Subscribe to AIR Release Notes
Trusted by Enterprises Worldwide









Today
18/09/2023
Version 3.12.4
Hot Fix
-
We have made the Consolidated Report button enabled for Cases that were created before version 3.12.3 was released. Users can now use Consolidated Reports as expected without any problem.
-
To learn more about consolidated report- read this article.
-
When a Task is Failed, even though an error message reflects the issue, shown as an “Unexpected Failure” message within the Tasks Details page (by hovering over the “eye” icon in the Status tab); the Console did not report the correct status immediately. We have fixed this issue and the correct status is now reported.
-
When a user chooses a 'Custom Option' to collect evidence and the mode of "Direct Collection" toggle (on Linux or MacOS) is changed while a Task is still running, the agent may crash. We have fixed this issue to avoid the possibility that the agent will crash.
07/09/2023
Version 3.12
Features
Streamline your investigation
-
DRONE analysis for macOS
-
MITRE ATT&CK Analyzer
-
As of v3.12 DRONE now has MITRE ATT&CK rules for macOS.
-
-
Dynamo Analyzer (Credit: Dilek G)
-
Dynamo will parse the AIR report generated as the result of a task assignment and highlight suspicious entries.
-
-
Browser History Analyzer
-
Chrome, Edge, IE (7-11), Firefox, Opera, Safari, Vivaldi, Waterfox and Brave are now all supported for macOS
-
-
Audit Event Analyzer
-
Brings advanced capability to AIR by scanning event records for keywords, hacker tools, and commands, setting verdicts based on criteria, guidelines, or Sigma rules.
-
-
-
Tooltips added to DRONE findings within the Consolidate Report
-
When a user hovers above a Verdict or Score finding listed in the Table view, they will be presented with a to a tooltip that explains how the result is derived.
-
-
Isolation of macOS endpoints
-
Expanding Isolation capability to the last major operating systems -macOS. (Fully supports Windows, Linux & macOS devices).
-
Regardless of the isolation state, the endpoint maintains communication with the AIR console to allow analysts performing their investigation by generating Tasks as usual.
-
-
Addition of a "Retry Upload" action for failed Task Assignments (Credit: Daniel M)
-
Should a failure occur during the evidence upload phase of a task, a "Retry Upload" feature is now available to resolve issues more efficiently. Key benefits include:
-
Elimination of the need for evidence re-acquisition, preserving the original data.
-
No additional disk space consumption.
-
The "Retry Upload" option repurposes the existing task assignment for the re-upload, preventing task duplication.
-
-
-
Simpler access to Off-Network Agent logs & Drone log files
-
Agent logs and Drone log files of Off Network are now saved in the same folder . This makes it easier to find any log files and share them with Binalyze Technical support or for troubleshooting by yourselves.
-
File name format is: Troubleshoot-[TIMESTAMP].zip.
-
Enriching evidence and artifacts
-
New Artifact types collected for macOS:
-
Discord Desktop Cache
-
Discord instant messaging and VoIP social platform with voice calls, video calls, text messaging, media and files in private chats or as part of communities called "servers".
-
-
Parallels Logs
-
Parallels is a software company best-known for Parallels Desktop for Mac that allows users to run Microsoft Windows systems on macOS computers.
-
-
Homebrew Logs
-
Homebrew is a free and open-source software package management system that simplifies the installation of software on macOS, as well as Linux.
-
-
Sophos Events Database
-
Sophos develops products for communication endpoint, encryption, network security, email security, mobile security and unified threat management.
-
-
Sophos Antivirus Logs
-
The AIR agent will now collect Sophos Antivirus logs.
-
-
-
New Evidence types for macOS:
-
Shared File List
-
The SharedFileList (SFL) in macOS is a system feature that manages "recent items" lists for applications and the system itself. These lists could include recently used applications, documents, servers, or even volumes. The files with the extensions .sfl and .sfl2 are plist (property list) files in binary format.
-
-
Shell/Bash History
-
The .bash_history file holds significant value for various reasons including command tracking which may reveal the activity of an attacker. However, note that the .bash_history file can be manipulated, cleared, or even disabled by knowledgeable users.
-
-
Synchronization and collaboration between teams
-
Customizable Banner Message (Credit: Helen T)
Users can now display important announcements via a banner on the console GUI for events like maintenance, upgrades, or config changes. The banner interface allows:
-
Scheduling via Start/End dates
-
Message editing - up to 512 characters
-
Color customization
-
URL linking
-
Banner dismissal to maximize screen space
This feature provides direct communication with AIR users and offers permission controls for message settings.
Enhancements
AIR Core Functions Enhancements
-
-
Timeline
Swipe through a Timeline Bar to view events, dates, or time periods that are outside the current visible area.
-
-
Click-and-drag: The user clicks on the timeline bar and drags it left or right to scroll through the timeline.
-
Swipe wheel: If the device supports a scroll wheel or touchpad gestures, the user can use it to scroll left or right on the timeline bar.
-
-
-
Triage
Many more new triage rule templates are available to assist when constructing triage task assignments including:
-
-
YARA - Find by size range
-
YARA - Find Portable Execution files only
-
YARA - Find PKZIP files only
-
YARA - Find by hash value after filtering by file size
-
Sigma - User account hidden by registry
-
osquery - Unusual Cron entries
-
osquery - Processes running with no binary on disk
-
-
-
Consolidated Reports Enhancements
-
Consolidated Report Module refactoring to provide Generic Report Module
-
This new module generates individual task assignment reports that maintain the same view and structure as the existing Consolidated Reports.
-
-
Triage results from osquery are now available in Consolidate Reports
-
osquery results are now also searchable from the Global Search.
-
Security Enhancements
-
Automatically renew default AIR SSL certificate (Credit: Ramesh P)
-
The Binalyze-generated self-signed certificate will now auto-renew when it's within 10 days of expiration.
-
Fixes
-
Issues connected with CPU limitations have been resolved (Credit: Helen T)
-
Expired Task Assignments will no longer delay subsequent Task Assignments (Credit: Christian K)
07/09/2023
24/08/2023
Version 3.11.1
3.11.1 is all about Timeline enhancements and bug fixes. Binalyze team would like to thank its customers who shared their feedback and input to help us improve the quality and usability of the Timeline Bar, Flags and Filters.
Enhancements
-
Several Timeline improvements including;
-
-
Enhanced Date and Time Selection: Users can now specify both start and end dates, with precision down to individual hours, facilitating more granular timeline investigations.
-
User-Defined Navigation: The introduction of arrow-based navigation allows users to move backward and forward through user-specified periods, as determined in the date/time selector.
-
Refined Zoom Capability: The Timeline histogram now supports zoom functionality down to a singular hour for precise analysis.
-
Dedicated Tab for Flagged Items: We have reintroduced a specialized tab within the Timeline view to prominently display flagged items, ensuring streamlined navigation for significant events.
-
Fixes
-
Event Id not displayed in Timeline UI
-
-
The Event ID artifact now populates its details in the Title column of the AIR Timeline UI. (Credit: Grant O)
-
-
Timeline flagging fixes
-
-
We've implemented multiple fixes to the flagging feature in the Timeline, resulting in overall usability enhancements.
-
21/08/2023
Version 3.11.0
Important Security Update (Credit - Caleb T and Tyler B)
We have added ACL settings to a driver object to prevent unauthorized access and potential privilege escalation.
Users should urgently deploy the updated agents to address this high-severity vulnerability
21/08/2023
08/08/2023
Version 3.10
NB: The MongoDB relies on the CPU architecture that runs your AIR server. For this update, AIR v3.10, the CPU has to be newer than 2011 for both Intel and AMD processors. If your processor architecture is older than this, it is not advised to update MongoDB.
Features
-
Disk Space limit configuration for Acquire Evidence Tasks
-
-
When evidence collections are stored on the local machine, this new feature, for macOS and Linux, will allow AIR users to determine the amount of free disk space to always be left available to the local user.
-
If a collection is not complete when the allocated disk space limit is reached, the collection at that point and the .ppc will be available to the analyst in the normal way.
-
The Task Status will be marked ‘Partially Completed’.
-
Task Logs will now be available in the Case Report, under Case Info, and in Consolidated Reports in the Case Summary. These logs will list any uncollected evidence items.
-
-
Bandwidth limit configuration for Acquire & Image Evidence Tasks
-
AIR users now have the ability to determine the amount of network bandwidth they wish to allocate to their AIR collections.
