PacketSafari
PacketSafari Agent investigation interface, used as the changelog hero background
Product updates

PacketSafari changelog

Weekly notes on the analyzer, Agent, Copilot, anoncap, performance, security, and on-prem delivery work that changes how teams investigate packet captures.

Latest update

Aug 24, 2026

Entries

27

Categories

7

Release notes

What changed

Public notes are grouped by customer impact, not by internal implementation records.

Week of August 24: VoIP troubleshooting and protocol fidelity

Added bounded call-quality and IPsec evidence, connected identity and network-path clues, and improved security-analysis accuracy for VoIP investigations.

PlatformSecurityBug fixesAgentPerformance

Platform

  • Added bounded VoIP call-quality dossiers that connect signaling, RTP quality, NAT traversal, observed paths, and supporting packet evidence without turning measurements into automatic fault claims.
  • Added IPsec coverage and quality context for encrypted VoIP paths, including explicit disclosure when the available capture cannot support a complete conclusion.
  • Connected identity, DNS, service, STP, and path observations into focused troubleshooting chains for faster movement from symptoms to inspectable evidence.

Security

  • Added bounded DNS behavior candidates and reconnect-aware cadence evidence while keeping promotion gates and coverage limits explicit.
  • Added an approval flow for threat-intelligence feeds that require outbound access, making controlled enrichment easier to review before it runs.
  • Improved security-analysis fidelity across web, email, file-sharing, authentication, tunneling, fragmentation, and protocol-transition traffic.

Agent

  • Improved investigation evidence attribution so reports and follow-up analysis retain the correct connection, finding, and capture context.
  • Kept optional path and correlation evidence nonblocking, allowing investigations to finish honestly when a supporting signal is unavailable.

Performance

  • Bounded RTP quality analysis and reused compact signaling, identity, and transport evidence to avoid unnecessary capture-wide work.
  • Improved stream and transaction handling for security analysis while keeping memory and evaluation work bounded on busy captures.

Bug fixes

  • Restored RTP candidate discovery, aligned VoIP signaling across views, preserved SIP call-family relationships, and corrected illegal-packet accounting.
  • Fixed VoIP and telecom evidence classification so observations are explained without being promoted into unsupported faults.
  • Suppressed unattributed TCP matches, preserved customer-facing finding titles, and tightened affected-system scope for campaign corroboration.
Open release note

Week of August 17: identity evidence, security analysis, and capture quality

Expanded identity and DNS evidence, added focused security behaviors, and made connection conclusions explicit about capture limits and remaining uncertainty.

SecurityAgentPerformanceBug fixesPlatform

Security

  • Expanded capture-wide identity and DNS evidence for resolver relationships, service discovery, tunneling indicators, and recurring destination behavior.
  • Added bounded behavioral signals for interactive command-and-control patterns, sparse identity transfers, captive-portal manipulation, and unusual service activity, with explicit qualification and coverage limits.
  • Added certificate-trust and transparency evidence so TLS investigations can distinguish observed trust material from unsupported conclusions.
  • Surfaced capture limitations alongside security results and gated strong TCP conclusions when duplication, slicing, or other capture-quality issues could distort the evidence.

Agent

  • Added a standalone PacketQL workspace for querying retained capture facts, with focused Agent actions that can reuse exact results without restarting an investigation.
  • Made Agent failures more actionable and preserved investigation state, upload context, and evidence attribution through final handoff and reconnects.
  • Strengthened Fast investigations so focused answers remain grounded in bounded packet evidence and capture-wide questions are redirected to broader analysis when needed.

Performance

  • Reduced repeated capture work by consolidating identity, service, duplicate-observation, and connection evidence into reusable bounded results.
  • Sped up capture profile initialization and Wi-Fi troubleshooting while adding traffic-burst impact context for faster connection triage.
  • Improved large-capture completion behavior so partial but valid evidence remains available with honest coverage instead of appearing complete or disappearing.

Platform

  • Made connection triage denser and easier to sort, with clearer security-risk labels, capture-quality status, and more reliable packet pivots.
  • Improved upload keep/discard controls and kept upload goals visible as captures move into Triage or Agent.

Bug fixes

  • Fixed canceled-upload cleanup, standalone Triage finalization, pending evaluation recovery, and several upload-to-investigation transition failures.
  • Corrected TCP quality, fragmented ACK, delayed-ACK, DNS, Wi-Fi, and service-attribution edge cases that could overstate or misplace a finding.
  • Improved protocol and security-analysis fidelity for malformed traffic, application transitions, and packet orientation across a wider range of captures.
Open release note

Week of August 10: guided investigations, threat intelligence, and operational reports

Made investigations and Final Reports more actionable, added offline threat-intelligence matching, and introduced explicit speed and team workflow controls.

