Binalyze is delighted to announce we are joining the EU’s ECHO Network project as a vendor, making us the first Digital Forensics and Incident Response participant in this network.
Binalyze is delighted to announce we are joining the EU’s ECHO Network project as a vendor, making us the first Digital Forensics and Incident Response participant in this network.
With the release of Binalyze AIR v1.8.0, we are introducing network capture capabilities to the acquisition profiles so you can capture both Network Flow (TCP/UDP connections) and PCAP IP packet data directly within the AIR platform. This upgrade brings significant advantages by further consolidating all your digital forensics activities into one solution and collaborative platform that delivers automation to save you time, reduce your costs and increase efficiency.
This is the stable release of the previous RC version (v.1.7.45)
Binalyze AIR v1.7.50 is now available.
Updated: 20.08.2024.
New feature: AIR-QRadar integration. Now, an acquisition can be started by triggering AIR via QRadar (credits: Esra Kulüp)
New feature: Added Roles and Privileges. Starting from this version AIR contains 70+ user privileges for more fine-grained control
New feature: Added backup support for case reports and config files. (Database backup is already available beginning from v1.7.16)
New feature: Added AES encryption option for backups
New feature: Added SFTP support to store backups on the remote server
New feature: Added performing bulk operations on the selected endpoints (adding/removing tags, deleting endpoints, starting acquisition triage, and much more. credits: Babak Mirzahosseiny)
New feature: Added triage support to Linux. Now, the file system and memory can be scanned using YARA rules. (credits: Hilko Bengen (https://github.com/hillu/) Author of go-yara (https://github.com/hillu/go-yara))
New feature: Added Custom Content collection from Linux distributions
Added progress update for compression and SFTP upload process on Linux
Added sending matched triage rules to Syslog
Added advance filter options to data grids
Added auto-generated shell script to facilitate Linux deb and rpm packages deployment
Added AIR integration guideline to documentation
Improved policy creation UI & UX
Improved setup process UI & UX
Improved custom SSL certificate information
Improved task completion status UX
Improved nats communication in agent
Implemented more secure cookie-based authentication
Optimized Audit logging performance
Optimized Syslog bulk processing performance
Fixed changing proxy settings when the license is lockdown
Fixed an issue in the agent installer
Fixed some security vulnerabilities
Minor changes and bug fixes
Binalyze AIR v1.7.40 is now available.
New Feature: CSV import support for Timeline
New Feature: Amazon S3 Bucket evidence repository support
New Feature: Azure Blob Storage evidence repository support
New Feature: LDAPS integration support
Changed Triggers to Webhooks
Added Sources field for Investigation
Added support for deleting timeline resources
Added LimaCharlie Webhook support
Added new predefined YARA rule: NSA Mitigating Webshells
Added name field to evidence repositories
Improved timeline filtering
Improved timeline performance
Improved progress reporting based on percentage and time on Linux agent
Improved recursive directory walk when compressing case directory on Linux agent
Improved isolation task assignment validation
Improved task cancellation for network share evidence repository on Windows agent
Improved SFTP upload on Windows agent
Fixed delay on task receiving after an agent is upgraded to a new version
Fixed deploy script bug for non-HTTPS servers
Fixed minor bugs on Linux agent
Fixed an issue in YARA scanner on Windows agent