Tag: Binalyze AIR

Binalyze AIR v5.16

What’s New?

  • AIR File Explorer XFS Partition Support: Added support for recognizing and parsing XFS partitions in disk images. Analysts can now browse and analyze evidence from XFS-based assets directly within AIR File Explorer.

  • Expanded Windows evidence coverage in Baseline Comparison: Baseline Comparison is enhanced with support for 40+ new Windows evidence sources, along with new section constants and table-to-section mappings to extend comparison coverage across file system activity, registry artifacts, system and network data, SRUM, and other forensic evidence sources. macOS section constants and mappings were also reformatted for improved consistency.

  • Enhanced RelayPro: Upgraded RelayPro with a new toolchain and dependency improvements enhances responder–console communication security and reliability. This ensures uninterrupted evidence transfers and more resilient responder connectivity during large-scale, distributed investigations.

New Features & Improvements


Expanded Windows evidence coverage in Baseline Comparison

Baseline Comparision coverage was significantly expanded through the addition of more than 40 new Windows evidence items with appropriate identifier fields and ignore fields mappings introduced to support accurate comparison behavior across a broader set of artifacts. To enable these new evidence types throughout the comparison pipeline, 12 new Windows section constants and related table-to-section mappings were also added. In addition, macOS section constants and table mappings were reformatted for more consistent alignment and improved maintainability.

The newly supported Windows evidence sources were added across multiple investigation areas, including file system and user activity artifacts such as crash dumps, recycle bin, system restore, downloads, shell bags, LNK files, and jump list data; registry artifacts such as AppCompatCache, UserAssist, Recent Docs, Typed URLs, Office MRU, and Open/Save MRU; system and network data including processes, TCP/UDP tables, ARP table, and volumes; SRUM-based usage artifacts covering application, network, timeline, energy, and connectivity data; and other high-value sources such as Amcache, browser downloads, dependency manifests, PowerShell ConsoleHost history, and user access logs. Through this expansion, broader visibility into Windows activity and configuration data was enabled, allowing change analysis to be performed with greater depth and consistency.

AIR File Explorer XFS Partition Support Improvements

Full disk images containing XFS partitions can now be opened in AIR File Explorer, and file types within those partitions are displayed correctly. This improvement was implemented to address cases where XFS-based evidence could be accessed, but file type information was not visible, limiting file review and triage during investigations. With this enhancement, evidence stored on XFS partitions can be examined more effectively, enabling faster validation of file contents and improving confidence in incident analysis for security analysts.


Responder Communication Optimization

RelayPro Dependency and Toolchain Upgrades

This release introduces an updated RelayPro component version that enhances responder–console communication reliability and strengthens encryption handling. The updated communication stack ensures secure transmission during live-response operations and improves failover handling for responders working through restrictive networks.

For investigation teams, this means greater confidence in evidence integrity and session reliability during real-time analysis or containment workflows. RelayPro’s enhanced dependency security reduces the risk of communication errors, ensuring uninterrupted connectivity between distributed responders and the AIR Console.

Prevent Avoidable HTTP Requests from Responder

Optimizations have been added to reduce redundant responder–console communication. Responders now suppress duplicate status reports and disable unnecessary retry attempts when a request fails with permanent error conditions (for example, 404, 403, 401 responses). This improvement reduces network overhead during widespread deployments and speeds up recovery during transient connectivity disruptions.


Bug Fixes

  • Incorrect Task Status Display: Resolved an issue where task statuses under Cases → Tasks appeared inconsistent when the main task was cancelled. Statuses now correctly reflect task outcomes across all views.

  • Proxy Configuration Not Applied to External Services: Corrected a defect where AIR Console’s proxy settings did not apply to outbound traffic for feature management and analytics services. Proxy enforcement is now consistent across all external integrations.

  • Investigation Hub Report Generation: Fixed a failure that prevented report generation from evidence sources while reports from findings succeeded. Evidence-based reports now generate reliably.

  • Acquisition Task Report Loading: Addressed an issue where the Investigation Hub report for certain acquisition tasks remained in a loading state. Reports now open consistently within the console.

  • Chrome History Acquisition Integrity: Improved file copy process for the Chrome History database to reduce the risk of corrupted SQLite files, ensuring analysts can examine browser activity with full integrity preservation.



Binalyze AIR v5.15

What’s New?

  • Enhanced interACT Session Visibility: When reviewing historical interACT sessions, the session header now displays the specific task name, helping analysts quickly identify which live-response session they are reviewing—especially when multiple sessions are open in separate tabs. This enhancement improves investigation context and analyst efficiency.

New Features & Improvements


AIR Settings

Independent Universal Trusted Certificate Store

Analysts and administrators can now securely add and manage Trusted Certificate Authorities directly within the AIR Console. Previously, this capability was restricted under proxy configuration, limiting flexibility for enterprises performing SSL inspection without proxies or those utilizing self-signed certificates. The new implementation introduces a certificate store independent of proxy settings, ensuring forensically sound authentication and minimizing reliance on manual container-level changes.

With this enhancement, organizations using strict SSL inspection or network monitoring can now deploy AIR without interruptions to licensing or updates. This proactive measure enhances compliance and operational continuity in high-security environments.


interACT

Display interACT Task Name in Historic Session Headers

In multi-session environments where analysts review past interACT activities, identifying the correct investigation session can be challenging. AIR now surfaces the task name (for example, “AX-Day2.2”) directly in the session header and browser tab. This improvement enhances visibility and supports faster navigation between concurrent evidence reviews.

For investigation workflows, this means analysts can immediately differentiate and correlate live-response sessions without confusion, improving auditability and speed during case validation or retrospective analysis.


Asset Management

Expanded Asset Filter Options

The Registered At field has been added to the Advanced Filters of the Assets page. Analysts can now filter assets based on their registration timestamp, allowing time-based scoping for both live and historical analysis. This feature streamlines investigation scoping, particularly useful when identifying assets registered during or after a known incident window.

Enhanced Auto Asset Tag Search

Tag search capabilities have been extended to include the content of tags rather than only their names. This improvement increases flexibility when classifying or correlating assets, especially in environments with rich tagging datasets. Analysts can quickly locate assets linked by contextual tag descriptions, enabling faster triage and focused response workflows.


Bug Fixes

  • Large Dataset Upload Timeout: Resolved an issue where large acquisition datasets exceeded timeout thresholds during upload or manual PPC processing. Upload stability and dataset handling within Investigation Hub have been improved to maintain continuity across extended acquisitions.

  • Windows Volume Imaging Issue: Fixed a Windows-specific image acquisition bug that caused unexpected failures during remote imaging tasks, ensuring consistent evidence capture across platforms.

  • “Key Not Found” and Authorization Errors in Console UI: Addressed errors occurring after version upgrades and during access to the Assets > Disk Images menu, affecting console usability and access control verification. Global Admin accounts now have consistent authorization visibility.

  • Git Repository Fork Mode Configuration: Resolved a configuration issue preventing edits to repositories in Fork mode where the system incorrectly enforced sync interval parameters.

  • AWS Integration Regional Limitation: Corrected the synchronization behavior that was prematurely terminating global scans if a single AWS region returned an explicit deny response. AIR now continues enumeration across other regions unaffected.