-
-
Ability to purge locally saved acquisition task data
-
This new action, ‘Purge Local Data’, will create a ‘Purge’ Task to remove all data generated for a task assignment on an endpoint.
-
Purge Local Data can also be run from the Case’s page to purge all data generated for a task assignment on an endpoint.
-
Purging local data will not affect the installed AIR agent, so it remains ready for new task assignments.
-
To use Purge Local Data, the privilege “Delete task assignment” is required.
-
Binalyze AIR now supports the collection of over 350 evidence items.
New evidence types collected for Windows:
-
LNK Files
-
AIR will analyze and parse LNK files which are often abused by hackers, who can leverage them to use legitimate applications (such as PowerShell) to download malware or other malicious files.
-
-
Users
-
User accounts are created and stored as objects in Active Directory Domain Services. These accounts can be compromised by bad actors and programs such as system services used to log on to a computer. A successful login generates an access token which includes the security identity and group memberships of the user account associated with the process or thread. Every process executed on behalf of this user has a copy of this access token.
-
-
Timeline
-
Windows 10 Timeline feature enables users to: (i) View their currently running apps and look back at their previous activities such as; opened documents, programs, images, videos or visited websites. (ii) Synchronize activities across devices. (iii) Provide information about applications that were executed within the last 30 days, such as application name, time when it was launched and its duration. This information can be of forensic value, helping to reconstruct events, even if the files, documents or applications have been deleted.
-
-
UAL Logs
-
User Access Logs (UAL) store a lot of information and often present IT admins with privacy concerns. One such feature helps correlate an account and the source IP address with actions performed remotely on systems, so potentially valuable to attackers. (Credit: Daniel M)
-
New Evidence Types For macOS:
-
Apple Audit Logs
-
macOS writes important operational and security information that can be useful to an attacker as a place to obfuscate changes that were recorded. As part of defense-in-depth, the files in /var/audit should be owned only by root with group wheel with read-only rights and no other access allowed. macOS ACLs should not be used for these files.
-
-
AnyDesk Logs
-
AnyDesk is a remote desktop application that provides platform-independent remote access to personal computers and other devices running the host application.
-
-
Teamviewer Logs
-
TeamViewer is a German remote access and remote control software application often concerned with the maintenance of computers and other devices.
-
New Evidence Type For Linux:
-
AnyDesk Logs
-
(See above)
-
-
Filtering of Tasks to determine the presence of DRONE data
-
AIR now creates a metadata flag: ‘hasDroneData’ which indicates that DRONE data exists for a particular Task and reports with DRONE data can be filtered for in the endpoint’s Task listings.
-
-
‘biunzip’ is a new command-line tool from Binalyze specifically designed to extract zip files generated by the AIR Off-Network Agent.
-
You can download the latest release of biunzip from the releases section on GitHub: Let’s build from here
-
Biunzip will either unzip a single zip file or unzip zip files in a directory using a CSV file.
-
This capability will allow running off-network investigation at scale, and at speed with minimum effort.
-
Enhancements
-
Huge Timeline improvements
-
The timeline events bar is now displayed in histogram format, making it clear when activity has taken place.
-
The timeline bar now has zoom-in and zoom-out capabilities allowing users to drill down from decades to individual hours.
-
Findings flags will be shown in the timeline bar.
-
Filtering down via start and end dates is now possible as is filtering by; decades, years, months and days.
-
-
Hash Values for all Event and Registry Files are now shown in all Case and Consolidated Reports.
-
These hash values are searchable via Global Searching.
-
-
Last Used fields added
-
To help better understand analyst’s activity within AIR, a ‘Last Used Field’ has been added to the following pages:
-
interACT Library
-
Evidence Repositories
-
API tokens
-
Webhooks
-
Acquisition (profiles)
-
Triage (profiles)
-
-
-
Backup AIR every 4 hours
-
It is now possible to automate your AIR backups to take place every 4 hours, or or as was available in previous versions; daily, weekly and monthly. (Credit: Daniel M)
-
-
Loading Bar added for Async Commands
-
A loading bar for ongoing asynchronous commands is now displayed in all interACT shell sessions.
-
Fixes
-
No significant fixes needed this month
05/07/2023
Version 3.9.2
Features
-
Acquisition Profiles now display average time taken to complete
-
-
This great new feature displays to the user the average time it takes to run a particular acquisition profile in their own AIR environment. This will help analysts make decisions as to which Profile is best suited to a particular circumstance. (Credit: Daniel M)
-
This feature is unique to the users own environment, so the collection of metrics will start afresh with each new AIR console install.
-
-
New wizard to add endpoints to a Timeline
-
This dedicated Timeline wizard will speed up and simplify the addition of endpoints to your Timelines. The new flow allows you to select endpoints, define the Task and then choose the post acquisition analyzers such as DRONE or any of the other AIR analyzers needed for your specific investigations.
-
This feature is aligned with the new Quick Start feature introduced in v3.8 - Both designed to simplify and speed up your investigations.
-
-
Five new Webhooks available in AIR:
-
Stellar EDR
-
LogicHub SOAR (DEVO)
-
Rapid7 InsightIDR
-
Fortigate SIEM
-
Dynatrace
-
Take advantage of AIR’s Webhooks to increase your SOC’s automated collections and analysis of data from endpoints and dramatically speed up all of your investigations.
-
New macOS evidence support - Apple System Logs
-
Apple System Log Files (.asl files) contain detailed records of various system events, processes, errors, warnings, and activities that occur on a macOS device.
-
-
New macOS evidence support - Apple Unified Logs
-
The Apple Unified Logs (AUL) system was introduced with macOS 10.12. It creates a standard log format used in all Apple operating systems, including macOS, iOS, watchOS, and tvOS. One of the most powerful filtering capabilities of AUL is the predicates.
-
AIR will present unified logs using the comprehensive set of predicates shown below:
-
User login events
-
Tccd events
-
Ssh activity events
-
Command line activity run with elevated privileges
-
Kernel extension events
-
Screen sharing events
-
Keychain unlock events
-
Sessions creation and destruction events
-
Detecting and blocking malicious software events
-
Failed sudo events
-
MDM Clients Events
-
-
Enhancements
-
Consolidated Report improvements
-
To support collaboration between analysts by highlighting important evidence and findings, we have added the option to bookmark items within Consolidated reports.
-
Users can also see who bookmarked an item and when they did so. They can also apply filters to show ‘Bookmarks’ or ‘Bookmarked by’.
-
A new ‘event viewing’ window will display expanded details for any item selected in the main viewing area.
-
Global Search has been enhanced for faster search returns.
-
-
YARA rule scans can be run via interACT
-
It is now possible to run YARA scans inside the AIR cross-platform remote shell, interACT. (Credit: Ramesh P)
-
-
YARA and Sigma rules use the same verification method
-
Binalyze AIR will now use matching validation methodologies for these two different rule types, so YARA and Sigma scanning can no longer be tasked to run any incompatible rules. (Credit: Antonio L)
-
Fixes
-
AWS S3 upload failures
-
Simultaneous upload issues to AWS S3 bucket and all other repositories have been fixed by enforcing sequential uploads only. (Credit: Simon L)
-
-
Reporting a Failed Status
-
When a Task is running, and something causes the agent to restart, a ‘failed’ status will be shown when the agent starts again if any of the tasks fail to complete.
-
-
Timeline imports to Chrome
-
An issue preventing Chrome uploads to the AIR Timeline has been resolved.
-
-
Authentication Errors for Public API's are fixed
05/07/2023
12/06/2023
Version 3.8
Features
-
New Quick Start wizard for launching AIR tasks.
-
-
This new feature is available from all AIR Console views, it speeds up and simplifies the launching of AIR tasks; Acquire Evidence, Acquire Image, Triage, interACT, Timeline, Compare and Schedule Acquisition.
-
-
Disk Images
-
AWS S3 and Azure evidence repositories now provide support for forensic disk image acquisitions. (Credit: Daniel M)
-
-
Downloading from Evidence Repositories - For individual endpoint Case Reports, it is now possible to directly download the evidence.zip file associated with that report:
-
A download button will be shown for the following sources:
-
-
AWS
-
Azure
-
-
-
A URL with a copy button will be shown for the following sources:
-
-
Local
-
SFTP
-
FTPS
-
SMB
-
-
-
-
AIR Backup - AWS S3 is now a supported repository for AIR backups (Credit: Daniel M)
-
Relay Server - Not everyone can have direct access from all of their endpoints to the AIR console. This new AIR Relay Server/traffic router capability, will allow network segments which need to remain air-gapped to communicate with the AIR console.
