PacketSafari

Week of August 3: faster Core Triage, stronger TCP evidence, and private controls

Reduced large-capture processing overhead, added focused TCP and east-west evidence, clarified IDS and Anoncap choices, and strengthened managed AI access.
performanceagentsecurityanoncapplatformbug fixeson prem

Performance

  • Consolidated more capture-wide Triage work into a shared single-read path, reducing repeated decoding across connection, IDS, protocol, and security analysis.
  • Made infrastructure discovery and specialist analysis demand driven, bounded TCP candidate ranking, and compacted saved results to lower memory and storage overhead on large captures.
  • Reused exact IDS and connection evidence across processing stages while retiring unnecessary temporary data after findings and coverage were safely saved.

Agent

  • Added a bounded TCP dossier workflow so focused investigations can assemble connection setup, health, timing, and packet evidence without broad capture scans.
  • Improved Agent handoff after Triage by finalizing saved evidence before launch and preserving capture identity and selected AI settings.

Security

  • Surfaced correlated east-west activity as inspectable findings while keeping packet-detail retrieval bounded.
  • Separated IDS source and coverage choices into a dedicated upload step, preserving the selected rules and exact coverage through the primary scan.

Anoncap

  • Added compact privacy-policy controls for private anonymization profiles and persisted the validated policy with each workflow.
  • Reconciled identity-handling rules across Anoncap and upload workflows so supported privacy choices remain consistent.

Platform

  • Added managed AI access-source selection with clearer subscription and provider approval flows for organization deployments.
  • Expanded supported alternative-model guidance and kept entitled AI choices stable across reconnects and long-running analysis.

Bug fixes

  • Fixed capture loading, connection evidence, and scan-completion edge cases that could stall Triage, lose exact evidence, or launch Agent before results were durable.
  • Improved cleanup and empty-result handling so completed analysis does not leave stale work or trigger duplicate scans.

On-prem

  • Strengthened controlled AI-provider routing and authentication-source provenance for private deployments with managed egress requirements.