Product updates

PacketSafari changelog

Weekly notes on the analyzer, Agent, Copilot, anoncap, performance, security, and on-prem delivery work that changes how teams investigate packet captures.

Latest update

Aug 10, 2026

Entries

25

Categories

7

Release notes

What changed

Public notes are grouped by customer impact, not by internal implementation records.

Week of August 10: guided investigations, threat intelligence, and operational reports

Made investigations and Final Reports more actionable, added offline threat-intelligence matching, and introduced explicit speed and team controls.

AgentBug fixesPerformanceSecurityPlatformAnoncapOn-prem

Agent

  • Added an explicit choice between a capture-wide Core-first start and a focused Agent start, with clearer confirmation and milestone ordering before an investigation begins.
  • Unified Preliminary Report, Verification, and Comprehensive Final Report milestones into one chronological investigation, with clearer live-stage navigation and concise completed reports.
  • Simplified new investigations around direct evidence handoffs so each stage can stop once it has a defensible answer, while preserving important alternatives, uncertainty, and capture-wide coverage limits.
  • Made Agent sessions and report activity durable across upload handoffs, reconnects, retries, and page restoration, reducing duplicate runs and missing or stale transcript content.
  • Made Final Reports more operational with fault-domain localization, actionable escalation guidance, authoritative titles, and reliable follow-up report activity.
  • Expanded Comprehensive Final Report review across the saved case, including earlier reports, authoritative Core results, and complete retained findings, so final conclusions can revisit all available evidence.
  • Kept quick questions separate from managed investigations while allowing executive summaries and security reviews to start without a custom prompt.
  • Added bounded PacketQL follow-up queries over retained Core facts so analysts, Agent, and Copilot can compare or rank one exact-generation fact family without rescanning the PCAP or persisting another result set.

Verification and evidence

  • Made verification dispositions traceable to stable claims and preserved supporting, contradicting, and baseline evidence through the final report.
  • Required deterministic Triage evidence before a Comprehensive Final Report can claim completion, while keeping cached preliminary evidence available to later stages.
  • Improved cross-flow TCP reasoning and retained exact selectors, sequence coordinates, control events, and connection-local evidence for packet-level review.
  • Improved bounded discovery for services on alternate ports and paired proxy or middlebox flows, while preserving TCP negotiation fingerprints for evidence-backed comparison.
  • Carried compact capture provenance, protocol prevalence, connection coverage, duplicate quality, and timestamp context into later stages without extra packet scans.
  • Made packet-tool results easier to inspect with richer typed previews, Markdown tables, preserved report headings, and explicit disclosure when a tool returned only partial coverage.
  • Made OT, telecom, and VoIP workspaces more evidence-led with explicit OT coverage layers, grouped protocol operations, signaling and media packet pivots, and bounded RTP loss/jitter comparison.

Bug fixes

  • Fixed upload-to-Agent transitions, stalled clarification flows, live milestone navigation, report hydration, email actions, and terminal transcript recovery.
  • Restored packet-tool execution and live Markdown rendering while keeping transient Agent thinking out of the saved customer transcript.
  • Stabilized saved report presentation and milestone handoffs, restored investigation counts in capture lists, improved ChatGPT reconnect guidance, and allowed capture deletion after failed Agent runs.
  • Required complete metadata validation before marking captures ready, so truncated sources fail explicitly instead of appearing successfully ingested.
  • Tightened TCP, ARP, DNS, telecom, and security-finding attribution so unsupported or unrelated packet evidence is not promoted into a customer conclusion.
  • Kept late-packet signals and capture-wide protocol coverage available through bounded large-capture scans so decisive anomalies and specialist analysis are not silently skipped.

Performance and platform

  • Added a faster large-capture path, bounded discovery and candidate recall by bytes, reused exact connection results, and localized reset-window analysis to avoid unnecessary capture-wide work.
  • Added saved whole-capture activity and integrity context, a selected-connection TCP quality summary, and on-demand RTP stream detail so transport investigations can move from capture quality to packet evidence without treating measurements as automatic fault verdicts.
  • Streamed capture cold-load progress and consolidated capture inventory, security projections, and full IDS work into bounded primary processing to reduce silent waits and repeated large-capture traversal.
  • Reduced backend startup overhead, separated web and worker startup paths, prioritized urgent queues, and bounded storage cleanup around active investigations.
  • Improved exported and visual reports by removing duplicate metadata and navigation-only citations, and deriving optional visuals only from exact Final Report evidence.
  • Added an optional Fast inference setting for eligible hosted investigations, with a completion receipt that shows requested and effective speed, fallback state, and charged Analysis runs.
  • Replaced generic AI usage units with explicit Analysis runs, Quick questions, and Prompt Coach entitlements, including shared and per-member visibility; completed investigations count only after successful completion.
  • Added Shared Teams packages with clearer capture allowances and a separate dedicated SaaS path.

