Week of August 24: VoIP troubleshooting and protocol fidelity

Added bounded call-quality and IPsec evidence, connected identity and network-path clues, and improved security-analysis accuracy.
platformsecuritybug fixesagentperformance

Platform

  • Added bounded VoIP call-quality dossiers that connect signaling, RTP quality, NAT traversal, observed paths, and supporting packet evidence without turning measurements into automatic fault claims.
  • Added IPsec coverage and quality context for encrypted VoIP paths, including explicit disclosure when the available capture cannot support a complete conclusion.
  • Connected identity, DNS, service, STP, and path observations into focused troubleshooting chains for faster movement from symptoms to inspectable evidence.

Security

  • Added bounded DNS behavior candidates and reconnect-aware cadence evidence while keeping promotion gates and coverage limits explicit.
  • Added an approval flow for threat-intelligence feeds that require outbound access, making controlled enrichment easier to review before it runs.
  • Improved security-analysis fidelity across web, email, file-sharing, authentication, tunneling, fragmentation, and protocol-transition traffic.

Agent

  • Improved investigation evidence attribution so reports and follow-up analysis retain the correct connection, finding, and capture context.
  • Kept optional path and correlation evidence nonblocking, allowing investigations to finish honestly when a supporting signal is unavailable.

Performance

  • Bounded RTP quality analysis and reused compact signaling, identity, and transport evidence to avoid unnecessary capture-wide work.
  • Improved stream and transaction handling for security analysis while keeping memory and evaluation work bounded on busy captures.

Bug fixes

  • Restored RTP candidate discovery, aligned VoIP signaling across views, preserved SIP call-family relationships, and corrected illegal-packet accounting.
  • Fixed VoIP and telecom evidence classification so observations are explained without being promoted into unsupported faults.
  • Suppressed unattributed TCP matches, preserved customer-facing finding titles, and tightened affected-system scope for campaign corroboration.