PacketSafari

Week of April 13: Agent evidence and TCP diagnosis

Agent evidence rendering, TCP diagnostics, upload readiness, and contextual detections now provide clearer packet findings and more reliable investigations.
agentbug fixesperformancesecurityplatform

Agent

  • Improved Agent evidence cards, transcript rendering, and error handling.
  • Fixed stale starter-brief runs, upload insight readiness, and Codex tool transcript rendering.
  • Added on-demand deep TCP diagnosis and richer analysis UX around packet evidence.

Analyzer

  • Added modeled TCP composite views, viewport-aware TCP charts, PMTUD fallback detection, malware delivery chain detection, and legacy exfiltration signals.
  • Expanded contextual severity handling for timing, transport, and TLS-SIP cases.
  • Restored case-library views and connected PCAP inventory to admin and PacketStats guidance.

Performance

  • Guarded PCAP sparklines against huge histograms and gated the web delivery detector with PacketStats.
  • Used lightweight upload status streams for live upload insights.

Bug fixes and security

  • Tightened authentication, magic-login expiry, tool fallbacks, and platform compatibility.
  • Fixed paginated totals in PCAP lists and local Wireshark column sync drift.