Security

  • Made security findings easier to read while keeping live scan state, deterministic findings, and Triage completion consistent across the investigation.
  • Added offline matching for exact IP, network, domain, URL, and file-hash indicators from managed or customer-supplied snapshots, with feed provenance, validity context, and packet or connection pivots.
  • Made threat-feed coverage explicit as ready, partial, or unavailable, and added bounded scheduled refreshes with visible freshness and updater health for configured feeds.

Anoncap

  • Coordinated capture retention and anoncap deletion with active Agent investigations so privacy cleanup cannot race an in-progress analysis.
  • Decoupled public Anoncap downloads from frontend releases so privacy-tool updates can be published independently.

On-prem

  • Made cluster profiles explicit about accelerator counts so single-node and multi-node deployment topologies match their advertised hardware.
Open release note

Week of August 3: faster Core Triage, stronger TCP evidence, and private controls

Reduced large-capture processing overhead, added focused TCP and east-west evidence, clarified IDS and Anoncap choices, and strengthened managed AI access.

PerformanceAgentSecurityAnoncapPlatformBug fixesOn-prem

Performance

  • Consolidated more capture-wide Triage work into a shared single-read path, reducing repeated decoding across connection, IDS, protocol, and security analysis.
  • Made infrastructure discovery and specialist processing demand driven, bounded TCP candidate ranking, and compacted durable results to lower memory, storage, and database overhead on large captures.
  • Reused exact IDS and connection foundations across processing stages while retiring bulky intermediates after their customer-visible findings and coverage were safely persisted.

Agent

  • Added a bounded TCP dossier workflow so focused investigations can assemble connection setup, health, timing, and packet evidence without broad capture scans.
  • Improved Agent handoff after Triage by finalizing persisted evidence before launch and keeping capture identity, selected runtime, and tool contracts intact.

Security

  • Surfaced correlated east-west activity as inspectable findings while keeping packet-detail retrieval bounded.
  • Separated IDS source and coverage choices into a dedicated upload step, preserving the selected rules and exact coverage through the primary scan.

Anoncap

  • Added compact privacy-policy controls for private anonymization profiles and persisted the validated policy with each workflow.
  • Reconciled identity-handling rules across the Anoncap engine, backend, and upload experience so supported privacy choices remain consistent.

Platform

  • Added managed AI access-source selection with clearer subscription and provider approval flows for organization deployments.
  • Expanded supported alternative-model guidance and kept entitled runtime choices stable across reconnects and worker execution.

Bug fixes

  • Fixed capture-load, native-fact, connection-stream, and scan-finalization edge cases that could stall Triage, lose exact evidence, or launch Agent before results were durable.
  • Tightened artifact lifecycle cleanup and authoritative empty-result handling so completed processors do not leave stale work or trigger duplicate scans.

On-prem

  • Strengthened controlled AI-provider routing and authentication-source provenance for private deployments with managed egress requirements.
Open release note

Week of July 27: guided intake, faster Triage, and expanded security analysis

Unified capture investigation setup, expanded capture-wide threat detection and IDS controls, improved upload and Triage performance, and made Agent reports and reconnects more dependable.

PlatformPerformanceAgentBug fixesSecurityAnoncapOn-prem

Platform

  • Unified investigation setup across upload, the capture library, and workspace views so the question, analysis workflow, operator control, privacy, and delivery choices stay coordinated without being conflated.
  • Added selectable Triage processing profiles with clearer planning estimates, progress stages, and a focused “Is the network at fault?” investigation shortcut.
  • Refined public plan and upload guidance so evaluation limits, enterprise options, and the distinction between preliminary and comprehensive results are easier to understand.

Performance

  • Reused exact capture foundations and persisted evidence across processing stages, avoiding redundant indexed snapshots and repeated packet scans.
  • Replaced expensive histogram work during intake with a bounded Sharkd activity preview, improving early capture feedback while deeper processing continues.
  • Streamed upload hashing and staging, reused capture metadata work, and folded deduplication and full IDS coverage into the primary packet scan to reduce repeated I/O before analysis.
  • Added bounded compiled-rule caching and deduplicated post-index artifacts so repeated security scans and large-capture processing use less CPU, memory, and storage.
  • Reduced capture-storage write amplification and tightened worker and IDS cache boundaries for more predictable large-capture operation.