  • Investigation Hub Data Handling Errors: Fixed the reported null property and missing field exceptions in task processing and data publishing services. These stability fixes ensure that investigation data imports and evidence processing continue without interruption.

  • Audit Log Performance Enhancements: Improved the search and pagination performance for audit logs in environments with very large asset counts. Query execution and caching have been optimized to reduce latency and prevent timeout errors.

  • Responder Unisolation Feedback: Enhanced feedback visibility during asset unisolation attempts. Responders now display clear status information when unisolation fails or is incomplete, improving clarity during containment and recovery operations.



Binalyze MITRE ATT&CK Analyzer is now at version 13.0.1

Microsoft 365 Detection Enhancements

The DRONE Tornado Analyzer now includes new detections focused on Microsoft 365 event telemetry. Analysts can identify unauthorized configuration changes such as modifications to audit log settings, narrowing of cmdlet auditing, external sharing misconfigurations, and reduced retention policies. These detections are critical for identifying unauthorized administrative activity and potential configuration weakening tactics observed in cloud investigations.

Additional correlation improvements flag brute-force login attempts, missed MFA flows, suspicious OAuth consent grants, and mailbox permission changes commonly associated with persistence techniques in business email compromise incidents.

Sigma Rule Updates

The integrated Sigma detection library has been synchronized with the latest rule updates from the SigmaHQ and Hayabusa repositories. This alignment expands coverage across both endpoint and cloud telemetry sources, bringing enhanced detection insight into unauthorized script execution, privilege escalation, and registry modification behaviors.

MITRE ATT&CK Analyzer / YARA Enhancements

Version 13.0.1 introduces YARA-based detection for Covenant C2 Grunt HTTP stager and implant activities. These additional signatures support early identification of adversary-controlled command-and-control frameworks during evidence analysis, increasing the confidence and precision of post-incident findings.

Binalyze AIR v5.14

What’s New?

  • Git-Managed Triage Rules: Security and investigation teams can now connect their organization’s Git repositories (GitHub, GitLab, Azure DevOps, or Bitbucket) directly to AIR to manage YARA, Sigma, and osquery triage rules as their single source of truth. This integration supports webhook-based synchronization, secure token handling, and ownership modes such as Mirror or Fork, ensuring consistent, auditable rule management during investigations.

  • Syslog Event Filtering for SIEM Integrations: SIEM-connected environments can now configure which AIR events are forwarded via Syslog. Analysts can focus on critical events, such as login failures or case creation, and exclude repetitive operational data to improve visibility in Splunk, QRadar, or Microsoft Sentinel.


New Features & Improvements

Hunt/Triage

Git-Managed Triage Rules

Analysts can now manage triage rule repositories directly within AIR using Git integrations. Supported platforms include GitHub, GitLab (both cloud and self-hosted), Azure DevOps, and Bitbucket. This update allows analysts to import rulesets as read-only Mirrors or organization-controlled Forks.

Synchronization is asynchronous and resilient, with built-in safeguards for file size and repository limits to prevent performance degradation. Webhooks have been added to trigger automatic updates upon commit or push events, and analysts can review sync details through the interface.

This feature strengthens governance and repeatability of Hunt/Triage operations by ensuring that rule sources are traceable, consistent, and version controlled — vital for regulated or multi-tenant organizations performing coordinated investigations.

Sigma Rule Metadata in Findings

The DRONE analysis component now surfaces additional metadata for Sigma-based findings, including rule Author and Status. Analysts can filter or group results based on these attributes to prioritize confirmed rules and distinguish experimental detections during evidence review.

This improvement encourages more focused security analysis workflows, ensuring organizations can tune detection interpretation based on operational relevance and reliability.


Settings and Integration

Syslog Event Filtering for SIEM Integration

Organizations integrating AIR with external SIEM solutions can now tailor which events are transmitted through Syslog. Three filtering modes are supported: send all events (default), include only selected events, or exclude specified event types. This capability allows security operations teams to minimize noise while ensuring that critical, high-value activities—such as case creation and authentication events—are always streamed.

In addition, AIR’s analytics now report adoption statistics for this feature, helping administrators audit configuration changes through integrated usage metrics.

For security analysts, this enhancement means more concise, actionable event data reaching their SIEM, enabling faster triage and correlation within broader detection ecosystems.

License Usage and Capacity Consistency

License usage reporting has been refined to provide more consistent asset and server capacity data across multiple AIR Consoles sharing a license key. Server and asset counters now more accurately reflect real-time usage, helping administrators maintain compliance and visibility across distributed deployments.

Network Isolation Improvements (Linux & macOS)

Network isolation on endpoints has been enhanced to address critical security gaps. Inbound and outbound traffic is now consistently filtered, and all pre-existing TCP connections are terminated when isolation is activated.

DNS and DHCP behavior has also been improved: they can now be enabled or disabled directly from Policies. When enabled during isolation, DNS/DHCP traffic is allowed system-wide. Additionally, exclusion policies for IPs and processes are now enforced bidirectionally (both inbound and outbound).

If the exclusion policy is empty, all inbound traffic and system DNS are blocked while DHCP remains allowed. These changes ensure more consistent and reliable endpoint isolation across Linux and macOS.


Responder and Tactical Components

Improved Collector Behavior Under Disk Space Constraints

Offline Responder collectors handling CSV operations now terminate gracefully when disk space is depleted. Previously, insufficient disk capacity could trigger excessive repeated logs. The updated behavior ensures immediate error signaling with accurate exit codes, helping analysts distinguish between collector failure types and maintain integrity assurance of collected evidence.

MITRE Version Visibility in Task Logs

The MITRE ATT&CK database version used in task executions is now recorded in task logs and visible within Investigation Hub. This visibility helps analysts correlate findings to the correct ATT&CK version during validation, ensuring version-aligned mapping and interpretation of adversary techniques across analyses.

Responder Service Start Reliability on Windows

Improvements have been made to ensure reliable Responder service startup following Windows patching and reboots. This resolves intermittent startup timeouts that previously resulted in loss of communication between assets and the Console.


RelayPro

RelayPro Operational Enhancements

RelayPro has been strengthened with internal architecture improvements that optimize proxy performance, connection pooling, and runtime configuration. Enhanced logging and reliability safeguards were introduced to support continuous operation at scale, ensuring stable connectivity between responders and the AIR Console during active investigations and large asset populations.


Bug Fixes

  • Investigation Hub and Reporting: Resolved multiple issues related to report generation, including timeouts and incomplete exports when processing large datasets (80+ assets or hundreds of thousands of findings). These fixes ensure stable and complete report output within the Investigation Hub and Case Closure Reports.

  • Filtering Accuracy: Fixed an issue where the “NOT contains” condition in the Findings page’s Advanced Filter returned empty results. This correction restores full functionality for complex search filters used during evidence analysis.

  • File and Repository Explorer: File Explorer and Repository Explorer now load content automatically when accessed, removing the need for manual refresh. This streamlines evidence browsing and improves analyst efficiency when exploring disk images or evidence repositories.

  • Access Control and Asset Permissions: Addressed a penetration test finding indicating potential exposure of asset-group and asset-tag data to read-only roles. AIR now enforces strict access control validation to ensure users only access asset data consistent with their assigned permissions.

