This article provides important information about StorageGuard™ version 10.1 by Core6, including new features, resolved issues, knowledgebase updates, and upgrade guidance.
In this article
- At a Glance – StorageGuard 10.1
- StorageGuard overview
- New in Version 10.1
- Installation Notes for this Release
- Upgrade for this Release
- Important Notes
- Known Issues
- Limitations
- Getting help
- Revision History
At a Glance – StorageGuard 10.1
- Change Control – Timeline of configuration changes per asset, AI-powered change risk scoring, point-in-time comparison, and authorized/unauthorized marking
- AI-Assisted Workflows – Guided remediation planning, AI-drafted custom configuration checks, and step-by-step system onboarding
- Expanded Platform Coverage – Dell SCG and Oracle ZFSSA added, plus a modernized Hitachi VSP scan
- ARMIS Integration – Enrich storage and backup assets in the ARMIS inventory with StorageGuard risk level and risk detail
StorageGuard overview
StorageGuard secures enterprise storage and backup environments by continuously assessing configuration posture and exposure. It automatically collects configuration data across platforms and identifies misconfigurations, drift from approved baselines, deviations from vendor hardening guidelines, compliance gaps, and ransomware protection weaknesses.
Operators can easily query configurations, investigate findings, and validate posture using natural language.
Key capabilities of StorageGuard
| Configuration & Drift Management | Security, Exposure & Compliance | Enterprise Platform Coverage |
|
|
|
New in Version 10.1
New features and highlights
This StorageGuard release introduces significant enhancements across configuration change management and integrations:
Change Control
A new Change Control area tracks and summarizes configuration changes across scanned assets over time. It includes:
- A vertical timeline of configuration changes for each scanned asset
- AI-powered risk scoring for each detected change
- The ability to compare a storage system against any past point in time
- The ability to mark changes as authorized or unauthorized
- Findings now include a Recent Configuration Changes section to shed light on the changes occurring prior to the detection of the finding
- An overview page with insight and trend information, including stability, change rate, and other metrics
Figure 1: The Change Control area
New AI-assisted workflows for onboarding, custom checks, and remediation
Generate a remediation plan for an asset
- Right-click an asset and select Remediation Planning to generate a suggested remediation plan for its findings.
- Plans can be scoped to critical findings only, configuration hardening, or vulnerabilities.
Figure 2: AI-assisted remediation planning
Define a new custom configuration check with the AI assistant
- Supply the check name and the storage or backup platform, then describe what you want to verify.
- The assistant then presents a complete check for your approval, including the mapped API endpoints, data fields, evaluation logic, and script.
Figure 3: Defining a custom check with the AI assistant
Onboard new systems with step-by-step guidance
- The AI assistant guides you through onboarding new systems onto StorageGuard, step by step.
Support Matrix
The following storage solutions were added to the support matrix:
- Dell Secure Connect Gateway (SCG) – Inventory, Custom Checks and Vulnerability Identification
- Oracle ZFS Storage Appliance (ZFSSA) – Full Support
Hitachi VSP scan reformed and expanded
The Hitachi VSP scan has been substantially revised and now offers greater flexibility: arrays can be scanned directly, through a separately installed Configuration Manager, and/or through Ops Center. The scan also covers the Hitachi management application layer – Common Services, Administrator, Automator, and others.
ARMIS integration
StorageGuard can now be integrated with ARMIS and can be used to enrich Storage/Backup Assets within the ARMIS inventory with risk level and risk detail information.
Enhanced security
This release includes security improvements and addresses third‑party vulnerabilities. Refer to Support Announcements for additional information.
