ranked by TAC notifications count and link directly to the corresponding per hostname filtered OS Updates or 3rd Party Patch Management Dashboard views.
● M365 User Security – Configurable Secondary Location expiration interval for Login Anomaly Detection
Login Anomaly Detection (LAD) has been enhanced with a configurable Secondary location expiration interval, allowing administrators to define how long a trusted secondary location remains excluded from location-based anomaly detections.
Available under the Advanced M365 User Security Network Settings, User Risk Management section, the new slider supports a range of 7 to 90 days, with a default value of 30 days. The configured interval applies to secondary locations when acknowledging Unusual login or Impossible travel detections, as well as when a previous primary location becomes secondary.
● DNS Security Network – Threat Type search for the Standard -> Latest Threats view
The Standard -> Latest Threats view in DNS Security Network has been enhanced with Threat Type search capabilities, allowing administrators to quickly locate and review threat records based on their classification. This provides more efficient filtering of threat data and aligns the experience with the existing DNS Security Endpoint functionality.
● Heimdal Dashboard – Access Control for Product Modules Overview visibility at login
A new View Product Modules Overview at login claim type (Access Control) has been introduced, allowing IT administrators to control whether the Group Policies Product Modules Overview is automatically displayed when a user logs in to the Heimdal Dashboard. When the claim is disabled, the overview is no longer automatically displayed at login, while the existing Modules Overview button and on-demand access remain unchanged.
● Heimdal Agent – Persistent isolation notification for end users
The Heimdal Agent now displays a persistent Device Isolated notification whenever an endpoint is isolated, regardless of whether the isolation was triggered manually, by Tamper Protection or by Device Protection Actions (DPA). The notification informs the end user that network access may be restricted and remains displayed for as long as the device is isolated. If dismissed, it is displayed again at the next login while the device remains isolated.
● Heimdal Dashboard – Enhanced module usage visibility
The DNS Security Network, Email Security, PASM and Remote Desktop Dashboard views now include a Usage statistic, providing additional visibility into the calculated usage for each module. An information tooltip explains how the displayed figure is calculated, based on the relevant module-specific usage logic for the last calendar month relative to the selected To date.
● ROI Report section relocated to Reports & Alerts
The ROI Report section has been moved from Unified Management to the dedicated Reports & Alerts area, accessible directly from the left-hand Dashboard menu. The ROI Report is displayed as the first tab when accessing the section.
Note: aside from its new location, the ROI Report functionality and availability remain unchanged. It continues to be available only when impersonating a corporate customer and is independent of the Manage reports and alerts area claim category.