AgentBug fixesPerformanceSecurityPlatformAnoncapOn-prem

Agent

  • Added an explicit choice between a capture-wide Core-first start and a focused Agent start, with clearer confirmation and milestone ordering before an investigation begins.
  • Unified Preliminary Report, Verification, and Comprehensive Final Report milestones into one chronological investigation, with clearer live-stage navigation and concise completed reports.
  • Simplified new investigations around direct evidence handoffs so each stage can stop once it has a defensible answer, while preserving important alternatives, uncertainty, and capture-wide coverage limits.
  • Made Agent sessions and report activity durable across upload handoffs, reconnects, retries, and page restoration, reducing duplicate runs and missing or stale transcript content.
  • Made Final Reports more operational with fault-domain localization, actionable escalation guidance, authoritative titles, and reliable follow-up report activity.
  • Expanded Comprehensive Final Report review across the saved case, including earlier reports, authoritative Core results, and complete retained findings, so final conclusions can revisit all available evidence.
  • Kept quick questions separate from managed investigations while allowing executive summaries and security reviews to start without a custom prompt.
  • Added bounded PacketQL follow-up queries over retained Core facts so analysts, Agent, and Copilot can compare or rank one exact-generation fact family without rescanning the PCAP or persisting another result set.

Verification and evidence

  • Made verification dispositions traceable to stable claims and preserved supporting, contradicting, and baseline evidence through the final report.
  • Required deterministic Triage evidence before a Comprehensive Final Report can claim completion, while keeping cached preliminary evidence available to later stages.
  • Improved cross-flow TCP reasoning and retained exact selectors, sequence coordinates, control events, and connection-local evidence for packet-level review.
  • Improved bounded discovery for services on alternate ports and paired proxy or middlebox flows, while preserving TCP negotiation fingerprints for evidence-backed comparison.
  • Carried compact capture provenance, protocol prevalence, connection coverage, duplicate quality, and timestamp context into later stages without extra packet scans.
  • Made packet-tool results easier to inspect with richer typed previews, Markdown tables, preserved report headings, and explicit disclosure when a tool returned only partial coverage.
  • Made OT, telecom, and VoIP workspaces more evidence-led with explicit OT coverage layers, grouped protocol operations, signaling and media packet pivots, and bounded RTP loss/jitter comparison.

Bug fixes

  • Fixed upload-to-Agent transitions, stalled clarification flows, live milestone navigation, report hydration, email actions, and terminal transcript recovery.
  • Restored packet-tool execution and live Markdown rendering while keeping transient Agent thinking out of the saved customer transcript.
  • Stabilized saved report presentation and milestone handoffs, restored investigation counts in capture lists, improved ChatGPT reconnect guidance, and allowed capture deletion after failed Agent runs.
  • Required complete metadata validation before marking captures ready, so truncated sources fail explicitly instead of appearing successfully ingested.
  • Tightened TCP, ARP, DNS, telecom, and security-finding attribution so unsupported or unrelated packet evidence is not promoted into a customer conclusion.
  • Kept late-packet signals and capture-wide protocol coverage available through bounded large-capture scans so decisive anomalies and specialist analysis are not silently skipped.

Performance and platform

  • Added a faster large-capture path, bounded discovery and candidate recall by bytes, reused exact connection results, and localized reset-window analysis to avoid unnecessary capture-wide work.
  • Added saved whole-capture activity and integrity context, a selected-connection TCP quality summary, and on-demand RTP stream detail so transport investigations can move from capture quality to packet evidence without treating measurements as automatic fault verdicts.
  • Streamed capture cold-load progress and consolidated capture inventory, security projections, and full IDS work into bounded primary processing to reduce silent waits and repeated large-capture traversal.
  • Reduced startup overhead, prioritized urgent investigations, and bounded storage cleanup around active work.
  • Improved exported and visual reports by removing duplicate metadata and navigation-only citations, and deriving optional visuals only from exact Final Report evidence.
  • Added an optional Fast inference setting for eligible hosted investigations, with a completion receipt that shows requested and effective speed, fallback state, and charged Analysis runs.
  • Replaced generic AI usage units with explicit Analysis runs, Quick questions, and Prompt Coach entitlements, including shared and per-member visibility; completed investigations count only after successful completion.
  • Added Shared Teams packages with clearer capture allowances and a separate dedicated SaaS path.

Security

  • Made security findings easier to read while keeping live scan state, deterministic findings, and Triage completion consistent across the investigation.
  • Added offline matching for exact IP, network, domain, URL, and file-hash indicators from managed or customer-supplied snapshots, with feed provenance, validity context, and packet or connection pivots.
  • Made threat-feed coverage explicit as ready, partial, or unavailable, and added bounded scheduled refreshes with visible freshness and updater health for configured feeds.

Anoncap

  • Coordinated capture retention and anoncap deletion with active Agent investigations so privacy cleanup cannot race an in-progress analysis.
  • Allowed Anoncap privacy-tool updates to be published independently from application updates.

