Skip to the main content.

AIR Release Notes




Version 3.4.3


  • Network Capture for Linux and macOS

    • Beginning in version 3.4, the network capture feature is available on Linux and macOS operating systems.

  • Display Real IP Addresses of Endpoints by using XFF (Credits: Aaron V.)

    • AIR Console can read and parse the HTTP requests and XFF headers from the Forward Proxy and associate them with the assets to determine the assets' real IP.

  • x64 support for Off-Network Microsoft Windows

    • Beginning in version 3.4, Microsoft Windows 64-bit Off-Network binary package is available and can be run on supported 64-bit architectures.

  • Disk Imaging

    • Binalyze AIR provides disk imaging which we call “Acquire Image”, for Microsoft Windows, Linux, and macOS operating systems.

  • The last Seen Endpoints filter parameter was added to API (Credits to Garmin)

    • “Get Endpoint” API request now has the Last Seen Endpoints filter parameter. So the assets can be listed by the last seen date.

  • AIR for Chrome

    • AIR For Chrome is the evidence collector extension for Chrome and ChromeOS. AIR For Chrome extension allows investigators and analysts to capture forensically sound data with a single click at machine speed.

  • The character limitation on the hostname field of the Endpoints is removed.

    • Beginning in version 3.4, there will be no character limitation for assets' hostnames. Assets that have hostnames longer than 15 characters won't be trimmed and shown as they are.

  • The Endpoint Details page has been improved

    • The new endpoint details page is more organized and practical and provides more information about the asset.

    • The name of the System Resources tab has been changed to Hardware, and Volume and disk information will be shown here.

    • Acquire button function has been expanded. When it is clicked, Acquire Evidence and Acquire Image options will appear, and users can select any of them to start a data acquisition or disk/volume imaging task.

    • Disk and volume imaging, what we call Acquire Image tasks, can be performed in Volume or Disk tabs under the Hardware section of the Endpoint Details page.


Version 3.3.1



  • Multiple Sigma Rule Upload

    • Investigators and Analysts can upload multiple Sigma rules to AIR Console at once

  • Taking Full Logical Volume Images by using the user interface

    • Investigators and Analysts can create full logical volumes of images using either a user interface or a secure remote shell interACT.

    • Microsoft Windows, Linux, and Apple macOS operating systems are supported

  • x64 support for Windows Agent

    • Beginning in version 3.3 64-bit version of the Microsoft Windows AIR Agent is available.

  • Case ID Prefix

    • Customers using more than one Binalyze AIR Console instance can now add a prefix to their Case IDs. Therefore there will not be experienced any confusion about Case IDs anymore.

  • Progress monitoring added to Get & Put commands on the interACT

    • Investigators and Analysts can see the file download progress from an endpoint (get command) and file upload to the endpoint from the library (put command) command outputs while using secure remote shell interACT.

  • MITRE ATT&CK Scanner was added to Binalyze AIR Automated Threat Analyzer, DRONE

    • When Investigators and Analysts scan their systems with DRONE, they can see the MITRE ATT&CK mapped results in the report. DRONE rules are continuously developed and mapped to the MITRE ATT&CK framework.


  • Some security improvements on AIR Console

  • Some performance improvements on AIR Console


  • Minor bug fixes



Version 3.2.4


Security Hot fix

  • Binalyze AIR uses the JWT library that was compromised, immediate actions have been taken to remediate and AIR v3.2.4, containing the hot-fixes for the related vulnerabilities, has been released as of today. This includes fixes for the indirect vulnerabilities due to second-level dependencies.

    Therefore, it is strongly recommended to update your existing AIR deployments to this latest version AIR v3.2.4 at your earliest convenience. 


Version 3.2.3


Hot Fix

  • Hot fix that includes typo fixes, timeline date filtering, and browser back button navigation caused regarding the dashboard



Version 3.2.2



  • Activity Overview Dashboard added

    • Activity Overview Dashboard is a dynamic dashboard that provides tabular and graphical information about the usage, benefits, and return on investment of the Binalyze AIR in the enterprise company.

  • Progress Monitoring was added to InterACT secure remote shell

    • Investigators can track the progress of the command and estimate how much time is left on the interACT shell

  • AIR Agent Proxy Support

    • AIR agent automatically identifies the proxy configuration on the endpoint and configures itself to access the required services over the proxy service.


  • Miscellaneous package and dependency updates


  • Several bugs fixed


Version 3.1



  • Golden image option was added to AIR Agent installation

    • AIR agent is now compatible with installation via a golden image for new device deployment. With this feature enabled, an administrator can prevent potential connection and availability problems that may have previously occurred on the AIR console for machines installed from a golden image.

  • New File System Enumeration evidence for Linux and macOS

    • Investigators can list the creation, modification, and access dates and times of the files and folders on the Linux and macOS filesystem as CSV files.



  • Baseline Comparison Reporting

  • Collapse/Expand All items under the Acquisition Profile section.

  • Acquisition Profile information was added to the Tasks list under the Endpoint details page.

