Week of August 10: guided investigations, threat intelligence, and operational reports
Made investigations and Final Reports more actionable, added offline threat-intelligence matching, and introduced explicit speed and team controls.
agentbug fixesperformancesecurityplatformanoncapon prem
Agent
- Added an explicit choice between a capture-wide Core-first start and a focused Agent start, with clearer confirmation and milestone ordering before an investigation begins.
- Unified Preliminary Report, Verification, and Comprehensive Final Report milestones into one chronological investigation, with clearer live-stage navigation and concise completed reports.
- Simplified new investigations around direct evidence handoffs so each stage can stop once it has a defensible answer, while preserving important alternatives, uncertainty, and capture-wide coverage limits.
- Made Agent sessions and report activity durable across upload handoffs, reconnects, retries, and page restoration, reducing duplicate runs and missing or stale transcript content.
- Made Final Reports more operational with fault-domain localization, actionable escalation guidance, authoritative titles, and reliable follow-up report activity.
- Expanded Comprehensive Final Report review across the saved case, including earlier reports, authoritative Core results, and complete retained findings, so final conclusions can revisit all available evidence.
- Kept quick questions separate from managed investigations while allowing executive summaries and security reviews to start without a custom prompt.
- Added bounded PacketQL follow-up queries over retained Core facts so analysts, Agent, and Copilot can compare or rank one exact-generation fact family without rescanning the PCAP or persisting another result set.
Verification and evidence
- Made verification dispositions traceable to stable claims and preserved supporting, contradicting, and baseline evidence through the final report.
- Required deterministic Triage evidence before a Comprehensive Final Report can claim completion, while keeping cached preliminary evidence available to later stages.
- Improved cross-flow TCP reasoning and retained exact selectors, sequence coordinates, control events, and connection-local evidence for packet-level review.
- Improved bounded discovery for services on alternate ports and paired proxy or middlebox flows, while preserving TCP negotiation fingerprints for evidence-backed comparison.
- Carried compact capture provenance, protocol prevalence, connection coverage, duplicate quality, and timestamp context into later stages without extra packet scans.
- Made packet-tool results easier to inspect with richer typed previews, Markdown tables, preserved report headings, and explicit disclosure when a tool returned only partial coverage.
- Made OT, telecom, and VoIP workspaces more evidence-led with explicit OT coverage layers, grouped protocol operations, signaling and media packet pivots, and bounded RTP loss/jitter comparison.
Bug fixes
- Fixed upload-to-Agent transitions, stalled clarification flows, live milestone navigation, report hydration, email actions, and terminal transcript recovery.
- Restored packet-tool execution and live Markdown rendering while keeping transient Agent thinking out of the saved customer transcript.
- Stabilized saved report presentation and milestone handoffs, restored investigation counts in capture lists, improved ChatGPT reconnect guidance, and allowed capture deletion after failed Agent runs.
- Required complete metadata validation before marking captures ready, so truncated sources fail explicitly instead of appearing successfully ingested.
- Tightened TCP, ARP, DNS, telecom, and security-finding attribution so unsupported or unrelated packet evidence is not promoted into a customer conclusion.
- Kept late-packet signals and capture-wide protocol coverage available through bounded large-capture scans so decisive anomalies and specialist analysis are not silently skipped.
Performance and platform
- Added a faster large-capture path, bounded discovery and candidate recall by bytes, reused exact connection results, and localized reset-window analysis to avoid unnecessary capture-wide work.
- Added saved whole-capture activity and integrity context, a selected-connection TCP quality summary, and on-demand RTP stream detail so transport investigations can move from capture quality to packet evidence without treating measurements as automatic fault verdicts.
- Streamed capture cold-load progress and consolidated capture inventory, security projections, and full IDS work into bounded primary processing to reduce silent waits and repeated large-capture traversal.
- Reduced backend startup overhead, separated web and worker startup paths, prioritized urgent queues, and bounded storage cleanup around active investigations.
- Improved exported and visual reports by removing duplicate metadata and navigation-only citations, and deriving optional visuals only from exact Final Report evidence.
- Added an optional Fast inference setting for eligible hosted investigations, with a completion receipt that shows requested and effective speed, fallback state, and charged Analysis runs.
- Replaced generic AI usage units with explicit Analysis runs, Quick questions, and Prompt Coach entitlements, including shared and per-member visibility; completed investigations count only after successful completion.
- Added Shared Teams packages with clearer capture allowances and a separate dedicated SaaS path.
Security
- Made security findings easier to read while keeping live scan state, deterministic findings, and Triage completion consistent across the investigation.
- Added offline matching for exact IP, network, domain, URL, and file-hash indicators from managed or customer-supplied snapshots, with feed provenance, validity context, and packet or connection pivots.
- Made threat-feed coverage explicit as ready, partial, or unavailable, and added bounded scheduled refreshes with visible freshness and updater health for configured feeds.
Anoncap
- Coordinated capture retention and anoncap deletion with active Agent investigations so privacy cleanup cannot race an in-progress analysis.
- Decoupled public Anoncap downloads from frontend releases so privacy-tool updates can be published independently.
On-prem
- Made cluster profiles explicit about accelerator counts so single-node and multi-node deployment topologies match their advertised hardware.