Agent

  • Added prompt coaching that helps turn broad questions into responsible fast-path investigations and redirects unfocused work toward capture-wide Triage when appropriate.
  • Shipped selector-first discovery and exact flow retrieval so focused investigations can reach packet evidence sooner without treating the whole capture as model context.
  • Made investigation threads, timelines, and report milestones durable across reconnects and page reloads, with safer recovery of active upload-launched runs.
  • Strengthened causal verification so strong preliminary candidates receive explicit verification outcomes and clearer customer-facing reports.

Bug fixes

  • Fixed chunk-upload permission isolation, upload finalization locking, and replay routing issues that could interrupt capture intake or launch the wrong investigation path.
  • Recovered stalled Triage follow-up work more reliably and kept active Triage, IDS, and Agent progress synchronized across capture views.
  • Corrected verification cards, report hydration, transcript replay, and milestone email layouts so completed findings remain visible and readable.
  • Restored contextual capture actions and preserved confirmed Triage settings when reopening or launching work from the capture library.

Security

  • Made enterprise retention behavior explicitly opt in and tightened storage permissions for uploaded chunks and runtime artifacts.
  • Added capture-wide behavioral C2 and periodic-callback detection with bounded connection evidence, explicit coverage, and guardrails for benign discovery traffic.
  • Expanded deterministic detection for DNS tunneling and covert channels, aggregate scans and floods, OT command anomalies, Active Directory attack paths, and RDP proxy downgrades.
  • Added selectable ET Open and Stamus Lateral rule sources for each investigation, with Stamus lateral-movement coverage enabled by default and manageable through Intelligence feeds.
  • Made complete IDS coverage durable and explicit across progress, findings, and clean outcomes, including recovery when an active scan lease expires.
  • Refreshed production dependency and supply-chain coverage, and packaged the egress firewall entrypoint used by controlled outbound deployments.

Anoncap

  • Consolidated Anoncap privacy controls across upload and existing-capture workflows, with simpler choices and clearer packet-slicing guidance.
  • Expanded private workflow coverage for anonymized uploads while keeping processing and investigation choices visible as separate controls.

On-prem

  • Completed the PostgreSQL-only runtime transition in active deployment guidance and removed obsolete Elasticsearch migration references.
  • Hardened nonroot worker storage and authentication persistence for longer-running managed investigations.
  • Expanded qualified local and alternative AI model support with cached capability records, drift audits, safer provider isolation, and controlled OpenRouter routing for egress-restricted deployments.
Open release note

Week of July 20: upload security, Triage, and enterprise assurance

Redesigned PCAP upload flows, enforced full IDS coverage for security analysis, clarified enterprise evaluation paths, and expanded customer assurance content.

PlatformSecurityAgentPerformanceBug fixesAnoncap

Platform

  • Redesigned the PCAP upload investigation wizard with clearer choices for question, analysis depth, Agent delivery, and security review.
  • Added a verified SaaS evaluation signup path and clearer pricing tiers for enterprise investigation, private AI, retention, and support capabilities.
  • Expanded customer assurance, compliance, privacy, terms, and subprocessor content so enterprise buyers can review deployment and trust details more directly.
  • Refreshed the public enterprise investigation, demos, support, security, and documentation pages around evidence-backed workflows.

Security

  • Made Security uploads require full IDS coverage before presenting security results.
  • Surfaced Suricata ATT&CK mappings and preserved MITRE alert details through sharkd scan sessions.
  • Separated marketing consent from operational service email so report delivery and product communications follow distinct customer choices.

Agent

  • Refined progressive investigation workflows across upload, Agent, Analyzer, Triage, reports, and docs so fast findings and verification stay easier to follow.
  • Validated progressive large-capture Agent workflows, including selector-focused runs and follow-up report delivery.

Performance

  • Raised supported upload sizing to 10 GiB where enterprise limits allow it and aligned nginx, rate-limit, and product guidance around larger captures.
  • Hardened sharkd runtime, ingestion queueing, IDS aggregation, and scan-session lifecycle behavior for more reliable capture processing.

Bug fixes

  • Fixed Suricata findings in capture summaries and upload insight signals.
  • Improved security dashboard presentation, upload lifecycle status, and analysis history labels during IDS and Agent runs.

Anoncap

  • Refreshed the public anoncap experience as part of the enterprise investigation story, with clearer workflow and download presentation.
Open release note

Week of July 13: progressive Agent, governance, and connection graphs

Added progressive upload analysis, delivered persisted visual reports, expanded enterprise organization governance, and improved scalable connection evidence.