  • YARA 4.2 update

  • FTPS support for full disk image

  • SSL/TLS proxy server support was enhanced



Version 3.0.5



  • RFC-3161 compatible evidence signing for the chain of custody


  • New Asset status, "Off-Network," added

  • AIR Console domain address updates are enhanced

  • New evidence types added

    • Docker Artifacts for Linux OS

    • Browser History Artifacts for Linux OS

    • Browser History Artifacts for macOS

    • RAM image collection for Linux

  • Agent uninstallation and purge operations are enhanced

  • Multi-file upload for Off-Network devices

  • Path of the evidence files added

  • Local IP addresses added to the endpoint details page

  • The full disk image for macOS


  • Case activity reporting to Binalyze cloud services [credit: Nixu]

  • DNS and ICMP Protocols are filtered when Endpoint Isolation


Version 2.10.2



  • AWS EC2 one-click agent deployment

  • Cloud forensics - Azure VM support

  • Azure VM one-click agent deployment

  • Auto Asset Tagging based on hostname, IP address, and subnet

  • Auto Asset Tagging based on custom rules with osquery builder

  • Linux full disc image via interACT


  • 7x speed improvement for most evidence acquisitions on macOS and Linux

  • You can now upload multiple YARA rules at once

  • Improved troubleshooting logs

  • Token support for MFA


  • Fixed an issue where sometimes recycle bin collection would fail

  • Fixed an issue that prevented baseline comparison on unreachable endpoints

  • Other minor bug fixes



Version 2.9.3



  • Fixed an agent uninstallation issue on Linux and macOS

  • Fixed an issue where in some cases, disk imaging would hang


Version 2.9.1



  • Added ability to enumerate Amazon AWS EC2 assets

  • Added Yara triage support to macOS assets

  • Added Baseline comparison for macOS assets

  • Added full disk image collection with interACT for Windows assets


  • Added ability to duplicate acquisition profiles


  • Fixed an issue where notifications were not shown about tasks in non-default Organisations

  • Fixed the wrong warning message when deleting a task from a case.

  • Fixed an issue where the user couldn't see the baseline comparison report even though the baseline acquisition task was finished.

  • Fixed the name column sorting in the interACT Library




Version 2.8.2



  • Added off-network Acquisition and Triage with portable agent

  • Added interACT for macOS

  • Added Tamper Detection for macOS agent


  • API now includes endpoints for Policy, Auto Asset Tagging, Triage Rules, and Users (Docs)

  • interACT shell now supports backslash (\) for newline

  • Updated and improved the powershell deployment script

  • Improved efficiency of e-Discovery and custom content collections


  • Fixed an issue where some users were not able to upload files to the interACT library

  • Fixed an issue where sending the same acquisition twice to the same timeline would result in duplications

  • Fixed an issue where an evidence repository that’s in use in a policy could be removed from the console

  • Fixed limitation on username length


Version 2.7.2



  • Fixed task migration scripts update

  • Fixed scheduled task comparison is missing on Baseline Comparison

  • Fixed connecting AD user with less than 5 characters

  • Fixed spelling mistake is shown On ESXi Agent Deployment Page

  • Fixed UI issues about ESXi tab



Version 2.7.1



  • Fixed a bug related to agent uninstallation process


Version 2.7.0



  • Added support for Apple macOS assets

  • Added Chromebook standalone collector (credit: Yuta K.)

  • Added ESXi standalone collector (credit: Andres S. and Mason T.)


  • Case selection is now optional with an Enterprise or MSOC license

  • API now includes endpoints for Repositories, Baseline, Case and Organizations (Docs)

  • Improved the retry process for interACT’s get and put commands


  • Fixed issue with downloading files with special characters via interACT

  • Fixed acquisition history graph on the dashboard

  • Fixed other minor functionality and UI issues

  • Fixed UTC time mismatch in DRONE for Windows event logs and event records

  • Fixed DRONE stability issue when using keyword search



Version 2.6.2





Version 2.6.1



  • Added asset baseline forensic comparison

  • Added support for FTPS evidence repositories

  • You can now have interACT sessions with isolated Windows endpoints


  • Added new evidence and artifact types to Windows acquisition

  • All active interACT sessions are now ended when interACT is disabled from settings

  • Added "New Rule" shortcut to Triage assignment screen

  • Added keyboard support for confirming and dismissing popups (Enter/Esc)

  • Improved evidence compression performance

  • Enabled option not to compress evidence on collection

  • Upgraded interACT curl executable to version 7.83.1

  • Upgraded interACT osquery executable to version 5.2.3

  • Improved performance of agent installation on Windows


  • Improved Auto Asset Tagging task assignment

  • Improved UI performance in various locations

  • Improved security of sensitive credentials saved in the AIR setting

  • Fixed an issue with the status of the agent update task

  • Fixed a bug in the interACT zip command

  • Fixed a minor bug in unique case directory creation on endpoints

  • Fixed other minor bugs


Version 2.5.1



  • Fixed a bug in the DRONE configuration file migration process.



Version 2.5.0



  • Added DRONE support for Linux

  • Added Sigma rule triage to Linux

  • Added shareable deployment feature

  • Added new organization management page

  • Added osquery command to interACT

  • Added mkdir command to interACT

  • Added sort and tree options to interACT pslist command


  • Added SSL Enforcement for accessing AIR. 

