Category: Release Notes – AIR

Binalyze AIR 4.11

Welcome to the AIR 4.11/4.10 release blog which introduces features and enhancements designed to streamline your forensic investigations and improve system functionality. 

Highlights include the debut of Frank, an AI Assistant poised to revolutionize investigation processes within the AIR console by offering real-time forensic support and insights. 

Additionally, we’ve again expanded our support for new evidence types to over 580 items across Windows, macOS, IBM AIX, and Linux. We have also introduced key enhancements like error reporting in disk imaging, task scheduling based on asset timezones for synchronized operations, and an improved Auto Asset Tagging wizard for organizational flexibility.

Thanks to some prompt feedback from some of our great customers, an important timestamp issue with the Event log content has been fixed.

Please read on for the details. 

Features

digital forensics and incident response AI assistant

AIR 4.11 Introduces Frank.AI – Your Forensic Investigation Copilot

We’re excited to unveil Frank.AI in our AIR 4.11 preview release. Frank is an AI Assistant designed to seamlessly integrate into your workflow, enhancing the forensic investigation process within the AIR console. Here’s everything you need to know about Frank.AI and how it can transform your investigative work.

What Can Frank.AI Do for You?

Frank.AI is not just another tool; it’s your investigation partner, available anytime, directly within the AIR console. Frank.AI aims to provide:

  • Direct Access: Instant availability across the AIR console for any inquiries, speeding up your investigations.

  • Instant Knowledge Support: Quick, AI-powered insights to bridge gaps in your forensic analysis, ensuring you’re always prepared for the next step.

  • Enhanced Rule Creation: Simplified creation of YARA, Sigma, and Osquery rules, expanding your toolkit without the complexity.

As we launch Frank.AI, remember that this is just the beginning. Frank.AI will evolve, shaped by your feedback and the integration of advanced AI technologies, to offer even more nuanced assistance.

Frank.AI in AIR 4.11: Preview Version Highlight

In this initial rollout, Frank.AI leverages the ChatGPT API to assist with forensic-related questions, including advice on YARA, Sigma, and Osquery rules. While this version doesn’t include fine-tuning or pre-training, it sets the groundwork for substantial future enhancements.

Upcoming Enhancement

  • Retrieval Augmented Generation (RAG): Future versions will see Frank.AI accessing a wider array of data sources for broader, more accurate responses.

  • Deeper AIR Ecosystem Integration: Frank.AI will eventually fetch data directly from the AIR database, integrating more deeply into the AIR framework for enhanced capabilities.

  • Advanced Analysis Features: Expect Frank.AI to offer anomaly detection and behavioral correlations by analyzing data through the AIR’s AI module.


How to Interact with Frank.AI

To start a conversation with Frank, look for the Frank AI chat icon on any page within the AIR Console, positioned in the bottom left corner over the settings icon. Frank is ready to assist with digital forensics, incident response, or any aspect of your investigation.

Requirements and Security

Frank.AI is hosted on one.binalyze.ai and available to all licensed AIR users. Developed with a focus on security, Frank.AI operates through a proxy server, ensuring that no customer data is sent to external services. Users are advised not to share confidential information within their messages and prompts.

The Road Ahead

Frank’s journey is just beginning, with ambitious plans for expansion and enhancement based on your feedback and the evolving needs of digital forensic investigations. Our dedicated Confluence page will keep you updated on Frank’s development and the exciting new features we have in store.

Conclusion

Frank.AI represents a significant leap forward in forensic investigations, providing AIR users with an intelligent, accessible assistant that simplifies complex processes and enhances investigative capabilities. As we continue to develop Frank.AI, we’re excited to see how it will transform the way you approach forensic analysis and investigation within the AIR ecosystem. 

digital forensics and incident response AI

 

Yet more evidence types are supported in 4.10/4.11

 

New Windows evidence types:


Binalyze AIR 4.9

Introduction

These latest AIR releases are all about automating the routine tasks of every AIR user, from the SOC analyst to the threat hunter. In addition to automatic evidence collection,  analysts can now also schedule tasks for Triage, disk/volume imaging, and auto asset tagging.  This ensures greater control, shifting the focus from manual to automated operations. To further streamline this process, and establish the Investigation Hub as your dedicated space to conduct every investigation, we’ve sunset the old reporting format. AIR’s Investigation Hub is automatically updated with findings and insights based on the tasks that are running in the background.

Additionally, we’d like to remind everyone that in the previous version, we introduced a new Docker container for the File Explorer feature. If you’re interested in utilizing File Explorer, please reach out to your customer success manager.

Please read on for the details:

 

Features
  • New Task Scheduling capability integrated into the AIR tasking wizard.

    • Investigators can now use the tasking wizard to schedule the following activities:

      • Evidence collections.

      • Triage/Threat Hunting. (Credit: Turgut Ö)

      • Disk and Volume Imaging.

      • Auto Asset Tagging. 

    • Scheduled tasks can be assigned to a Case.

    • The timezone for task execution can be adjusted.

    • The recurrence rate can be set to Daily, Weekly, or Monthly.

    • The sequence can be stopped at a particular date and time or after a defined number of occurrences.

007443ef-c68e-4753-99b9-8115f6660ff5

  • New Windows evidence type

    • AIR now parses the Window $USN Journal and saves this file to the evidence repository as a .csv file for easy analysis (Credit: David C) 

ca685529-f28c-44a2-9a46-435d7cc04fad

 

  • Isolate multiple assets simultaneously 

    • Users can now select multiple assets and execute a bulk action to isolate any desired number of assets simultaneously. (Credit: Samer H) 

Binalyze AIR 4.7 Release

Features

In AIR version 4.7, a new Docker container has been introduced to enable the new File Explorer feature. If you plan to use File Explorer and are upgrading from an older version instead of performing a fresh installation, you can upgrade as usual. Only contact our support team if you want to enable the File Explorer feature.

Introducing AIR’s new File Explorer

AIR can now be used to explore the file systems of Windows, macOS, and Linux systems where full disk or volume images have been acquired in the RAW format. 

The forensic image can be added to AIR as a new Asset in a three-step process:

  • 1. On the Assets page, click on the ‘Add New’ button and then select Disk Image:

4.7(1)     

  • 2. Select your connected repository and then the raw disk image you wish to explore:

 4.7(2)

 

  • 3. Select ‘Create Asset’: