Week of August 3: faster Core Triage, stronger TCP evidence, and private controls
Reduced large-capture processing overhead, added focused TCP and east-west evidence, clarified IDS and Anoncap choices, and strengthened managed AI access.
performanceagentsecurityanoncapplatformbug fixeson prem
Performance
- Consolidated more capture-wide Triage work into a shared single-read path, reducing repeated decoding across connection, IDS, protocol, and security analysis.
- Made infrastructure discovery and specialist analysis demand driven, bounded TCP candidate ranking, and compacted saved results to lower memory and storage overhead on large captures.
- Reused exact IDS and connection evidence across processing stages while retiring unnecessary temporary data after findings and coverage were safely saved.
Agent
- Added a bounded TCP dossier workflow so focused investigations can assemble connection setup, health, timing, and packet evidence without broad capture scans.
- Improved Agent handoff after Triage by finalizing saved evidence before launch and preserving capture identity and selected AI settings.
Security
- Surfaced correlated east-west activity as inspectable findings while keeping packet-detail retrieval bounded.
- Separated IDS source and coverage choices into a dedicated upload step, preserving the selected rules and exact coverage through the primary scan.
Anoncap
- Added compact privacy-policy controls for private anonymization profiles and persisted the validated policy with each workflow.
- Reconciled identity-handling rules across Anoncap and upload workflows so supported privacy choices remain consistent.
Platform
- Added managed AI access-source selection with clearer subscription and provider approval flows for organization deployments.
- Expanded supported alternative-model guidance and kept entitled AI choices stable across reconnects and long-running analysis.
Bug fixes
- Fixed capture loading, connection evidence, and scan-completion edge cases that could stall Triage, lose exact evidence, or launch Agent before results were durable.
- Improved cleanup and empty-result handling so completed analysis does not leave stale work or trigger duplicate scans.
On-prem
- Strengthened controlled AI-provider routing and authentication-source provenance for private deployments with managed egress requirements.