*This feature will be enabled per demand. If you're interested, contact your customer success.
Enhancements
-
Task Naming - Users can customize the individual Tasks' name. In doing so, this will override the default auto-task naming function. If the user decides not to give the task a customized name, AIR will revert to its auto-task naming convention.
-
Settings Menu - Streamlining the main settings menu by relocating the following to the sub-settings tab; Users/Roles, Evidence Repositories and Licence options.
-
The new settings menu is grouped as follows:
-
General - Version, Logging, License, Connection, Console Proxy.
-
Endpoints - Agent updates,, Tamper detection, Active directory.
-
Security - SSL certificate, SSL root CA, Console port, IP restriction, Authentication, SSO.
-
Features - Enable interACT, Resolve Agent Public IP, Case selection, RFC3161 Time-stamping, SMTP, Syslog / SIEM.
-
Users/Roles
-
Evidence Repositories
-
Backup
-
New artifacts for collection - For macOS, in both ‘Full’ and ‘Quick’ acquisition profiles we have added; Quarantine Events, Sudo Last Run, iMessages, Dock Items (dock.plist) and Document Revisions.
-
UX improvement - In the Timeline view it is now possible to select or deselect all evidence categories with a checkbox found at the top of the evidence category listings.
-
UI improvements - To improve workflow:
-
When creating a New Case in AIR, the Organization field will not be automatically populated anymore, it will remain blank so that the user is ‘forced’ to think about which Organization the New Case should be attributed to.
-
The auto expansion animation has been removed from the left side navigation menu of the UI.
-
Evidence Repository - It is now possible to define a Domain Name for any new SMB Evidence Repositories.
-
Triage Rules - There is now no limit to the number of triage rules available to investigators.(Credit Antonio L)
-
Yara - AIR’s version of Yara has been updated to Yara v4.3.1.
-
interACT opens in a new window - allowing users to continue to use the Console UI and have several interACT sessions active simultaneously.
-
interACT auto-complete - Navigation between the auto-complete options is now possible with tab key. (Credit: Christian K)
-
$mft as a .csv improvement - The full file path for each $mft record entry will now be included in the .csv generated by an AIR, ‘$mft as csv’ collection.
-
CPU limit for macOS - Users can now limit the amount of CPU usage available to the AIR agent on the endpoint when assigning a task.
Fixes
-
OSquery on Triage bug fixes. (Credit: Christian K)
-
Timeline bug fixes. (Credit: Ramesh P)
11/05/2023
Version 3.7
Features
-
Triage Match Count Column
-
In the Task window it is now possible to select, from a column selector, to display a column for Match Counts, and if the user filters by Triage the Match Count column will be added automatically to the filtered results.
-
-
New Webhook - Microsoft Sentinel
-
AIR now has built-in support for a Microsoft Sentinel Webhook (Credit to Elisa.com - Finland).
-
-
Mandatory Case Selection Option
-
This new feature allows Enterprise and MSOC customers to enforce the selection of a case for all Acquisition and Triage tasks ensuring that all collections and tasking results are attributed to a case. For FIS customers this feature will always be active by default.
-
-
New Chrome artifacts for Mac Linux and Windows
-
For Mac, Linux and Windows support has been added for parsed evidence from Chrome; Bookmarks, Cookies, Downloads, User Profiles, Extensions and Browsing History
-
-
Isolation Support for Linux
-
Linux endpoints can now be 'Isolated' from within the Endpoints Details UI window.
-
-
New 'Last Seen' Endpoint Filter
-
AIR now allows for the date and time filtering of endpoints by; 'Last Seen After', 'Last Seen Before' and 'Last Seen Between'.
-
-
Apple macOS TCC collection
-
AIR now supports the collection of Mac TCC (Transparency, Consent and Control) data.
-
IMPORTANT: In order to benefit from these new features, you should install our new DataBase. Click here to learn more.
Enhancements
MITRE ATT&CK enhancements
-
MITRE ATT&CK Rules with Drone for Acquisition and Triage Tasks
-
Users can now see and select the MITRE ATT&CK analyzer in both the Acquire Evidence and Triage Tasking windows. In these views it is now also possible to see when AIR last checked our MITRE ATT&CK database to ensure that the user has access to the latest MITRE ATT&CK definitions for AIR.
-
-
MITRE ATT&CK Rules support for off-network tasks
-
The same level of support mentioned above for MITRE ATT&CK is now also available for off-network Evidence Acquisitions and Triaging.
-
-
MITRE ATT&CK Tactics Widget View within Consolidated Report
-
The Consolidated Report now aligns and displays artifacts by the number of times a particular MITRE ATT&CK Tactic, Technique or Finding has been identified. The Technique and Sub-Technique identified will also be displayed along with a direct link to the relevant MITRE ATT&CK webpage.
-
-
MITRE ATT&CK Auto update
-
Binalyze AIR will now automatically check for any new MITRE ATT&CK updates as soon as a user opens the Acquire Evidence or Triage Tasking windows. An internet connected AIR installation is required, ensuring customers always have access to the latest AIR MITRE ATT&CK definitions. (Off-Line support will be coming in future versions)
-
Consolidated Report enhancements
-
Consolidated Report: MITRE ATT&CK Report View
-
The Consolidated Report front page now displays a MITRE ATT&CK overview report.
-
-
Consolidated Report: Event Records Consolidation
-
Event Records are now consolidated in human readable format for investigators.
-
-
Consolidated Report: Global Search
-
Global Searching is now possible across Consolidated Reports. This feature addition is super powerful, and allows users to search across all of the acquisition and triage data that constructs a Consolidated Report from multiple endpoints in any particular case.
-
-
Consolidated Report: Process Details View
-
An event details module has been added at the bottom of the evidence item page, so when an item is selected in the upper window, if there is additional information available it will be displayed in the lower details window.
-
-
Consolidated Report: Process Tree View
-
A Tree view is now available for processes within Consolidated Reports.
-
-
Consolidated Report: CSV export
-
It is now possible to export Evidence Items from within the Consolidated Report to CSV.
-
Fixes
-
Security fix related to endpoint isolation
-
Security fix related to the installation process
-
Security fix related to the password reset process
-
Security fix related to access to server files
11/05/2023
17/04/2023
Version 3.6
Features
-
Public key authentication support was added to SFTP evidence repositories
-
Users can use public key authentication on SFTP servers or services such as Amazon Transfer Family to store the evidence and artifacts.
-
Users can use either a username and password authentication or public key authentication on SFTP on Evidence Repository
Enhancements
-
N/A
Fixes
-
Minor bug fixes
10/04/2023
Version 3.5.1
Features
-
Consolidated Report.
-
The Consolidated report is a single, easy-to-read DFIR intelligence report, that displays Acquisition and Triage acquired data from multiple endpoints in one report.
-
Triage with OSQuery.
-
Analysts can now create, modify and run OSQuery queries across multiple assets in the AIR Triage GUI, along with our pre-existing YARA and Sigma capabilities.
-
Timeline support was added for Linux and macOS.
-
Investigators and analysts can add Linux and macOS artifacts to AIR Timelines. Leverage this addition to have just one Timeline with multiple endpoints from all 3 operating systems; Windows, Mac and Linux. This is potentially another massive boost to speeding up investigation times.
-
Importing Chrome/Chromebook collections to Binalyze AIR Console
-
Investigators and analysts can now add standalone Chrome evidence acquisition results (PPC file) to Binalyze AIR
-
New Artifacts and Evidence for macOS and Linux.
-
More than 35 new artifacts and evidence types, such as Apache, Nginx, MySQL, PostgreSQL, MongoDB, Docker, KnowledgeC, and more system-related logs were added to Binalyze AIR
-
Organization Tags
-
Managed SOCs partners (MSSPs) can add, remove, list and group their Organizations by Tags. This would simplify operational day to day needs, since it is much simpler to define and classify each Organization by 1 or multiple Tags. The new capability is available also via the API.
Enhancements
-
N/A
Fixes
-
interACT get the command’s unresponsiveness bug fixed
-
interACT session termination bug fixed
10/04/2023
10/03/2023
Version 3.4.3
Features
-
Network Capture for Linux and macOS
-
Beginning in version 3.4, the network capture feature is available on Linux and macOS operating systems.