  • Added auto asset tag rules for Apache, Redis, Mysql and Rabbitmq

  • Added tamper detection type to audit log description

  • Added filtering endpoints by label

  • Added filtering audit logs by endpoint name

  • Added TACTICAL and DRONE KB download links

  • Added required privileges section to interACT command help pages

  • Improved endpoint update performance

  • View and Update Organization privileges moved from system privileges to user privileges

  • Hardened to prevent less-privileged users from accessing sensitive settings data

  • Upgraded interACT curl executable to version 7.82.0

  • Improved tamper detection 

  • Improved triage to allow the same Yara rule name in different rulesets

  • Added time frame limit to DRONE Event Records Analyzer

  • Improved DRONE Ransomware Analyzer performance. Added total and per channel limit for Events of Interest and Event Records analyzer.


  • Fixed a minor issue on global search

  • Fixed evidence repository path validation bug

  • Fixed Endpoint label delete issue

  • Fixed e-Discovery patterns search issue

  • Fixed interACT curl command's missing CA certificates on Windows

  • Fixed a bug in sigma triage to kill DRONE process when task is canceled

  • Fixed an issue with the DRONE Linux x86 build.

  • Fixed other minor bugs

  • UI/UX improvements


Version 2.4.0

Blog News: v2.4.0



  • Added e-Discovery collection to acquisition profiles (credit Yalkin D.)

  • Added Tamper detection to agent

  • Added agent support for Linux arm64 (aarch64)

  • Added curl command to interACT

  • Added hex command to interACT


  • Added IP Address column to Endpoint table

  • Added silent installation tooltip for SCCM agent deployment

  • Added endpoint name to audit log filter

  • DRONE keyword search capability is now more visible

  • Improved zip command in interACT - Now zips to folder

  • Added new metrics for case report memory section


  • Fixed unquoted service path issue after a config update (CVE-2021-42563)

  • Fixed minor issues on timeline export

  • Fixed duplicated user validation issue

  • Fixed evidence repository name and path validation issue

  • Fixed system resource usage not updating in interACT session issue

  • Fixed renaming evidence repository issue

  • Fixed an issue that allowed task assignment to endpoints with an old agent

  • Fixed webhook addresses not updated after a change of console address

  • Fixed SFTP current directory support

  • Fixed opening report issue in Safari browser

  • Fixed minor issue on Sigma rule parser

  • Fixed minor issue on Drone table

  • Fixed minor UI issues



Version 2.3.6


  • Fixed a bug that broke the database migration step on v2.3.5

  • Fixed minor memory leak in the Events of Interest analyzer


Version 2.3.5

Blog News: v2.3.5


  • Added Sigma rule triage for Windows

  • Added autocomplete functionality to interACT

  • Added ServiceNow support to webhooks


  • Added new privilege to allow changing endpoint label

  • Added auto asset tag rules for Docker and Kubernetes

  • Added version information to settings

  • Added ability to handle Unicode file paths in YARA scanner

  • Added ability to specify a temporary staging directory for acquisition tasks that use evidence repository

  • Improved evidence collection on low capacity endpoints by letting AIR automatically select the volume with the greatest available free space (credits: Babak M.)

  • Improved evidence repository background upload mechanism with persistent retries

  • Improved case export functionality


  • Fixed minor memory leak of canceled tasks

  • Fixed minor logging issues

  • Fixed interACT exec command stdin issues on Windows

  • Fixed a bug related to listing unsupported drone analyzers

  • Fixed case filter issue

  • Fixed policy list on task creation, missing policies

  • Fixed case-sensitive username issues

  • Fixed case day counter

  • Fixed minor bugs on the report

  • Fixed other minor bugs



Version 2.3.0

Blog News: v2.3.0


  • InterACT: A cross-platform remote shell session capability that allows the users to run commands on remote endpoints for triage, mitigation, and remediation purposes in situations such as cyber incident response activities.


  • Improved windows agent installation

  • Improved endpoint tag assignment

  • Increased timeout duration for Azure Blob Storage


  • Fixed incorrect tag-endpoint count

  • Fixed scheduled instant execution

  • Fixed invalid SFTP port

  • Fixed returning wrong http status code for invalid evidence repository Id

  • Fixed organization search criteria

  • Fixed timeline wrong date range issue on export

  • Fixed multiple role assignment issue on UI

  • Fixed showing "Reset filter" button in the timeline

  • Fixed organizations tag gaps on the UI

  • Fixed privilege hierarchy issue between organization and global admin roles

  • Fixed not showing 404 page for case section

  • Fixed webhook URLs display issue in some cases

  • Fixed duplicated start date field in scheduled task detail

  • Fixed no link issue on "see details" text on Settings > Connection page

  • Fixed broken KB links for Webhooks and SSO


Version 2.2.1 

Blog News: v2.2.1

  • Added Slack integration support

  • Added Mattermost integration support

  • Fixed timeline sort issue

  • Fixed viewing case.ppc issue on failed tasks

    Read the detailed notes




Version 2.2.0 (RC)