On-prem

  • Made cluster profiles explicit about accelerator counts so single-node and multi-node deployment topologies match their advertised hardware.
Open release note

Week of August 3: faster Core Triage, stronger TCP evidence, and private controls

Reduced large-capture processing overhead, added focused TCP and east-west evidence, clarified IDS and Anoncap choices, and strengthened managed AI access.

PerformanceAgentSecurityAnoncapPlatformBug fixesOn-prem

Performance

  • Consolidated more capture-wide Triage work into a shared single-read path, reducing repeated decoding across connection, IDS, protocol, and security analysis.
  • Made infrastructure discovery and specialist analysis demand driven, bounded TCP candidate ranking, and compacted saved results to lower memory and storage overhead on large captures.
  • Reused exact IDS and connection evidence across processing stages while retiring unnecessary temporary data after findings and coverage were safely saved.

Agent

  • Added a bounded TCP dossier workflow so focused investigations can assemble connection setup, health, timing, and packet evidence without broad capture scans.
  • Improved Agent handoff after Triage by finalizing saved evidence before launch and preserving capture identity and selected AI settings.

Security

  • Surfaced correlated east-west activity as inspectable findings while keeping packet-detail retrieval bounded.
  • Separated IDS source and coverage choices into a dedicated upload step, preserving the selected rules and exact coverage through the primary scan.

Anoncap

  • Added compact privacy-policy controls for private anonymization profiles and persisted the validated policy with each workflow.
  • Reconciled identity-handling rules across Anoncap and upload workflows so supported privacy choices remain consistent.

Platform

  • Added managed AI access-source selection with clearer subscription and provider approval flows for organization deployments.
  • Expanded supported alternative-model guidance and kept entitled AI choices stable across reconnects and long-running analysis.

Bug fixes

  • Fixed capture loading, connection evidence, and scan-completion edge cases that could stall Triage, lose exact evidence, or launch Agent before results were durable.
  • Improved cleanup and empty-result handling so completed analysis does not leave stale work or trigger duplicate scans.

On-prem

  • Strengthened controlled AI-provider routing and authentication-source provenance for private deployments with managed egress requirements.
Open release note

Week of July 27: guided intake, faster Triage, and expanded security analysis

Unified capture investigation setup, expanded capture-wide threat detection and IDS controls, improved upload and Triage performance, and made Agent reports and reconnects more dependable.

PlatformPerformanceAgentBug fixesSecurityAnoncapOn-prem

Platform

  • Unified investigation setup across upload, the capture library, and workspace views so the question, analysis workflow, operator control, privacy, and delivery choices stay coordinated without being conflated.
  • Added selectable Triage processing profiles with clearer planning estimates, progress stages, and a focused “Is the network at fault?” investigation shortcut.
  • Refined public plan and upload guidance so evaluation limits, enterprise options, and the distinction between preliminary and comprehensive results are easier to understand.

Performance

  • Reused exact capture evidence across processing stages, avoiding redundant preparation and repeated packet scans.
  • Replaced expensive early activity summaries with a bounded preview, improving initial capture feedback while deeper processing continues.
  • Reused upload metadata and combined deduplication with full IDS coverage to reduce repeated input work before analysis.
  • Reused prepared security rules and deduplicated derived evidence so repeated scans use less CPU, memory, and storage.
  • Reduced unnecessary capture-storage writes for more predictable large-capture operation.

Agent

  • Added prompt coaching that helps turn broad questions into responsible fast-path investigations and redirects unfocused work toward capture-wide Triage when appropriate.
  • Shipped selector-first discovery and exact flow retrieval so focused investigations can reach packet evidence sooner without treating the whole capture as model context.
  • Made investigation threads, timelines, and report milestones durable across reconnects and page reloads, with safer recovery of active upload-launched runs.
  • Strengthened causal verification so strong preliminary candidates receive explicit verification outcomes and clearer customer-facing reports.

Bug fixes

  • Fixed chunk-upload permission isolation, upload finalization locking, and replay routing issues that could interrupt capture intake or launch the wrong investigation path.
  • Recovered stalled Triage follow-up work more reliably and kept active Triage, IDS, and Agent progress synchronized across capture views.
  • Corrected verification cards, report hydration, transcript replay, and milestone email layouts so completed findings remain visible and readable.
  • Restored contextual capture actions and preserved confirmed Triage settings when reopening or launching work from the capture library.