-
-
Display Real IP Addresses of Endpoints by using XFF (Credits: Aaron V.)
-
AIR Console can read and parse the HTTP requests and XFF headers from the Forward Proxy and associate them with the assets to determine the assets' real IP.
-
-
x64 support for Off-Network Microsoft Windows
-
Beginning in version 3.4, Microsoft Windows 64-bit Off-Network binary package is available and can be run on supported 64-bit architectures.
-
-
Disk Imaging
-
Binalyze AIR provides disk imaging which we call “Acquire Image”, for Microsoft Windows, Linux, and macOS operating systems.
-
-
The last Seen Endpoints filter parameter was added to API (Credits to Garmin)
-
“Get Endpoint” API request now has the Last Seen Endpoints filter parameter. So the assets can be listed by the last seen date.
-
-
AIR for Chrome
-
AIR For Chrome is the evidence collector extension for Chrome and ChromeOS. AIR For Chrome extension allows investigators and analysts to capture forensically sound data with a single click at machine speed.
-
Enhancements
-
The character limitation on the hostname field of the Endpoints is removed.
-
Beginning in version 3.4, there will be no character limitation for assets' hostnames. Assets that have hostnames longer than 15 characters won't be trimmed and shown as they are.
-
-
The Endpoint Details page has been improved
-
The new endpoint details page is more organized and practical and provides more information about the asset.
-
The name of the System Resources tab has been changed to Hardware, and Volume and disk information will be shown here.
-
Acquire button function has been expanded. When it is clicked, Acquire Evidence and Acquire Image options will appear, and users can select any of them to start a data acquisition or disk/volume imaging task.
-
Disk and volume imaging, what we call Acquire Image tasks, can be performed in Volume or Disk tabs under the Hardware section of the Endpoint Details page.
-
06/02/2023
Version 3.3.1
Features
-
Multiple Sigma Rule Upload
-
Investigators and Analysts can upload multiple Sigma rules to AIR Console at once
-
-
Taking Full Logical Volume Images by using the user interface
-
Investigators and Analysts can create full logical volumes of images using either a user interface or a secure remote shell interACT.
-
Microsoft Windows, Linux, and Apple macOS operating systems are supported
-
-
x64 support for Windows Agent
-
Beginning in version 3.3 64-bit version of the Microsoft Windows AIR Agent is available.
-
-
Case ID Prefix
-
Customers using more than one Binalyze AIR Console instance can now add a prefix to their Case IDs. Therefore there will not be experienced any confusion about Case IDs anymore.
-
-
Progress monitoring added to Get & Put commands on the interACT
-
Investigators and Analysts can see the file download progress from an endpoint (get command) and file upload to the endpoint from the library (put command) command outputs while using secure remote shell interACT.
-
-
MITRE ATT&CK Scanner was added to Binalyze AIR Automated Threat Analyzer, DRONE
-
When Investigators and Analysts scan their systems with DRONE, they can see the MITRE ATT&CK mapped results in the report. DRONE rules are continuously developed and mapped to the MITRE ATT&CK framework.
-
Enhancements
-
Some security improvements on AIR Console
-
Some performance improvements on AIR Console
Fixes
-
Minor bug fixes
06/02/2023
11/01/2023
Version 3.2.4
Security Hot fix
-
Binalyze AIR uses the JWT library that was compromised, immediate actions have been taken to remediate and AIR v3.2.4, containing the hot-fixes for the related vulnerabilities, has been released as of today. This includes fixes for the indirect vulnerabilities due to second-level dependencies.
Therefore, it is strongly recommended to update your existing AIR deployments to this latest version AIR v3.2.4 at your earliest convenience.
10/01/2023
Version 3.2.3
Hot Fix
-
Hot fix that includes typo fixes, timeline date filtering, and browser back button navigation caused regarding the dashboard
10/01/2023
05/01/2023
Version 3.2.2
Features
-
Activity Overview Dashboard added
-
Activity Overview Dashboard is a dynamic dashboard that provides tabular and graphical information about the usage, benefits, and return on investment of the Binalyze AIR in the enterprise company.
-
-
Progress Monitoring was added to InterACT secure remote shell
-
Investigators can track the progress of the command and estimate how much time is left on the interACT shell
-
-
AIR Agent Proxy Support
-
AIR agent automatically identifies the proxy configuration on the endpoint and configures itself to access the required services over the proxy service.
-
Enhancements
-
Miscellaneous package and dependency updates
Fixes
-
Several bugs fixed
30/11/2022
Version 3.1
Features
-
Golden image option was added to AIR Agent installation
-
AIR agent is now compatible with installation via a golden image for new device deployment. With this feature enabled, an administrator can prevent potential connection and availability problems that may have previously occurred on the AIR console for machines installed from a golden image.
-
-
New File System Enumeration evidence for Linux and macOS
-
Investigators can list the creation, modification, and access dates and times of the files and folders on the Linux and macOS filesystem as CSV files.
-
Enhancements
-
Baseline Comparison Reporting
-
Collapse/Expand All items under the Acquisition Profile section.
-
Acquisition Profile information was added to the Tasks list under the Endpoint details page.
-
YARA 4.2 update
-
FTPS support for full disk image
-
SSL/TLS proxy server support was enhanced
30/11/2022
02/11/2022
Version 3.0.5
Features
-
RFC-3161 compatible evidence signing for the chain of custody
Enhancements
-
New Asset status, "Off-Network," added
-
AIR Console domain address updates are enhanced
-
New evidence types added
-
Docker Artifacts for Linux OS
-
Browser History Artifacts for Linux OS
-
Browser History Artifacts for macOS
-
RAM image collection for Linux
-
-
Agent uninstallation and purge operations are enhanced
-
Multi-file upload for Off-Network devices
-
Path of the evidence files added
-
Local IP addresses added to the endpoint details page
-
The full disk image for macOS
Fixes
-
Case activity reporting to Binalyze cloud services [credit: Nixu]
-
DNS and ICMP Protocols are filtered when Endpoint Isolation
04/10/2022
Version 2.10.2
Features
-
AWS EC2 one-click agent deployment
-
Cloud forensics - Azure VM support
-
Azure VM one-click agent deployment
-
Auto Asset Tagging based on hostname, IP address, and subnet
-
Auto Asset Tagging based on custom rules with osquery builder
-
Linux full disc image via interACT
Enhancements
-
7x speed improvement for most evidence acquisitions on macOS and Linux
-
You can now upload multiple YARA rules at once
-
Improved troubleshooting logs
-
Token support for MFA
Fixes
-
Fixed an issue where sometimes recycle bin collection would fail
-
Fixed an issue that prevented baseline comparison on unreachable endpoints
-
Other minor bug fixes
04/10/2022
16/09/2022
Version 2.9.3
Fixes
-
Fixed an agent uninstallation issue on Linux and macOS
-
Fixed an issue where in some cases, disk imaging would hang
01/09/2022
Version 2.9.1
Features
-
Added ability to enumerate Amazon AWS EC2 assets
-
Added Yara triage support to macOS assets
-
Added Baseline comparison for macOS assets
-
Added full disk image collection with interACT for Windows assets
Enhancements
-
Added ability to duplicate acquisition profiles
Fixes
-
Fixed an issue where notifications were not shown about tasks in non-default Organisations
-
Fixed the wrong warning message when deleting a task from a case.
-
Fixed an issue where the user couldn't see the baseline comparison report even though the baseline acquisition task was finished.
-
Fixed the name column sorting in the interACT Library
01/09/2022
04/08/2022
Version 2.8.2
Features
-
Added off-network Acquisition and Triage with portable agent
-
Added interACT for macOS
-
Added Tamper Detection for macOS agent
Enhancements
-
API now includes endpoints for Policy, Auto Asset Tagging, Triage Rules, and Users (Docs)
-
interACT shell now supports backslash (\) for newline
-
Updated and improved the powershell deployment script
-
Improved efficiency of e-Discovery and custom content collections
Fixes
-
Fixed an issue where some users were not able to upload files to the interACT library
-
Fixed an issue where sending the same acquisition twice to the same timeline would result in duplications
-
Fixed an issue where an evidence repository that’s in use in a policy could be removed from the console
-
Fixed limitation on username length
08/07/2022
Version 2.7.2
Fixes
-
Fixed task migration scripts update
-
Fixed scheduled task comparison is missing on Baseline Comparison
-
Fixed connecting AD user with less than 5 characters
-
Fixed spelling mistake is shown On ESXi Agent Deployment Page
-
Fixed UI issues about ESXi tab
08/07/2022
01/07/2022
Version 2.7.1
Fix
-
Fixed a bug related to agent uninstallation process
29/06/2022
Version 2.7.0
Features
-
Added support for Apple macOS assets
-
Added Chromebook standalone collector (credit: Yuta K.)