  • Asset Management and Role Permissions: Corrected permission logic preventing Organization Admin roles from successfully executing the “Create Disk Image Asset” action in SaaS environments. Role-based operations now behave consistently with configuration across deployment types.

  • Export Stability under Resource Load: General performance improvements were added to avoid incomplete ZIP creation or gateway timeouts during bulk export actions. These refinements help maintain system stability in high-load investigation environments.

  • API Token and Syslog Logging: Fixed inconsistencies where Create and Delete API Token events were not transmitted to external SIEMs via Syslog despite appearing in AIR’s local audit logs.

  • Audit Log Job Optimization: The DeleteOldAuditLogs job has been re-engineered to execute deletions in small batches instead of one large transaction, reducing latency and minimizing impact on shared infrastructure performance.

  • SRUM Collector Value Overflow: Fixed integer overflow that caused insertion errors during SRUM data processing, ensuring stability and accurate timeline analysis. Due to the complexity and high cost of creating a migration for existing console data, legacy records were not modified. As a result, previously opened cases that contain older field types may continue to experience errors related to type differences. To ensure correct functionality with the updated responder fields, customers should create new cases using the new responder configuration when encountering this issue.

  • Investigation Hub Evidence Refresh Issue: Fix applied so that after importing new evidences (CSV/PST), all existing evidences remain visible without requiring page refresh.

  • Asset Uninstall Modal: Fixed the bug where the “Uninstall Responder” modal remained open after operations completed. The modal now closes automatically, confirming successful action completion.

  • Responder Startup Reliability: Enhanced the Windows Responder service behavior to ensure it starts successfully after system reboots following patch installations, eliminating timeout-related communication issues.



Binalyze MITRE ATT&CK Analyzer is now at version 12.5.2

MITRE ATT&CK Analyzer / YARA

This update includes targeted false positive corrections across several YARA and MITRE-mapped detection rules. These refinements deliver more accurate detection outcomes, reducing unnecessary findings for analysts during automated DRONE analysis workflows.

Sigma

DRONE has been synchronized with the latest Sigma rule contributions from SigmaHQ and Hayabusa repositories. This ensures analysts have access to the newest community-sourced detection content aligned with current adversary techniques, extending the breadth and relevance of automated behavioral detection within AIR.

Binalyze AIR v5.13

New Features & Improvements


AIR Console

MITRE ATT&CK Rules Download Optimization and Resilience

The AIR Console now manages MITRE ATT&CK Rules package downloads more efficiently, with improved retry logic and automatic validation of transferred data. This helps investigation teams working with MITRE ATT&CK–based analyses retrieve required rule packs faster and with higher reliability. Both SaaS and on‑prem deployments benefit from improved throughput and reduced risk of incomplete downloads.

Binalyze AIR v5.12

What’s New?

  • Advanced Time Display and Copy Options – The DateTime component within AIR Console now allows analysts to view and copy timestamps in multiple formats including UTC, ISO, local, and relative time. This enhancement streamlines correlation activities across multiple evidence sources and logs during complex investigations.

  • Improved Kerberos Event Collection for KDC Event ID 42 – Added support for critical Kerberos Key Distribution Center events (Event ID 42) within default Windows event collection profiles. This expands detection visibility for authentication downgrade or anomaly scenarios often relevant in enterprise breaches.

New Features & Improvements


Evidence Acquisition & Display Enhancements

Enhance DateTime Component with Detailed Time Display and Formatting Options

The DateTime display now includes a contextual pop‑over that reveals different time formats such as UTC (ISO 8601), UTC, local, relative, and timestamp representations. This multi‑format visibility simplifies event timeline correlation during investigations where evidence originates from assets in different time zones.

When copying any timestamp, AIR generates an event record, supporting operational auditing and user behavior tracking. This aids analysts by ensuring that every time reference used in investigation reports maintains forensic‑level traceability.


Event Log Collection Enhancements

Event Logs Collection Refactor for Windows Profiles

The predefined acquisition profiles for Full, Quick, and Compromise Assessment evidence collection now capture broader and more relevant event record IDs. The expansion improves coverage for key system, security, and application events often linked to suspicious activities or lateral movement indicators.

Analysts benefit from improved context in timeline analysis and reduced need to manually configure event lists. With 214 events in the Full profile, 78 in Quick, and 31 in Compromise Assessment, investigation teams gain deeper operational visibility while maintaining efficient collection volumes.

Support Microsoft KDC Event ID 42 in Default Windows Event Collection

Event ID 42 from the Microsoft‑Windows‑Kerberos‑Key‑Distribution‑Center provider is now included in the default Windows event collection profiles. This change ensures that analysts can identify and investigate Kerberos authentication anomalies such as RC4‑HMAC downgrade attempts. The inclusion streamlines detection workflows without requiring custom configuration, strengthening security visibility across enterprise assets.


File Explorer Improvements

Increase Default Number of Items per Page

The default view within the File Explorer has been expanded to display 100 items per page by default. This change enhances usability during evidence review by reducing pagination and improving contextual visibility for analysts exploring large directory structures within acquired disk images.

File Explorer Multiple Directory Selection Fix

File path handling has been improved when selecting multiple directories for evidence collection. The fix ensures that each directory path is independently compiled, enabling accurate retrieval of targeted evidence folders without unwanted path concatenation. Analysts can now confidently select multiple structures in a single acquisition operation with predictable results.


System and Performance Enhancements

Improved Endpoint Name Change Handling to Enhance System Performance

In certain environments, endpoint name change events could previously be triggered due to misconfigured deployments, particularly in cases involving golden image deployments that did not follow the provided deployment guidelines.This scenario could result in a high volume of asset name changes, generating excessive audit logs and triggering updates on investigations. The combination of frequent asset name updates, audit log generation, and related notifications created significant system load, leading to performance degradation.

In addition, audit log generation and event-based notifications related to endpoint name changes have been disabled, as their operational impact outweighed their functional value.

To improve overall system performance and protect core AIR functionality, endpoint name change handling on investigations and the related audit log generation have been removed, as their operational impact outweighed their functional value. Additionally, the warning status indicating a high number of endpoint name changes—this was added to provide improper golden image deployments—has been removed, as it relied on audit log data.


DRONE Analysis Improvements

Rule Package Updates and Stability Improvements

Underlying logic within DRONE Analyzer and evidence re‑analysis workflows has been refined to prevent nil cache entries that could cause tasks to stall. This ensures that re‑analysis operations on pre‑collected evidence now execute reliably, providing uninterrupted automation for retrospective detection.

The update improves the integrity of re‑analysis tasks, especially valuable for analysts conducting follow‑up reviews using newly released detection rules or refined analyzers.


Responder Component Improvements

Field Naming Enhancement for saveToType and saveToURL

User‑facing configuration fields governing evidence storage destinations have been adjusted for improved clarity. The previous technical naming has been aligned with more intuitive labels, reducing confusion when setting up automatic evidence uploads to external repositories. This small but impactful update enhances ease of use for analysts defining collection workflows or reviewing task configurations.


Bug Fixes

  •  Responder Task Display Field Naming – Standardized the display text for save‑to‑type fields within evidence upload configurations. The corrected naming prevents user confusion during responder configuration.

