<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=3026858&amp;fmt=gif">

AIR Release Notes




Version 2.2.0 (RC)


  • Added exporting endpoints as CSV

  • Added exporting cases as CSV

  • Added exporting case activities as CSV

  • Added exporting case notes as CSV

  • Added exporting case endpoints as CSV

  • Added exporting audit logs as CSV

  • Added exporting timeline events as CSV

  • Added Yara external variables and removed yara+ modules (file, process)

  • Upgraded Yara to 4.1

  • Enriched triage case report for file matches for Linux


  • Added webhook support for Elasticsearch Logstash Kibana (ELK)

  • Added webhook support for SumoLogic

  • Improved task queues

  • Improved triage performance

  • Improved handling of cancel tasks

  • Improved connection timeouts

  • Improved log rotation

  • Improved log format

  • Improved logging

  • Improved Triage case report

  • Updated the application icon for the Windows agent

  • Added timeout for evidence repositories on agent


  • Added retry for agent HTTP requests

  • Added retry for failed case file uploads

  • Introduced Linux systemd service restart on failure

  • Fixed compression progress reporting

  • Fixed HTTP response close

  • Fixed a race condition for HTTP transport

  • Fixed progress reporting

  • Fixed self match possibility of custom content collection for Linux

  • Fixed misc. minor bugs



Version 2.1.5

  • UI/UX improvements on case containers

  • Fixed minor bugs related to case containers

  • Fixed drone autopilot issue on scheduled tasks and webhooks.

  • Fixed a bug about using azure storage as evidence repository on linux agents



Version 2.1.0 (RC-2)

  • Added additional functionality to cases feature

  • Minor fixes and improvements



Version 2.0.5

  • Added FQDN support for console address

  • Added a Quick Intro guide to help new users get started with AIR

  • Fixed an issue on SSO with 8443 port

  • Console migration process moved to task logic

  • Minor Linux agent fixes:

    • Minor http timeout fix

    • Minor triage command line parameter fix for excluded files

    • Visit poll interval overflow fix for 32bit architectures

  • Minor Windows agent fixes:

    • Minor improvement on isolation



Version 2.1.0 (RC)


  • Added case container feature

  • Added FIS license support


  • Fixed a minor issue related to the auto-asset-tagging feature

  • Fixed organization admin privileges issue

  • Minor UI/UX fixes


Version 2.0.1

This is the stable version of the latest RC (v2.0-RC)

In this version;

  • Added new predefined acquisition profile: Compromise Assessment

  • Added deployment script support for Windows agents

  • Added webhook parser for Cortex XSOAR and Splunk Phantom

  • Added new evidence type for Windows agents: Collecting USB Storage History

  • Improved license validation messages

  • Improved temporary path usage for Windows agents

  • Fixed a bug related to timeline event count

  • Fixed a bug related to sending events to syslog

  • Fixed a bug related to canceling Auto Tag Asset task on Windows agents

  • Major performance improvements



Version 2.0 (RC)



  • Added AIR-DRONE Integration (available only for acquisition and timeline for now) - rapid keyword searching, anomaly finding, scanning SIGMA rules live directly on any endpoint, and many other DRONE features are available now in AIR.

  • Added Auto Asset Tagging feature - tag your assets automatically by the conditions you provide.

  • Added Off-Network Endpoints feature - add and filter off-network endpoints.

  • Added PPC Import to Timeline feature - import PPC files collected from offline or online environments to Timeline.

  • Added IP Restrictions feature - restrict access to the AIR Console based on IP addresses or IP blocks.

  • Added UI Port Splitting feature - enables you to serve AIR Console and Endpoint requests from separated ports. With this feature, you can create separate firewall rules in AIR.

  • Added Drone findings on the Timeline

  • Added SMB Repository Support for Linux

  • Added Pardus Linux Support

  • Added Super glob meta (double star) support for custom content

  • Added IP Restriction Reset Script

  • Added an ability to download case reports from the endpoint detail task page

  • Added hashes.csv file that contains hashes of the files in the case report

  • Added detailed step by step task statuses (Processing, Compressing, Uploading, Analyzing)

  • Added support for .pfx, .der SSL certificate types

  • Added supported Linux distributions information to deploy the page

  • Added "Send to Timeline" action to Acquisition tasks

  • Added displaying support for PPC file metadata

  • AIR UI has a new design layout now


  • Improved more user-friendly error messages

  • Improved database connection functionality on backend

  • Improved case report view options on the endpoint detail page

  • Improved global search bar visibility for each page

  • Improved notification module "Mark All as Read" accessibility

  • Improved showing EULA in AIR setup

  • Improved and simplified AIR deployment with Docker for Linux

  • Improved performance while opening the Case Report.