AgentPerformancePlatformSecurityBug fixesOn-prem

Agent

  • Added progressive upload analysis lifecycle tracking so early findings, deferred reports, and verified follow-up work stay connected as one investigation.
  • Delivered persisted visual Agent reports in the app and follow-up emails, with dark-theme report polish and cited packet-evidence visuals.
  • Hardened replay, stream continuity, final report resolution, and deferred report delivery so reopened or long-running Agent sessions recover more cleanly.
  • Added deeper verification guidance for Agent runs, including stronger Diameter, ICMP, TCP, Wi-Fi, VoIP, and telecom investigation behavior.

Performance

  • Improved connection insights graphs, tables, state accuracy, and on-demand TCP trace loading for larger connection inventories.
  • Reused bounded TCP evidence across graph tabs and scaled connection rule attribution so heavy traces can surface clearer connection-level explanations.
  • Split protocol post-index and packetstats processing into more bounded runtime modules, improving reliability of derived evidence generation.

Platform

  • Added enterprise organization administration, capacity controls, workspace governance, and clearer organization documentation.
  • Preserved SaaS AI upgrade intent through checkout and made paid-plan AI access requirements explicit in upload and Agent workflows.
  • Added runtime data-retention maintenance controls and canonical ingestion stage families for clearer operational status.

Security

  • Bound customer AI egress approvals and enterprise AI worker authority to organizations.
  • Hardened organization authorization boundaries and documented workspace security behavior.
  • Improved newsletter unsubscribe and SNS feedback handling for customer communication controls.

Bug fixes

  • Fixed connection finding evidence, hotspot evidence correctness, connection detail loading, and scalable graph generation.
  • Added upload report capacity fallback persistence so a report can still be surfaced when the primary Agent path is capacity-limited.
  • Restored Agent page initialization, stream controls, frontend report API imports, and required artifact failure propagation.

On-prem

  • Updated enterprise and on-prem deployment guidance around organization governance, capacity planning, upload limits, and controlled AI egress.
Open release note

Week of July 6: upload report controls and large-capture validation

Added upload-time Agent report controls, strengthened report completion, expanded large-capture validation, and hardened AI egress certificates.

AgentPerformanceSecurityBug fixes

Agent

  • Added upload report settings so teams can choose Agent run behavior during upload instead of waiting until the investigation page opens.
  • Hardened Agent report completion and export recovery so finished analyses are less likely to miss report artifacts after longer runs.

Performance

  • Expanded large-capture packetstats validation coverage to keep recommended scan ranges and anchor evidence reliable on heavier traces.
  • Tightened post-index and packetstats coverage checks so analyzer readiness depends on the evidence needed for large-capture triage.

Security

  • Extended generated AI egress proxy leaf certificate lifetime to reduce avoidable provider connection failures in controlled egress deployments.

Bug fixes

  • Improved cached Agent evidence fetch behavior used by report exports and reopened investigation views.
Open release note

Week of June 29: Wi-Fi triage, RCA reports, and static delivery

Improved Wi-Fi investigation surfaces, added visual RCA report exports, strengthened transport guidance, and hardened SaaS static runtime paths.

PerformanceAgentBug fixesPlatform

Performance

  • Added Wi-Fi frame taxonomy and hotspot signals so wireless captures surface beacon, probe, retry, and quality patterns more directly.
  • Improved topology, DSCP, and TCP response modeling signals in analyzer context so performance investigations get clearer path and congestion evidence.
  • Optimized small Wi-Fi capture imports and deferred heavier analyzer insight loading to make first views responsive on lighter traces.

Agent

  • Added visual RCA report support so Agent findings can be exported with richer evidence and investigation context.
  • Connected Wi-Fi dashboard findings to Agent prompts and packet pivots, helping teams move from a wireless symptom to targeted analysis.
  • Persisted Agent launch audit metadata so upload-to-Agent handoffs are easier to recover and explain.

Bug fixes

  • Fixed Wi-Fi dashboard hydration, fallback, recovery, and pulse states so wireless evidence remains visible across capture refreshes.
  • Retained failed upload preprocess sources and fixed a terminal follow-up ingest stage to make failed or interrupted imports easier to diagnose.
  • Tuned duplicate capture-quality warnings so recapture guidance is less noisy.

Platform

  • Refreshed public demo, marketing, pricing, and Packet AI comparison pages for the SaaS site.
  • Hardened static export canaries and frontend runtime path generation for the next PacketSafari deployment.
Open release note

Week of June 22: steadier Agent reporting and transport evidence

Improved upload report handoff, richer Agent evidence replay, Citrix transport quality signals, on-prem proxy guidance, and anoncap fidelity coverage.