  • Fixed responder registration handling for environments where multiple assets share identical cloud instance IDs. AIR now intelligently distinguishes assets based on unique identifiers derived from OpenStack UUID or other reliable metadata sources.

  • Addressed a race condition in Tactical Windows Legacy v3.22.0 that could trigger SQLite insert errors during rapid evidence writing. This fix improves the reliability of artifact acquisition on Windows assets.

  • Corrected path concatenation in File Explorer evidence collection so directories are properly resolved. Analysts can now select multiple target directories accurately.

  • Resolved organization selection dropdown disappearing after switching to API‑created organizations within the Console UI. Navigation now remains consistent across all organization types.

  • Improved handling for Audit Logs export API in SaaS mode to prevent timeouts during heavy system activity. The export now operates reliably even when continuous audit events are being written.

  • Fixed several summary and filtering issues on the AIR Home page including unreachable status filters and incorrect category filtering. Home Summary sections now accurately reflect asset and case status counts.

  • Improved Auto-Scaling and Recovery Stability for SaaS Tenants, Some SaaS tenants previously experienced extended auto-scaling and recovery durations due to a potential issue related to database connection handling during application startup.



Binalyze MITRE ATT&CK Analyzer is now at version 12.4.0

Dynamo Analyzer

The Dynamo Analyzer updates focus on refining detection precision and reducing noise. Obsolete functions were removed to streamline the analysis pipeline. False‑positive suppression improvements now filter benign command‑line events from common Windows system processes. A new RunMRU analyzer identifies potentially suspicious commands launched from registry RunMRU entries, giving analysts contextual insight into executed commands that may indicate persistence or manual execution attempts.

Detection for high‑risk file extensions in email attachments was expanded, enhancing visibility into initial access vectors. Overall, the update increases accuracy and ensures faster, cleaner analytical output across browser, shimcache, and process‑based evidence.

MITRE ATT&CK Analyzer / YARA

The YARA and MITRE ATT&CK analyses have been strengthened with new detections for threats such as Pulsar RAT, Interlock ransomware components, OrcaC2 implants, and CrashFix malicious extension. Analysts can now detect these families automatically during DRONE analysis without supplementary rules. Network‑based remote access tools like NetSupport now generate higher‑severity alerts given their frequent use in unauthorized remote access operations. In addition, detections for PowerShell scripts employing XOR obfuscation on Base64 payloads help spot evasion techniques in investigations. The expanded coverage reduces manual rule management and offers forensic‑level detection depth across evidence sets.

Sigma Rules

DRONE now integrates the latest Sigma rule releases from SigmaHQ and Hayabusa repositories, updating hundreds of correlation patterns for system logs and security events. These enhancements ensure that investigation teams leverage community‑validated behavioral signatures to identify new adversary techniques within collected evidence.

Binalyze AIR v5.11

What’s New?

  • Google Cloud Storage support – AIR now supports evidence upload and archival to Google Cloud Storage. This provides analysts and investigation teams with greater flexibility in selecting secure cloud repositories for collected evidence, improving integration with multi-cloud environments and accelerating post-incident data availability for review.

  • Golden Image hostname conflict alert – AIR automatically identifies assets that share duplicated hostnames due to image deployment errors and raises a visible alert within the Console. This ensures analysts can maintain asset integrity during investigations and prevents misattribution of evidence sources.

  • Asset menu restructuring – The redesigned Asset view separates Assets into three intuitive sections: Devices, Disk Images, and Cloud Assets. This streamlined layout helps analysts quickly locate relevant evidence sources, assess responder status, and initiate investigation workflows with improved clarity.

New Features & Improvements


AIR Console – Management

Golden Image Hostname Conflict Alert for Devices

AIR now detects when identical hostnames appear across multiple assets, often due to improper image cloning. When such a condition occurs, AIR displays a clear alert in the Console interface. This helps maintain evidence integrity by preventing investigators from assigning findings to misidentified assets.

For investigation teams, this feature eliminates ambiguity during timeline analysis or DRONE comparison tasks by ensuring each asset’s identity remains unique and traceable across evidence collections and response actions.

Asset Menu Changes

The Asset section of AIR Console has been restructured to separate Devices, Disk Images, and Cloud Assets into distinct categories. Each category includes its own tree view, preset filters, and tailored data grid columns. This structural clarity allows analysts to navigate large environments efficiently, identify responder connectivity status, and focus on relevant evidence sources.

Add Task ID Filter to Get Tasks by Case ID API

The backend API now supports filtering tasks within a specific investigation by task ID. This accelerates evidence tracking, allowing analysts to isolate relevant processing events or review discrete acquisitions as part of automated investigation pipelines.

By refining task selection, investigation teams can quickly pinpoint and validate the execution of evidence collection steps within complex multi-asset operations, improving overall investigative precision.

Filter Users with Role Tag

A new filter capability based on user roles has been added to the management interface. Investigation administrators can now quickly locate users or analysts with specific access permissions, streamlining audit reviews and response approvals.

This enhancement supports improved operational security and control, ensuring that only authorized users are assigned investigation privileges aligned with their organizational roles.


AIR Console & Responder – Evidence Repository

Google Cloud Storage Support

Analysts can now store investigation evidence directly in Google Cloud Storage, extending AIR’s existing multi-cloud compatibility. This enhancement simplifies integration for organizations using Google Cloud as part of their security data infrastructure.

During evidence acquisition or upload task configuration, users can define a Google Cloud Storage repository as the destination. This capability helps ensure forensically sound, integrity-preserving preservation of large evidence sets across global cloud environments while supporting compliance and retention requirements.

For more details: Knowledge Base


Bug Fixes

  • Timeline date selection ignores empty range and snaps to nearest date – Resolved an issue in the Timeline view that caused selected empty date ranges to automatically shift to the nearest available data range. The Timeline now respects the exact range selected by the analyst and accurately displays empty periods when applicable, ensuring chronological integrity during investigation review.

  • Tasks page unresponsive under high task volume – Fixed an issue where the Tasks page failed to load or become unresponsive after a large number of tasks were executed. The performance of task listing and pagination has been improved to support high-volume investigation environments reliably.


Binalyze MITRE ATT&CK Analyzer is now at version 11.6.0

Dynamo Analyzer

The DRONE analysis engine introduces refined detection criteria for process anomalies on Windows. Priority-based process checks have been removed to reduce false alerts, while new logic identifies suspicious process paths and command-line attributes that may indicate adversary use of system binaries for unauthorized activity. Additional enhancements include matching administrative share access events and identifying tool names linked to known privilege escalation or lateral movement behaviors. DRONE also now detects PuTTY host key caches, highlighting potential unauthorized remote access operations.

Sigma

Sigma detection rules have been fully synchronized with the latest repositories from SigmaHQ and Hayabusa. This update expands AIR’s coverage for modern adversary techniques and ensures more consistent cross-referencing with current MITRE ATT&CK mappings during investigation correlation.

Binalyze AIR v5.10

AIR – v5.10 Release Notes

What’s New?