-
Added ESXi standalone collector (credit: Andres S. and Mason T.)
Enhancements
-
Case selection is now optional with an Enterprise or MSOC license
-
API now includes endpoints for Repositories, Baseline, Case and Organizations (Docs)
-
Improved the retry process for interACT’s get and put commands
Fixes
-
Fixed issue with downloading files with special characters via interACT
-
Fixed acquisition history graph on the dashboard
-
Fixed other minor functionality and UI issues
-
Fixed UTC time mismatch in DRONE for Windows event logs and event records
-
Fixed DRONE stability issue when using keyword search
29/06/2022
10/06/2022
Version 2.6.1
Features
-
Added asset baseline forensic comparison
-
Added support for FTPS evidence repositories
-
You can now have interACT sessions with isolated Windows endpoints
Enhancements
-
Added new evidence and artifact types to Windows acquisition
-
All active interACT sessions are now ended when interACT is disabled from settings
-
Added "New Rule" shortcut to Triage assignment screen
-
Added keyboard support for confirming and dismissing popups (Enter/Esc)
-
Improved evidence compression performance
-
Enabled option not to compress evidence on collection
-
Upgraded interACT curl executable to version 7.83.1
-
Upgraded interACT osquery executable to version 5.2.3
-
Improved performance of agent installation on Windows
Fixes
-
Improved Auto Asset Tagging task assignment
-
Improved UI performance in various locations
-
Improved security of sensitive credentials saved in the AIR setting
-
Fixed an issue with the status of the agent update task
-
Fixed a bug in the interACT zip command
-
Fixed a minor bug in unique case directory creation on endpoints
-
Fixed other minor bugs
09/05/2022
Version 2.5.1
Fix
-
Fixed a bug in the DRONE configuration file migration process.
09/05/2022
21/04/2022
Version 2.5.0
Features
-
Added DRONE support for Linux
-
Added Sigma rule triage to Linux
-
Added shareable deployment feature
-
Added new organization management page
-
Added osquery command to interACT
-
Added mkdir command to interACT
-
Added sort and tree options to interACT pslist command
Enhancements
-
Added SSL Enforcement for accessing AIR.
-
Added auto asset tag rules for Apache, Redis, Mysql and Rabbitmq
-
Added tamper detection type to audit log description
-
Added filtering endpoints by label
-
Added filtering audit logs by endpoint name
-
Added TACTICAL and DRONE KB download links
-
Added required privileges section to interACT command help pages
-
Improved endpoint update performance
-
View and Update Organization privileges moved from system privileges to user privileges
-
Hardened to prevent less-privileged users from accessing sensitive settings data
-
Upgraded interACT curl executable to version 7.82.0
-
Improved tamper detection
-
Improved triage to allow the same Yara rule name in different rulesets
-
Added time frame limit to DRONE Event Records Analyzer
-
Improved DRONE Ransomware Analyzer performance. Added total and per channel limit for Events of Interest and Event Records analyzer.
Fixes
-
Fixed a minor issue on global search
-
Fixed evidence repository path validation bug
-
Fixed Endpoint label delete issue
-
Fixed e-Discovery patterns search issue
-
Fixed interACT curl command's missing CA certificates on Windows
-
Fixed a bug in sigma triage to kill DRONE process when task is canceled
-
Fixed an issue with the DRONE Linux x86 build.
-
Fixed other minor bugs
-
UI/UX improvements
16/03/2022
Version 2.4.0
Features
-
Added e-Discovery collection to acquisition profiles (credit Yalkin D.)
-
Added Tamper detection to agent
-
Added agent support for Linux arm64 (aarch64)
-
Added curl command to interACT
-
Added hex command to interACT
Enhancements
-
Added IP Address column to Endpoint table
-
Added silent installation tooltip for SCCM agent deployment
-
Added endpoint name to audit log filter
-
DRONE keyword search capability is now more visible
-
Improved zip command in interACT - Now zips to folder
-
Added new metrics for case report memory section
Fixes
-
Fixed unquoted service path issue after a config update (CVE-2021-42563)
-
Fixed minor issues on timeline export
-
Fixed duplicated user validation issue
-
Fixed evidence repository name and path validation issue
-
Fixed system resource usage not updating in interACT session issue
-
Fixed renaming evidence repository issue
-
Fixed an issue that allowed task assignment to endpoints with an old agent
-
Fixed webhook addresses not updated after a change of console address
-
Fixed SFTP current directory support
-
Fixed opening report issue in Safari browser
-
Fixed minor issue on Sigma rule parser
-
Fixed minor issue on Drone table
-
Fixed minor UI issues
16/03/2022
09/03/2022
Version 2.3.6
Fixes
-
Fixed a bug that broke the database migration step on v2.3.5
-
Fixed minor memory leak in the Events of Interest analyzer
23/02/2022
Version 2.3.5
Features
-
Added Sigma rule triage for Windows
-
Added autocomplete functionality to interACT
-
Added ServiceNow support to webhooks
Enhancements
-
Added new privilege to allow changing endpoint label
-
Added auto asset tag rules for Docker and Kubernetes
-
Added version information to settings
-
Added ability to handle Unicode file paths in YARA scanner
-
Added ability to specify a temporary staging directory for acquisition tasks that use evidence repository
-
Improved evidence collection on low capacity endpoints by letting AIR automatically select the volume with the greatest available free space (credits: Babak M.)
-
Improved evidence repository background upload mechanism with persistent retries
-
Improved case export functionality
Fixes
-
Fixed minor memory leak of canceled tasks
-
Fixed minor logging issues
-
Fixed interACT exec command stdin issues on Windows
-
Fixed a bug related to listing unsupported drone analyzers
-
Fixed case filter issue
-
Fixed policy list on task creation, missing policies
-
Fixed case-sensitive username issues
-
Fixed case day counter
-
Fixed minor bugs on the report
-
Fixed other minor bugs
23/02/2022
24/01/2022
Version 2.3.0
Features
-
InterACT: A cross-platform remote shell session capability that allows the users to run commands on remote endpoints for triage, mitigation, and remediation purposes in situations such as cyber incident response activities.
Enhancements
-
Improved windows agent installation
-
Improved endpoint tag assignment
-
Increased timeout duration for Azure Blob Storage
Fixes
-
Fixed incorrect tag-endpoint count
-
Fixed scheduled instant execution
-
Fixed invalid SFTP port
-
Fixed returning wrong http status code for invalid evidence repository Id
-
Fixed organization search criteria
-
Fixed timeline wrong date range issue on export
-
Fixed multiple role assignment issue on UI
-
Fixed showing "Reset filter" button in the timeline
-
Fixed organizations tag gaps on the UI
-
Fixed privilege hierarchy issue between organization and global admin roles
-
Fixed not showing 404 page for case section
-
Fixed webhook URLs display issue in some cases
-
Fixed duplicated start date field in scheduled task detail
-
Fixed no link issue on "see details" text on Settings > Connection page
-
Fixed broken KB links for Webhooks and SSO
09/12/2021
Version 2.2.1
-
Added Slack integration support
-
Added Mattermost integration support
-
Fixed timeline sort issue
-
Fixed viewing case.ppc issue on failed tasks
09/12/2021
25/11/2021
Version 2.2.0 (RC)
Features
-
Added exporting endpoints as CSV
-
Added exporting cases as CSV
-
Added exporting case activities as CSV
-
Added exporting case notes as CSV
-
Added exporting case endpoints as CSV
-
Added exporting audit logs as CSV
-
Added exporting timeline events as CSV
-
Added Yara external variables and removed yara+ modules (file, process)
-
Upgraded Yara to 4.1
-
Enriched triage case report for file matches for Linux
Enhancements
-
Added webhook support for Elasticsearch Logstash Kibana (ELK)
-
Added webhook support for SumoLogic
-
Improved task queues
-
Improved triage performance
-
Improved handling of cancel tasks
-
Improved connection timeouts
-
Improved log rotation
-
Improved log format
-
Improved logging
-
Improved Triage case report
-
Updated the application icon for the Windows agent
-
Added timeout for evidence repositories on agent
Fixes
-
Added retry for agent HTTP requests
-
Added retry for failed case file uploads
-
Introduced Linux systemd service restart on failure
-
Fixed compression progress reporting
-
Fixed HTTP response close
-
Fixed a race condition for HTTP transport
-
Fixed progress reporting
-
Fixed self match possibility of custom content collection for Linux
-
Fixed misc. minor bugs
18/11/2021
Version 2.1.5
-
UI/UX improvements on case containers
-
Fixed minor bugs related to case containers
-
Fixed drone autopilot issue on scheduled tasks and webhooks.
