Week of August 17: identity evidence, security analysis, and capture quality
Expanded identity and DNS evidence, added focused security behaviors, and made connection conclusions more transparent about capture limitations.
securityagentperformancebug fixesplatform
Security
- Expanded capture-wide identity and DNS evidence for resolver relationships, service discovery, tunneling indicators, and recurring destination behavior.
- Added bounded behavioral signals for interactive command-and-control patterns, sparse identity transfers, captive-portal manipulation, and unusual service activity, with explicit qualification and coverage limits.
- Added certificate-trust and transparency evidence so TLS investigations can distinguish observed trust material from unsupported conclusions.
- Surfaced capture limitations alongside security results and gated strong TCP conclusions when duplication, slicing, or other capture-quality issues could distort the evidence.
Agent
- Added a standalone PacketQL workspace for querying retained capture facts, with focused Agent actions that can reuse exact results without restarting an investigation.
- Made Agent failures more actionable and preserved investigation state, upload context, and evidence attribution through final handoff and reconnects.
- Strengthened Fast investigations so focused answers remain grounded in bounded packet evidence and capture-wide questions are redirected to broader analysis when needed.
Performance
- Reduced repeated capture work by consolidating identity, service, duplicate-observation, and connection evidence into reusable bounded results.
- Sped up capture profile initialization and Wi-Fi troubleshooting while adding traffic-burst impact context for faster connection triage.
- Improved large-capture completion behavior so partial but valid evidence remains available with honest coverage instead of appearing complete or disappearing.
Platform
- Made connection triage denser and easier to sort, with clearer security-risk labels, capture-quality status, and more reliable packet pivots.
- Improved upload keep/discard controls and kept upload goals visible as captures move into Triage or Agent.
Bug fixes
- Fixed canceled-upload cleanup, standalone Triage finalization, pending evaluation recovery, and several upload-to-investigation transition failures.
- Corrected TCP quality, fragmented ACK, delayed-ACK, DNS, Wi-Fi, and service-attribution edge cases that could overstate or misplace a finding.
- Improved protocol and security-analysis fidelity for malformed traffic, application transitions, and packet orientation across a wider range of captures.
