Tag: Binalyze AIR

Binalyze AIR v5.4

What’s New?

  • DRONE analysis on previously or newly collected evidence files — Analysts can now initiate DRONE analysis directly from the Investigation Hub on any existing evidence file, whether or not it was previously analyzed by a responder. This enables rapid reassessment after rule updates and supports first-time analysis of evidence returned without prior DRONE processing, streamlining forensic validation and re-evaluation workflows.

 

  • RelayPro — A major milestone introducing the new secure, authenticated HTTPS relay server that replaces the legacy relay implementation. RelayPro enhances secure responder-to-console communication with JWT-based two-step authentication, independent deployment, manual administrative control, and improved reliability. RelayPro provides stronger assurance of data integrity and traceable asset communications within restrictive or segmented environments.

 

  • Bulk User Import via Email List or CSV Upload — Simplifies large-scale onboarding by allowing administrators to import users in bulk with role and group metadata. This improvement accelerates enterprise deployments and ensures consistent privilege configurations for security operations teams.
  • macOS Evidence Expansion — The responder now supports the collection of previously missing raw evidence sets from macOS systems, including SSH, Launchd, etc. configuration, Crashes, Apple System Logs, Gatekeeper data, and others — offering deeper asset visibility during Apple ecosystem investigations.

New Features & Improvements


AIR – Asset & Task Management

Rename the Triage Module to “Hunt/Triage”

The module renaming improves concept alignment with forensic workflows, emphasizing proactive hunting and triage analysis capabilities from within the same interface. It helps analysts better associate the feature with rule-based anomaly detection and evidence interrogation.

Triage Rules – Name and Tag Enhancements

A new mandatory name field has been added to Hunt/Triage rules, improving identification and readability across detection configurations. Analysts can now assign descriptive titles in addition to detailed descriptions, with character limits introduced for better data management.
Support for rule tagging during creation or update has been implemented, making it easier to categorize and organize triage logic based on tactics, data sources, or operational context. Deleting tags is also now fully supported, empowering analysts to maintain a focused and updated ruleset with minimal clutter.

Support Delete Hunt/Triage Rule Tag

Hunt/Triage tags can now be easily deleted, making management of categorization structures more flexible. Analysts can reorganize or clean up unused rule tags efficiently, helping maintain clarity within growing rule repositories.

Bulk Delete Support

Users can conduct bulk deletions for several feature sets—hunt/triage rules, acquisition profiles, auto asset tags, interACT command snippets, search profiles, tokens, and subscriptions. This feature removes redundant configuration data en masse, simplifying maintenance of forensic configurations and automation objects.


AIR – Settings

Bulk User Import Capability via Email List or CSV Upload

This enhancement introduces the ability to import multiple users simultaneously by uploading a CSV file or a list of email addresses. Optional metadata, such as organization, role, or group, can be included in the data for automatic assignment. A preview step allows validation before applying changes. For large enterprise security operations teams, this feature expedites onboarding, reduces human error, and maintains consistent access structures across operational environments.

Adding Version Convention to .abf Backup File Names

Backup management now incorporates version tagging directly into .abf file names, allowing teams to easily identify the AIR version linked to each backup. This improvement minimizes confusion during recovery and helps investigators quickly restore environments corresponding to specific builds for testing or audit verification.


AIR – Investigation Hub

Add DRONE Analysis Progress Indicator for Investigation Hub

Complementing the re-analysis capability, the Investigation Hub interface now includes a DRONE Analysis progress section under task details. security operations team can monitor DRONE analysis states, view running or completed analyses, and access outcomes within the same case environment. This improvement reduces the need for separate logs or external monitoring and ensures transparency during longer-running forensic evaluations.


Supported Evidence

Extended macOS Evidence Collection

New evidence collectors have been introduced for macOS systems, covering areas previously unavailable for collection. Analysts can now acquire SSH configuration files, Launchd and Cron job definitions, ETC system files, Installed Applications, Apple System and Crash logs, Chromium extensions, Gatekeeper configurations, and Startup Hook artifacts such as Re-Opened Apps and Login/Logout Hooks. Each data source enhances visibility into execution persistence and system-level behaviors familiar to macOS adversarial techniques, enabling more complete cross-platform forensic baselines.

A full, OS-specific listing is available in the Knowledge Base, showing which evidence and artifact items appear in the Investigation Hub, whether their source files are collected, and which artifacts provide parsed data or raw file collections.