  • Improved SSL Certificate installation

  • Minor improvements/fixes on case report

  • Upgraded MongoDB version to 4.4.7


  • Fixed an issue related to uninstallation of windows agent manually

  • Fixed LDAP issue occurring while trying to login AIR with username@domain format

  • Fixed task queue cancellation

  • Fixed Proxy SSL issue

  • Fixed organization name update issue

  • Fixed organization filter bug on the policy creation page

  • Minor UI/UX fixes


Version 1.8.3

  • Minor changes and improvements

Click here to learn how to migrate from v1.7.61 to v1.8



Version 1.8.2

This is the stable version of the latest RC (v1.8.0-rc)

In this version;

  • Added AIR CLI Support

    • Added to restore using a backup file support

    • Added to reset local user password support

  • Improved AWS S3 Bucket upload on Windows agent

  • Improved Custom Content Collection on Windows agent

  • Fixed some minor bugs

Click here to learn how to migrate from v1.7.61 to v1.8


Version 1.8.0 (RC)


  • Added Docker-based installation support. Once a stable version of v1.8 is released, docker will be the only deployment option. Since then, the MSI installer will no longer be available. Our knowledge base page is available to show how to install the new version of AIR: https://kb.binalyze.com/air#setup

  • Added multiple organization support.

  • Added Azure AD single sign-on support.

  • Added 2FA support.

  • Added stateless queue-based background worker system.

  • Added network capture option to acquisition profile.

  • Added device name and os on agent visit requests.

  • Added deployment token to deploy endpoints more secure way.

  • Added some rules to prevent confusion and irregularity on users/roles (Only Global Admins can create Roles, predefined roles cannot be updated).

  • Added Wazuh integration support.


  • Added ability to unisolate an endpoint, whether it's already isolated or not, for easier troubleshooting.

  • Added predefined roles: Organization Admin, L1&L2 Analyst, L3&L4 Analyst, Maintenance Engineer.

  • Added authorization guard for unauthorized users while accessing organization-specific resources and deployment-related pages.

  • Optimized all database indexes for the organization system.

  • Moved policy priority-based config to order-based config.

  • Improved the stateless task scheduler.

  • Improved create tag rest endpoint for organization system.

  • Improved policy-endpoint match stats.

  • Improved caching by moving it from in-memory to a queue-based infrastructure.

  • Improved the backup feature.

  • Updated policy priority/order to clear up the confusion

  • Removed default SMTP connection, users have to enable the SMTP settings to send emails such as password reset

  • Improved auto-isolate operation after reboot


  • Fixed task data error on getting task by id.

  • Added aborting existing TCP connections after Isolate operation

Additional instructions for existing customers:

  • Once a stable version of v1.8 is released, migration documentation and technical support will be provided for existing customers.



Version 1.7.61

  • Fixed NATS blocking call problem.

  • This is the last AIR Console version that supports the MSI installer. In future releases, Docker will be the only deployment option.


Version 1.7.60

  • Fixed password reset bug.

  • Improved endpoint console address migration feature.



Version 1.7.55

  • Added ability to change the console address to migrate endpoints to a new AIR instance.


Version 1.7.50

This is the stable release of the previous RC version (v.1.7.45)

  • Blog News: v1.7.50

  • Fixed a bug upgrading endpoints with old version to newer version

  • Fixed notifying NATS for the endpoints that need to be upgraded to the new version

  • Fixed a bug regarding database backup

  • Added support for validating settings for Azure Blob Storage and AWS S3



Version 1.7.45 (RC)