Additional changes and enhancements
The following section highlights additional notable changes or enhancements:
| Id | Description |
| SG-23692 | System-wide users can view dashboards as other user profiles using the 'View as' option. In addition, charts in the dashboard can be resized after clicking the edit option. |
| SG-30138 | The system now offers Asset List and Asset Detail reports in the catalogue. Also added executive summary reports: Baseline Configuration Overview, Vulnerabilities Overview, Assets Overview |
| SG-32484 | A user can now override the system-provided end of support date for a model or version |
| SG-30772 | A certificate management utility is now available (contact support for additional information); also the certificate used for the web UI can now be managed through the Settings tab |
| SG-32751 | Support for the modern NDFC REST API |
| SG-27530 | Support for SSH Tunnel for collectors (optional) |
| SG-32711 | Added support for filtration by CI Groups in the Configuration Compliance Report |
| SG-32213 | Added support for CVSS Score Version 4.0 |
|
SG-31932 SG-29788 |
Expanded PowerFlex configuration collection (SSO users, groups, LDAP, auth API) |
| SG-31836 | 'Fix It' expanded to support API calls |
| SG-31723 | Ability to add a Partner logo image and show it in reports |
| SG-31703 | Expanded Commvault configuration collection (user, CommCell Properties API) |
| SG-31702 | Expanded IBM Storage Protect configuration collection (query admin CLI) |
| SG-31698 | Expanded Dell Networker configuration collection (usergroups API) |
| SG-29064 | Expanded NetApp ONTAP collection (totps, duo, oauth2, ocsp APIs) |
| SG-31548 | Added License Usage info to the Telemetry report |
| SG-31461 | Simplified StorageGuard scan tasks |
| SG-31460 | Introduced a System Alert to notify administrators of any conflicts between existing overridden configurations and changes applied during the upgrade process |
| SG-31457 | Scan timeout, parallel scanning, and other advanced scan settings have been moved from General System Properties to a dedicated Scan > Advanced Settings section for improved accessibility |
| SG-30719 | Improved Asset discovery for NetApp Active IQ Unified Manager |
| SG-29760 | Added beta support for the Cohesity (Veritas) NetBackup 52x0 Appliance platform |
| SG-32064 | Assets view now includes the underlying Data Domain node systems |
| SG-24638 | Assets view now includes the underlying Dell ECS model |
| SG-34028 | Added the ability to configure an AI provider for AI-powered change risk scoring (disabled by default) |
| SG-34616 | The custom check definition UI has been modified to facilitate simplified custom check setup. In addition, the AI assistant has been enhanced to allow the definition of custom check based on free text provided by the end user. |
| SG-34001 | Upgraded Apache Tomcat to version 10.1.59 |
Fixed issues
The following issues are resolved:
| Id | Description |
|
SG-32883 SG-32882 SG-32871 SG-32867 |
Resolved accuracy and presentation issues in HPE Alletra checks and findings:
|
| SG-34091 |
Resolved accuracy and presentation issues in Brocade checks and findings:
|
|
SG-34092 SG-27651 |
Resolved accuracy and presentation issues in Cisco checks and findings:
|
|
SG-32142 SG-27060 |
Resolved accuracy and presentation issues in Commvault checks and findings:
|
|
SG-32342 SG-32341 |
Resolved accuracy and presentation issues in Dell Data Domain checks and findings:
|
| SG-34088 |
Resolved accuracy and presentation issues in Hitachi VSP checks and findings:
|
| SG-32958 |
Resolved accuracy and presentation issues in IBM FlashSystem checks and findings:
|
| SG-28989 |
Resolved accuracy and presentation issues in ONTAP checks and findings:
|
|
SG-30082 SG-30081 |
Resolved Asset presentation issues for NetApp:
|
| SG-32282 |
Resolved accuracy and presentation issues in NetBackup Flex Appliance checks and findings:
|
|
SG-32063 SG-32065 |
Resolved PowerFlex Inventory issues:
|
|
SG-31825 SG-31823 |
Resolved accuracy and presentation issues in Dell PowerFlex checks and findings:
|
| SG-27051 |
Resolved accuracy and presentation issues in Dell PowerStore checks and findings:
|
| SG-32946 |
Resolved VSAN related issues:
|
|
SG-33399 SG-22653 SG-33383 |
Resolved License counting issues:
|
|
SG-32439 SG-31554 |
Resolved Finding Management issues:
|
| SG-28627 | Added Properties for controlling the Unisphere for PowerMax (U4P) scan timeout |
Knowledgebase Updates
The following section describes new and modified checks.
New checks
The following table identifies systems for which new checks have been added:
| System type | Number of new checks |
| Cisco SAN | 31 |
| FlashSystem / Virtualize | 30 |
| PowerProtect DD | 29 |
| IBM DS | 19 |
| StorageGRID | 19 |
| VMAX / PowerMax | 16 |
| Commvault | 14 |
| Brocade FC Networking | 13 |
| Hitachi VSP | 13 |
| ONTAP | 12 |
| Unisphere for VMAX/PowerMax | 10 |
| IBM DS Manager | 8 |
| NetWorker | 7 |
| PowerFlex | 7 |
| IBM Storage Protect | 6 |
| Hitachi OpsCenter | 3 |
| Hitachi OpsCenter Administrator | 3 |
| Total | 240 |
For the detailed list of checks, contact support.