Security

  • Made enterprise retention explicitly opt in and tightened storage permissions for uploaded data and saved analysis outputs.
  • Added capture-wide behavioral C2 and periodic-callback detection with bounded connection evidence, explicit coverage, and guardrails for benign discovery traffic.
  • Expanded deterministic detection for DNS tunneling and covert channels, aggregate scans and floods, OT command anomalies, Active Directory attack paths, and RDP proxy downgrades.
  • Added selectable ET Open and Stamus Lateral rule sources for each investigation, with Stamus lateral-movement coverage enabled by default and manageable through Intelligence feeds.
  • Made complete IDS coverage durable and explicit across progress, findings, and clean outcomes, including recovery when an active scan lease expires.
  • Refreshed supply-chain safeguards and controlled outbound-access coverage.

Anoncap

  • Consolidated Anoncap privacy controls across upload and existing-capture workflows, with simpler choices and clearer packet-slicing guidance.
  • Expanded private workflow coverage for anonymized uploads while keeping processing and investigation choices visible as separate controls.

On-prem

  • Simplified on-prem data-service guidance and removed obsolete transition instructions.
  • Hardened storage and authentication persistence for longer-running managed investigations.
  • Expanded qualified local and alternative AI model support with compatibility checks, safer provider isolation, and controlled routing for egress-restricted deployments.
Open release note

Week of July 20: upload security, Triage, and enterprise assurance

Redesigned PCAP upload flows, enforced full IDS coverage for security analysis, clarified enterprise evaluation paths, and expanded customer assurance content.

PlatformSecurityAgentPerformanceBug fixesAnoncap

Platform

  • Redesigned the PCAP upload investigation wizard with clearer choices for question, analysis depth, Agent delivery, and security review.

Security

  • Made Security uploads require full IDS coverage before presenting security results.
  • Surfaced Suricata ATT&CK mappings and preserved MITRE alert details throughout security analysis.
  • Separated optional product communication consent from operational service email so report delivery follows distinct customer choices.

Agent

  • Refined progressive investigation workflows across upload, Agent, Analyzer, Triage, reports, and docs so fast findings and verification stay easier to follow.
  • Improved progressive large-capture Agent workflows, including selector-focused runs and follow-up report delivery.

Performance

  • Raised supported upload sizing to 10 GiB where enterprise limits allow it and aligned safeguards and product guidance around larger captures.
  • Improved capture processing and IDS reliability for large or long-running security analyses.

Bug fixes

  • Fixed Suricata findings in capture summaries and upload insight signals.
  • Improved security dashboard presentation, upload lifecycle status, and analysis history labels during IDS and Agent runs.
Open release note

Week of July 13: progressive Agent, governance, and connection graphs

Added progressive upload analysis, delivered persisted visual reports, expanded enterprise organization governance, and improved scalable connection evidence.

AgentPerformancePlatformSecurityBug fixesOn-prem

Agent

  • Added progressive upload analysis lifecycle tracking so early findings, deferred reports, and verified follow-up work stay connected as one investigation.
  • Delivered persisted visual Agent reports in the app and follow-up emails, with dark-theme report polish and cited packet-evidence visuals.
  • Hardened replay, stream continuity, final report resolution, and deferred report delivery so reopened or long-running Agent sessions recover more cleanly.
  • Added deeper verification guidance for Agent runs, including stronger Diameter, ICMP, TCP, Wi-Fi, VoIP, and telecom investigation behavior.

Performance

  • Improved connection insights graphs, tables, state accuracy, and on-demand TCP trace loading for larger connection inventories.
  • Reused bounded TCP evidence across graph tabs and scaled connection rule attribution so heavy traces can surface clearer connection-level explanations.
  • Made protocol and PacketStats processing more bounded, improving reliability of derived evidence on larger captures.

Platform

  • Added enterprise organization administration, capacity controls, workspace governance, and clearer organization documentation.
  • Preserved SaaS AI upgrade intent through checkout and made paid-plan AI access requirements explicit in upload and Agent workflows.
  • Added data-retention maintenance controls and clearer capture-processing status stages.

Security

  • Bound customer AI egress approvals and enterprise AI execution authority to organizations.
  • Hardened organization authorization boundaries and documented workspace security behavior.
  • Improved newsletter unsubscribe and delivery-feedback handling for customer communication controls.

Bug fixes

  • Fixed connection finding evidence, hotspot evidence correctness, connection detail loading, and scalable graph generation.
  • Added upload report capacity fallback persistence so a report can still be surfaced when the primary Agent path is capacity-limited.
  • Restored Agent startup, live-stream controls, report loading, and visible failure handling for required outputs.

On-prem

  • Updated enterprise and on-prem deployment guidance around organization governance, capacity planning, upload limits, and controlled AI egress.
Open release note

Week of July 6: upload report controls and large-capture validation

Added upload-time Agent report controls, strengthened report completion, expanded large-capture validation, and hardened AI egress certificate handling.

AgentPerformanceSecurityBug fixes

Agent

  • Added upload report settings so teams can choose Agent run behavior during upload instead of waiting until the investigation page opens.
  • Hardened Agent report completion and export recovery so finished analyses are less likely to miss report artifacts after longer runs.