  • New Feature: CSV import support for Timeline

  • New Feature: Amazon S3 Bucket evidence repository support

  • New Feature: Azure Blob Storage evidence repository support

  • New Feature: LDAPS integration support

  • Changed Triggers to Webhooks

  • Added Sources field for Investigation

  • Added support for deleting timeline resources

  • Added LimaCharlie Webhook support

  • Added new predefined YARA rule: NSA Mitigating Webshells

  • Added name field to evidence repositories

  • Improved timeline filtering

  • Improved timeline performance

  • Improved progress reporting based on percentage and time on Linux agent

  • Improved recursive directory walk when compressing case directory on Linux agent

  • Improved isolation task assignment validation

  • Improved task cancellation for network share evidence repository on Windows agent

  • Improved SFTP upload on Windows agent

  • Fixed delay on task receiving after an agent is upgraded to a new version

  • Fixed deploy script bug for non-HTTPS servers

  • Fixed minor bugs on Linux agent

  • Fixed an issue in YARA scanner on Windows agent


Version 1.7.41

  • Minor bug fixes



Version 1.7.40

  • Blog News: v1.7.40

  • New feature: AIR-QRadar integration. Now, an acquisition can be started by triggering AIR via QRadar (credits: Esra Kulüp)

  • New feature: Added Roles and Privileges. Starting from this version AIR contains 70+ user privileges for more fine-grained control

  • New feature: Added backup support for case reports and config files. (Database backup is already available beginning from v1.7.16)

  • New feature: Added AES encryption option for backups

  • New feature: Added SFTP support to store backups on the remote server

  • New feature: Added performing bulk operations on the selected endpoints (adding/removing tags, deleting endpoints, starting acquisition triage, and much more. credits: Babak Mirzahosseiny)

  • New feature: Added triage support to Linux. Now, the file system and memory can be scanned using YARA rules. (credits: Hilko Bengen (https://github.com/hillu/) Author of go-yara (https://github.com/hillu/go-yara))

  • New feature: Added Custom Content collection from Linux distributions

  • Added progress update for compression and SFTP upload process on Linux

  • Added sending matched triage rules to Syslog

  • Added advance filter options to data grids

  • Added auto-generated shell script to facilitate Linux deb and rpm packages deployment

  • Added AIR integration guideline to documentation

  • Improved policy creation UI & UX

  • Improved setup process UI & UX

  • Improved custom SSL certificate information

  • Improved task completion status UX

  • Improved nats communication in agent

  • Implemented more secure cookie-based authentication

  • Optimized Audit logging performance

  • Optimized Syslog bulk processing performance

  • Fixed changing proxy settings when the license is lockdown

  • Fixed an issue in the agent installer

  • Fixed some security vulnerabilities

  • Minor changes and bug fixes


Version 1.7.35

  • New feature: GNU/Linux support for Debian and Redhat based distributions (Preview)

  • New feature: Added SFTP support to evidence repositories

  • New feature: Added compression and encryption support for evidence

  • New feature: Added endpoint isolation for Windows platform

  • New feature: Added policy support that gives you the ability to manage evidence repository location, compression, encryption, and CPU limit based on rules (credits: Turkcell CDC)

  • Added extended file information for triage files

  • Added dependecy checking to evidence repository deletion process

  • Added linux acquisition evidence list

  • Added "Use options provided in policies" and "Use custom options" choices to the acquisition, triage, trigger process

  • Added platform column to endpoint datagrid

  • Added platform, isolation status, and policy filters to endpoint page

  • Added Linux deploy steps to deploy page

  • Added assigning log retrieval task to offline endpoints.

  • Optimized caching to minimize performance bottlenecks caused by high request load

  • Optimized security token check performance

  • Optimized concurrent message handling on Nats server

  • Refactored worker pool to works based on priority

  • Refactored the endpoint task queue to work with the task configs in policies and custom configs

  • Removed patrol from AIR

  • Fixed XSS exploit on audit logs

  • Fixed the performance bottleneck on the task progress update process

  • Fixed a memory leak in the visit process on the windows agent

  • Fixed a problem in windows agent installation version check

  • Updated EULA

  • Minor UX improvements

  • Minor bug fixes



Version 1.7.31

  • Fixed the bug related to task assignment to endpoints that are associated with multiple tags