Renamed checks
| Previous check name | New check name |
| SG-C0448T187V04: Trusted certificate-authority (CA) | SG-C0448T187V02: Trusted certificate-authority (CA) |
| SG-C0154T151V01: SNMP manager configuration | SG-C0154T254V01: SNMP manager configuration |
| SG-C0001T139V01: Audit logging status | SG-C0001T151V01: Audit logging status |
| SG-C0119T139V01: Unapproved user groups | SG-C0119T254V01: Unapproved user groups |
| SG-C0231T139V01: Non-default local users | SG-C0231T254V01: Non-default local users |
| SG-C0016T121V02: Required Syslog servers | SG-C0016T091V02: Required Syslog servers |
| SG-C0363T121V02: SE client security level | SG-C0363T091V02: SE client security level |
| SG-C0449T091V01: Approved DNS servers | SG-C0449T121V01: Approved DNS servers |
| SG-C0243T091V01: DNS server configuration | SG-C0243T121V01: DNS server configuration |
| SG-C0315T091V01: Approved SYMAPI servers | SG-C0315T121V02: Approved SYMAPI servers |
| SG-C0163T091V01: Approved AD domain | SG-C0163T121V02: Approved AD domain |
| SG-C0175T091V01: Event types enabled for audit logging | SG-C0175T121V02: Event types enabled for audit logging |
| SG-C0171T091V01: NTP server configuration | SG-C0171T121V01: NTP server configuration |
| SG-C0015T091V02: Approved Syslog servers | SG-C0015T121V02: Approved Syslog servers |
| SG-C0065T091V01: Data at-rest encryption | SG-C0065T121V02: Data at-rest encryption |
| SG-C0432T091V01: NTP server redundancy | SG-C0432T121V01: NTP server redundancy |
| SG-C0039T091V01: LDAP server configuration | SG-C0039T121V01: LDAP server configuration |
| SG-C0060T091V01: DNS server redundancy | SG-C0060T121V01: DNS server redundancy |
| SG-C0213T091V01: Use of secure LDAP | SG-C0213T121V01: Use of secure LDAP |
| SG-C0039T121V02: LDAP server configuration | SG-C0039T091V02: LDAP server configuration |
| SG-C0365T248V01: SSL authentication status | SG-C0365T225V01: SSL authentication status |
Note: Added a "(Solutions Enabler)" suffix for Dell PowerMax checks that are applicable only when the Solutions Enabler CLI data source is configured and used.
Removed checks
Hitachi VSP legacy HiCommand checks
- SG-C0159T151V01: HiCommandCLI password
- SG-C0160T151V01: Tiered storage manager CLI password
- SG-C0161T151V01: RADIUS authentication protocol
- SG-C0186T151V01: WWN security
- SG-C0201T151V01: Device manager IP ACL
- SG-C0256T151V01: Cipher suite strength
- SG-C0280T151V01: User ID is enable on password
- SG-C0352T151V01: CIM comm security
- SG-C0355T151V01: External server communication
- SG-C0356T151V01: HDC comm security
- SG-C0357T151V01: HDvM SN comm security
- SG-C0358T151V01: HTTP security mode
- SG-C0378T151V01: FTP server status
- SG-C0389T151V01: SSLv2 Hello status
Installation Notes for this Release
Read the Installation Procedure Chapter of the User Guide for guidance about installing StorageGuard v10.1. In addition, review the Deployment and Scanning resources for guidance about the StorageGuard infrastructure requirements and the preparations needed for scanning your datacenters.
Upgrade for this Release
An upgrade path to version 10.1 is available from the 9.2.8 release and above. If your system is currently installed with an earlier release, an upgrade to version 9.2.8 or above is mandatory before upgrading to version 10.1.
Important notes:
- The upgrade will require the complete stop of StorageGuard operations, including data collection and data analysis. While it is fully automatic, the length of the upgrade process may require several hours to complete in large environments. During this time, it is important not to restart the StorageGuard server or terminate the upgrade task. In addition, it is essential that the database used by StorageGuard be available throughout the upgrade process.
- Important – If your scanned environment includes Hitachi VSP, take particular care to review the Upgrading to StorageGuard 10.1 for Hitachi VSP Environments section to learn about changes and steps required prior to upgrading.
- Prior to upgrading, take care to read the release notes in full, and make any necessary changes to the StorageGuard infrastructure and/or to user account permissions as required, and ensure sufficient free disk space is available on the master server. It is important to review newly required read-only privileged commands and make necessary changes to sudo (or any other privilege management solution used to grant the required permissions, such as PowerBroker, UPM, sesudo) to allow StorageGuard to run the commands.
- Prior to upgrading, verify you have an up-to-date backup of the StorageGuard server disk drives using your standard backup tools, and an up to date StorageGuard database export.