  • Google Cloud Platform (GCP) Support: AIR now extends its cloud forensics and asset management capabilities to Google Cloud Platform. Security and investigation teams can now enumerate, sync, and deploy Responders directly to their GCP assets, enabling consistent, forensically sound evidence collection and incident investigation across multi-cloud environments.

  • interACT 2FA Disable Option: Allows global administrators to disable Two-Factor Authentication (2FA) for interACT access when operational flexibility is required during live-response investigations.

  • Custom Evidence Collection Naming: A new capability in Settings → Console Settings → Features allows users to customize how evidence files and folders are named—whether saved locally on assets or uploaded to remote Evidence Repositories. Users can define a naming template by combining text with variables such as Timestamp, Organization Name, Task Name, Asset Name, and Case ID. Using / in the template creates folder structures for logical organization. This improves repository maintenance and ensures clear separation of evidence in multi-tenant environments. Folder names are limited to 50 characters.

  • Full Text Search: Enables investigators to search both file contents and metadata on remote assets using keywords or regex patterns. This allows targeted searches across documents, configuration files, logs, and other text-based data to quickly identify indicators of compromise, policy violations, or evidence of data exfiltration. The feature supports keyword and pattern matching, reusable search profiles, file-type filtering, and cross-platform investigations for faster, more focused evidence discovery.


New Features & Improvements


AIR – Integrations

Google Cloud Platform Support

The addition of Google Cloud Platform (GCP) integration brings full cloud forensics parity with existing AWS and Azure support. Analysts can now establish visibility into GCP assets, synchronize them with the AIR Console, and deploy Responders for data acquisition and incident response workflows. The integration leverages service accounts and organization-level synchronization to ensure investigator access is forensically sound and within tenant authorization boundaries.

Once configured, analysts can manage their GCP accounts via the Cloud Platforms page—performing synchronization, asset enumeration, and deployment directly through the AIR interface. This feature improves investigation readiness across hybrid or multi-cloud environments, reducing manual configuration overhead during critical incident investigations.

Application Information API

A new API endpoint provides authenticated systems and administrators with core version and configuration information about their AIR deployment. The API returns details such as console version, responder version, and active feature flags across the tenant environment. This serves as a foundational mechanism for integration partners and support automation—enabling both configuration validation and automated platform health monitoring.

For organizations integrating AIR with orchestration systems, this API helps verify feature availability before initiating evidence collection or response workflows, ensuring compatibility and auditability during automated operations.


AIR – Settings

interACT 2FA Enforcement

Administrators now have granular control over Two-Factor Authentication (2FA) for users leveraging interACT. The new setting allows global administrators to disable Two-Factor Authentication (2FA) for interACT access when operational flexibility is required during live-response investigations.


AIR – Asset & Task Management

Custom Evidence Collection Naming

A new capability in Settings → Console Settings → Features allows users to customize how evidence files and folders are named—whether saved locally on assets or uploaded to remote Evidence Repositories. Users can define a naming template by combining text with variables such as Timestamp, Organization Name, Task Name, Asset Name, and Case ID. Using / in the template creates folder structures for logical organization. This improves repository maintenance and ensures clear separation of evidence in multi-tenant environments. Folder names are limited to 50 characters.


Full Text Search

Allows investigators to search both file contents and metadata on remote assets using keywords or regex patterns. This allows targeted searches across documents, configuration files, logs, and other text-based data to quickly identify indicators of compromise, policy violations, or evidence of data exfiltration. The feature supports keyword and pattern matching, reusable search profiles, file-type filtering, and cross-platform investigations for faster, more focused evidence discovery.


AIR – User Experience Improvements

Resizable Modal Pages

The AIR Console’s modal pages are now fully resizable. Analysts reviewing collected evidence or findings can adjust the panel dimension for better visibility of artifact details or visual data such as screenshots and event matrices. This enhancement enhances usability during in-depth investigative reviews where comparison between multiple views or correlated data points is necessary.

User Search Field for Case Visibility

Investigation managers can now search the user list when assigning case visibility. This feature adds a responsive search bar within the assignment modal, enabling faster and more accurate selection in accounts with extensive user bases. The enhancement improves access management speed during time-sensitive investigations and reduces operational friction in large collaborative environments.

Search Count for Acquisition Profile Evidence Groups

AIR now displays the number of search results within each acquisition profile evidence group. This improvement provides analysts immediate feedback about the completeness and scope of captured evidence, significantly improving validation before moving into deeper analysis or correlation workflows. Investigation teams benefit from faster confirmation of expected data coverage across selected evidence categories.


TACTICAL – Windows Evidence Analysis

Enhanced Evidence Context Availability

Improvements to Windows evidence processing address inconsistencies in how UserAssist and Amcache artifacts are parsed and presented. Timestamp and metadata normalization ensures these artifacts align correctly within investigative timelines, reducing ambiguity during activity reconstruction. This results in a more reliable interpretation of user execution and application usage on Windows assets.


Bug Fixes

  • Duplicate Endpoint Registration Conflict : Fixed an issue where Linux assets with unique responder IDs were assigned the same Endpoint ID, causing visibility conflicts and continuous audit log generation. The updated logic ensures unique endpoint registration across redeployments, preserving accurate asset representation within the console.

  • UserAssist Focus Time Conversion : Addressed incorrect conversion of Focus Time values in the UI. Metrics now accurately reflect recorded milliseconds, resolving analytical inconsistencies during timeline correlation or application activity reviews.

  • DRONE YARA Recursion Logic: Fixed an infinite recursion logic issue when scanning root directories in DRONE Yara analysis configurations. Scans now properly adhere to defined recursion levels, improving performance and preventing unintended recursive loops.

  • Shellbag Timestamp Alignment: DRONE now consistently uses slot_modified_time across all Shellbag-related findings. This provides investigators a reliable timestamp metric for access chronology during Windows environment analysis.

  • Event Log Search Result Handling: Addressed additional error conditions that occasionally caused “No Records Found” messages during event record access. UI synchronization now ensures consistent linkage between findings and underlying records.

  • Sigma XML Key/Value Filtering: Improved XML key/value handling in Sigma parser to correctly evaluate multi-key comparisons. The updated logic ensures more accurate correlation for WMI persistence detection cases and similar behavioral rules.

  • Amcache Inconsistency Fix: Corrected parsing mismatches leading to missing Amcache entries compared to third-party tools. Analysts now receive a more comprehensive and validated dataset during Windows artifact review.



Binalyze MITRE ATT&CK Analyzer is now at version 11.5.0

Dynamo Analyzer

The Dynamo Analyzer received maintenance updates focusing on rule accuracy and identification breadth. Legacy detections tied to administrative share naming have been removed, while SRUM analysis references were standardized across application, network, and timeline dimensions. Additionally, detection coverage now includes a broader set of known hacker tool names to support proactive identification of malicious utilities during automated analysis.

MITRE ATT&CK Analyzer / YARA

The updated ATT&CK and YARA definitions expand recognition across several adversary techniques used by groups such as Tomiris. The analyzer now detects the JLORAT infector implant, ReverseSocks5 proxy utilities, and kernel drivers associated with privilege escalation or stealth behaviors. Rule refinements include additional suspicious keywords such as “ReverseShell” used in executable build paths. Together, these updates enhance AIR’s ability to expose covert persistence and remote access mechanisms unseen by prior rule sets.