Chrome Quick Assist

A new collector has been introduced to capture Chrome Quick Assist artifacts, providing visibility into remote support session activity.

This evidence will help investigators trace legitimate remote help sessions and identify instances where adversaries may leverage trusted remote access tools for persistence or lateral movement.


RelayPro

RelayPro represents a fundamental architectural evolution in secure relay operations. It implements a fully authenticated HTTPS proxy with JWT-based two-step verification for responders connecting through constrained networks. Unlike the previous SOCKS5 relays, RelayPro separates its deployment from endpoint agents, reducing attack surface and aligning with best security practices. Configuration is registered via the AIR Console to ensure only validated relays can relay traffic.

Each connection between a responder and RelayPro is authenticated, logged, and validated, providing end-to-end integrity and accountability for every command or evidence transfer. Logging has been modernized with JSON formatting accessible only from local administration, removing remote exposure risks. For DFIR specialists, RelayPro ensures traceable network intermediary communication and hardens AIR deployments in heavily segmented infrastructures or zero-trust environments.


DRONE

DRONE Analysis on the collected evidence file

The new DRONE Analysis Task introduces the capability to execute re-analysis on previously collected evidence directly on the AIR Console. Analysts can initiate this task on any case assignment, asset, or task detail page via the Run DRONE Analysis action. The feature operates entirely on the server side, leveraging existing DRONE processors to analyze already collected evidence without requiring endpoint connectivity. This advancement is crucial for post-incident investigations where analysts must validate updated threat intelligence or rule sets against archived evidence.

For responders working offline, analysis can also be triggered on evidence missing DRONE packages, ensuring full diagnostic coverage. Re-analysis results are written seamlessly into existing cases, preserving investigative continuity. DRONE-based re-analysis significantly enhances investigation agility by enabling rapid re-correlations and retrospective detection within both online and air-gapped scenarios.

DRONE analysis on existing evidence files

The new DRONE Analysis task introduces the ability to run or re-run analysis on any previously or newly collected evidence directly from the AIR Console. Analysts can initiate this task from any case, asset, or task detail page using the Run DRONE Analysis action.

This process runs entirely on the server side, using existing DRONE processors to analyze evidence without requiring asset connectivity. It is particularly valuable for post-incident investigations where analysts need to validate updated threat intelligence or newly added detection rules against previously collected evidence.

It is important to note that not all DRONE analyses can be performed server-side. Certain analysis modules — such as MITRE ATT&CK mapping and other context-aware detections — rely on the live asset for responder-side execution. When DRONE is run on collected evidence, these responder-dependent analyses are unavailable, but all compatible server-side rules and detections will execute as normal.

For responders working in offline or air-gapped environments, DRONE analysis can also be triggered on evidence that was collected without an embedded DRONE package, ensuring complete diagnostic coverage. Results are written directly into the originating case, maintaining full investigative continuity.

By allowing retrospective analysis and re-correlation within both connected and isolated environments, DRONE analysis enhances investigation agility and supports forensic-level validation across all collected evidence.


Bug Fixes

  • Investigation Hub – MITRE Tactic Interaction: Fixed an issue where only the first tactic or technique link was clickable when multiple MITRE mappings were shown. All mapped tactics now open correctly, supporting complete navigation for threat correlation.
  • SMB Event Parsing: Addressed a decoding issue where SMB hex-formatted address strings appeared incorrectly escaped or truncated in DRONE databases. The updated converter preserves valid hexadecimal strings precisely.
  • Search in Sigma Hunt/Triage Event Records: Resolved a blocker where no results appeared for searches within Sigma Hunt/Triage records. Filtering and search now operate consistently across all evidence tables, improving investigative efficiency.


Binalyze MITRE ATT&CK Analyzer is now at version 10.8.0

Dynamo Analyzer

The Dynamo Analyzer has been upgraded with more comprehensive detection coverage across Windows, macOS, and Linux. It now identifies hacker and remote monitoring tools, suspicious commands, and relevant MITRE ATT&CK associations across numerous data types, including PowerShell logs, registry artifacts, scheduled tasks, and browser data. A new Browser Downloads Analyzer extends behavioral insight into potential malware delivery mechanisms through download patterns and referrers. The Amcache module has been retitled “Amcache Program Analyzer” to clarify its operational focus.

Additional refinements improve matching accuracy, introduce SRUM data enrichment, and enhance temporal context tracking for process analysis—significantly improving clarity and forensic reconstruction of attacker actions.