  • Added exporting endpoints as CSV

  • Added exporting cases as CSV

  • Added exporting case activities as CSV

  • Added exporting case notes as CSV

  • Added exporting case endpoints as CSV

  • Added exporting audit logs as CSV

  • Added exporting timeline events as CSV

  • Added Yara external variables and removed yara+ modules (file, process)

  • Upgraded Yara to 4.1

  • Enriched triage case report for file matches for Linux


  • Added webhook support for Elasticsearch Logstash Kibana (ELK)

  • Added webhook support for SumoLogic

  • Improved task queues

  • Improved triage performance

  • Improved handling of cancel tasks

  • Improved connection timeouts

  • Improved log rotation

  • Improved log format

  • Improved logging

  • Improved Triage case report

  • Updated the application icon for the Windows agent

  • Added timeout for evidence repositories on agent


  • Added retry for agent HTTP requests

  • Added retry for failed case file uploads

  • Introduced Linux systemd service restart on failure

  • Fixed compression progress reporting

  • Fixed HTTP response close

  • Fixed a race condition for HTTP transport

  • Fixed progress reporting

  • Fixed self match possibility of custom content collection for Linux

  • Fixed misc. minor bugs



Version 2.1.5

  • UI/UX improvements on case containers

  • Fixed minor bugs related to case containers

  • Fixed drone autopilot issue on scheduled tasks and webhooks.

  • Fixed a bug about using azure storage as evidence repository on linux agents



Version 2.1.0 (RC-2)

  • Added additional functionality to cases feature

  • Minor fixes and improvements



Version 2.0.5

  • Added FQDN support for console address

  • Added a Quick Intro guide to help new users get started with AIR

  • Fixed an issue on SSO with 8443 port

  • Console migration process moved to task logic

  • Minor Linux agent fixes:

    • Minor http timeout fix

    • Minor triage command line parameter fix for excluded files

    • Visit poll interval overflow fix for 32bit architectures

  • Minor Windows agent fixes:

    • Minor improvement on isolation



Version 2.1.0 (RC)


  • Added case container feature

  • Added FIS license support


  • Fixed a minor issue related to the auto-asset-tagging feature

  • Fixed organization admin privileges issue

  • Minor UI/UX fixes


Version 2.0.1

This is the stable version of the latest RC (v2.0-RC)

In this version;

  • Added new predefined acquisition profile: Compromise Assessment

  • Added deployment script support for Windows agents

  • Added webhook parser for Cortex XSOAR and Splunk Phantom

  • Added new evidence type for Windows agents: Collecting USB Storage History

  • Improved license validation messages

  • Improved temporary path usage for Windows agents

  • Fixed a bug related to timeline event count

  • Fixed a bug related to sending events to syslog

  • Fixed a bug related to canceling Auto Tag Asset task on Windows agents

  • Major performance improvements



Version 2.0 (RC)



  • Added AIR-DRONE Integration (available only for acquisition and timeline for now) - rapid keyword searching, anomaly finding, scanning SIGMA rules live directly on any endpoint, and many other DRONE features are available now in AIR.

  • Added Auto Asset Tagging feature - tag your assets automatically by the conditions you provide.

  • Added Off-Network Endpoints feature - add and filter off-network endpoints.

  • Added PPC Import to Timeline feature - import PPC files collected from offline or online environments to Timeline.

  • Added IP Restrictions feature - restrict access to the AIR Console based on IP addresses or IP blocks.

  • Added UI Port Splitting feature - enables you to serve AIR Console and Endpoint requests from separated ports. With this feature, you can create separate firewall rules in AIR.

  • Added Drone findings on the Timeline

  • Added SMB Repository Support for Linux

  • Added Pardus Linux Support

  • Added Super glob meta (double star) support for custom content

  • Added IP Restriction Reset Script

  • Added an ability to download case reports from the endpoint detail task page

  • Added hashes.csv file that contains hashes of the files in the case report

  • Added detailed step by step task statuses (Processing, Compressing, Uploading, Analyzing)

  • Added support for .pfx, .der SSL certificate types

  • Added supported Linux distributions information to deploy the page

  • Added "Send to Timeline" action to Acquisition tasks

  • Added displaying support for PPC file metadata

  • AIR UI has a new design layout now


  • Improved more user-friendly error messages

  • Improved database connection functionality on backend

  • Improved case report view options on the endpoint detail page

  • Improved global search bar visibility for each page

  • Improved notification module "Mark All as Read" accessibility

  • Improved showing EULA in AIR setup

  • Improved and simplified AIR deployment with Docker for Linux

  • Improved performance while opening the Case Report.