Sigma

DRONE now integrates the latest Sigma rule corpus from both SigmaHQ and Hayabusa repositories. This ensures continuous alignment with community detection research and provides analysts with up-to-date behavioral coverage for Windows event patterns and adversary techniques.

Binalyze AIR 5.8

What’s New?

  • Evidence Collection in Windows Recovery Environment – AIR Windows off‑network responders can now collect evidence while operating inside the Windows Recovery Environment (WinRE). This enhancement allows analysts to acquire and preserve evidence from non‑bootable assets, reducing time and cost by avoiding full disk imaging while maintaining forensically sound collection.

  • Timezone Visibility and Filtering on the Assets Page – Assets in the Console now display their time zones in the asset detail view and can be filtered by timezone. This assists investigation teams in correlating multi‑regional logs and evidence timelines, accelerating timeline reconstruction across distributed environments.

  • macOS Artifact Expansion – Added support to collect macOS Spotlight indexes and USB Storage History artifacts. These enrich visibility into file creation, indexing behavior, and external device access, key evidence sources for insider activity and data movement investigations.

  • PowerShell Console Host History Line Numbering – Parsed results for PowerShell console history now display line numbers, allowing investigators to reference command execution order precisely and improve forensic timeline correlation during live response analysis.

  • MFT CSV Performance Refactor – The Master File Table (MFT) CSV export process has been refactored to use a faster, multi‑threaded parser, significantly reducing analysis time while maintaining evidence integrity. This supports large‑scale acquisitions and improves analyst productivity during file‑system timeline reviews.

  • Proxy Configuration Evidence Enhancement – Proxy configuration data is now included in collected evidence, allowing analysts to verify system‑level network redirection and potential unauthorized proxy use during the investigation of lateral movement or data exfiltration.

New Features & Improvements


AIR

Timezone Field for Assets

Each asset now includes a dedicated timezone field, visible on asset detail pages and filterable in the advanced search. This improves the correlation of evidence timestamps when investigating incidents spanning multiple geographies or distributed environments.

Analysts can quickly organize assets by timezone to validate whether log events align across regional systems or correlate deviations with adversary activities executed in different time windows.


TACTICAL

Evidence Collection within Windows Recovery Environment

Off-network responders can now operate in offline mode within Windows Recovery Environment (WinRE) to collect evidence when systems cannot boot normally. This capability enables the extraction of registry hives, event logs, and file artifacts directly from non‑operational assets without rebuilding the system or imaging the entire disk.

The feature helps analysts recover evidence from critical hosts after ransomware or system‑level compromise, preserving evidence integrity before remediation. Running the off‑network responder from a bootable USB drive ensures the collection process remains isolated and forensically sound.

Proxy Configuration Evidence Enhancements

Proxy configuration evidence has been extended to include a broader detection of system‑defined proxy settings. During an investigation, analysts can now verify proxy configurations to identify hidden network interception, redirection, or misconfiguration that may reveal traces of command‑and‑control communication or exfiltration channels.

MFT CSV Refactor with Enhanced Performance

The MFT (Master File Table) CSV export operation for Windows assets has been refactored to employ optimized parsing and resource utilization techniques. This delivers substantial performance improvements, significantly reducing parse time on large file systems.

This directly benefits analysts performing file-timeline correlation or change-detection tasks, accelerating triage in enterprise‑scale investigation scenarios.

PowerShell Console Host History Line Numbering

Parsed PowerShell Console Host History artifacts now include line number annotations. This refinement provides investigators with a clear command-execution order during user activity reconstruction, improving the accuracy of the timeline correlation between host actions and observed alerts.

macOS  Spotlight Artifacts

New evidence types have been introduced for macOS systems. Spotlight artifact collection provides visibility into system index data, revealing files that were accessed or created, even if they were later deleted from user directories.

Combined, these enhance macOS investigation depth and augment visibility into user behavior and adversary traces across Apple environments.

USB Storage History for macOS

A new artifact source now captures historical records of USB storage device connections on macOS assets. Analysts can identify device identifiers, connection timestamps, and usage relationships to support the validation of data theft or exfiltration hypotheses.


Responder

Configurable HTTP Request Headers

Responders can now override or add custom HTTP headers for console communications. This enables advanced network control or integration scenarios in which security gateways or monitoring tools require specific request identifiers without compromising protocol integrity.

Although primarily a convenience for integration, the feature helps enterprise security teams maintain consistent communication policies while keeping evidence transfer secure and auditable.

interACT Execution Command Update

The interACT execution command has been enhanced with a new --background alias (also available as --nowait), allowing analysts to execute commands asynchronously. This prevents command‑line session blocking during longer evidence collection operations.

Improvements to standard output and error stream handling prevent unexpected terminations and ensure complete records for audit logging, maintaining chain‑of‑custody assurance for interactive command activity.

Updated User‑Agent Header for Requests

Responders now identify themselves using updated, configurable User‑Agent header strings when sending requests to the Console. This ensures compatibility with enterprise firewalls and modern cloud proxy solutions, improving communication reliability across managed environments.


Bug Fixes

  • Edge Cookies Acquisition: Updated evidence collector paths for Microsoft Edge to include the latest “NetworkCookies” directory structure introduced in recent versions. This ensures accurate browser cookie collection and visibility inside Investigation Hub.

  • Case.db OS Version Correction: Fixed a discrepancy where Investigation Hub displayed Windows 11 Pro systems as Windows 10 Pro. The correction ensures accurate operating system reporting for all assets contributing to a case.

  • SAM Users and Groups Relationship: Corrected the issue preventing group names from displaying correctly under SAM Users acquisition results. Associations between users and groups are now properly recorded and visible in the Investigation Hub.

  • DRONE Filename Parsing: Resolved bug where filenames starting with zero caused path separator misinterpretation during YARA scanning, ensuring consistent evidence processing regardless of filename format.



Binalyze MITRE ATT&CK Analyzer is now at version 11.4.0

Dynamo Analyzer

The analyzer set has been expanded with coverage across multiple evidence types, including shell histories, browser activities, registry behaviors, and system configuration sources. These new analyzers enhance the detection of user activity, persistence mechanisms, and file execution patterns across Windows, macOS, and Linux disk images. Additionally, extended pattern recognition improves the identification of remote management and hacker tool usage through enriched analysis of command and environment variables.

MITRE ATT&CK Analyzer / YARA

Detection rules have been updated to identify Dystopia Windows RAT variants that leverage Discord, Telegram, and GitHub for command‑and‑control. Broader refinements across existing signatures further reduce false positives and strengthen behavioral coverage against unauthorized remote access activity.

Sigma

DRONE now incorporates the latest Sigma rule updates from both the SigmaHQ and Hayabusa repositories, ensuring analysts benefit from the most current community‑derived detection intelligence directly integrated into automated analysis workflows.

Binalyze AIR v5.7

What’s New?

  • Maintenance Mode for Device Assets: Analysts can now place assets into Maintenance Mode to safely prevent task execution while performing diagnostics or hardware maintenance. This prevents interference from live data collection or unintentional evidence overwrites during sensitive investigation windows. interACT and log gathering remain available, ensuring forensic continuity.