Performance

  • Improved PacketStats coverage on large captures to keep recommended scan ranges and anchor evidence reliable on heavier traces.
  • Tightened readiness checks so large-capture Triage waits for the evidence it needs.

Security

  • Extended generated AI egress proxy leaf certificate lifetime to reduce avoidable provider connection failures in controlled egress deployments.

Bug fixes

  • Improved cached Agent evidence fetch behavior used by report exports and reopened investigation views.
Open release note

Week of June 29: Wi-Fi triage and RCA reports

Wi-Fi investigation views, visual RCA report exports, and transport guidance now provide clearer packet evidence for troubleshooting and handoff across teams.

PerformanceAgentBug fixesPlatform

Performance

  • Added Wi-Fi frame taxonomy and hotspot signals so wireless captures surface beacon, probe, retry, and quality patterns more directly.
  • Improved topology, DSCP, and TCP response modeling signals in analyzer context so performance investigations get clearer path and congestion evidence.
  • Optimized small Wi-Fi capture imports and deferred heavier analyzer insight loading to make first views responsive on lighter traces.

Agent

  • Added visual RCA report support so Agent findings can be exported with richer evidence and investigation context.
  • Connected Wi-Fi dashboard findings to Agent prompts and packet pivots, helping teams move from a wireless symptom to targeted analysis.
  • Preserved Agent launch history so upload-to-Agent handoffs are easier to recover and explain.

Bug fixes

  • Fixed Wi-Fi dashboard hydration, fallback, recovery, and pulse states so wireless evidence remains visible across capture refreshes.
  • Retained failed upload sources and improved follow-up processing so interrupted imports are easier to diagnose.
  • Tuned duplicate capture-quality warnings so recapture guidance is less noisy.
Open release note

Week of June 22: steadier Agent reporting and transport evidence

Improved upload report handoff, richer Agent evidence replay, Citrix transport quality signals, on-prem proxy guidance, and anoncap fidelity coverage.

AgentPerformanceBug fixesOn-premAnoncapPlatform

Agent

  • Made upload report triage more reliable when an analysis moves from upload into Agent, including deferred report emails and handoff edge cases.
  • Improved Agent replay recovery so reopened investigations preserve richer evidence previews without duplicate streamed events.
  • Rendered cached decode ranges, enriched connection pages, record list cells, and tool output summaries more clearly in Agent evidence cards.
  • Added a bottom thinking state for quiet Agent runs so long-running analysis still shows visible progress.

Performance

  • Added Citrix transport quality analysis to help teams spot ICA session health issues and navigate directly to relevant protocol signals.
  • Fixed deferred DNS and TLS evidence processing so large-capture readiness and starter briefs have more complete context.
  • Tightened capture completion and derived readiness gates to avoid showing stale or premature analysis states.

Bug fixes

  • Fixed analyzer breadcrumb navigation races and upload report progress badge states in active investigation workflows.
  • Corrected nested structured answer summaries and cached evidence rendering so timeline content is easier to scan.
  • Improved report email durability when deferred Agent report delivery is interrupted.

On-prem

  • Documented corporate upstream proxy setup and refreshed on-prem egress approval guidance.
  • Hardened controlled proxy access, including safer email credentials and outbound-access safeguards.

Anoncap

  • Updated IDS fidelity and telco anoncap sweep coverage, including the public anoncap capability matrix.
  • Updated packet processing with the latest Anoncap fidelity improvements.

Platform

  • Surfaced demo account expiration in the app account menu and profile view.
  • Improved application compatibility and release readiness across the latest SaaS updates.
Open release note

Week of June 15: steadier no-AI workflows and analyzer signals

No-AI shared capture behavior, Agent continuity, and analyzer hotspot signals are stronger for dependable packet investigations without model access today.

Bug fixesAgentPlatformSecurityPerformance

Bug fixes

  • Kept no-AI shared captures from showing AI insights or waiting after analysis has already been skipped.
  • Guarded upload insights and starter brief refreshes so stale capture transitions cannot overwrite the active analysis view.
  • Fixed Agent chat reuse conflicts and tightened streamed message deduplication so returning to an investigation is less likely to show duplicate or conflicting responses.

Agent

  • Made reopened Agent plans and transcripts retain a cleaner, more consistent activity trail.
  • Updated AI lane documentation around upload and entitlement flows so teams can more clearly tell when public, private, or no-AI behavior applies.

Performance

  • Added an incomplete-handshake fan-in signal for analyzer hotspot guidance, giving teams better evidence when connection setup patterns point to investigation priorities.
  • Improved consistency of Citrix ICA hotspot guidance across representative captures.

Security

  • Strengthened session-token handling as part of routine platform hardening.
Open release note

Week of June 8: clearer AI lanes and steadier analysis flows

Added clearer AI mode controls, stabilized Agent reattach behavior, and improved capture-list and file-preview reliability across interrupted sessions.