MITRE ATT&CK Analyzer / YARA

YARA-based detections have gained multiple new signatures identifying RATs, backdoors, and malicious utilities such as PipeMagic, Veeamp, Cloudflare Tunnel (cloudflared), Kazuar, and credential dumpers leveraging the WerfaultSecure binary. Extended rules also improve recognition of encoded PowerShell execution, credential access attempts, and exploitation of vulnerable drivers for privilege escalation. These updates deliver sharper threat visibility aligned with evolving ATT&CK techniques.

Sigma

The DRONE integration now includes the newest Sigma rule sets from both SigmaHQ and Hayabusa repositories. This ensures ongoing alignment with community threat intelligence and expands pattern coverage for Windows and Sysmon event sources while maintaining backward compatibility with prior Sigma rule definitions.

Binalyze AIR v5.4

What’s New?

  • DRONE analysis on previously or newly collected evidence files — Analysts can now initiate DRONE analysis directly from the Investigation Hub on any existing evidence file, whether or not it was previously analyzed by a responder. This enables rapid reassessment after rule updates and supports first-time analysis of evidence returned without prior DRONE processing, streamlining forensic validation and re-evaluation workflows.

 

  • RelayPro — A major milestone introducing the new secure, authenticated HTTPS relay server that replaces the legacy relay implementation. RelayPro enhances secure responder-to-console communication with JWT-based two-step authentication, independent deployment, manual administrative control, and improved reliability. RelayPro provides stronger assurance of data integrity and traceable asset communications within restrictive or segmented environments.

 

 

  • Bulk User Import via Email List or CSV Upload — Simplifies large-scale onboarding by allowing administrators to import users in bulk with role and group metadata. This improvement accelerates enterprise deployments and ensures consistent privilege configurations for security operations teams.

  • macOS Evidence Expansion — The responder now supports the collection of previously missing raw evidence sets from macOS systems, including SSH, Launchd, etc. configuration, Crashes, Apple System Logs, Gatekeeper data, and others — offering deeper asset visibility during Apple ecosystem investigations.

New Features & Improvements


AIR – Asset & Task Management

Rename the Triage Module to “Hunt/Triage”

The module renaming improves concept alignment with forensic workflows, emphasizing proactive hunting and triage analysis capabilities from within the same interface. It helps analysts better associate the feature with rule-based anomaly detection and evidence interrogation.

Triage Rules – Name and Tag Enhancements

A new mandatory name field has been added to Hunt/Triage rules, improving identification and readability across detection configurations. Analysts can now assign descriptive titles in addition to detailed descriptions, with character limits introduced for better data management.
Support for rule tagging during creation or update has been implemented, making it easier to categorize and organize triage logic based on tactics, data sources, or operational context. Deleting tags is also now fully supported, empowering analysts to maintain a focused and updated ruleset with minimal clutter.

Support Delete Hunt/Triage Rule Tag

Hunt/Triage tags can now be easily deleted, making management of categorization structures more flexible. Analysts can reorganize or clean up unused rule tags efficiently, helping maintain clarity within growing rule repositories.

Bulk Delete Support

Users can conduct bulk deletions for several feature sets—hunt/triage rules, acquisition profiles, auto asset tags, interACT command snippets, search profiles, tokens, and subscriptions. This feature removes redundant configuration data en masse, simplifying maintenance of forensic configurations and automation objects.


AIR – Settings

Bulk User Import Capability via Email List or CSV Upload

This enhancement introduces the ability to import multiple users simultaneously by uploading a CSV file or a list of email addresses. Optional metadata, such as organization, role, or group, can be included in the data for automatic assignment. A preview step allows validation before applying changes. For large enterprise security operations teams, this feature expedites onboarding, reduces human error, and maintains consistent access structures across operational environments.

Adding Version Convention to .abf Backup File Names

Backup management now incorporates version tagging directly into .abf file names, allowing teams to easily identify the AIR version linked to each backup. This improvement minimizes confusion during recovery and helps investigators quickly restore environments corresponding to specific builds for testing or audit verification.


AIR – Investigation Hub

Add DRONE Analysis Progress Indicator for Investigation Hub

Complementing the re-analysis capability, the Investigation Hub interface now includes a DRONE Analysis progress section under task details. security operations team can monitor DRONE analysis states, view running or completed analyses, and access outcomes within the same case environment. This improvement reduces the need for separate logs or external monitoring and ensures transparency during longer-running forensic evaluations.