  • Improved SSL Certificate installation

  • Minor improvements/fixes on case report

  • Upgraded MongoDB version to 4.4.7


  • Fixed an issue related to uninstallation of windows agent manually

  • Fixed LDAP issue occurring while trying to login AIR with username@domain format

  • Fixed task queue cancellation

  • Fixed Proxy SSL issue

  • Fixed organization name update issue

  • Fixed organization filter bug on the policy creation page

  • Minor UI/UX fixes


Version 1.8.3

  • Minor changes and improvements

Go to knowledgebase to learn how to migrate from v1.7.61 to v1.8



Version 1.8.2

This is the stable version of the latest RC (v1.8.0-rc)

In this version;

  • Added AIR CLI Support

    • Added to restore using a backup file support

    • Added to reset local user password support

  • Improved AWS S3 Bucket upload on Windows agent

  • Improved Custom Content Collection on Windows agent

  • Fixed some minor bugs

Go to knowledgebase to learn how to migrate from v1.7.61 to v1.8


Version 1.8.0 (RC)


  • Added Docker-based installation support. Once a stable version of v1.8 is released, docker will be the only deployment option. Since then, the MSI installer will no longer be available. Our knowledge base page is available to show how to install the new version of AIR:

  • Added multiple organization support.

  • Added Azure AD single sign-on support.

  • Added 2FA support.

  • Added stateless queue-based background worker system.

  • Added network capture option to acquisition profile.

  • Added device name and os on agent visit requests.

  • Added deployment token to deploy endpoints more secure way.

  • Added some rules to prevent confusion and irregularity on users/roles (Only Global Admins can create Roles, predefined roles cannot be updated).

  • Added Wazuh integration support.


  • Added ability to unisolate an endpoint, whether it's already isolated or not, for easier troubleshooting.

  • Added predefined roles: Organization Admin, L1&L2 Analyst, L3&L4 Analyst, Maintenance Engineer.

  • Added authorization guard for unauthorized users while accessing organization-specific resources and deployment-related pages.

  • Optimized all database indexes for the organization system.

  • Moved policy priority-based config to order-based config.

  • Improved the stateless task scheduler.

  • Improved create tag rest endpoint for organization system.

  • Improved policy-endpoint match stats.

  • Improved caching by moving it from in-memory to a queue-based infrastructure.

  • Improved the backup feature.

  • Updated policy priority/order to clear up the confusion

  • Removed default SMTP connection, users have to enable the SMTP settings to send emails such as password reset

  • Improved auto-isolate operation after reboot


  • Fixed task data error on getting task by id.

  • Added aborting existing TCP connections after Isolate operation

Additional instructions for existing customers:

  • Once a stable version of v1.8 is released, migration documentation and technical support will be provided for existing customers.



Version 1.7.61

  • Fixed NATS blocking call problem.

  • This is the last AIR Console version that supports the MSI installer. In future releases, Docker will be the only deployment option.


Version 1.7.60

  • Fixed password reset bug.

  • Improved endpoint console address migration feature.



Version 1.7.55

  • Added ability to change the console address to migrate endpoints to a new AIR instance.


Version 1.7.50

This is the stable release of the previous RC version (v.1.7.45)

  • Blog News: v1.7.50

  • Fixed a bug upgrading endpoints with old version to newer version

  • Fixed notifying NATS for the endpoints that need to be upgraded to the new version

  • Fixed a bug regarding database backup

  • Added support for validating settings for Azure Blob Storage and AWS S3



Version 1.7.45 (RC)

  • New Feature: CSV import support for Timeline

  • New Feature: Amazon S3 Bucket evidence repository support

  • New Feature: Azure Blob Storage evidence repository support

  • New Feature: LDAPS integration support

  • Changed Triggers to Webhooks

  • Added Sources field for Investigation

  • Added support for deleting timeline resources

  • Added LimaCharlie Webhook support

  • Added new predefined YARA rule: NSA Mitigating Webshells

  • Added name field to evidence repositories

  • Improved timeline filtering

  • Improved timeline performance

  • Improved progress reporting based on percentage and time on Linux agent

  • Improved recursive directory walk when compressing case directory on Linux agent

  • Improved isolation task assignment validation

  • Improved task cancellation for network share evidence repository on Windows agent

  • Improved SFTP upload on Windows agent

  • Fixed delay on task receiving after an agent is upgraded to a new version

  • Fixed deploy script bug for non-HTTPS servers

  • Fixed minor bugs on Linux agent

  • Fixed an issue in YARA scanner on Windows agent


Version 1.7.41

  • Minor bug fixes



Version 1.7.40

  • Blog News: v1.7.40

  • New feature: AIR-QRadar integration. Now, an acquisition can be started by triggering AIR via QRadar (credits: Esra Kulüp)

  • New feature: Added Roles and Privileges. Starting from this version AIR contains 70+ user privileges for more fine-grained control

  • New feature: Added backup support for case reports and config files. (Database backup is already available beginning from v1.7.16)

  • New feature: Added AES encryption option for backups

  • New feature: Added SFTP support to store backups on the remote server

  • New feature: Added performing bulk operations on the selected endpoints (adding/removing tags, deleting endpoints, starting acquisition triage, and much more. credits: Babak Mirzahosseiny)

  • New feature: Added triage support to Linux. Now, the file system and memory can be scanned using YARA rules. (credits: Hilko Bengen ( Author of go-yara (

  • New feature: Added Custom Content collection from Linux distributions

  • Added progress update for compression and SFTP upload process on Linux

  • Added sending matched triage rules to Syslog

  • Added advance filter options to data grids

  • Added auto-generated shell script to facilitate Linux deb and rpm packages deployment