AgentBug fixesPerformancePlatform

Agent

  • Added clearer public and private AI mode metadata across Agent reports, analysis history, capture lists, and exported findings.
  • Introduced gated AI mode selection in Agent and Copilot so teams can confirm the intended analysis lane before starting work.
  • Polished Agent transcript, history, and upload-to-analysis flows so active investigations are easier to follow.

Bug fixes

  • Fixed stale stopped Agent runs that could appear active or auto-reattach after they had already ended.
  • Prevented duplicate live final answers during Agent streaming and improved terminal-state handling when reconnecting to an analysis.
  • Made file previews and downloads more reliable during bursts of live analysis updates.

Performance

  • Sped up built-in PCAP list filters so large workspaces respond more consistently.
  • Kept capture list rows useful even when histogram previews fail, instead of letting optional preview data block the list.
Open release note

Week of June 1: cleaner hotspot guidance

Packet hotspot scoping is tighter, SaaS renewal guidance is clearer, and documentation delivery is more reliable across PacketSafari workflows and releases.

Bug fixesPerformanceAgentPlatform

Bug fixes

  • Reduced duplicate parent connection hotspots so packet-list and Agent pivots stay focused on the actual evidence window.
  • Limited noisy connection hotspots that could distract from higher-value TCP, DNS, RTP, and mDNS signals.
  • Fixed Codex compatibility gaps in Agent sessions and clarified Paddle renewal notifications for SaaS users.

Performance

  • Tightened sampled minimap hotspots and TCP stall hotspot parents so large traces produce less broad, repetitive guidance.
  • Added coverage around bounded HTTP auth, RTP, TCP timing, sparse ACK, duplicate ACK, and DNS hotspot behavior.

Platform

  • Improved public documentation navigation and release-readiness checks for analyzer hotspot guidance.
Open release note

Week of May 25: bounded hotspot evidence and production fixes

Packet evidence is more focused, stale hotspot guidance is repaired, and production responsiveness is improved across Agent investigation workflows today.

PerformanceBug fixesAgentPlatform

Performance

  • Localized DNS, ARP, SIP, Wi-Fi, SMB, TCP stall, DF-clear retransmission, and security-alert hotspots to actionable packet windows.
  • Suppressed broad minimap and PacketStats spans that made large captures feel noisier than they needed to be.
  • Improved AI history, PCAP quick filters, application responsiveness, and upload-insight loading.

Agent and Copilot

  • Carried representative hotspot guidance into Ask AI and packet pivots so Agent and Copilot answers start closer to the right frames.
  • Fixed Copilot completed-run replay and completion projection for reattached chats.
  • Improved cached Agent evidence rendering and saved-analysis display after upload report delivery.

Bug fixes

  • Fixed oversized field-range handling, client-log acceptance, capture reprocessing cleanup, and stale hotspot guidance.
  • Hardened duplicate upload detection, PCAP scope refresh, password reset validation, and recovery from interrupted capture preparation.

Platform

  • Added an admin activity summary page, protocol presence icons in the PCAP list, stable demo capture IDs, and polished Agent report email rendering.
  • Improved controlled email delivery and transactional email templates.
Open release note

Week of May 18: telco hotspots and large-capture bounds

Telecom hotspot evidence is more precise, while safer and faster large-capture windows keep bounded packet context useful for Agent investigations today.

PerformanceBug fixesAgent

Performance

  • Bound PacketStats hotspots on large captures so broad traces produce representative evidence instead of oversized packet spans.
  • Trimmed enriched connection read paths to reduce latency while loading connection-heavy captures.
  • Surfaced bounded hotspot evidence directly in the packet list for quicker analyst triage.

Agent

  • Added structured JSON text extraction support so streamed and persisted AI outputs can be normalized more consistently.
  • Improved telecom hotspot fidelity and consistency across representative telco-heavy captures.

Bug fixes

  • Fixed skipped-analysis handling, interface guidance, and live reconnection around long-running analysis flows.
Open release note

Week of May 11: upload, Agent, and reprocess stability

Upload-time analysis is broader, reprocessing preserves metadata, and Agent runs reconnect more reliably across long or interrupted investigations today.

AgentBug fixesPerformanceSecurityOn-prem

Agent

  • Added a prompt-driven Agent upload flow with clearer starter prompts, recent-run continuity, and preserved final answers.
  • Improved Agent reattach behavior, upload report polling, transcript replay, AI history rendering, and quick summary email flows.
  • Placed recent AI runs and starter prompts into a cleaner upload workflow so users can resume analysis without losing context.

Performance

  • Integrated a full PacketStats workflow with large-scan safeguards, reusable capture sessions, and stronger connection prioritization.
  • Adapted parallel processing to available host capacity and raised safe large-capture limits where resources allow it.
  • Improved packet row click responsiveness, fast-scroll loading, and security summary polling bounds.

