Week of July 27: guided intake, faster Triage, and expanded security analysis

Unified capture investigation setup, expanded capture-wide threat detection and IDS controls, improved upload and Triage performance, and made Agent reports and reconnects more dependable.
platformperformanceagentbug fixessecurityanoncapon prem

Platform

  • Unified investigation setup across upload, the capture library, and workspace views so the question, analysis workflow, operator control, privacy, and delivery choices stay coordinated without being conflated.
  • Added selectable Triage processing profiles with clearer planning estimates, progress stages, and a focused “Is the network at fault?” investigation shortcut.
  • Refined public plan and upload guidance so evaluation limits, enterprise options, and the distinction between preliminary and comprehensive results are easier to understand.

Performance

  • Reused exact capture foundations and persisted evidence across processing stages, avoiding redundant indexed snapshots and repeated packet scans.
  • Replaced expensive histogram work during intake with a bounded Sharkd activity preview, improving early capture feedback while deeper processing continues.
  • Streamed upload hashing and staging, reused capture metadata work, and folded deduplication and full IDS coverage into the primary packet scan to reduce repeated I/O before analysis.
  • Added bounded compiled-rule caching and deduplicated post-index artifacts so repeated security scans and large-capture processing use less CPU, memory, and storage.
  • Reduced capture-storage write amplification and tightened worker and IDS cache boundaries for more predictable large-capture operation.

Agent

  • Added prompt coaching that helps turn broad questions into responsible fast-path investigations and redirects unfocused work toward capture-wide Triage when appropriate.
  • Shipped selector-first discovery and exact flow retrieval so focused investigations can reach packet evidence sooner without treating the whole capture as model context.
  • Made investigation threads, timelines, and report milestones durable across reconnects and page reloads, with safer recovery of active upload-launched runs.
  • Strengthened causal verification so strong preliminary candidates receive explicit verification outcomes and clearer customer-facing reports.

Bug fixes

  • Fixed chunk-upload permission isolation, upload finalization locking, and replay routing issues that could interrupt capture intake or launch the wrong investigation path.
  • Recovered stalled Triage follow-up work more reliably and kept active Triage, IDS, and Agent progress synchronized across capture views.
  • Corrected verification cards, report hydration, transcript replay, and milestone email layouts so completed findings remain visible and readable.
  • Restored contextual capture actions and preserved confirmed Triage settings when reopening or launching work from the capture library.

Security

  • Made enterprise retention behavior explicitly opt in and tightened storage permissions for uploaded chunks and runtime artifacts.
  • Added capture-wide behavioral C2 and periodic-callback detection with bounded connection evidence, explicit coverage, and guardrails for benign discovery traffic.
  • Expanded deterministic detection for DNS tunneling and covert channels, aggregate scans and floods, OT command anomalies, Active Directory attack paths, and RDP proxy downgrades.
  • Added selectable ET Open and Stamus Lateral rule sources for each investigation, with Stamus lateral-movement coverage enabled by default and manageable through Intelligence feeds.
  • Made complete IDS coverage durable and explicit across progress, findings, and clean outcomes, including recovery when an active scan lease expires.
  • Refreshed production dependency and supply-chain coverage, and packaged the egress firewall entrypoint used by controlled outbound deployments.

Anoncap

  • Consolidated Anoncap privacy controls across upload and existing-capture workflows, with simpler choices and clearer packet-slicing guidance.
  • Expanded private workflow coverage for anonymized uploads while keeping processing and investigation choices visible as separate controls.

On-prem

  • Completed the PostgreSQL-only runtime transition in active deployment guidance and removed obsolete Elasticsearch migration references.
  • Hardened nonroot worker storage and authentication persistence for longer-running managed investigations.
  • Expanded qualified local and alternative AI model support with cached capability records, drift audits, safer provider isolation, and controlled OpenRouter routing for egress-restricted deployments.