-
Fixed a bug about using azure storage as evidence repository on linux agents
18/11/2021
9/11/2021
Version 2.1.0 (RC-2)
-
Added additional functionality to cases feature
-
Minor fixes and improvements
01/11/2021
Version 2.0.5
-
Added FQDN support for console address
-
Added a Quick Intro guide to help new users get started with AIR
-
Fixed an issue on SSO with 8443 port
-
Console migration process moved to task logic
-
Minor Linux agent fixes:
-
Minor http timeout fix
-
Minor triage command line parameter fix for excluded files
-
Visit poll interval overflow fix for 32bit architectures
-
-
Minor Windows agent fixes:
-
Minor improvement on isolation
-
01/11/2021
12/10/2021
Version 2.1.0 (RC)
New:
-
Added case container feature
-
Added FIS license support
Fixes:
-
Fixed a minor issue related to the auto-asset-tagging feature
-
Fixed organization admin privileges issue
-
Minor UI/UX fixes
22/9/2021
Version 2.0.1
This is the stable version of the latest RC (v2.0-RC)
In this version;
-
Added new predefined acquisition profile: Compromise Assessment
-
Added deployment script support for Windows agents
-
Added webhook parser for Cortex XSOAR and Splunk Phantom
-
Added new evidence type for Windows agents: Collecting USB Storage History
-
Improved license validation messages
-
Improved temporary path usage for Windows agents
-
Fixed a bug related to timeline event count
-
Fixed a bug related to sending events to syslog
-
Fixed a bug related to canceling Auto Tag Asset task on Windows agents
-
Major performance improvements
22/9/2021
9/9/2021
Version 2.0 (RC)
New:
-
Added AIR-DRONE Integration (available only for acquisition and timeline for now) - rapid keyword searching, anomaly finding, scanning SIGMA rules live directly on any endpoint, and many other DRONE features are available now in AIR.
-
Added Auto Asset Tagging feature - tag your assets automatically by the conditions you provide.
-
Added Off-Network Endpoints feature - add and filter off-network endpoints.
-
Added PPC Import to Timeline feature - import PPC files collected from offline or online environments to Timeline.
-
Added IP Restrictions feature - restrict access to the AIR Console based on IP addresses or IP blocks.
-
Added UI Port Splitting feature - enables you to serve AIR Console and Endpoint requests from separated ports. With this feature, you can create separate firewall rules in AIR.
-
Added Drone findings on the Timeline
-
Added SMB Repository Support for Linux
-
Added Pardus Linux Support
-
Added Super glob meta (double star) support for custom content
-
Added IP Restriction Reset Script
-
Added an ability to download case reports from the endpoint detail task page
-
Added hashes.csv file that contains hashes of the files in the case report
-
Added detailed step by step task statuses (Processing, Compressing, Uploading, Analyzing)
-
Added support for .pfx, .der SSL certificate types
-
Added supported Linux distributions information to deploy the page
-
Added "Send to Timeline" action to Acquisition tasks
-
Added displaying support for PPC file metadata
-
AIR UI has a new design layout now
Improvements:
-
Improved more user-friendly error messages
-
Improved database connection functionality on backend
-
Improved case report view options on the endpoint detail page
-
Improved global search bar visibility for each page
-
Improved notification module "Mark All as Read" accessibility
-
Improved showing EULA in AIR setup
-
Improved and simplified AIR deployment with Docker for Linux
-
Improved performance while opening the Case Report.
-
Improved SSL Certificate installation
-
Minor improvements/fixes on case report
-
Upgraded MongoDB version to 4.4.7
Fixes:
-
Fixed an issue related to uninstallation of windows agent manually
-
Fixed LDAP issue occurring while trying to login AIR with:
username@domain format -
Fixed task queue cancellation
-
Fixed Proxy SSL issue
-
Fixed organization name update issue
-
Fixed organization filter bug on the policy creation page
-
Minor UI/UX fixes
18/8/2021
Version 1.8.3
-
Minor changes and improvements
Go to knowledgebase to learn how to migrate from v1.7.61 to v1.8
18/8/2021
17/8/2021
Version 1.8.2
This is the stable version of the latest RC (v1.8.0-rc)
In this version;
-
Added AIR CLI Support
-
Added to restore using a backup file support
-
Added to reset local user password support
-
-
Improved AWS S3 Bucket upload on Windows agent
-
Improved Custom Content Collection on Windows agent
-
Fixed some minor bugs
Go to knowledgebase to learn how to migrate from v1.7.61 to v1.8
14/7/2021
Version 1.8.0 (RC)
New:
-
Added Docker-based installation support. Once a stable version of v1.8 is released, docker will be the only deployment option. Since then, the MSI installer will no longer be available. Our knowledge base page is available to show how to install the new version of AIR
-
Added multiple organization support.
-
Added stateless queue-based background worker system.
-
Added device name and os on agent visit requests.
-
Added deployment token to deploy endpoints more secure way.
-
Added some rules to prevent confusion and irregularity on users/roles (Only Global Admins can create Roles, predefined roles cannot be updated).
Improvements:
-
Added ability to unisolate an endpoint, whether it's already isolated or not, for easier troubleshooting.
-
Added predefined roles: Organization Admin, L1&L2 Analyst, L3&L4 Analyst, Maintenance Engineer.
-
Added authorization guard for unauthorized users while accessing organization-specific resources and deployment-related pages.
-
Optimized all database indexes for the organization system.
-
Moved policy priority-based config to order-based config.
-
Improved the stateless task scheduler.
-
Improved create tag rest endpoint for organization system.
-
Improved policy-endpoint match stats.
-
Improved caching by moving it from in-memory to a queue-based infrastructure.
-
Improved the backup feature.
-
Updated policy priority/order to clear up the confusion
-
Removed default SMTP connection, users have to enable the SMTP settings to send emails such as password reset
-
Improved auto-isolate operation after reboot
Fixes:
-
Fixed task data error on getting task by id.
-
Added aborting existing TCP connections after Isolate operation
Additional instructions for existing customers:
-
Once a stable version of v1.8 is released, migration documentation and technical support will be provided for existing customers.
14/7/2021
12/7/2021
Version 1.7.61
-
Fixed NATS blocking call problem.
-
This is the last AIR Console version that supports the MSI installer. In future releases, Docker will be the only deployment option.
2/7/2021
Version 1.7.60
-
Fixed password reset bug.
-
Improved endpoint console address migration feature.
2/7/2021
21/6/2021
Version 1.7.55
-
Added ability to change the console address to migrate endpoints to a new AIR instance.