Bug fixes

  • Safely reprocessed existing captures while preserving ownership, access controls, public sharing, and capture history.
  • Fixed upload insight refresh, raw-only capture states, report transcript duplication, Nagle promotion, stale connection snapshots, and AI usage exhaustion handling.
  • Added bounded recovery for truncated uploads and transient capture-processing failures.

Security and on-prem

  • Guarded SaaS heavy endpoints with rate limits and restricted PCAP downloads to owners and admins.
  • Improved on-prem data reliability, update validation, and entitlement guidance.
Open release note

Week of May 4: bulk analysis and capture summaries

Large-capture processing, analysis summaries, and capture-aware Agent intake now provide faster evidence discovery and more focused investigation starts.

PerformanceAgentBug fixesPlatform

Performance

  • Added bounded bulk-analysis and representative summaries for larger captures.
  • Reused completed capture evidence and deferred only the work that still required processing.
  • Improved large-capture readiness and made JA fingerprint evidence reusable across investigations.

Agent

  • Added capture-aware intake framing and clarification prompts so Agent runs can ask for the missing scenario details before deep investigation.
  • Routed analysis through capture navigation maps, reducing mismatches between Agent evidence and analyzer navigation.

Bug fixes

  • Fixed finding completion, missing JA summaries, stale analysis placeholders, and DNS-over-HTTPS rule coverage.
  • Improved bounded rule-statistics controls and guarded broad AI analysis profiles.

Platform

  • Improved bulk-analysis configuration and packet-engine compatibility validation.
Open release note

Week of April 27: faster large-capture processing

Upload processing, PacketStats readiness, capture summaries, and platform reliability now make large-capture investigations faster and more dependable.

PerformanceBug fixesPlatformAgent

Performance

  • Sped up upload processing with bounded packet reads and more efficient DNS and TLS evidence collection.
  • Removed redundant ARP and DNS work, reused upload insight summaries, and reduced stored PacketStats overhead.
  • Added guarded full-context analysis with explicit packet limits for detailed evidence requests.

Platform

  • Improved cross-platform validation for the interface, capture engine, and integrated investigation workflows.
  • Expanded IDS fidelity checks to keep security results consistent across releases.
  • Improved production build reliability for larger application bundles.

Agent and analyzer

  • Added PCAP list AI analysis overview, capture quality summaries, and clearer AI thread history details.
  • Moved AI analyses earlier in workspace navigation and tuned PCAP action colors.

Bug fixes

  • Fixed upload packet view routing, PCAP library navigation, OT tab availability, upload insight readiness, and production Agent placeholders.
  • Corrected AI usage quota units and queued histogram materialization fallbacks.
Open release note

Week of April 20: faster processing, Agent intake, and anoncap

Capture processing now avoids repeated work, Agent intake carries better case context, and refreshed anoncap workflows improve investigation readiness.

PerformanceAgentAnoncapSecurityOn-prem

Performance

  • Combined more PacketStats work into shared bounded scans to reduce repeated capture processing.
  • Added clearer upload processing timings and diagnostics for delayed capture readiness.
  • Reused existing protocol summaries and reduced supplemental probing during capture preparation.

Agent

  • Added Agent case context intake for scenario, measurement point, appliance, and symptom details.
  • Added cooperative cancellation status for eligible heavy analysis tasks.
  • Kept PCAP starter risks visible across navigation and repaired Codex transcript history rendering.

Anoncap

  • Refreshed Anoncap downloads, public-share presets, adaptive slicing defaults, and fileset guidance.
  • Added protocol coverage regressions and clearer pro comparison rows for field-aware anonymization.

Security and on-prem

  • Added admin AI usage and entitlement controls, on-prem license management, safer updates, and SAML certificate fingerprint configuration.
  • Restricted Agent debug payloads to admins and gated analyzer telemetry behind explicit opt-in.
Open release note

Week of April 13: Agent evidence and TCP diagnosis

Agent evidence rendering, TCP diagnostics, upload readiness, and contextual detections now provide clearer packet findings and more reliable investigations.

AgentBug fixesPerformanceSecurityPlatform

Agent

  • Improved Agent evidence cards, transcript rendering, and error handling.
  • Fixed stale starter-brief runs, upload insight readiness, and Codex tool transcript rendering.
  • Added on-demand deep TCP diagnosis and richer analysis UX around packet evidence.

Analyzer

  • Added modeled TCP composite views, viewport-aware TCP charts, PMTUD fallback detection, malware delivery chain detection, and legacy exfiltration signals.
  • Expanded contextual severity handling for timing, transport, and TLS-SIP cases.
  • Restored case-library views and connected PCAP inventory to admin and PacketStats guidance.

