Week of July 27: guided intake, faster Triage, and expanded security analysis
Unified capture investigation setup, expanded capture-wide threat detection and IDS controls, improved upload and Triage performance, and made Agent reports and reconnects more dependable.
platformperformanceagentbug fixessecurityanoncapon prem
Platform
- Unified investigation setup across upload, the capture library, and workspace views so the question, analysis workflow, operator control, privacy, and delivery choices stay coordinated without being conflated.
- Added selectable Triage processing profiles with clearer planning estimates, progress stages, and a focused “Is the network at fault?” investigation shortcut.
- Refined public plan and upload guidance so evaluation limits, enterprise options, and the distinction between preliminary and comprehensive results are easier to understand.
Performance
- Reused exact capture foundations and persisted evidence across processing stages, avoiding redundant indexed snapshots and repeated packet scans.
- Replaced expensive histogram work during intake with a bounded Sharkd activity preview, improving early capture feedback while deeper processing continues.
- Streamed upload hashing and staging, reused capture metadata work, and folded deduplication and full IDS coverage into the primary packet scan to reduce repeated I/O before analysis.
- Added bounded compiled-rule caching and deduplicated post-index artifacts so repeated security scans and large-capture processing use less CPU, memory, and storage.
- Reduced capture-storage write amplification and tightened worker and IDS cache boundaries for more predictable large-capture operation.
Agent
- Added prompt coaching that helps turn broad questions into responsible fast-path investigations and redirects unfocused work toward capture-wide Triage when appropriate.
- Shipped selector-first discovery and exact flow retrieval so focused investigations can reach packet evidence sooner without treating the whole capture as model context.
- Made investigation threads, timelines, and report milestones durable across reconnects and page reloads, with safer recovery of active upload-launched runs.
- Strengthened causal verification so strong preliminary candidates receive explicit verification outcomes and clearer customer-facing reports.
Bug fixes
- Fixed chunk-upload permission isolation, upload finalization locking, and replay routing issues that could interrupt capture intake or launch the wrong investigation path.
- Recovered stalled Triage follow-up work more reliably and kept active Triage, IDS, and Agent progress synchronized across capture views.
- Corrected verification cards, report hydration, transcript replay, and milestone email layouts so completed findings remain visible and readable.
- Restored contextual capture actions and preserved confirmed Triage settings when reopening or launching work from the capture library.
Security
- Made enterprise retention behavior explicitly opt in and tightened storage permissions for uploaded chunks and runtime artifacts.
- Added capture-wide behavioral C2 and periodic-callback detection with bounded connection evidence, explicit coverage, and guardrails for benign discovery traffic.
- Expanded deterministic detection for DNS tunneling and covert channels, aggregate scans and floods, OT command anomalies, Active Directory attack paths, and RDP proxy downgrades.
- Added selectable ET Open and Stamus Lateral rule sources for each investigation, with Stamus lateral-movement coverage enabled by default and manageable through Intelligence feeds.
- Made complete IDS coverage durable and explicit across progress, findings, and clean outcomes, including recovery when an active scan lease expires.
- Refreshed production dependency and supply-chain coverage, and packaged the egress firewall entrypoint used by controlled outbound deployments.
Anoncap
- Consolidated Anoncap privacy controls across upload and existing-capture workflows, with simpler choices and clearer packet-slicing guidance.
- Expanded private workflow coverage for anonymized uploads while keeping processing and investigation choices visible as separate controls.
On-prem
- Completed the PostgreSQL-only runtime transition in active deployment guidance and removed obsolete Elasticsearch migration references.
- Hardened nonroot worker storage and authentication persistence for longer-running managed investigations.
- Expanded qualified local and alternative AI model support with cached capability records, drift audits, safer provider isolation, and controlled OpenRouter routing for egress-restricted deployments.