9/6/2021
Version 1.7.50
This is the stable release of the previous RC version (v.1.7.45)
-
Fixed a bug upgrading endpoints with old version to newer version
-
Fixed notifying NATS for the endpoints that need to be upgraded to the new version
-
Fixed a bug regarding database backup
-
Added support for validating settings for Azure Blob Storage and AWS S3
9/6/2021
27/5/2021
Version 1.7.45 (RC)
-
New Feature: CSV import support for Timeline
-
New Feature: Amazon S3 Bucket evidence repository support
-
New Feature: Azure Blob Storage evidence repository support
-
New Feature: LDAPS integration support
-
Changed Triggers to
Webhooks -
Added Sources field for Investigation
-
Added support for deleting timeline resources
-
Added LimaCharlie Webhook support
-
Added new predefined YARA rule:
NSA Mitigating Webshells -
Added name field to evidence repositories
-
Improved timeline filtering
-
Improved timeline performance
-
Improved progress reporting based on percentage and time on Linux agent
-
Improved recursive directory walk when compressing case directory on Linux agent
-
Improved isolation task assignment validation
-
Improved task cancellation for network share evidence repository on Windows agent
-
Improved SFTP upload on Windows agent
-
Fixed delay on task receiving after an agent is upgraded to a new version
-
Fixed deploy script bug for non-HTTPS servers
-
Fixed minor bugs on Linux agent
-
Fixed an issue in YARA scanner on Windows agent
6/5/2021
Version 1.7.41
-
Minor bug fixes
6/5/2021
27/4/2021
Version 1.7.40
-
New feature: AIR-QRadar integration. Now, an acquisition can be started by triggering AIR via QRadar (credits: Esra Kulüp)
-
New feature: Added Roles and Privileges. Starting from this version AIR contains 70+ user privileges for more fine-grained control
-
New feature: Added backup support for case reports and config files. (Database backup is already available beginning from v1.7.16)
-
New feature: Added AES encryption option for backups
-
New feature: Added SFTP support to store backups on the remote server
-
New feature: Added performing bulk operations on the selected endpoints (adding/removing tags, deleting endpoints, starting acquisition triage, and much more. credits: Babak Mirzahosseiny)
-
New feature: Added triage support to Linux. Now, the file system and memory can be scanned using YARA rules. (credits: Hilko Bengen (https://github.com/hillu/) Author of go-yara (https://github.com/hillu/go-yara))
-
New feature: Added Custom Content collection from Linux distributions
-
Added progress update for compression and SFTP upload process on Linux
-
Added sending matched triage rules to Syslog
-
Added advance filter options to data grids
-
Added auto-generated shell script to facilitate Linux deb and rpm packages deployment
-
Added AIR integration guideline to documentation
-
Improved policy creation UI & UX
-
Improved setup process UI & UX
-
Improved custom SSL certificate information
-
Improved task completion status UX
-
Improved nats communication in agent
-
Implemented more secure cookie-based authentication
-
Optimized Audit logging performance
-
Optimized Syslog bulk processing performance
-
Fixed changing proxy settings when the license is lockdown
-
Fixed an issue in the agent installer
-
Fixed some security vulnerabilities
-
Minor changes and bug fixes
31/3/2021
Version 1.7.35
-
New feature: GNU/Linux support for Debian and Redhat based distributions (Preview)
-
New feature: Added compression and encryption support for evidence
-
New feature: Added policy support that gives you the ability to manage evidence repository location, compression, encryption, and CPU limit based on rules (credits: Turkcell CDC)
-
Added extended file information for triage files
-
Added dependecy checking to evidence repository deletion process
-
Added linux acquisition evidence list
-
Added "Use options provided in policies" and "Use custom options" choices to the acquisition, triage, trigger process
-
Added platform column to endpoint datagrid
-
Added platform, isolation status, and policy filters to endpoint page
-
Added Linux deploy steps to deploy page
-
Added assigning log retrieval task to offline endpoints.
-
Optimized caching to minimize performance bottlenecks caused by high request load
-
Optimized security token check performance
-
Optimized concurrent message handling on Nats server
-
Refactored worker pool to works based on priority
-
Refactored the endpoint task queue to work with the task configs in policies and custom configs
-
Removed patrol from AIR
-
Fixed XSS exploit on audit logs
-
Fixed the performance bottleneck on the task progress update process
-
Fixed a memory leak in the visit process on the windows agent
-
Fixed a problem in windows agent installation version check
-
Updated EULA
-
Minor UX improvements
-
Minor bug fixes
31/3/2021
1/3/2021
Version 1.7.31
-
Fixed the bug related to task assignment to endpoints that are associated with multiple tags
25/2/2021
Version 1.7.30
-
Improved triage match results
-
Improved AD sync performance
-
Improved audit log db write transactions
-
Improved license capacity checks
-
Improved LDAP login
-
Highly optimized task core module performance
-
Highly optimized endpoint task queue memory usage
-
Highly optimized audit log storage
-
Highly optimized realtime task assignment to endpoints
-
Optimized logging on agent
-
Optimized debugging log on worker tasks
-
Optimized Agent Installer download performance
-
Optimized task result upload performance
-
Optimized db bulk operations
-
Optimized triage rule storage
-
Optimized task storage
-
Refactored worker core module
-
Fixed an issue related to sending triage task result
-
Fixed performance issue caused by Patrol module
-
Fixed disappearing endpoint tags after AD sync issue
-
Fixed loading up tasks to endpoint queue issue caused by db migration
-
Fixed the register required bug that is caused by latency on endpoint registration
-
Fixed the performance issue on visit requests caused by agent update load balancer
-
Fixed investigating same endpoints multiple times in the same investigation
-
Fixed security token mismatch bug on visit requests
-
Fixed the bug caused by reloading task details on the UI
-
Fixed the bug related to license validation for online and offline environments
25/2/2021
27/1/2021
Version 1.7.24
-
Fixed a critical issue on the task assignment module
24/1/2021
Version 1.7.23
-
Improved endpoint connection error logging
-
Changed max memory cache size to maximum
-
Highly improved memory usage of the endpoint task queue
-
Increased node's memory usage limit to 6GB
-
Reduced effect of long-running tasks on the starting speed of the application
-
Fixed performance and memory issue on sending events to Syslog and audit logs
-
Fixed a minor bug on the endpoint registration issue
-
Fixed a minor bug on fix endpoint issue task
-
Fixed a minor bug on the installer
24/1/2021
18/1/2021
Version 1.7.21
-
Fixed an issue in UI
-
Other minor bug fixes and improvements
14/1/2021
Version 1.7.20
-
Fixed minor bugs
14/1/2021
11/1/2021
Version 1.7.16 (RC)
-
Added getting endpoint system resources feature
-
Added database backup feature that allows admin to create database backups regularly (credits: Turkcell CDC)
-
Added version column to the endpoint page
-
Added two new endpoint issue types
-
Added agent update management feature (credits: Turkcell CDC)
-
Added capability to fix registration issue for endpoints that re-installed
-
Improved error report sending on the installer
-
Improved offline license check
-
Improved endpoint issue filter
-
Improved dashboard page statistics
-
Improved automatic page data polling
-
Highly improved backend and agent logs
-
Improved re-upload task mechanism
-
Fixed an issue on triggers that cause not to ignore recurring requests
-
Fixed getting 404 when trying to download an external resource from the report
-
Fixed an issue in task fail upload condition
-
Fixed an exception in downloads collector
-
Other minor bug fixes and improvements
2021
29/12/2020
Version 1.7.13 (RC)
-
Fixed an issue in agent installer
-
Other minor bug fixes and improvements
29/12/2020
22/12/2020
Version 1.7.12 (RC)
-
Highly improved Yara Scanner speed
-
Improved getting agent logs from AIR
-
Improved process collector
-
Fixed an issue in Yara Scanner
-
Fixed an issue in Prefetch collector
17/12/2020
Version 1.7.11 (RC Sunburst Edition)
Fixed minor typo
17/12/2020
17/12/2020
Version 1.7.10 (RC Sunburst Edition)
-
Added FireEye Red Team Tool Countermeasures Yara Rule
-
Added FireEye Mandiant SunBurst Countermeasures Yara Rule
-
Added support for both filesystem and memory triage
-
Added support for getting agent logs from AIR
-
Added support for agent log rotating
-
Highly improved AIR backend for concurrent operations
-
Fixed an issue in triage results
-
Fixed a minor issue in license
-
Other minor bug fixes and improvements
14/12/2020
Version 1.7.8 (RC)
-
Fixed an issue in event log parser
14/12/2020
10/12/2020
Version 1.7.7 (RC)
-
Added Log Retrieval action to endpoint
-
Added Timeline action to endpoint group and endpoint tag tree
-
Added Reset Password support for users
-
Added scroll support for timeline
-
Added downloading case entries from report
-
Improved TimelineIR experience
-
Fixed minor install/uninstall bugs
-