  • Added AIR integration guideline to documentation

  • Improved policy creation UI & UX

  • Improved setup process UI & UX

  • Improved custom SSL certificate information

  • Improved task completion status UX

  • Improved nats communication in agent

  • Implemented more secure cookie-based authentication

  • Optimized Audit logging performance

  • Optimized Syslog bulk processing performance

  • Fixed changing proxy settings when the license is lockdown

  • Fixed an issue in the agent installer

  • Fixed some security vulnerabilities

  • Minor changes and bug fixes


Version 1.7.35

  • New feature: GNU/Linux support for Debian and Redhat based distributions (Preview)

  • New feature: Added SFTP support to evidence repositories

  • New feature: Added compression and encryption support for evidence

  • New feature: Added endpoint isolation for Windows platform

  • New feature: Added policy support that gives you the ability to manage evidence repository location, compression, encryption, and CPU limit based on rules (credits: Turkcell CDC)

  • Added extended file information for triage files

  • Added dependecy checking to evidence repository deletion process

  • Added linux acquisition evidence list

  • Added "Use options provided in policies" and "Use custom options" choices to the acquisition, triage, trigger process

  • Added platform column to endpoint datagrid

  • Added platform, isolation status, and policy filters to endpoint page

  • Added Linux deploy steps to deploy page

  • Added assigning log retrieval task to offline endpoints.

  • Optimized caching to minimize performance bottlenecks caused by high request load

  • Optimized security token check performance

  • Optimized concurrent message handling on Nats server

  • Refactored worker pool to works based on priority

  • Refactored the endpoint task queue to work with the task configs in policies and custom configs

  • Removed patrol from AIR

  • Fixed XSS exploit on audit logs

  • Fixed the performance bottleneck on the task progress update process

  • Fixed a memory leak in the visit process on the windows agent

  • Fixed a problem in windows agent installation version check

  • Updated EULA

  • Minor UX improvements

  • Minor bug fixes



Version 1.7.31

  • Fixed the bug related to task assignment to endpoints that are associated with multiple tags


Version 1.7.30

  • Improved triage match results

  • Improved AD sync performance

  • Improved audit log db write transactions

  • Improved license capacity checks

  • Improved LDAP login

  • Highly optimized task core module performance

  • Highly optimized endpoint task queue memory usage

  • Highly optimized audit log storage

  • Highly optimized realtime task assignment to endpoints

  • Optimized logging on agent

  • Optimized debugging log on worker tasks

  • Optimized Agent Installer download performance

  • Optimized task result upload performance

  • Optimized db bulk operations

  • Optimized triage rule storage

  • Optimized task storage

  • Refactored worker core module

  • Fixed an issue related to sending triage task result

  • Fixed performance issue caused by Patrol module

  • Fixed disappearing endpoint tags after AD sync issue

  • Fixed loading up tasks to endpoint queue issue caused by db migration

  • Fixed the register required bug that is caused by latency on endpoint registration

  • Fixed the performance issue on visit requests caused by agent update load balancer

  • Fixed investigating same endpoints multiple times in the same investigation

  • Fixed security token mismatch bug on visit requests

  • Fixed the bug caused by reloading task details on the UI

  • Fixed the bug related to license validation for online and offline environments



Version 1.7.24

  • Fixed a critical issue on the task assignment module


Version 1.7.23

  • Improved endpoint connection error logging

  • Changed max memory cache size to maximum

  • Highly improved memory usage of the endpoint task queue

  • Increased node's memory usage limit to 6GB

  • Reduced effect of long-running tasks on the starting speed of the application

  • Fixed performance and memory issue on sending events to Syslog and audit logs

  • Fixed a minor bug on the endpoint registration issue

  • Fixed a minor bug on fix endpoint issue task

  • Fixed a minor bug on the installer



Version 1.7.21

  • Fixed an issue in UI

  • Other minor bug fixes and improvements


Version 1.7.20

  • Fixed minor bugs



Version 1.7.16 (RC)

  • Added getting endpoint system resources feature

  • Added database backup feature that allows admin to create database backups regularly (credits: Turkcell CDC)

  • Added version column to the endpoint page

  • Added two new endpoint issue types

  • Added agent update management feature (credits: Turkcell CDC)

  • Added capability to fix registration issue for endpoints that re-installed

  • Improved error report sending on the installer

  • Improved offline license check

  • Improved endpoint issue filter

  • Improved dashboard page statistics

  • Improved automatic page data polling

  • Highly improved backend and agent logs

  • Improved re-upload task mechanism

  • Fixed an issue on triggers that cause not to ignore recurring requests

  • Fixed getting 404 when trying to download an external resource from the report

  • Fixed an issue in task fail upload condition

  • Fixed an exception in downloads collector

  • Other minor bug fixes and improvements



Version 1.7.13 (RC)

  • Fixed an issue in agent installer

  • Other minor bug fixes and improvements



Version 1.7.12 (RC)

  • Highly improved Yara Scanner speed

  • Improved getting agent logs from AIR

  • Improved process collector

  • Fixed an issue in Yara Scanner

  • Fixed an issue in Prefetch collector


Version 1.7.11 (RC Sunburst Edition)