AgentPerformanceBug fixesOn-premAnoncapPlatform

Agent

  • Made upload report triage more reliable when an analysis moves from upload into Agent, including deferred report emails and handoff edge cases.
  • Improved Agent replay recovery so reopened investigations preserve richer evidence previews without duplicate streamed events.
  • Rendered cached decode ranges, enriched connection pages, record list cells, and tool output summaries more clearly in Agent evidence cards.
  • Added a bottom thinking state for quiet Agent runs so long-running analysis still shows visible progress.

Performance

  • Added Citrix transport quality analysis to help teams spot ICA session health issues and navigate directly to relevant protocol signals.
  • Fixed queued DNS and TLS metadata materialization so large-capture readiness and starter briefs have more complete post-index context.
  • Tightened capture completion and derived readiness gates to avoid showing stale or premature analysis states.

Bug fixes

  • Fixed analyzer breadcrumb navigation races and upload report progress badge states in active investigation workflows.
  • Corrected nested structured answer summaries and cached evidence rendering so timeline content is easier to scan.
  • Improved report email task durability when a worker is interrupted during deferred Agent report delivery.

On-prem

  • Documented corporate upstream proxy setup and refreshed on-prem egress approval guidance.
  • Hardened the iron-proxy integration, including SES static credential handling and generated proxy guard configuration.
  • Added a safer SaaS frontend-only publish switch and backend build metadata handling for release operations.

Anoncap

  • Updated IDS fidelity and telco anoncap sweep coverage, including the public anoncap capability matrix.
  • Pinned the Wireshark build to include the latest anoncap fix used by PacketSafari processing.

Platform

  • Surfaced demo account expiration in the app account menu and profile view.
  • Refreshed frontend dependency policy and release markers through the beta.70 SaaS candidate series.
Open release note

Week of June 15: steadier no-AI workflows and analyzer signals

Improved no-AI shared capture behavior, strengthened Agent continuity, added analyzer hotspot signals, and hardened static delivery.

Bug fixesAgentPlatformSecurityPerformance

Bug fixes

  • Kept no-AI shared captures from showing AI insights or waiting on packetstats polling after analysis is already in a skipped terminal state.
  • Guarded upload insights and starter brief refreshes so stale capture transitions cannot overwrite the active analysis view.
  • Fixed Agent chat reuse conflicts and tightened streamed message deduplication so returning to an investigation is less likely to show duplicate or conflicting responses.

Agent

  • Simplified persisted plan normalization in Agent transcripts so reopened analysis runs keep a cleaner, more consistent activity trail.
  • Updated AI lane documentation around upload and entitlement flows so teams can more clearly tell when public, private, or no-AI behavior applies.

Performance

  • Added an incomplete-handshake fan-in signal for analyzer hotspot guidance, giving teams better evidence when connection setup patterns point to investigation priorities.
  • Registered Citrix ICA hotspot fixture contracts to keep protocol-specific analyzer behavior covered by repeatable public corpus cases.

Platform

  • Generated static SEO assets for the public frontend and fixed CloudFront handling for static WASM assets used by the analyzer site.
  • Published the v10.0.0-beta.60 release marker and refreshed release portal deployment guidance.

Security

  • Updated the backend JWT dependency requirement as part of routine platform hardening.
Open release note

Week of June 8: clearer AI lanes and steadier analysis flows

Added clearer AI mode controls, stabilized Agent reattach behavior, and improved capture list and file preview reliability.

AgentBug fixesPerformancePlatform

Agent

  • Added clearer public and private AI mode metadata across Agent reports, analysis history, capture lists, and exported findings.
  • Introduced gated AI mode selection in Agent and Copilot so teams can confirm the intended analysis lane before starting work.
  • Polished Agent transcript, history, and upload-to-analysis flows so active investigations are easier to follow.

Bug fixes

  • Fixed stale stopped Agent runs that could appear active or auto-reattach after they had already ended.
  • Prevented duplicate live final answers during Agent streaming and improved terminal-state handling when reconnecting to an analysis.
  • Made file-object previews and downloads more reliable when sharkd returns multiple websocket payloads together.

Performance

  • Routed built-in PCAP list quick filters through explicit SQL fast paths so large workspaces respond more consistently.
  • Kept capture list rows useful even when histogram previews fail, instead of letting optional preview data block the list.

Platform

  • Updated the public product story and docs around PacketSafari Triage, AI lanes, and launch-time analysis paths.
  • Marked the release portal environment as SaaS and prepared follow-on beta releases for the current candidate line.
Open release note

Week of June 1: cleaner hotspot guidance and release housekeeping

Refined packet hotspot scoping, clarified SaaS renewal messaging, and tightened compatibility checks.