Fixed trigger recurrence bug
-
Fixed other minor bugs
-
Removed setting AD and proxy configs from the installer
3/12/2020
Version 1.7.6 (Beta)
-
Minor improvements and bug fixes
3/12/2020
30/11/2020
Version 1.7.4 (Beta)
-
Fixed an issue in event log parser
27/11/2020
Version 1.7.3 (Beta)
-
Added support for downloading report as HTML (credits: Turkcell CDC)
-
Improved Quick Acquisition Profile
-
Improved agent update mechanism (credits: Orhan Solak - Barikat Cyber Security)
-
Fixed an issue in agent task processing mechanism (credits: Burak Karapınar - HAVELSAN)
-
Fixed an issue in agent manual uninstallation (credits: Orhan Solak - Barikat Cyber Security)
27/11/2020
20/11/2020
Version 1.7.1 (Beta)
-
Added TimelineIR feature
-
Added Binalyze Patrol feature
-
Added audit logs feature
-
Added role-based access control
-
Added "Acquire Evidence", "Schedule Acquisition", "Triage" and "Delete Endpoint" actions by tag
-
Highly improved agent performance
-
Highly improved agent memory usage
-
Improved settings page to separate The Users, License, and Evidence Repositories pages
-
Improved case file upload to handle .ppc files
-
Improved the installer prerequisites to handle the newer version of NodeJS
-
Improved debug logs
-
The minimum memory requirement for the AIR server increased to 8GB
-
Other minor bug fixes and improvements
13/10/2020
Version 1.6.14
-
Added support for parsing SRUM Application Resource Usage
-
Added support for parsing SRUM Network Data Usage
-
Added new event records
-
Added MAC time to crash dumps
-
Added Custom Content collection from all drives (credits: Mason Toups)
-
Added Triage on all disk drives (credits: Mason Toups)
-
Added host content to report
-
Added export process table as CSV (credits: Alexander Jarvis)
-
Added Last Write Time for Installed Applications
-
Added support for CPU usage limitation (credits: Turkcell CDC)
-
Added Refresh button to the endpoint groups section
-
Added Delete All Tags button to the endpoint tags section
-
Added Delete button to all detail pages
-
Improved settings page design
-
Improved design of table action buttons
-
Improved Browser History acquisition
-
Improved Network Share connection check
-
Improved exception handling
-
Fixed an issue with event logs
-
Fixed WMI query exception problem
-
Fixed Downloads section processed count
-
Fixed an issue with timestamping
13/10/2020
27/9/2020
Version 1.6.11
-
Improved endpoint tags
-
Improved installer (credits: Babak Mirzahosseiny)
-
Fixed LDAP user login authentication (credits: Turkcell CDC)
-
Fixed LDAP endpoints register problem (credits: Turkcell CDC)
-
Fixed enable/disable debug logging bug
17/9/2020
Version 1.6.9
-
Added feature of adding tags to endpoints (credits: Yalkın Demirkaya)
-
Added LDAP Sync option to endpoint group tree
-
Added refresh button to the endpoint tags section
-
Added delete tag action to the endpoint tags section
-
Added New Profile button to acquisition profiles dropdowns
-
Improved server logger to make logs more readable
17/9/2020
8/9/2020
Version 1.6.8
-
Added the Recent Tasks section to the dashboard
-
Added task assignment delete option
-
Added Scheduled Acquisition edit option
-
Added confirmation modal to Active Directory settings
-
Added status line to the task detail page
-
Added select all option to triage list of the endpoint
-
Added uninstall task assignment for unmanaged endpoints on a visit request
-
Added onetime scheduled task removal after execution
-
Added task execution history to dashboard backend API
-
Added task assignment removal to backend API
-
Added nats server port status checker job
-
Added match count stats to task details
-
Added support to login with an LDAP account
-
Added sending user deleted event to Syslog
-
Added e-mail field for the user
-
Improved task removal
-
Improved LDAP sync (credits: Babak Mirzahosseiny)
-
Improved SMTP validation logic
-
Improved server restart logic (credits: Babak Mirzahosseiny)
-
Improved agent https connection (credits: Babak Mirzahosseiny)
-
Refactored task assignment and scheduler
-
Fixed changing LDAP endpoint group after visit request (credits: Babak Mirzahosseiny)
-
Fixed https redirection bug (credits: Babak Mirzahosseiny)
-
Fixed report process tree view
-
Minor improvements and bug fixes
14/8/2020
Version 1.6.4 (Code Name: Sirius)
-
New backend in NestJS (TypeScript) with 100% unit test coverage
-
New frontend in Vue.js
-
Added auto-complete support for YARA rule editor
-
Added support for YARA rule validation
-
Added group triage feature
-
Added global search feature
-
Added filtering support to all tables
-
Added local search for each page
-
Added security token refresh for triggers
-
Added new evidence types
-
Added new Custom Content collection editor
-
Added required port detection to the installer
-
Added Active Directory server setting alongside domain name
-
Added Memcache for decreasing response times
-
Added support for the upcoming Compromise Assessment feature (PPC file)
-
Added retry feature to agents in case there is no connection to evidence repository
-
Highly improved evidence selection page
-
Highly improved UX for task actions
-
Fixed minor issues in installer
-
Fixed minor issues in the Case report
-
Fixed an issue in NATS
-
Fixed an issue in license handling
-
Fixed Smart Screen warning on agent installation
14/8/2020
17/5/2020
Version 1.4.1
-
Added collection of Autorun locations
-
Added collection of Downloaded Files information
-
Added collection of RDP Cache Files
-
Added port availability check for the installer
-
Added new license models
-
Added support for offline licensing
-
Added support for task cancellation
-
Highly improved report
-
Highly improved calculation on visit interval
-
Improved UI/UX
-
Fixed an issue with timezone handling
-
Fixed an issue in group task assignments
-
Fixed app manifest problem for console service
-
Removed internet dependency from the installer
-
Minor updates and improvements
13/4/2020
Version 1.4
-
Added support for Triage on FileSystem and Memory using YARA+
-
Added support for installation on Windows 7+ OSes
-
Added support for assigning a task to all endpoints in endpoint groups
-
Added support for sending case report after the task completion
-
Added support for anonymous network share connections
-
Added support for send notifications for failed tasks
-
Added Online filter into endpoints page
-
Added support for network share folder permissions check
-
Added support for updating endpoint details for upgraded OSes
-
Added support for filtering with endpoint groups are added
-
Added resilience to case report sending
-
Added sending match count after triage task completes
-
Added Yara rule validation
-
Added validating Yara rule file
-
Added sending Yara rule error message if the wrong rule provided
-
Added sending duration during the task
-
Highly improved evidence acquisition to network shares
-
Improved agent logs
-
Improved exception handling
-
Improved uninstall task
-
Improved fetching array from JSON
-
Improved network share authentication
-
Fixed an issue in LDAP Sync
-
Fixed unhandled exception with JSON GetValue
-
Fixed unhandled exception
-
Fixed wrong function usage for JSON
-
Fixed an issue with agent log
-
Removed unnecessary console API calls
-
Removed console out messages
-
Removed .NET Core dependency
-
Minor updates and improvements
13/4/2020
2020
26/12/2019
Version 1.3.6
-
Fixed an issue in agent update
-
Fixed an issue in license handling
-
Fixed a UX issue in agent register
25/12/2019
Version 1.3.5
-
Improved UI/UX
-
Highly optimized client connection handling
-
Highly optimized database operations
-
Added support for Custom Content
-
Added support for Syslog
-
Added console auditing logs
-
Added support for DB migration
-
Added edit button to tables
-
Added endpoint filter links to dashboard statistics
-
Improved license handling
-
Performance optimizations
-
Fixed an issue in LDAP synchronization
-
Fixed an issue leading to duplicate domain
-
Fixed an issue in tasks page showing incorrect endpoint
-
Fixed an issue in task scheduler
-
Fixed an issue in installer test LDAP button
-
Fixed an issue in installer test proxy button
-
Minor updates and improvements
25/12/2019
21/11/2019
Version 1.3.3
-
Improved UI/UX
-
Added validation to settings save
-
Fixed screenshot not captured issue
-
Fixed clipboard not captured issue
-
Fixed UsnJournal not retrieved issue
-
Fixed Active Directory paging issue
-
Fixed multiple Active Directory groups issue
-
Added scroll to Active Directory groups
19/11/2019
Version 1.3
-
Major architectural improvements
-
Major security enhancements (credits: Mehmet İNCE & https://invictuseurope.com)
-
Improved NATS real-time messaging
-
Improved email template
-
Added support for generic Webhook integration with SIEM, SOAR, and EDR products.
-
Added Custom Content Collection
-
Added administrator manifest to installers
-
Added logging for prerequisities
-
Added LDAP / Proxy test buttons to settings
-
Added support for SSL
-
Added 404 Not Found pages
-
Fixed an issue with forgot password dialog
-
Fixed an issue with Console updater
-
Fixed an issue with client IP handling
-
Fixed an issue with environment variables
-
Other minor bug fixes and improvements
19/11/2019
2019
AIR was born on 21st October 2019 with our first public Beta release 1.2.1