Week of August 3: faster Core Triage, stronger TCP evidence, and private controls

Reduced large-capture processing overhead, added focused TCP and east-west evidence, clarified IDS and Anoncap choices, and strengthened managed AI access.
performanceagentsecurityanoncapplatformbug fixeson prem

Performance

  • Consolidated more capture-wide Triage work into a shared single-read path, reducing repeated decoding across connection, IDS, protocol, and security analysis.
  • Made infrastructure discovery and specialist processing demand driven, bounded TCP candidate ranking, and compacted durable results to lower memory, storage, and database overhead on large captures.
  • Reused exact IDS and connection foundations across processing stages while retiring bulky intermediates after their customer-visible findings and coverage were safely persisted.

Agent

  • Added a bounded TCP dossier workflow so focused investigations can assemble connection setup, health, timing, and packet evidence without broad capture scans.
  • Improved Agent handoff after Triage by finalizing persisted evidence before launch and keeping capture identity, selected runtime, and tool contracts intact.

Security

  • Surfaced correlated east-west activity as inspectable findings while keeping packet-detail retrieval bounded.
  • Separated IDS source and coverage choices into a dedicated upload step, preserving the selected rules and exact coverage through the primary scan.

Anoncap

  • Added compact privacy-policy controls for private anonymization profiles and persisted the validated policy with each workflow.
  • Reconciled identity-handling rules across the Anoncap engine, backend, and upload experience so supported privacy choices remain consistent.

Platform

  • Added managed AI access-source selection with clearer subscription and provider approval flows for organization deployments.
  • Expanded supported alternative-model guidance and kept entitled runtime choices stable across reconnects and worker execution.

Bug fixes

  • Fixed capture-load, native-fact, connection-stream, and scan-finalization edge cases that could stall Triage, lose exact evidence, or launch Agent before results were durable.
  • Tightened artifact lifecycle cleanup and authoritative empty-result handling so completed processors do not leave stale work or trigger duplicate scans.

On-prem

  • Strengthened controlled AI-provider routing and authentication-source provenance for private deployments with managed egress requirements.