Supported Evidence

Extended macOS Evidence Collection

New evidence collectors have been introduced for macOS systems, covering areas previously unavailable for collection. Analysts can now acquire SSH configuration files, Launchd and Cron job definitions, ETC system files, Installed Applications, Apple System and Crash logs, Chromium extensions, Gatekeeper configurations, and Startup Hook artifacts such as Re-Opened Apps and Login/Logout Hooks. Each data source enhances visibility into execution persistence and system-level behaviors familiar to macOS adversarial techniques, enabling more complete cross-platform forensic baselines.

A full, OS-specific listing is available in the Knowledge Base, showing which evidence and artifact items appear in the Investigation Hub, whether their source files are collected, and which artifacts provide parsed data or raw file collections.

Chrome Quick Assist

A new collector has been introduced to capture Chrome Quick Assist artifacts, providing visibility into remote support session activity.

This evidence will help investigators trace legitimate remote help sessions and identify instances where adversaries may leverage trusted remote access tools for persistence or lateral movement.


RelayPro

RelayPro represents a fundamental architectural evolution in secure relay operations. It implements a fully authenticated HTTPS proxy with JWT-based two-step verification for responders connecting through constrained networks. Unlike the previous SOCKS5 relays, RelayPro separates its deployment from endpoint agents, reducing attack surface and aligning with best security practices. Configuration is registered via the AIR Console to ensure only validated relays can relay traffic.

Each connection between a responder and RelayPro is authenticated, logged, and validated, providing end-to-end integrity and accountability for every command or evidence transfer. Logging has been modernized with JSON formatting accessible only from local administration, removing remote exposure risks. For DFIR specialists, RelayPro ensures traceable network intermediary communication and hardens AIR deployments in heavily segmented infrastructures or zero-trust environments.


DRONE

DRONE Analysis on the collected evidence file

The new DRONE Analysis Task introduces the capability to execute re-analysis on previously collected evidence directly on the AIR Console. Analysts can initiate this task on any case assignment, asset, or task detail page via the Run DRONE Analysis action. The feature operates entirely on the server side, leveraging existing DRONE processors to analyze already collected evidence without requiring endpoint connectivity. This advancement is crucial for post-incident investigations where analysts must validate updated threat intelligence or rule sets against archived evidence.

For responders working offline, analysis can also be triggered on evidence missing DRONE packages, ensuring full diagnostic coverage. Re-analysis results are written seamlessly into existing cases, preserving investigative continuity. DRONE-based re-analysis significantly enhances investigation agility by enabling rapid re-correlations and retrospective detection within both online and air-gapped scenarios.

DRONE analysis on existing evidence files

The new DRONE Analysis task introduces the ability to run or re-run analysis on any previously or newly collected evidence directly from the AIR Console. Analysts can initiate this task from any case, asset, or task detail page using the Run DRONE Analysis action.

This process runs entirely on the server side, using existing DRONE processors to analyze evidence without requiring asset connectivity. It is particularly valuable for post-incident investigations where analysts need to validate updated threat intelligence or newly added detection rules against previously collected evidence.

It is important to note that not all DRONE analyses can be performed server-side. Certain analysis modules — such as MITRE ATT&CK mapping and other context-aware detections — rely on the live asset for responder-side execution. When DRONE is run on collected evidence, these responder-dependent analyses are unavailable, but all compatible server-side rules and detections will execute as normal.

For responders working in offline or air-gapped environments, DRONE analysis can also be triggered on evidence that was collected without an embedded DRONE package, ensuring complete diagnostic coverage. Results are written directly into the originating case, maintaining full investigative continuity.

By allowing retrospective analysis and re-correlation within both connected and isolated environments, DRONE analysis enhances investigation agility and supports forensic-level validation across all collected evidence.


Bug Fixes

  • Investigation Hub – MITRE Tactic Interaction: Fixed an issue where only the first tactic or technique link was clickable when multiple MITRE mappings were shown. All mapped tactics now open correctly, supporting complete navigation for threat correlation.

  • SMB Event Parsing: Addressed a decoding issue where SMB hex-formatted address strings appeared incorrectly escaped or truncated in DRONE databases. The updated converter preserves valid hexadecimal strings precisely.

  • Search in Sigma Hunt/Triage Event Records: Resolved a blocker where no results appeared for searches within Sigma Hunt/Triage records. Filtering and search now operate consistently across all evidence tables, improving investigative efficiency.