Version 1.7.30

  • Improved triage match results

  • Improved AD sync performance

  • Improved audit log db write transactions

  • Improved license capacity checks

  • Improved LDAP login

  • Highly optimized task core module performance

  • Highly optimized endpoint task queue memory usage

  • Highly optimized audit log storage

  • Highly optimized realtime task assignment to endpoints

  • Optimized logging on agent

  • Optimized debugging log on worker tasks

  • Optimized Agent Installer download performance

  • Optimized task result upload performance

  • Optimized db bulk operations

  • Optimized triage rule storage

  • Optimized task storage

  • Refactored worker core module

  • Fixed an issue related to sending triage task result

  • Fixed performance issue caused by Patrol module

  • Fixed disappearing endpoint tags after AD sync issue

  • Fixed loading up tasks to endpoint queue issue caused by db migration

  • Fixed the register required bug that is caused by latency on endpoint registration

  • Fixed the performance issue on visit requests caused by agent update load balancer

  • Fixed investigating same endpoints multiple times in the same investigation

  • Fixed security token mismatch bug on visit requests

  • Fixed the bug caused by reloading task details on the UI

  • Fixed the bug related to license validation for online and offline environments



Version 1.7.24

  • Fixed a critical issue on the task assignment module


Version 1.7.23

  • Improved endpoint connection error logging

  • Changed max memory cache size to maximum

  • Highly improved memory usage of the endpoint task queue

  • Increased node's memory usage limit to 6GB

  • Reduced effect of long-running tasks on the starting speed of the application

  • Fixed performance and memory issue on sending events to Syslog and audit logs

  • Fixed a minor bug on the endpoint registration issue

  • Fixed a minor bug on fix endpoint issue task

  • Fixed a minor bug on the installer



Version 1.7.21

  • Fixed an issue in UI

  • Other minor bug fixes and improvements


Version 1.7.20

  • Fixed minor bugs



Version 1.7.16 (RC)

  • Added getting endpoint system resources feature

  • Added database backup feature that allows admin to create database backups regularly (credits: Turkcell CDC)

  • Added version column to the endpoint page

  • Added two new endpoint issue types

  • Added agent update management feature (credits: Turkcell CDC)

  • Added capability to fix registration issue for endpoints that re-installed

  • Improved error report sending on the installer

  • Improved offline license check

  • Improved endpoint issue filter

  • Improved dashboard page statistics

  • Improved automatic page data polling

  • Highly improved backend and agent logs

  • Improved re-upload task mechanism

  • Fixed an issue on triggers that cause not to ignore recurring requests

  • Fixed getting 404 when trying to download an external resource from the report

  • Fixed an issue in task fail upload condition

  • Fixed an exception in downloads collector

  • Other minor bug fixes and improvements



Version 1.7.13 (RC)

  • Fixed an issue in agent installer

  • Other minor bug fixes and improvements



Version 1.7.12 (RC)

  • Highly improved Yara Scanner speed

  • Improved getting agent logs from AIR

  • Improved process collector

  • Fixed an issue in Yara Scanner

  • Fixed an issue in Prefetch collector


Version 1.7.11 (RC Sunburst Edition)

Fixed minor typo



Version 1.7.10 (RC Sunburst Edition)

  • Added FireEye Red Team Tool Countermeasures Yara Rule

  • Added FireEye Mandiant SunBurst Countermeasures Yara Rule

  • Added support for both filesystem and memory triage

  • Added support for getting agent logs from AIR

  • Added support for agent log rotating

  • Highly improved AIR backend for concurrent operations

  • Fixed an issue in triage results

  • Fixed a minor issue in license

  • Other minor bug fixes and improvements


Version 1.7.8 (RC)

  • Fixed an issue in event log parser



Version 1.7.7 (RC)

  • Added Log Retrieval action to endpoint

  • Added Timeline action to endpoint group and endpoint tag tree

  • Added Reset Password support for users

  • Added scroll support for timeline

  • Added downloading case entries from report

  • Improved TimelineIR experience

  • Fixed minor install/uninstall bugs

  • Fixed trigger recurrence bug

  • Fixed other minor bugs

  • Removed setting AD and proxy configs from the installer


Version 1.7.6 (Beta)

  • Minor improvements and bug fixes



Version 1.7.4 (Beta)

  • Fixed an issue in event log parser


Version 1.7.3 (Beta)

  • Added support for downloading report as HTML (credits: Turkcell CDC)

  • Improved Quick Acquisition Profile

  • Improved agent update mechanism (credits: Orhan Solak - Barikat Cyber Security)