Bug fixesPerformanceAgentPlatform

Bug fixes

  • Reduced duplicate parent connection hotspots so packet-list and Agent pivots stay focused on the actual evidence window.
  • Limited noisy connection hotspots that could distract from higher-value TCP, DNS, RTP, and mDNS signals.
  • Fixed Codex compatibility gaps in the Agent runtime and clarified Paddle renewal notifications for SaaS users.

Performance

  • Tightened sampled minimap hotspots and TCP stall hotspot parents so large traces produce less broad, repetitive guidance.
  • Added coverage around bounded HTTP auth, RTP, TCP timing, sparse ACK, duplicate ACK, and DNS hotspot behavior.

Platform

  • Retired legacy knowledge-base route publishing in favor of the current public docs route model.
  • Added a SaaS hotspot contract checker for the next.packetsafari.com candidate host.
Open release note

Week of May 25: bounded hotspot evidence and production fixes

Focused packet evidence, repaired stale hotspot guidance, and improved production responsiveness.

PerformanceBug fixesAgentPlatform

Performance

  • Localized DNS, ARP, SIP, Wi-Fi, SMB, TCP stall, DF-clear retransmission, and security-alert hotspots to actionable packet windows.
  • Suppressed broad minimap and PacketStats spans that made large captures feel noisier than they needed to be.
  • Improved AI history list queries, PCAP quick filters, backend responsiveness, and upload-insights hot paths.

Agent and Copilot

  • Carried representative hotspot guidance into Ask AI and packet pivots so Agent and Copilot answers start closer to the right frames.
  • Fixed Copilot completed-run replay and completion projection for reattached chats.
  • Improved cached Agent evidence rendering and saved-analysis display after upload report delivery.

Bug fixes

  • Fixed field-row range overflow handling, client log ingestion content-type handling, generation-scoped reprocess cleanup, and stale backend hotspot guidance.
  • Hardened duplicate upload detection, PCAP scope refresh, password reset validation, and orphaned indexing lock healing.

Platform

  • Added an admin activity summary page, protocol presence icons in the PCAP list, stable demo capture IDs, and polished Agent report email rendering.
  • Wired SES delivery through the egress proxy path and improved transactional email templates.
Open release note

Week of May 18: telco hotspots and large-capture bounds

Improved telecom hotspot fidelity and made large-capture evidence windows safer and faster.

PerformanceBug fixesAgent

Performance

  • Bound PacketStats hotspots on large captures so broad traces produce representative evidence instead of oversized packet spans.
  • Trimmed enriched connection read paths to reduce latency while loading connection-heavy captures.
  • Surfaced bounded hotspot evidence directly in the packet list for quicker analyst triage.

Agent

  • Added structured JSON text extraction support so streamed and persisted AI outputs can be normalized more consistently.
  • Improved telecom hotspot fidelity for telco-heavy traces and aligned private telco harness coverage with current fixtures.

Bug fixes

  • Fixed skip-scan handling, UI heuristics, and SSE reattach behavior around long-running analysis flows.
Open release note

Week of May 11: upload, Agent, and reprocess stability

Expanded upload-time analysis, protected reprocess metadata, and made Agent run continuity more reliable.

AgentBug fixesPerformanceSecurityOn-prem

Agent

  • Added a prompt-driven Agent upload flow with clearer starter prompts, recent-run continuity, and preserved final answers.
  • Improved Agent reattach behavior, upload report polling, transcript replay, AI history rendering, and quick summary email flows.
  • Placed recent AI runs and starter prompts into a cleaner upload workflow so users can resume analysis without losing context.

Performance

  • Integrated a full PacketStats scan workflow with large-scan guards, cached sharkd sessions, and stronger connection prioritization.
  • Autosized worker concurrency from host resources and raised the indexing ceiling where the host can safely handle it.
  • Improved packet row click responsiveness, fast-scroll loading, and security summary polling bounds.

Bug fixes

  • Safely reprocessed existing captures while preserving owners, ACLs, public access, and migration metadata.
  • Fixed upload insight refresh, raw-only capture states, report transcript duplication, Nagle promotion, stale connection snapshots, and AI usage exhaustion handling.
  • Added recovery for truncated uploads with editcap and bounded sharkd indexing retries.

Security and on-prem

  • Guarded SaaS heavy endpoints with rate limits and restricted PCAP downloads to owners and admins.
  • Wired the on-prem runtime to PostgreSQL and improved release tooling, migration checks, and entitlement documentation.
Open release note

Week of May 4: bulk analysis and scan-plan summaries

Advanced large-capture materialization, scan-plan summaries, and capture-aware Agent intake.