Fixed minor typo



Version 1.7.10 (RC Sunburst Edition)

  • Added FireEye Red Team Tool Countermeasures Yara Rule

  • Added FireEye Mandiant SunBurst Countermeasures Yara Rule

  • Added support for both filesystem and memory triage

  • Added support for getting agent logs from AIR

  • Added support for agent log rotating

  • Highly improved AIR backend for concurrent operations

  • Fixed an issue in triage results

  • Fixed a minor issue in license

  • Other minor bug fixes and improvements


Version 1.7.8 (RC)

  • Fixed an issue in event log parser



Version 1.7.7 (RC)

  • Added Log Retrieval action to endpoint

  • Added Timeline action to endpoint group and endpoint tag tree

  • Added Reset Password support for users

  • Added scroll support for timeline

  • Added downloading case entries from report

  • Improved TimelineIR experience

  • Fixed minor install/uninstall bugs

  • Fixed trigger recurrence bug

  • Fixed other minor bugs

  • Removed setting AD and proxy configs from the installer


Version 1.7.6 (Beta)

  • Minor improvements and bug fixes



Version 1.7.4 (Beta)

  • Fixed an issue in event log parser


Version 1.7.3 (Beta)

  • Added support for downloading report as HTML (credits: Turkcell CDC)

  • Improved Quick Acquisition Profile

  • Improved agent update mechanism (credits: Orhan Solak - Barikat Cyber Security)

  • Fixed an issue in agent task processing mechanism (credits: Burak Karapınar - HAVELSAN)

  • Fixed an issue in agent manual uninstallation (credits: Orhan Solak - Barikat Cyber Security)



Version 1.7.1 (Beta)

  • Added TimelineIR feature

  • Added Binalyze Patrol feature

  • Added audit logs feature

  • Added role-based access control

  • Added "Acquire Evidence", "Schedule Acquisition", "Triage" and "Delete Endpoint" actions by tag

  • Highly improved agent performance

  • Highly improved agent memory usage

  • Improved settings page to separate The Users, License, and Evidence Repositories pages

  • Improved case file upload to handle .ppc files

  • Improved the installer prerequisites to handle the newer version of NodeJS

  • Improved debug logs

  • The minimum memory requirement for the AIR server increased to 8GB

  • Other minor bug fixes and improvements


Version 1.6.14

  • Added support for parsing SRUM Application Resource Usage

  • Added support for parsing SRUM Network Data Usage

  • Added new event records

  • Added MAC time to crash dumps

  • Added Custom Content collection from all drives (credits: Mason Toups)

  • Added Triage on all disk drives (credits: Mason Toups)

  • Added host content to report

  • Added export process table as CSV (credits: Alexander Jarvis)

  • Added Last Write Time for Installed Applications

  • Added support for CPU usage limitation (credits: Turkcell CDC)

  • Added Refresh button to the endpoint groups section

  • Added Delete All Tags button to the endpoint tags section

  • Added Delete button to all detail pages

  • Improved settings page design

  • Improved design of table action buttons

  • Improved Browser History acquisition

  • Improved Network Share connection check

  • Improved exception handling

  • Fixed an issue with event logs

  • Fixed WMI query exception problem

  • Fixed Downloads section processed count

  • Fixed an issue with timestamping



Version 1.6.11

  • Improved endpoint tags

  • Improved installer (credits: Babak Mirzahosseiny)

  • Fixed LDAP user login authentication (credits: Turkcell CDC)

  • Fixed LDAP endpoints register problem (credits: Turkcell CDC)

  • Fixed enable/disable debug logging bug


Version 1.6.9

  • Added feature of adding tags to endpoints (credits: Yalkın Demirkaya)

  • Added LDAP Sync option to endpoint group tree

  • Added refresh button to the endpoint tags section

  • Added delete tag action to the endpoint tags section

  • Added New Profile button to acquisition profiles dropdowns

  • Improved server logger to make logs more readable



Version 1.6.8

  • Added the Recent Tasks section to the dashboard

  • Added task assignment delete option

  • Added Scheduled Acquisition edit option

  • Added confirmation modal to Active Directory settings

  • Added status line to the task detail page

  • Added select all option to triage list of the endpoint

  • Added uninstall task assignment for unmanaged endpoints on a visit request

  • Added onetime scheduled task removal after execution

  • Added task execution history to dashboard backend API

  • Added task assignment removal to backend API

  • Added nats server port status checker job

  • Added match count stats to task details

  • Added support to login with an LDAP account

  • Added sending user deleted event to Syslog

  • Added e-mail field for the user

  • Improved task removal

  • Improved LDAP sync (credits: Babak Mirzahosseiny)

  • Improved SMTP validation logic

  • Improved server restart logic (credits: Babak Mirzahosseiny)

  • Improved agent https connection (credits: Babak Mirzahosseiny)

  • Refactored task assignment and scheduler

  • Fixed changing LDAP endpoint group after visit request (credits: Babak Mirzahosseiny)

  • Fixed https redirection bug (credits: Babak Mirzahosseiny)

