Week of August 10: guided investigations, defensible verification, and durable recovery

Clarified Core-first and focused starts, simplified evidence-led investigations, improved report inspection, and tightened large-capture reliability.
agentbug fixesperformancesecurityplatformanoncap

Agent

  • Added an explicit choice between a capture-wide Core-first start and a focused Agent start, with clearer confirmation and milestone ordering before an investigation begins.
  • Unified Preliminary Report, Verification, and Comprehensive Final Report milestones into one chronological investigation, with clearer live-stage navigation and concise completed reports.
  • Simplified new investigations around direct evidence handoffs so each stage can stop once it has a defensible answer, while preserving important alternatives, uncertainty, and capture-wide coverage limits.
  • Made Agent sessions and report activity durable across upload handoffs, reconnects, retries, and page restoration, reducing duplicate runs and missing or stale transcript content.
  • Kept quick questions separate from managed investigations while allowing executive summaries and security reviews to start without a custom prompt.

Verification and evidence

  • Made verification dispositions traceable to stable claims and preserved supporting, contradicting, and baseline evidence through the final report.
  • Required deterministic Triage evidence before a Comprehensive Final Report can claim completion, while keeping cached preliminary evidence available to later stages.
  • Improved cross-flow TCP reasoning and retained exact selectors, sequence coordinates, control events, and connection-local evidence for packet-level review.
  • Improved bounded discovery for services on alternate ports and paired proxy or middlebox flows, while preserving TCP negotiation fingerprints for evidence-backed comparison.
  • Made packet-tool results easier to inspect with richer typed previews, Markdown tables, preserved report headings, and explicit disclosure when a tool returned only partial coverage.

Bug fixes

  • Fixed upload-to-Agent transitions, stalled clarification flows, live milestone navigation, report hydration, email actions, and terminal transcript recovery.
  • Restored packet-tool execution and live Markdown rendering while keeping transient Agent thinking out of the saved customer transcript.
  • Tightened TCP, ARP, DNS, telecom, and security-finding attribution so unsupported or unrelated packet evidence is not promoted into a customer conclusion.
  • Kept late-packet signals and capture-wide protocol coverage available through bounded large-capture scans so decisive anomalies and specialist analysis are not silently skipped.

Performance and platform

  • Added a faster large-capture path, reused exact connection results, and localized reset-window analysis to avoid unnecessary capture-wide work.
  • Reduced backend startup overhead, separated web and worker startup paths, prioritized urgent queues, and bounded storage cleanup around active investigations.
  • Improved exported and visual reports by removing duplicate metadata and navigation-only citations, and deriving optional visuals only from exact Final Report evidence.

Security

  • Made security findings easier to read while keeping live scan state, deterministic findings, and Triage completion consistent across the investigation.

Anoncap

  • Coordinated capture retention and anoncap deletion with active Agent investigations so privacy cleanup cannot race an in-progress analysis.
  • Decoupled public Anoncap downloads from frontend releases so privacy-tool updates can be published independently.