  • Global Search for Acquisition Profile Evidence Groups: Analysts can perform consolidated searches across all acquisition profiles and their associated evidence groups, significantly improving visibility and retrieval in large-scale investigations.

  • Acquire Evidence Menu Expansion: The “Acquire Evidence” section in the Quick Start menu now expands to show “From Device,” “From Disk Image,” and “From Cloud” options. This clearly differentiates evidence collection sources and helps analysts plan data acquisition strategies across hybrid infrastructures.

  • Device, Disk Image, and Cloud Menus in Navigation: The Asset menu has been redesigned to display Device, Disk Image, and Cloud as distinct top-level entries. This makes it faster for analysts to locate and manage specific asset types during ongoing operations.

  • Feedback Form and UI Flow Updates: A new feedback form enables analysts to provide direct, feature-level feedback from within AIR (limited to five submissions per day). The updated Resource Center layout ensures better visibility without obstructing navigation.

New Features & Improvements


AIR – Asset & Task Management

Implement Maintenance Mode for Device Assets

Maintenance Mode allows assets to be temporarily excluded from receiving automated tasks during planned maintenance or diagnostic sessions. Once activated, the mode restricts all actions except interACT and log gathering to preserve system stability and investigation continuity. Scheduled or bulk tasks automatically skip maintained assets, ensuring analysts prevent any accidental evidence interruption.

This feature addresses operational challenges where cloned or duplicated asset instances could previously respond with conflicting data. By isolating assets, analysts maintain chain-of-custody and ensure collected information remains contextually accurate. Maintenance Mode status is easily visible within filters and device details pages, supporting transparent asset control across large environments.

Acquire Evidence New Menu Structure

The “Acquire Evidence” section inside the Quick Start panel now expands into three distinct options—From Device, From Disk Image, and From Cloud. Each option guides analysts toward the applicable evidence acquisition path, allowing more targeted data gathering depending on the investigative context.

The new hierarchy promotes workflow clarity and improves onboarding for analysts operating across hybrid or multi-cloud environments. “From Disk Image” and “From Cloud” are marked as “Coming Soon,” preparing users for upcoming capabilities while maintaining consistent navigation design.

Asset Menu Changes

The primary navigation has been redesigned to replace the single “Asset” entry with separate Device, Disk Image, and Cloud menus. This ensures analysts can quickly access asset categories relevant to their operations without applying additional filters.

Device entries are drawn directly from responder APIs, while disk image and cloud asset types are sourced from the consolidated assets dataset. The design improves scalability for incident response workflows where analysts may manage thousands of distinct artifacts across asset classes.

Global Search for Acquisition Profile Evidence Groups

With this improvement, global search queries now return results for acquisition profile evidence groups. Analysts gain high-level visibility into evidence created under different profiles, making it easier to identify connections and perform comprehensive cross-case comparisons during active investigations.


AIR – Settings and UI Enhancements

Implementation of Feedback Form

This version introduces a built-in feedback mechanism that allows analysts to share direct insights from within the AIR Console. Each user may submit feedback up to five times per day, and entries are sent securely to the internal support channel for review.


AIR – Auth

User Role Name or Role ID in API Token Creation

Role and identification details have been enriched in token creation APIs to facilitate more consistent audit and authorization tracking across integrated systems. Analysts managing automation or delegated investigation tasks benefit from clearer accountability for token-based operations.


Bug Fixes

  • UI Overlap on New Policy Page: Corrected layout issue where Organization dropdown overlapped the Notifications panel, improving visual clarity and usability.

  • Schedule Task Duplication: Fixed a backend issue that caused duplicate tasks to appear during scheduled scans once execution began. The process now ensures each scheduled task instance triggers a single execution record.

  • Task Assignment in Offline Environments: Resolved an offline mode error preventing task assignment when exclusion files were inaccessible. Analysts can now run full or offline collection workflows without interruption.

  • Shareable Deployment Page Fixes: Corrected link behaviors causing broken or misleading redirects on shareable deployment pages. Asset links now behave consistently without exposing dummy login screens or undefined version indicators. Download links for release certificates now correctly trigger downloads.

  • Keyword Upload Validation: Improved keyword upload validation for acquisitions. Blank lines and unsupported characters are now automatically sanitized, preventing acquisition task failures.

  • Hunt/Triage Update Warning Message: Refined warning messages when updating Hunt/Triage rules created by other users, ensuring clearer communication about organization-level permissions.

  • Resource Center Icon Alignment: Adjusted UI positioning of the Resource Center element so that navigation controls remain accessible on smaller screens.



Binalyze MITRE ATT&CK Analyzer is now at version 11.3.1

Dynamo Analyzer

Detection logic has been expanded to include broader identification of hacker and remote monitoring management tools, with refined application name analysis to increase coverage. These enhancements improve the analyst’s ability to uncover unauthorized remote access utilities and misused commercial tools within collected evidence. Additional tuning enhances detection for crypto-mining related domains across network and DNS artifacts.

MITRE ATT&CK Analyzer / YARA

New detection rules cover Akira_V2 ransomware variants, along with associated binaries and ransom notes. Updates also enhance identification of PowerShell abuse techniques—such as AMSI bypass and ETW logging disablement—improving visibility into stealth tactics used on Windows assets. Detection of backdoors and implants like PlushDaemon, EdgeStepper, and C# AdaptixC2 frameworks expands the platform’s insight into advanced intrusion activity. Continuous refinement of driver-based threats such as Ollama.sys and hlpdrv.sys delivers deeper defensive analytics for kernel-level attacks.

Sigma

DRONE now includes the latest Sigma rule updates from both SigmaHQ and Hayabusa repositories. These updates extend behavioral coverage across event and log-based detections, ensuring analysts can continuously correlate current adversary techniques against timeline evidence within AIR’s Investigation Hub.

Binalyze AIR 5.6

What’s New?

  • Investigation Hub Live Collaboration and Activity Sync: Analysts can now observe real-time user presence, comment updates, and evidence flag changes within the Investigation Hub. This enables investigation teams to collaborate simultaneously on the same evidence and instantly see each other’s actions without refreshing the view.

  • Investigation Hub Search Enhancements with Prefix Support: The new prefix search capability allows using the “*” symbol in the Investigation Hub to find evidence names or keywords starting with a given text. This makes it faster to locate related items across large investigations, particularly when searching partial filenames, process names, or user activities.

  • Maintenance Window Configuration for SaaS Environments: Administrators can now select preferred maintenance windows directly within AIR. This ensures updates and maintenance operations occur within defined time slots, providing predictable scheduling for managed tenants.

  • Command Snippets Management Improvements: Snippets can now be tagged and grouped, making it easier to filter or categorize repeatable live-response actions in interACT sessions—improving operational efficiency and consistency for investigation teams.

  • Hunt/Triage Location Inclusion and Exclusion Support: Analysts define precise include/exclude path patterns for each platform in the Hunt/Triage feature. This ensures keyword and YARA scanning occurs only on relevant directories—improving performance and reducing noise during evidence analysis.

  • Expanded Evidence Support for macOS and Linux: New artifact sources, including DNF/YUM History, SSH Files, System Logs, and software update information, improve cross-platform visibility and provide deeper forensic coverage for investigations.

