Week of August 17: identity evidence, security analysis, and capture quality

Expanded identity and DNS evidence, added focused security behaviors, and made connection conclusions more transparent about capture limitations.
securityagentperformancebug fixesplatform

Security

  • Expanded capture-wide identity and DNS evidence for resolver relationships, service discovery, tunneling indicators, and recurring destination behavior.
  • Added bounded behavioral signals for interactive command-and-control patterns, sparse identity transfers, captive-portal manipulation, and unusual service activity, with explicit qualification and coverage limits.
  • Added certificate-trust and transparency evidence so TLS investigations can distinguish observed trust material from unsupported conclusions.
  • Surfaced capture limitations alongside security results and gated strong TCP conclusions when duplication, slicing, or other capture-quality issues could distort the evidence.

Agent

  • Added a standalone PacketQL workspace for querying retained capture facts, with focused Agent actions that can reuse exact results without restarting an investigation.
  • Made Agent failures more actionable and preserved investigation state, upload context, and evidence attribution through final handoff and reconnects.
  • Strengthened Fast investigations so focused answers remain grounded in bounded packet evidence and capture-wide questions are redirected to broader analysis when needed.

Performance

  • Reduced repeated capture work by consolidating identity, service, duplicate-observation, and connection evidence into reusable bounded results.
  • Sped up capture profile initialization and Wi-Fi troubleshooting while adding traffic-burst impact context for faster connection triage.
  • Improved large-capture completion behavior so partial but valid evidence remains available with honest coverage instead of appearing complete or disappearing.

Platform

  • Made connection triage denser and easier to sort, with clearer security-risk labels, capture-quality status, and more reliable packet pivots.
  • Improved upload keep/discard controls and kept upload goals visible as captures move into Triage or Agent.

Bug fixes

  • Fixed canceled-upload cleanup, standalone Triage finalization, pending evaluation recovery, and several upload-to-investigation transition failures.
  • Corrected TCP quality, fragmented ACK, delayed-ACK, DNS, Wi-Fi, and service-attribution edge cases that could overstate or misplace a finding.
  • Improved protocol and security-analysis fidelity for malformed traffic, application transitions, and packet orientation across a wider range of captures.