  • Fixed an issue in agent task processing mechanism (credits: Burak Karapınar - HAVELSAN)

  • Fixed an issue in agent manual uninstallation (credits: Orhan Solak - Barikat Cyber Security)



Version 1.7.1 (Beta)

  • Added TimelineIR feature

  • Added Binalyze Patrol feature

  • Added audit logs feature

  • Added role-based access control

  • Added "Acquire Evidence", "Schedule Acquisition", "Triage" and "Delete Endpoint" actions by tag

  • Highly improved agent performance

  • Highly improved agent memory usage

  • Improved settings page to separate The Users, License, and Evidence Repositories pages

  • Improved case file upload to handle .ppc files

  • Improved the installer prerequisites to handle the newer version of NodeJS

  • Improved debug logs

  • The minimum memory requirement for the AIR server increased to 8GB

  • Other minor bug fixes and improvements


Version 1.6.14

  • Added support for parsing SRUM Application Resource Usage

  • Added support for parsing SRUM Network Data Usage

  • Added new event records

  • Added MAC time to crash dumps

  • Added Custom Content collection from all drives (credits: Mason Toups)

  • Added Triage on all disk drives (credits: Mason Toups)

  • Added host content to report

  • Added export process table as CSV (credits: Alexander Jarvis)

  • Added Last Write Time for Installed Applications

  • Added support for CPU usage limitation (credits: Turkcell CDC)

  • Added Refresh button to the endpoint groups section

  • Added Delete All Tags button to the endpoint tags section

  • Added Delete button to all detail pages

  • Improved settings page design

  • Improved design of table action buttons

  • Improved Browser History acquisition

  • Improved Network Share connection check

  • Improved exception handling

  • Fixed an issue with event logs

  • Fixed WMI query exception problem

  • Fixed Downloads section processed count

  • Fixed an issue with timestamping



Version 1.6.11

  • Improved endpoint tags

  • Improved installer (credits: Babak Mirzahosseiny)

  • Fixed LDAP user login authentication (credits: Turkcell CDC)

  • Fixed LDAP endpoints register problem (credits: Turkcell CDC)

  • Fixed enable/disable debug logging bug


Version 1.6.9

  • Added feature of adding tags to endpoints (credits: Yalkın Demirkaya)

  • Added LDAP Sync option to endpoint group tree

  • Added refresh button to the endpoint tags section

  • Added delete tag action to the endpoint tags section

  • Added New Profile button to acquisition profiles dropdowns

  • Improved server logger to make logs more readable



Version 1.6.8

  • Added the Recent Tasks section to the dashboard

  • Added task assignment delete option

  • Added Scheduled Acquisition edit option

  • Added confirmation modal to Active Directory settings

  • Added status line to the task detail page

  • Added select all option to triage list of the endpoint

  • Added uninstall task assignment for unmanaged endpoints on a visit request

  • Added onetime scheduled task removal after execution

  • Added task execution history to dashboard backend API

  • Added task assignment removal to backend API

  • Added nats server port status checker job

  • Added match count stats to task details

  • Added support to login with an LDAP account

  • Added sending user deleted event to Syslog

  • Added e-mail field for the user

  • Improved task removal

  • Improved LDAP sync (credits: Babak Mirzahosseiny)

  • Improved SMTP validation logic

  • Improved server restart logic (credits: Babak Mirzahosseiny)

  • Improved agent https connection (credits: Babak Mirzahosseiny)

  • Refactored task assignment and scheduler

  • Fixed changing LDAP endpoint group after visit request (credits: Babak Mirzahosseiny)

  • Fixed https redirection bug (credits: Babak Mirzahosseiny)

  • Fixed report process tree view

  • Minor improvements and bug fixes


Version 1.6.4 (Code Name: Sirius)

  • New backend in NestJS (TypeScript) with 100% unit test coverage

  • New frontend in Vue.js

  • Added auto-complete support for YARA rule editor

  • Added support for YARA rule validation

  • Added group triage feature

  • Added global search feature

  • Added filtering support to all tables

  • Added local search for each page

  • Added security token refresh for triggers

  • Added new evidence types

  • Added new Custom Content collection editor

  • Added required port detection to the installer

  • Added Active Directory server setting alongside domain name

  • Added Memcache for decreasing response times

  • Added support for the upcoming Compromise Assessment feature (PPC file)