PerformanceAgentBug fixesPlatform

Performance

  • Built bulk-analysis fact contracts, scheduler primitives, scan-plan summaries, and PacketSafari-wide representative summaries for larger captures.
  • Reused postindex rows across materialization epochs and queued only deferred work where inline results were already available.
  • Advanced 1.2 GB materialization validation and moved JA signatures into shared postindex facts.

Agent

  • Added capture-aware intake framing and clarification prompts so Agent runs can ask for the missing scenario details before deep investigation.
  • Routed analysis through capture navigation maps, reducing mismatches between Agent evidence and analyzer navigation.

Bug fixes

  • Fixed postindex finding completion semantics, missing JA summary state, stale postindex placeholders, and DoH profile rule coverage.
  • Allowed scan-plan rulestats parameters and guarded broad AI profile rules for scan-plan execution.

Platform

  • Added bulk-analysis validation harnesses, runtime settings, and support for building patched Wireshark refs.
Open release note

Week of April 27: large-capture materialization and test ladder

Improved upload indexing speed, PacketStats materialization, capture summaries, and release validation.

PerformanceBug fixesPlatformAgent

Performance

  • Sped up upload indexing materialization with native sharkd range reads, bounded DNS and TLS metadata paths, and reduced tshark fallbacks.
  • Collapsed redundant ARP and DNS postindex queries, reused upload insight snapshots, and trimmed stored PacketStats payloads.
  • Added guarded full-context shard workers and packet caps for fields-row evidence requests.

Platform

  • Added the test ladder harness and stabilized non-paid validation lanes for frontend, backend, sharkd, and integration coverage.
  • Expanded IDS fidelity manifest support and stored fidelity baselines under the external data root.
  • Increased the frontend build heap limit for static production builds.

Agent and analyzer

  • Added PCAP list AI analysis overview, capture quality summaries, and clearer AI thread history details.
  • Moved AI analyses earlier in workspace navigation and tuned PCAP action colors.

Bug fixes

  • Fixed upload packet view routing, PCAP library navigation, OT tab availability, upload insight readiness, and production Agent placeholders.
  • Corrected AI usage quota units and queued histogram materialization fallbacks.
Open release note

Week of April 20: fused indexing, Agent intake, and anoncap

Combined postindex scans, added Agent case context, and refreshed anoncap workflows and docs.

PerformanceAgentAnoncapSecurityOn-prem

Performance

  • Fused postindex manifest rows into PacketStats scans and enabled safe ranged execution for repeated postindex work.
  • Added upload indexing timing breakdowns, sharkd transport timing, and manifest hydration diagnostics.
  • Reduced supplemental signal probes and reused PacketStats protocol rows during indexing.

Agent

  • Added Agent case context intake for scenario, measurement point, appliance, and symptom details.
  • Added cooperative cancellation status for eligible heavy analysis tasks.
  • Kept PCAP starter risks visible across navigation and repaired Codex transcript history rendering.

Anoncap

  • Refreshed the anoncap marketing flow, download page, feature matrix, public-share presets, adaptive slicing defaults, and coherent fileset documentation.
  • Added protocol coverage regressions and clearer pro comparison rows for field-aware anonymization.

Security and on-prem

  • Added admin AI usage controls, entitlement controls, on-prem license tooling, active runtime image release behavior, and SAML certificate fingerprint configuration.
  • Restricted Agent debug payloads to admins and gated analyzer telemetry behind explicit opt-in.
Open release note

Week of April 13: Agent evidence, TCP diagnosis, and corpus coverage

Improved Agent evidence rendering, TCP diagnostics, upload readiness, and contextual detections.

AgentBug fixesPerformanceSecurityPlatform

Agent

  • Improved Codex Agent evidence rendering, cache and endpoint evidence cards, transcript rendering, and error handling.
  • Fixed stale starter-brief runs, upload insight readiness, and Codex tool transcript rendering.
  • Added on-demand deep TCP diagnosis and richer analysis UX around packet evidence.

Analyzer

  • Added modeled TCP composite views, viewport-aware TCP charts, PMTUD fallback detection, malware delivery chain detection, and legacy exfiltration signals.
  • Expanded contextual severity handling for timing, transport, and TLS-SIP cases.
  • Restored corpus case library surfaces and connected PCAP inventory into admin and packet-stats documentation.

Performance

  • Guarded PCAP sparklines against huge histograms and gated the web delivery detector with PacketStats.
  • Used lightweight upload status streams for live upload insights.