Binalyze MITRE ATT&CK Analyzer is now at version 10.8.0

Dynamo Analyzer

The Dynamo Analyzer has been upgraded with more comprehensive detection coverage across Windows, macOS, and Linux. It now identifies hacker and remote monitoring tools, suspicious commands, and relevant MITRE ATT&CK associations across numerous data types, including PowerShell logs, registry artifacts, scheduled tasks, and browser data. A new Browser Downloads Analyzer extends behavioral insight into potential malware delivery mechanisms through download patterns and referrers. The Amcache module has been retitled “Amcache Program Analyzer” to clarify its operational focus.

Additional refinements improve matching accuracy, introduce SRUM data enrichment, and enhance temporal context tracking for process analysis—significantly improving clarity and forensic reconstruction of attacker actions.

MITRE ATT&CK Analyzer / YARA

YARA-based detections have gained multiple new signatures identifying RATs, backdoors, and malicious utilities such as PipeMagic, Veeamp, Cloudflare Tunnel (cloudflared), Kazuar, and credential dumpers leveraging the WerfaultSecure binary. Extended rules also improve recognition of encoded PowerShell execution, credential access attempts, and exploitation of vulnerable drivers for privilege escalation. These updates deliver sharper threat visibility aligned with evolving ATT&CK techniques.

Sigma

The DRONE integration now includes the newest Sigma rule sets from both SigmaHQ and Hayabusa repositories. This ensures ongoing alignment with community threat intelligence and expands pattern coverage for Windows and Sysmon event sources while maintaining backward compatibility with prior Sigma rule definitions.

Binalyze AIR v5.0

What’s New?


  • Redesigned Timeline in Investigation Hub: The Timeline has been rebuilt for speed, precision, and interactivity. Analysts can now run high-performance attribute-based searches, apply advanced evidence-specific filters, and visualize events, findings, and flags in zoomable charts. Infinite-scroll tables with enriched metadata enable direct flagging, note-taking, and pivoting between timeline and evidence views. Exports to CSV (with optional detailed evidence context) streamline reporting, compliance, and collaborative workflows.
    New Timeline applies only to cases created after the 5.0 release.The previous timeline views will still be available temporarily for historical cases, but they will be deprecated with the 5.2 release.










  • Enhanced Case Management with Insights & Customization: The Cases module now includes visual task and disk usage metrics, member highlights, and a case overview panel for instant situational awareness. A redesigned Kanban board supports fully customizable tags and categories, allowing teams to organize, prioritize, and triage cases by type, severity, or workflow with greater flexibility.




  • Fleet AI – Multi-Agent DFIR Assistance with BYOAI Support: Fleet AI transforms natural language into expert-level technical outputs, enabling DFIR teams to generate threat hunting rules, scripts, and answers to investigative questions instantly. New in 5.0, BYOAI support allows connection to OpenAI GPT, Anthropic Claude, Google Gemini, and self-hosted Ollama models—empowering teams with customizable, privacy-focused AI capabilities.




 

New Features & Improvements

Investigation Hub

New Interactive Timeline

The Timeline feature has been completely overhauled and integrated directly into the Investigation Hub. This enables analysts to gain insights into events, flags, and findings across investigations with fine-grained temporal resolution. The timeline supports multiple time granularities (hour/day/month/year), interactive zooming, and a cursor with contextual highlights. Users can scroll, filter, and annotate time-ranged events, making it a powerful visual engagement point for time-based forensic analysis.

Timeline Table Enhancements

A redesigned Timeline table now lists all timeline events. Analysts can use it to inspect metadata, assign flags, create notes, or promote timeline events to confirmed findings. All changes to flags and notes are fully synchronized across the platform. The interface supports infinite scrolling, detailed expandable panels, and a high level of visual fidelity in representing time-correlated data. It complements the event bars to streamline root cause identification during incidents.

Evidence Category Specific Filters for Timeline

The Advanced Filters interface has been enhanced to allow filtering not only on standard investigation fields, but also using evidence-category specific attributes. You can now apply filters based on IP addresses, paths, user IDs and other fields unique to different types of forensic artifacts (e.g., unified audit logs, process lists, file systems). Highlighted fields explain why certain events were captured, with options to add these filters on click. This brings precision and depth to timeline data searches without visual clutter.

Functionally Enriched Timeline Bar

The timeline header view supports interactive zoom (keyboard/mouse), cursor locking, indicator visuals for out-of-view time slots, flags and findings overlays, and state persistence. Toggle switches allow showing or hiding flagged or finding-related events. Navigation is seamless via UI or keyboard shortcuts, all providing the forensics analyst with a fluid way to scale investigations over time.

Flagging and Finding Integration with Timeline

Flagging and finding operations have been extended across all views. Actions taken on timeline events will reflect in evidence and findings as well, ensuring consistent views regardless where the action originates. This bi-directional synchronization helps ensure analytical steps are fully traceable and consistent across modules.

Timeline Mini Map & Zoom Range Indicator

A mini-map below the timeline shows full activity distributions across your investigation. Users can select viewports, scroll horizontally, or apply zoom-in ranges directly from the mini-map view. This provides an immediate awareness of data density over time and supports analysts in exploring large ranges effectively without visual fatigue.

Filter-Aware Timeline View

Global filters—such as dates, assets, finding types, and evidence categories—are now persistent and actively constrain visible ranges on the timeline. Disabled range regions visually communicate current filters. Additionally, if views are out of bounds, informative warnings ensure analysts are never misled by partial evidence renders.

Timeline Preferences Panel

The timeline bar supports multiple layout and display options. Users can switch between bar or line chart views, choose to display or hide empty ranges for compact timelines, and toggle cursor visibility. These preferences let analysts adapt views for complex investigations or high-volume triage needs.

Timeline Evidence Synchronization & Visualization

Each evidence item now can optionally show where and how its data appears on the Timeline. Analysts can click on a timestamp in evidence detail panel to jump directly to the timeline segment, or use context filters to see only timeline events from a particular artifact. This cross-linking streamlines correlation and root cause analysis.

Display Flags / Findings Toggle Controls

New toggle controls allow selective viewing of flags and finding indicators across the Timeline. This improves clarity during large or long-running investigations and supports focused drill-down during follow-ups or collaborative analysis.

Export Timeline Table with Evidence

Users now have the ability to export Timeline event tables to CSV—either with UTC/Z timestamps or local time. A toggle allows export of associated evidence metadata in JSON format. This export mechanism can assist investigations that require importing timeline artifacts into external case systems, or for cross-organization communication and auditing.

Timeline Table and Bar Chart Synchronization

A toggle has been introduced to synchronize focus between the timeline bar chart and the corresponding data table. When enabled, any zoom, pan, or date range selection in the chart view will reflect in the table below. Activated by default, this synchronization ensures investigators focus exclusively on relevant time-bound events with no manual toggling between context layers.

Flag-Based Sorting for Findings

Findings and evidence tables can now be sorted by Flag status. This enhancement is crucial for post-incident reviews, allowing analysts to immediately focus on findings previously marked during investigations. Analysts can leverage this to return to prioritized artifacts without re-filtering large datasets.


 

Case Management

Case Overview & Metrics

The case overview page has been revitalized to present key investigation metrics such as total assets, task distribution by type and status, team members, disk usage, and case notes. A new metrics overview panel offers aggregated views of case counts by status, asset volumes, disk usage, and task types over time, helping coordinators monitor throughput and resource allocation. A fixed insights pane provides a persistent at-a-glance summary of case activity, asset counts, and disk usage directly from the Cases page.

Detailed Case View

Clicking on a case now opens an expanded view or details drawer containing complete metadata, including tasks, assigned members, tags, notes, and disk usage. Ownership can be assigned directly, and collaborative note-taking with tagging and mentions is supported. Visual task breakdowns make it easy for managers to assess the scope, progress, and contributions of each team member.

Kanban Board Redesign

The Kanban interface has been modernized with full drag-and-drop support for case cards and dynamic column updates. Cards display enriched metadata, including tags, categories, and assignments, for quick identification of high-priority cases. User-specific layout preferences for grouping by status, tag, or category are saved for a seamless experience.

Tags & Categories for Flexible Organization

A new tag and category model enables analysts to classify cases with visual labels such as Malware or Phishing, and workflow categories such as For Review or Escalated. Cases can be grouped dynamically by status, tag, or category to reflect organizational priorities, with grouping logic respecting organizational scope for real-time workload segmentation.

Insight-Driven Case Management

The case insights panel aggregates investigation statistics and timelines into a single view for DFIR leads, integrating task metrics, disk usage tracking, and asset counts to support data-driven prioritization and escalation decisions.

Asset and Task Management

Enhanced Evidence Upload Strategy

Task data downloading from repositories has been improved to detect and handle interrupted or incomplete archive writes. This enhancement prevents partial evidence archives from silently corrupting post-processing and improves forensic traceability.

Improved interACT Shell Session Handling

Terminating an interACT remote shell session using the UI close action now ensures task status is correctly marked as completed. Additionally, controls for minimizing and exiting fullscreen are now fully visible, even after layout changes—addressing analyst UX complaints in remote operations.

One-Click DRONE Configuration

Initiating acquisition tasks with DRONE analyzers now includes an improved UX flow—allowing users to select a single option and enable all related analysis logic. This simplification accelerates task creation, especially in time-sensitive breach scenarios.


 

Fleet AI

Fleet AI is Binalyze’s next-generation multi-agent intelligence platform built to provide SOC and response teams with on-demand, expert-level assistance. It transforms natural language prompts into actionable, technical outputs—removing complexity and speeding up every stage of the investigative workflow.

Multi-Agent Intelligence for Investigations

Fleet AI hosts specialized agents capable of handling different DFIR-related tasks:


  • Detection Engineer Agent: Converts investigative objectives into professional-grade threat hunting rules.



  • Scripting Agent: Translates plain English into interACT commands.



  • These agents operate collaboratively to produce contextual, precise outputs that are ready for immediate use.


Natural Language to Actionable Results


  • Analysts can describe investigative needs in everyday language—Fleet AI handles the translation into technical rules, queries, and commands.



  • Eliminates the need to memorize syntax, consult documentation, or wait for specialist input.



  • Supports complex multi-step requests by breaking them down and generating results for each stage.


BYOAI – Bring Your Own AI (New in 5.0)

Fleet AI now allows customers to connect their own AI models or accounts for enhanced flexibility and privacy:


  • OpenAI GPT



  • Anthropic Claude



  • Google Gemini



  • Ollama


BYOAI ensures sensitive investigative data can remain within customer-controlled environments.

AWS Bedrock integration is planned for a future release.

Enterprise-Ready Design


  • Authentication & Security: JWT-based authentication supports secure integration with enterprise identity systems.



  • Speech-to-Text: Converts verbal queries into Fleet AI prompts, enabling faster hands-free interactions.



  • Deployment Options: Embedded directly in the Binalyze AIR UI for a seamless investigative environment.


Modern Architecture


  • Backend: FastAPI for high-performance, scalable processing.



  • Frontend: Next.js chat interface for smooth, real-time interaction.



  • Modes: Iframe-embedded deployments without additional dependencies.



  • Optimized for responsiveness and low-latency communication with AI models.


Integration with the DFIR Workflow

Fleet AI is designed to integrate directly into investigation workflows inside AIR:


  • Suggests relevant interACT commands while reviewing evidence.



  • Generates threat hunting rules based on findings.



  • Produces technical documentation and investigation reports without manual drafting.



  • By embedding expertise directly into the platform, Fleet AI reduces time-to-insight and helps standardize investigative output quality.



 

Integrations

Improved Role Handling for API Users

The update user API now supports both role IDs and role tags (e.g., “l1_l2_analyst”) to simplify automation workflows, especially when integrating with external identity and provisioning systems.

Support for Acquisition Profile Metadata

Case task query APIs now include metadata about acquisition profiles and custom task types. This allows sorting, filtering, and reporting based on which methodology was used per task—critical for consolidating analytical evidence and profiling collection behaviors.


Settings

SSL Certificate Identifier Algorithm Update

The serial number generation logic for internal SSL certificates has been hardened for increased cryptographic entropy and compatibility with key management tools.

Improved Role Update Flexibility

User update endpoints now support passing role names in addition to role IDs, improving human readability and automation compatibility across identity tooling pipelines.


 

Bug Fixes


  • Repository Explorer – Processor Not Found Error: Addressed a production-level UI/backend inconsistency where users received a “Processor Not Found” error in repository contexts. This situation prevented effective file browsing and strained case loading efforts during live investigations.



  • SSO User Group Persistence: Resolved an issue in which SSO-linked users were being unintentionally removed from user groups. This bug mostly affected teams operating large-scale environments with regulated access control schemes.



  • Improved IIS Autotag Rule Logic: Updated the auto asset tagging heuristic to avoid falsely identifying Windows 11 endpoints as IIS servers due to the presence of the default /inetpub directory. This misclassification could otherwise affect triage flows and policy assignments.