New Features & Improvements


AIR Console – Investigation Hub

Investigation Hub Live Activities, Data Reload and User Presence

This release further enhances real-time collaboration within the Investigation Hub. Active users are now visible in the interface, allowing analysts to see who else is working on the same case or evidence category. When actions such as flagging items, adding notes, or findings occur, all connected users receive immediate updates without manual refresh. Bulk actions performed by others are summarized with short status messages. These enhancements make the Investigation Hub a live, synchronized workspace where multiple analysts can collaboratively drive an investigation while maintaining full traceability.

The “Live Activities” and “User Presence” features can be toggled from the Investigation Hub user preferences button. For fast-paced incident response operations, this capability reduces communication delays and improves awareness of concurrent investigation actions.

Prefix Search in Investigation Hub

The Investigation Hub now supports prefix-based filtering. When analysts type a term followed by an asterisk (“*”), the system returns all evidence or findings beginning with that prefix. For instance, entering “inv*” retrieves matches such as “investigation” or “inventory.”

This enhancement is particularly valuable for analysts who need to rapidly investigate multiple variations of a file name, process, or event in large datasets.


AIR Console – Settings

Maintenance Window Implementation

Administrators can now define structured maintenance windows by selecting preferred days and times in the settings interface. These parameters control when SaaS maintenance and auto-updates may occur, ensuring predictable operations during off-peak hours. Each maintenance window defines a start time, duration, and day of week, all of which are retrievable through management APIs.

This configuration helps minimize interruptions during critical investigations and ensures alignment with internal change control policies.


AIR Console – Evidence Acquisition

Redesign Acquisition Profile Evidence Categories and Tabs

The acquisition profile interface is fully redesigned for clarity and usability. Tabs are reorganized into clear evidence groups such as System, Memory, Network, Disk & Filesystem, Applications, and Event Logs. Analysts now benefit from alphabetically ordered artifact lists and inline descriptions for quick comprehension. Each evidence item includes a tooltip describing its contents and importance.

A new “Only Show Selected” filter allows focusing on active collection settings. Together, these updates streamline acquisition configuration, ensure completeness, and improve planning for targeted investigations or large-scale asset acquisitions.


AIR Console – Notifications

Notification Broadcasting Service with SSE

Periodic polling for notifications has been replaced with Server-Sent Events (SSE). Instead of sending repeated requests every few seconds, AIR Console now pushes notifications to the UI instantly when new events occur. This reduces unnecessary traffic, improves efficiency, and provides immediate alert visibility for analysts monitoring active cases or system updates.

For investigation teams, this means that findings, responder updates, or evidence collection statuses appear in real time with lower network overhead and faster situational awareness.


Responder and RelayPro

Hunt/Triage Inclusion-Exclusion Support

With version 5.6.0, Hunt/Triage operations now support pre-scan inclusion and exclusion rules. Analysts can define directory patterns to include or omit during scanning. Each platform (Windows, macOS, Linux) can have separate path lists defined via console or policy configurations. Validation ensures patterns are accepted correctly and executed as expected by responders.

This level of control allows investigation teams to focus on specific areas such as user profiles, temp directories, or system logs while skipping irrelevant locations. As a result, hunts/triages execute faster with reduced false positives and more targeted evidence coverage.

Responder Connection and Authentication Enhancements

Multiple improvements have been implemented in the Responder communication and authentication flows, including better handling of token refresh and timeout conditions. These changes strengthen system resilience during long-running investigations and ensure sustained secure connectivity even under adverse network conditions.

General Code and RelayPro Improvements

RelayPro now employs optimized buffer allocation and socket deadline management to prevent potentially idle connection debt. The synchronization of graceful exits across proxy connections enhances system stability and prevents resource leaks, improving long-term reliability in environments with continuous remote communication between the console and assets.


Evidence Expansion

New macOS and Linux Evidence Sources

Evidence acquisition coverage has been significantly expanded for both macOS and Linux platforms. The following new artifact sources have been added:

  • macOS: DMG File Opened, File Last Used, Finder Mounted Volume, Keyboard Dictionary, Mount, Software Update Information.

  • Linux: DNF History, SSH Files, ETC Files, Sysmon Logs, and YUM History.

These additions provide broader cross-platform investigation coverage. Analysts can trace activity histories, mount operations, and track configuration changes across operating systems, thereby improving the completeness of post-incident investigations.


Database

Support for Encrypted Connections for PostgreSQL Servers

PostgreSQL connections used by AIR are now secured with SSL encryption. This update ensures all data exchanges between the AIR Console and its database are encrypted in transit, meeting compliance requirements and reinforcing data protection for investigation records.

Bug Fixes

  • Global Search Input Reset Issue: Resolved a problem where typing quickly in the Global Search bar caused text to disappear or reset while searches were executed. AIR now waits until input stabilizes before re-triggering searches, preventing data loss during typing.

  • Task List Sorting Problem: Fixed an issue in the Task Details view where column sorting stopped functioning after reopening the column selection panel. Sorting now behaves consistently across all columns.

  • Auto Asset Tagging Task Completion: Addressed a condition causing some asset tagging operations to stay in “processing” despite completion. Task states now stay correctly aligned with responder responses, including when NATS is enabled.

  • Policy Isolation Allow List Transmission: A communication issue preventing isolation policy allow lists from being sent from the AIR Console to responders has been corrected. The feature now works as expected for applied network isolation workflows. (Credits: Ahmet M.)

  • ScreenConnect Artifact Collection: Corrected missing ScreenConnect log acquisition in Windows responder evidence sets. These artifacts are again reliably collected for remote assistance investigation scenarios.

  • Browser Login Data Timestamp Alignment: Fixed incorrect ordering of “Date Created” and “Date Last Used” fields in browser login data parsing for Windows evidence.



Binalyze MITRE ATT&CK Analyzer is now at version 11.0.0

Dynamo Analyzer

Detection coverage is expanded with intelligence-driven analytics. Version 10.9 introduced the identification of suspicious commands, file paths, and PowerShell behaviors within Windows registry environment variables. These rules highlight possible persistence and command execution activity tied to adversary tactics.

Version 11.0 further enhances this by adding a new SRUM Application Timeline Analyzer. This analyzer examines collected SRUM data to surface the use of remote monitoring or hacking tools across systems. It also refines recognition of common tool names used within investigations, delivering improved prioritization and context for analysts.

MITRE ATT&CK Analyzer / YARA

Detection coverage has been broadened to include additional remote access and reconnaissance utilities, such as FleetDeck, GoToResolve, Miradore, N-Able, Nezha Agent, PDQ, RustScan, and updated Vidar Stealer variants. Together, these rules improve AIR’s ability to highlight unauthorized remote access software and network reconnaissance patterns across both newly collected and historical evidence.

Ongoing refinements enhance accuracy, reduce false positives, and strengthen the classification of backdoor behaviors and encoded PowerShell execution activity detected on assets.

Sigma

The integrated Sigma engine now aligns fully with the latest SigmaHQ and Hayabusa repository updates. These rule improvements ensure analysts benefit from the latest community-driven detections and enhanced alignment with the MITRE ATT&CK tactics and techniques classification, enabling faster investigation, hunt/triage, and automated correlation within DRONE findings.