- Once the upgrade on the master StorageGuard server is completed and the Tomcat service starts, StorageGuard will automatically check and upgrade the StorageGuard collectors. There is no manual collector upgrade process. For gradual collector upgrade, disable the collectors before initiating the upgrade on the master server, and gradually enable the collectors you wish to upgrade following the completion of the software upgrade on the master server.
To upgrade from version 10.0 to version 10.1:
- Login as a local administrator to the master StorageGuard Server.
- Run Core6Platform_10.1.exe as an administrator.
- Click Next on the Welcome screen.
- Select “Yes, upgrade Core6 Suite 10.0 to 10.1”.
- Accept the License Agreement and click Next.
- Accept the GNU License Agreement and click Next.
- Select whether to perform a database export prior to upgrading and whether to start Tomcat after the upgrade completes and click Next. It is recommended to keep the default settings.
- Click Install to begin the Software Upgrade process. This process may require up to several hours to complete, depending on the size of the scanned environment.
- Click Finish.
Note: Version 10.1 includes enhancements to the scan task user experience and scope definition model. Existing scan tasks will be automatically upgraded during installation. We recommend validating scan task scopes after the upgrade to ensure they align with your current scanning requirements.
Upgrading to StorageGuard 10.1 for Hitachi VSP Environments
StorageGuard 10.1 replaces the legacy Hitachi VSP probe with a family of dedicated new Hitachi REST data sources: Configuration Manager, OpsCenter Administrator, OpsCenter Common Services and VSP One Block. The VSP arrays themselves are collected by the Configuration Manager data source or by VSP One Block (direct to the array's SVOS REST API).
Migration steps
- Disable the existing Hitachi VSP (legacy HiCommand) probes – do not delete them yet.
- Add a new Hitachi data source using one of the connection options below.
- Run Discovery on the new data source.
- Confirm the VSP systems fall within the scope of a security policy.
- Run a scan.
- Run Security Analysis to evaluate checks against the new data.
- Verify the results against the legacy data.
- Remove the disabled legacy HiCommand probes.
Connection options
- Option A – Direct to a single array. Onboard a Configuration Manager data source – one data source per array. Use when there is no centralized OpsCenter deployment, or for a small number of arrays.
- Option B – Centralized Configuration Manager. Onboard a Configuration Manager data source pointed at a Configuration Manager server that manages multiple VSPs; Discovery adds every VSP registered on it. Use when Configuration Manager is deployed centrally but the wider OpsCenter suite is not.
-
Option C – OpsCenter Common Services (recommended where available). Onboard an OpsCenter Common Services data source. This does two things:
- Scans Common Services itself – StorageGuard collects its configuration (users, groups, LDAP/AD, identity providers, session settings) and evaluates a dedicated set of security checks against it.
- Discovery reads the services registered with Common Services and automatically creates the OpsCenter Administrator and Configuration Manager data sources. The Configuration Manager data source discovers and collects the VSP arrays data, exactly as in Option B.
Note: Credentials and connectivity policy are inherited from the Common Services data source (overridable per data source), so no further setup is needed before scanning. Option C is the fastest way to onboard everything and the only option that also extends coverage to the OpsCenter management layer (Common Services and Administrator).
Important Notes
Database Locale requirement
The Database instance used as the backend database for the Core6 Platform must be configured with the English Locale.
Scan of Storage and Replication Management servers
It is recommended to scan all production and DR storage management servers as hosts, even if they are already configured as storage proxies. Storage proxy scans operate at the API/CLI level, while host scans of the management servers enable collection of additional configuration files and settings.
Scan of Windows hosts through WMI
Scanning of Windows hosts updated with KB3139940 might fail with an “Access Is Denied” message. To overcome this failure, please make sure that the user configured to authenticate to this server is a member of the Local Administrator group on the StorageGuard server. StorageGuard also provides an alternative method of scanning Windows servers using WMI which requires PowerShell version 5.1 or higher.
User account for technical support only
The csadmin user provides access to support tools that can cause damage if not used properly; This user is intended to be used by Core6 support engineers only. Enable and login with the csadmin user only when directed to do so by support personnel. This user is locked by default.
Recommended scan protocol for Windows hosts
StorageGuard supports a variety of scan options for Windows hosts. The recommended scan option is using WinRM over HTTPS.
NetApp ZAPI no longer supported
Before upgrading to this release, ensure you’ve enabled REST API access for the StorageGuard scan account.