Performance

  • Guarded PCAP sparklines against huge histograms and gated the web delivery detector with PacketStats.
  • Used lightweight upload status streams for live upload insights.

Bug fixes and security

  • Tightened authentication, magic-login expiry, tool fallbacks, and platform compatibility.
  • Fixed paginated totals in PCAP lists and local Wireshark column sync drift.
Open release note

Week of April 6: security, on-prem, and Codex streaming

On-premises onboarding, capture access controls, signed sharing, and live Codex steering strengthen secure PacketSafari investigation workflows and reporting.

SecurityAgentOn-premAnoncapBug fixes

Security

  • Hardened memory endpoints, capture file access, anonymous fallback behavior, XML import, CSV export, BYO key storage, and Codex tool identity checks.
  • Escaped untrusted report metadata and report prompt content before rendering.
  • Reapplied capture ACL checks to workspace Agent runs and added signed viewer access for private lab captures.

On-prem

  • Added on-prem onboarding, registry-driven secret provisioning, initial admin bootstrap guidance, and cleaner local data root handling.
  • Improved packet-engine consistency and on-prem configuration reliability.

Agent

  • Added live Codex steering, thread state passthrough, shared prompt actions, and trace-specific starter brief previews.
  • Improved Agent continuity and reduced dependency on intermediary AI components.

Anoncap

  • Added the anoncap landing page, adaptive slicing, unsupported-payload policy controls, map reports, and upload report flows.

Bug fixes

  • Fixed manual archive and restore actions, missing capture handling, PacketStats recovery, analyzer fallbacks, and content rendering errors.
Open release note

Week of March 30: platform hardening and SaaS controls

Dashboards are more stable, SaaS plan controls are clearer, and stronger upload and identity safeguards improve PacketSafari platform reliability overall.

SecurityPlatformBug fixesPerformance

Platform

  • Stabilized dashboards and chat synchronization.
  • Added SaaS paywalls, pricing upsells, social login flags, and profile-based egress allowlists.
  • Improved PacketStats presentation, admin diagnostics, and upload audit history.

Security

  • Hardened controlled outbound access with explicit host approval requirements.
  • Expanded enterprise auth controls, on-prem proxy flow hardening, and egress allowlist coverage.
  • Removed an obsolete analysis update path and clarified the supply-chain policy.

Analyzer

  • Added permission-aware PCAP duplicate detection, optimistic PCAP deletion, compact security summaries, and compact PacketStats summaries.
  • Improved memory items and telecom summaries in Agent-facing analysis.

Bug fixes

  • Fixed workspace navigation for captures and rules.
  • Tightened network topology label coverage and PacketStats regression behavior.
Open release note
v4.1.0-next

Agent transcript controls and on-prem onboarding

Agent progress replay is sharper, AI authentication choices are clearer, and guided on-premises onboarding makes private deployments easier to qualify.

AgentOn-premPlatform
  • Improved Agent transcript playback with clearer nested event rendering, replay controls, and workflow-state handling for longer investigations.
  • Expanded AI authentication choices so deployments can separate shared credentials, stored user API keys, and ChatGPT or Codex login more cleanly.
  • Added a clearer guided handoff from initial on-prem setup through validation and completion.
Open release note
v4.0.0

Platform experience refresh

PacketSafari now delivers faster, cleaner, and more consistent investigation workflows across the refreshed platform experience and analyzer interface.

Platform
  • Refreshed core services for longer support windows and more reliable operation.
  • Standardized layouts, visual patterns, and accessibility across the interface.
  • Made Copilot, Agent, and capture tools exchange investigation context more consistently.
Open release note
v3.9.0

Wireshark 4.7 engine

Analyzer parsing now tracks Wireshark 4.7, expanding dissector and field coverage so teams can inspect more protocols with current packet-decoding support.

PlatformPerformance
  • Updated dissection profiles to match Wireshark 4.7 field names and enums.
  • Improved decode compatibility for newer TLS, QUIC, and HTTP/3 flows.
  • Reduced mismatch warnings when importing traces from 4.7+ clients.
Open release note
v3.8.0

Copilot chat upgrades

Copilot chat now streams faster, builds stronger capture context, and returns clearer packet-analysis answers with a more dependable investigation flow.

Agent
  • Improved context assembly for large traces so Copilot stays grounded in packet evidence.
  • Added richer citations from frames, protocols, and follow-stream summaries.
  • Streamlined live chat playback to reduce latency spikes during long answers.
Open release note
v3.7.0

Most-requested Agent mode: Evidence Trail

Evidence Trail mode keeps Agent investigations focused, repeatable, and annotated, with a clearer sequence of findings and reviewable packet evidence.

Agent
  • Runs playbook-style investigations with explicit goals and checkpoints.
  • Captures tool calls, reasoning, and outputs for smoother analyst handoffs.
  • Produces a final report with links to frames, streams, and exports.
Open release note