  • Case Import Stability: Fixed an issue in which SaaS users experienced incomplete task data within Investigation Hub due to intermittent failures in temporary file downloads during import. This was caused by unflushed disk writes that rendered archives unreadable. The fix improves reliability for case-based evidence visibility when operating in S3-backed environments.



  • Export Accuracy Fixes for Asset Lists: Resolved a reported bug in which the “Managed” status field displayed incorrect values in exported asset data.



  • UI Improvements for interACT: interACT task windows now close correctly when terminated via the ‘x’ button, resolving an issue where tasks were stuck in “processing” state. Additionally, window sessions and maximize/close UI controls are now rendered correctly in all resolution settings.



 

Binalyze MITRE ATT&CK Analyzer is now at version 10.3.2

MITRE ATT&CK Analyzer / YARA

A wave of crucial updates enhances detection capabilities across multiple malware categories. New signatures now identify RustyClaw, a Rust-based downloader; SnipBot (RomCom 5.0), which exhibits data exfiltration and post-exploitation capabilities; and Mythic C2 based malware leveraging recent WinRAR vulnerabilities. Additionally, detection covers obfuscated VBScript, heartCrypt packers, and variants used by threat groups like UAT-5647 and UAT-7237. Improvements were also made in identifying Cobalt Strike strings and LNK file padding exploits targeting known CVEs.

Dynamo Analyzer

Detection logic now identifies high-frequency scheduled tasks, which are often signs of automated persistence or malware propagation mechanisms. Naming detection of known hacker tools across evidence further assists DFIR analysts in quickly determining adversarial toolkit usage during triage and deeper investigations.

Sigma

The embedded Sigma engine has been updated to include advanced detections for PowerShell-based data collection and newly contributed rules from Hayabusa and SigmaHQ, increasing its efficacy in recognizing attacker behavior patterns across logs and endpoint activities.

Upcoming Events

Alongside your regular check-ins with your Customer Account Director, we have two upcoming opportunities to connect and learn:

Public Launch WebinarSeptember 10, 2025
Join Lee Sult, Binalyze’s Chief Investigator, for a high-level overview of AIR and its latest capabilities, including the redesigned Timeline feature. While aimed at those less familiar with AIR, customers are very welcome to attend.
Register here →

Quarterly Customer WebinarSeptember 17, 2025
Our first customer-only session, hosted by the Binalyze CERT team, will dive into workflow best practices — starting with how to leverage AIR 5.0’s API for supercharged workflow automation.
Save the date and bring your questions! Save your seat now →

Best regards,
Binalyze Team

The Future of SOC: Smarter, Faster, and More Resilient

Security Operations Centers (SOCs) are evolving. The traditional model—reliant on alert-driven workflows and manual, cumbersome investigations—is struggling to keep up with the complexity and volume of cyber threats. The SOC of the future must be faster, smarter, and more resilient, embracing efficiency driving automation, forensic insights, and seamless integration across security tools.

Why Business Email Compromise Investigations Need a New Approach

BEC Attacks: Silent But Costly Threat

Business Email Compromise (BEC) remains one of the most financially damaging cyber threats, with global losses exceeding $50 billion over the past decade (FBI IC3, 2023). Unlike traditional phishing attacks, BEC is not about malware—it’s about deception, social engineering, and compromised identities. In the security stack, the human element remains the weakest link, as BEC exploits human trust and error rather than technical vulnerabilities, making employees the primary target for social engineering attacks.

CSCRF Compliance: Turning Regulatory Challenges into Cyber Resilience

The Security Exchange Board of India’s (SEBI) Cybersecurity and Cyber Resilience Framework (CSCRF) is set to become a game-changer for India’s financial sector. With mandatory compliance deadlines that began in January 2025, financial institutions must adopt robust cybersecurity practices, faster incident response, and continuous audit readiness.

Binalyze AIR in Action: Detect malware on a potentially infected system

Detecting malware on a potentially infected system requires more than just waiting for alerts—it demands an investigative mindset. Proactive threat hunting and forensic analysis are crucial for uncovering hidden threats that may evade conventional detection. Binalyze AIR empowers teams with the tools to not only respond to known threats but also proactively investigate suspicious activity. By combining automation and deep forensic capabilities with integrated threat detection techniques, AIR transforms investigations into opportunities for uncovering compromises early, reducing risks, and staying ahead of attackers.