  • Added retry feature to agents in case there is no connection to evidence repository

  • Highly improved evidence selection page

  • Highly improved UX for task actions

  • Fixed minor issues in installer

  • Fixed minor issues in the Case report

  • Fixed an issue in NATS

  • Fixed an issue in license handling

  • Fixed Smart Screen warning on agent installation



Version 1.4.1

  • Added collection of Autorun locations

  • Added collection of Downloaded Files information

  • Added collection of RDP Cache Files

  • Added port availability check for the installer

  • Added new license models

  • Added support for offline licensing

  • Added support for task cancellation

  • Highly improved report

  • Highly improved calculation on visit interval

  • Improved UI/UX

  • Fixed an issue with timezone handling

  • Fixed an issue in group task assignments

  • Fixed app manifest problem for console service

  • Removed internet dependency from the installer

  • Minor updates and improvements


Version 1.4

  • Added support for Triage on FileSystem and Memory using YARA+

  • Added support for installation on Windows 7+ OSes

  • Added support for assigning a task to all endpoints in endpoint groups

  • Added support for sending case report after the task completion

  • Added support for anonymous network share connections

  • Added support for send notifications for failed tasks

  • Added Online filter into endpoints page

  • Added support for network share folder permissions check

  • Added support for updating endpoint details for upgraded OSes

  • Added support for filtering with endpoint groups are added

  • Added resilience to case report sending

  • Added sending match count after triage task completes

  • Added Yara rule validation

  • Added validating Yara rule file

  • Added sending Yara rule error message if the wrong rule provided

  • Added sending duration during the task

  • Highly improved evidence acquisition to network shares

  • Improved agent logs

  • Improved exception handling

  • Improved uninstall task

  • Improved fetching array from JSON

  • Improved network share authentication

  • Fixed an issue in LDAP Sync

  • Fixed unhandled exception with JSON GetValue

  • Fixed unhandled exception

  • Fixed wrong function usage for JSON

  • Fixed an issue with agent log

  • Removed unnecessary console API calls

  • Removed console out messages

  • Removed .NET Core dependency

  • Minor updates and improvements




Version 1.3.6

  • Fixed an issue in agent update

  • Fixed an issue in license handling

  • Fixed a UX issue in agent register


Version 1.3.5

  • Improved UI/UX

  • Highly optimized client connection handling

  • Highly optimized database operations

  • Added support for Custom Content

  • Added support for Syslog

  • Added console auditing logs

  • Added support for DB migration

  • Added edit button to tables

  • Added endpoint filter links to dashboard statistics

  • Improved license handling

  • Performance optimizations

  • Fixed an issue in LDAP synchronization

  • Fixed an issue leading to duplicate domain

  • Fixed an issue in tasks page showing incorrect endpoint

  • Fixed an issue in task scheduler

  • Fixed an issue in installer test LDAP button

  • Fixed an issue in installer test proxy button

  • Minor updates and improvements



Version 1.3.3

  • Improved UI/UX

  • Added validation to settings save

  • Fixed screenshot not captured issue

  • Fixed clipboard not captured issue

  • Fixed UsnJournal not retrieved issue

  • Fixed Active Directory paging issue

  • Fixed multiple Active Directory groups issue

  • Added scroll to Active Directory groups


Version 1.3

  • Major architectural improvements

  • Major security enhancements (credits: Mehmet İNCE & https://invictuseurope.com)

  • Improved NATS real-time messaging

  • Improved email template

  • Added Custom Content Collection

  • Added administrator manifest to installers

  • Added logging for prerequisities

  • Added LDAP / Proxy test buttons to settings

  • Added support for SSL

  • Added 404 Not Found pages

  • Fixed an issue with forgot password dialog

  • Fixed an issue with Console updater

  • Fixed an issue with client IP handling

  • Fixed an issue with environment variables

  • Other minor bug fixes and improvements


Jan 1st

Add your timeline event here.


AIR was born on 21st October 2019 with our first public Beta release 1.2.1

Download the AIR Features Guide
It only takes 2 mins to setup your free AIR trial
Providing Cyber Resilience to World-class Enterprises Globally
PwC Garmin Sophos Turkish Airlines KPMG EY Deloitte Turkcell Integrity360