  • Fixed report process tree view

  • Minor improvements and bug fixes


Version 1.6.4 (Code Name: Sirius)

  • New backend in NestJS (TypeScript) with 100% unit test coverage

  • New frontend in Vue.js

  • Added auto-complete support for YARA rule editor

  • Added support for YARA rule validation

  • Added group triage feature

  • Added global search feature

  • Added filtering support to all tables

  • Added local search for each page

  • Added security token refresh for triggers

  • Added new evidence types

  • Added new Custom Content collection editor

  • Added required port detection to the installer

  • Added Active Directory server setting alongside domain name

  • Added Memcache for decreasing response times

  • Added support for the upcoming Compromise Assessment feature (PPC file)

  • Added retry feature to agents in case there is no connection to evidence repository

  • Highly improved evidence selection page

  • Highly improved UX for task actions

  • Fixed minor issues in installer

  • Fixed minor issues in the Case report

  • Fixed an issue in NATS

  • Fixed an issue in license handling

  • Fixed Smart Screen warning on agent installation



Version 1.4.1

  • Added collection of Autorun locations

  • Added collection of Downloaded Files information

  • Added collection of RDP Cache Files

  • Added port availability check for the installer

  • Added new license models

  • Added support for offline licensing

  • Added support for task cancellation

  • Highly improved report

  • Highly improved calculation on visit interval

  • Improved UI/UX

  • Fixed an issue with timezone handling

  • Fixed an issue in group task assignments

  • Fixed app manifest problem for console service

  • Removed internet dependency from the installer

  • Minor updates and improvements


Version 1.4

  • Added support for Triage on FileSystem and Memory using YARA+

  • Added support for installation on Windows 7+ OSes

  • Added support for assigning a task to all endpoints in endpoint groups

  • Added support for sending case report after the task completion

  • Added support for anonymous network share connections

  • Added support for send notifications for failed tasks

  • Added Online filter into endpoints page

  • Added support for network share folder permissions check

  • Added support for updating endpoint details for upgraded OSes

  • Added support for filtering with endpoint groups are added

  • Added resilience to case report sending

  • Added sending match count after triage task completes

  • Added Yara rule validation

  • Added validating Yara rule file

  • Added sending Yara rule error message if the wrong rule provided

  • Added sending duration during the task

  • Highly improved evidence acquisition to network shares

  • Improved agent logs

  • Improved exception handling

  • Improved uninstall task

  • Improved fetching array from JSON

  • Improved network share authentication

  • Fixed an issue in LDAP Sync

  • Fixed unhandled exception with JSON GetValue

  • Fixed unhandled exception

  • Fixed wrong function usage for JSON

  • Fixed an issue with agent log

  • Removed unnecessary console API calls

  • Removed console out messages

  • Removed .NET Core dependency

  • Minor updates and improvements




Version 1.3.6

  • Fixed an issue in agent update

  • Fixed an issue in license handling

  • Fixed a UX issue in agent register


Version 1.3.5

  • Improved UI/UX

  • Highly optimized client connection handling

  • Highly optimized database operations

  • Added support for Custom Content

  • Added support for Syslog

  • Added console auditing logs

  • Added support for DB migration

  • Added edit button to tables

  • Added endpoint filter links to dashboard statistics

  • Improved license handling

  • Performance optimizations

  • Fixed an issue in LDAP synchronization

  • Fixed an issue leading to duplicate domain

  • Fixed an issue in tasks page showing incorrect endpoint

  • Fixed an issue in task scheduler

  • Fixed an issue in installer test LDAP button

  • Fixed an issue in installer test proxy button

  • Minor updates and improvements



Version 1.3.3

  • Improved UI/UX

  • Added validation to settings save

  • Fixed screenshot not captured issue

  • Fixed clipboard not captured issue

  • Fixed UsnJournal not retrieved issue

  • Fixed Active Directory paging issue

  • Fixed multiple Active Directory groups issue

  • Added scroll to Active Directory groups


Version 1.3

  • Major architectural improvements

  • Major security enhancements (credits: Mehmet İNCE &

  • Improved NATS real-time messaging

  • Improved email template

  • Added support for generic Webhook integration with SIEM, SOAR, and EDR products.

  • Added Custom Content Collection

  • Added administrator manifest to installers

  • Added logging for prerequisities

  • Added LDAP / Proxy test buttons to settings

  • Added support for SSL

  • Added 404 Not Found pages

  • Fixed an issue with forgot password dialog

  • Fixed an issue with Console updater

  • Fixed an issue with client IP handling

  • Fixed an issue with environment variables

  • Other minor bug fixes and improvements


Jan 1st

Add your timeline event here.

Jan 1st

Add your timeline event here.


AIR was born on 21st October 2019 with our first public Beta release 1.2.1

Download the AIR Features Guide
New call-to-action
Trusted by Enterprises Worldwide
logo-customers-pwc logo-customers-garmin logo-customers-sophos logo-customers-thy logo-customers-kpmg solis-security logo-customers-ey logo-customers-deloitte logo-customers-turkcell elisa-logo-4 logo-customers-integrity360