Obsolete reports
The following reports are obsolete and were removed:
- Installed Software (Host)
- SAN Switch Version
- SAN Zone Details
Known Issues
The following section highlights additional notable known product issues:
| Id | Description |
| SG-29904 | The Cisco probe may execute commands for disabled features resulting in “Cmd exec error” |
| SG-29876 | Under Scan Troubleshooting, the Storage column may not show the Storage System Name. Workaround: the name is presented in the Summary column |
| SG-29861 | Under Compliance, the details column may present “Successfully scanned” even though the relevant API/CLI command failed; this is because the “Successfully scanned” message refers to the overall system's scan status and not specifically for the API/CLI command used in this check. Workaround: Review failed commands under the Scan Troubleshooting or Task Manager UI |
| SG-27459 | Brocade FOS commands executed as part of a script do not report an error if fail to execute |
| SG-21689 | Uninstalling SG update from “Add/Remove Programs” does not work as expected |
| SG-32972 | Large command/API outputs may be too extensive for effective comparison |
| SG-3088 | The Windows installer creates a local Apache service account by default. Review and replace it with an approved service account if required by your organization's policies |
Limitations
Assigning a profile to an Active Directory group
When assigning a profile to an AD Universal Group, the StorageGuard master server must have access to the Global Catalog of the AD Forest.
When assigning a profile to an AD Local Domain Group, StorageGuard will not be able to assign the Profile to AD Users from a different Domain – even though such configuration is valid within AD. In other words – an AD user can log in to StorageGuard (with all the correct profiles assigned) only if each AD Local Domain Group it belongs to is part of the same AD Domain the AD user belongs to.
Special characters are converted during object import to StorageGuard
When importing names and properties of objects from CSV/CMDB/API, special characters such as “&”, ‘no-break-space’ and certain UTF8 chars are converted to alphanumeric chars.
In specific cases scan error messages are not sufficiently informative
The Scan Troubleshooting screen occasionally presents scan error messages that include the error code, but no additional details.
Workaround: Run the erroneous command or script manually to see the full scan error message. If further assistance is required, contact Technical Support.
SSH key supports only keys with less than 4000 characters [P-6645]
Elevated rights required for certain read‑only API calls and commands
Some optional read‑only APIs and commands executed by StorageGuard on specific platforms require elevated privileges. Granting these rights is recommended to enable a more comprehensive risk analysis, but it is not mandatory.
Regardless of the permissions granted, StorageGuard executes read‑only APIs and commands only.
Platform‑specific notes:
- Commvault: Certain optional read‑only API calls (including SNMP, 2FA and Audit Trail APIs) require elevated rights.
- Dell PowerProtect Data Domain: Some read‑only commands require the limited‑admin or the admin role. Alternatively, the scan user can be configured with the read‑only user role.
- Dell Unity (Unisphere for Unity): Some read‑only API calls require the Security Administrator role. Alternatively, the scan user can be configured with the read‑only operator role.
- Hitachi Ops Center: Some read‑only API calls require the Security Administrator role. Alternatively, the scan user can be configured with the read‑only operator role.
- HPE Alletra 6000: User administration APIs are available only to admin users, which means some checks can only be executed with Admin privileges.
- Dell Unisphere for PowerMax: A few read-only API calls require the Security Administrator role. On embedded Management, several read-only APIs require the administrator role.
- Veeam VBR: Several read-only API calls require the Veeam Backup Administrator role.
- Windows hosts: OS‑level scanning (via WinRM or WMI) runs read‑only commands and queries but requires elevated rights. OS‑level scans are optional but recommended, in addition to application‑level scans, for comprehensive security configuration analysis.
- Dell PPDM: The read-only API used for the SG-C0464T227V01: Disaster recovery backups check requires administrator privileges
CVE detection limitation
StorageGuard may report a CVE vulnerability that was either worked around or mitigated through remedial steps other than applying software updates.
CVE knowledgebase
The CVE knowledgebase is limited to advisories and CVEs that have been publicly announced by the vendor, MITRE or other source to the community.
PowerMax 5978 patch level
StorageGuard cannot determine the patch level for Dell PowerMax 5978 arrays, only the microcode.
NetApp StorageGRID model and serial number (SG-30081)
The StorageGuard inventory does not present StorageGRID model and serial number in the inventory due to API limitations.
System requirements
For more information about system requirements and software limitations, please refer to Documentation – Help Center | Core6.
Getting help
If you have a current maintenance agreement, you may access Technical Support information at www.core6.com/support.
Customer service information is available at www.core6.com/contact.
If you forget or lose the StorageGuard administrator password, contact Technical Support.
Revision History
Document revision history:
| Revision | Date | Description |
| 1.0 | 15 September 2026 | Initial publication |
| 2.0 | 22 September 2026 | Updated list of enhancements |
Comments
0 comments
Please sign in to leave a comment.