Bug fixes and security

  • Tightened auth behavior, magic login expiry coverage, tool execution fallbacks, dependency age policy, and runtime compatibility.
  • Fixed paginated totals in PCAP lists and local Wireshark column sync drift.
Open release note

Week of April 6: security, on-prem, and Codex streaming

Shipped on-prem onboarding, stronger capture access controls, signed sharing, and live Codex steering.

SecurityAgentOn-premAnoncapBug fixes

Security

  • Hardened memory endpoints, capture file access, anonymous fallback behavior, XML import, CSV export, BYO key storage, and Codex tool identity checks.
  • Escaped untrusted report metadata and report prompt content before rendering.
  • Reapplied capture ACL checks to workspace Agent runs and added signed viewer access for private lab captures.

On-prem

  • Added on-prem onboarding, registry-driven secret provisioning, initial admin bootstrap guidance, and cleaner local data root handling.
  • Improved Wireshark runtime packaging, production base image pinning, and env layout deduplication.

Agent

  • Added live Codex steering, thread state passthrough, shared prompt actions, and trace-specific starter brief previews.
  • Migrated the backend AI runtime off LangChain toward the native PacketSafari Agent runtime.

Anoncap

  • Added the anoncap landing page, adaptive slicing, unsupported-payload policy controls, map reports, and upload report flows.

Bug fixes

  • Fixed manual archive and restore actions, missing capture-file handling, packetstats regeneration, analyzer runtime fallbacks, and frontend content entry syntax.
Open release note

Week of March 30: runtime hardening and SaaS controls

Stabilized SQL-backed runtime views, added SaaS paywalls, and improved upload and identity controls.

SecurityPlatformBug fixesPerformance

Platform

  • Stabilized SQL-backed dashboards and chat runtime sync.
  • Added SaaS paywalls, pricing upsells, social login flags, and profile-based egress allowlists.
  • Improved packet-stats runtime surfaces, admin diagnostics, and upload audit logging.

Security

  • Hardened container egress with host approval requirements and adopted uv-managed runtime Python package installation.
  • Expanded enterprise auth controls, on-prem proxy flow hardening, and egress allowlist coverage.
  • Removed a stale Zeek update path and documented the supply-chain policy.

Analyzer

  • Added permission-aware PCAP duplicate detection, optimistic PCAP deletion, compact security summaries, and compact PacketStats summaries.
  • Improved memory items and telecom summaries in Agent-facing analysis.

Bug fixes

  • Fixed workspace navigation routes for captures and rules.
  • Tightened network topology label coverage and PacketStats regression behavior.
Open release note
v4.1.0-next

Agent transcript controls and on-prem onboarding

Sharper Agent progress replay, clearer runtime auth choices, and documented on-prem deployment handoff.

AgentOn-premPlatform
  • Improved Agent transcript playback with clearer nested event rendering, replay controls, and workflow-state handling for longer investigations.
  • Expanded runtime AI auth handling so deployments can separate shared deployment credentials, stored user API keys, and ChatGPT / Codex login more cleanly.
  • Documented the current on-prem onboarding handoff so installs move from host bootstrap into /onprem/onboarding with a clearer validation and finalize flow.
Open release note
v4.0.0

Modern stack rebuild

Rewrote the platform on current libraries and a Nuxt UI frontend for faster, cleaner workflows.

Platform
  • Migrated core services to the latest runtime stacks for longer support windows.
  • Refreshed the UI on Nuxt 4 + Nuxt UI to standardize layouts, tokens, and accessibility.
  • Unified API contracts so Copilot, Agent, and capture tools share the same data shape.
Open release note
v3.9.0

Wireshark 4.7 engine

Analyzer parsing now tracks Wireshark 4.7 for richer dissectors and field coverage.

PlatformPerformance
  • Updated dissection profiles to match Wireshark 4.7 field names and enums.
  • Improved decode compatibility for newer TLS, QUIC, and HTTP/3 flows.
  • Reduced mismatch warnings when importing traces from 4.7+ clients.
Open release note
v3.8.0

Copilot chat upgrades

Faster streaming, stronger context building, and clearer answers in Copilot.

Agent
  • Improved context assembly for large traces so Copilot stays grounded in packet evidence.
  • Added richer citations from frames, protocols, and follow-stream summaries.
  • Streamlined live chat playback to reduce latency spikes during long answers.
Open release note
v3.7.0

Most-requested Agent mode: Evidence Trail

A new Agent mode that keeps investigations tight, repeatable, and annotated.

Agent
  • Runs playbook-style investigations with explicit goals and checkpoints.
  • Captures tool calls, reasoning, and outputs for smoother analyst handoffs.
  • Produces a final report with links to frames, streams, and exports.
Open release note