<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Release Notes - AIR</title>
    <link>https://marketing.binalyze.com/air-release-notes</link>
    <description>We are constantly improving AIR! Read the latest news related to the world's fastest &amp; most comprehensive Enterprise Forensics Suite.</description>
    <language>en</language>
    <pubDate>Tue, 25 Aug 2026 10:38:03 GMT</pubDate>
    <dc:date>2026-08-25T10:38:03Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Binalyze AIR 5.25</title>
      <link>https://marketing.binalyze.com/air-release-notes/binalyze-air-5-25</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-5-25" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;What’s New?&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset status notifications improve response readiness.&lt;/strong&gt; AIR can now notify teams when a Responder-backed asset becomes Unreachable or Unmanaged, based on preferences configured in Notification Settings. This helps analysts identify coverage gaps earlier and avoid starting response actions against assets that are no longer ready for investigation tasks.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;System Resources now highlights operational risk before it affects investigations.&lt;/strong&gt; On-premise deployments now have a redesigned System Resources view with CPU, memory, and disk cards, plus an application-wide low-disk warning. This helps administrators detect capacity issues before evidence collection, analysis, or reporting workflows are impacted.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;New Features &amp;amp; Improvements&lt;/h1&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Investigation Hub and Case Workflows&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Improved Investigation Hub reliability during imports&lt;/h3&gt; 
&lt;p&gt;Several Investigation Hub import paths have been strengthened to preserve evidence consistency during concurrent or retried imports. AIR now handles overlapping case and task-assignment imports more safely, isolates temporary evidence databases per import, and avoids shared-state races during DRONE result ingestion.&lt;/p&gt; 
&lt;p&gt;These improvements reduce the risk of missing findings, duplicated imported rows, inflated counters, or incomplete evidence visibility after interruptions. For analysts, this means Investigation Hub results are more dependable during large investigations or when the same task data is opened from more than one workflow.&lt;/p&gt; 
&lt;p&gt;DRONE findings and DRONE analysis imports now coordinate more safely when both write results for the same task assignment. AIR also recovers analysis rows that could previously be removed by a concurrent cleanup path, improving confidence that automated findings remain available after import completion.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Evidence Collection and Responder Operations&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Default Memory Limit is now 4 GiB&lt;/h3&gt; 
&lt;p&gt;The default Memory Limit for responder tasks is now 4 GiB. Previously, a missing memory configuration meant unlimited memory usage. The new default limits the resource exposure of task execution while preserving the option to set unlimited memory deliberately.&lt;/p&gt; 
&lt;p&gt;The 4 GiB default appears in task customization, policy configuration, and interACT shell task options. The Default Policy also converges to 4 GiB during upgrade, so new tasks that follow the Default Policy inherit the safer limit automatically.&lt;/p&gt; 
&lt;p&gt;Entering 0 or clearing the Memory Limit field still means unlimited. Existing custom policies keep their stored values, including explicit unlimited values. This allows administrators to keep intentionally configured exceptions while improving the default posture for the broader fleet.&lt;/p&gt; 
&lt;p&gt;Integration users should note that task callers that omit a memory value now receive the 4 GiB resolved default. To restore unlimited behavior for those callers, create a higher-priority custom policy with Memory Limit cleared or set to 0.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Linux Responder packages for older and newer kernels&lt;/h3&gt; 
&lt;p&gt;AIR now ships two Linux Responder packages so both older and modern Linux assets stay supported:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Legacy&lt;/strong&gt; — for Linux kernel 2.6.32 and above. Use this on older distributions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Edge&lt;/strong&gt; — for Linux kernel 3.2 and above. Use this on modern distributions.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;These kernel ranges follow the Go runtime used to build each package. The Edge package is built with Go 1.26, which requires Linux kernel 3.2 or newer. The Legacy package keeps support for older kernels that cannot run that runtime.&lt;/p&gt; 
&lt;p&gt;When a Linux Responder is downloaded or deployed, the package that matches the asset’s kernel should be chosen. For assets already managed by AIR, later updates use the matching package automatically.&lt;/p&gt; 
&lt;p&gt;&lt;strong style="color: #33485b;"&gt;What happens to existing Linux assets: &lt;/strong&gt;AIR does not yet know which package an already-installed Linux Responder should use. Those assets therefore receive the Legacy package on their first update after this change. After that update, AIR can match the asset’s kernel: hosts running kernel 3.2 or newer move to the Edge package on the next update. Older kernels stay on Legacy.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Responder User-Agent management through CDN records&lt;/h3&gt; 
&lt;p&gt;AIR can now retrieve validated User-Agent records from the Responder CDN and deliver the appropriate value to responders through the existing configuration flow. This allows User-Agent values to be updated without requiring a responder release.&lt;/p&gt; 
&lt;p&gt;The Console periodically refreshes the record set, validates freshness and format, stores the accepted version locally, and recalculates configuration tags only for affected assets. This keeps responder configuration changes targeted and avoids unnecessary updates across unaffected platforms.&lt;/p&gt; 
&lt;p&gt;This improvement helps administrators respond faster when endpoint security controls require updated User-Agent strings for responder communication.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Default-secure deployment commands&lt;/h3&gt; 
&lt;p&gt;Deployment commands now validate TLS certificates by default. For on-premise environments that use self-signed or private certificates, authenticated administrators can explicitly choose the insecure copy option where available, or pass the documented script flag manually.&lt;/p&gt; 
&lt;p&gt;This change improves the default security posture of responder deployment while preserving an operational escape hatch for controlled on-premise environments. SaaS and shareable deployment links do not offer the TLS bypass option.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Asset Visibility, Notifications, and Response&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Asset status change notifications&lt;/h3&gt; 
&lt;p&gt;AIR now generates notifications when responder-backed assets become Unreachable or Unmanaged, based on preferences configured in Notification Settings. Notifications can be delivered through in-app, email, Slack, Teams, and Mattermost channels according to the customer’s notification configuration.&lt;/p&gt; 
&lt;p&gt;These alerts help analysts and administrators detect asset availability or management changes before starting collection or response tasks. For example, if an asset becomes Unreachable, teams can address connectivity or responder readiness before relying on that asset for evidence collection.&lt;/p&gt; 
&lt;p&gt;Notifications are deduplicated by asset and state transition so repeated scans do not create excessive noise for the same condition.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;System Resources visibility and low-disk warning&lt;/h3&gt; 
&lt;p&gt;The System Resources page has been redesigned for on-premise deployments. It now presents CPU, memory, and disk utilization as cards with warning and critical states.&lt;/p&gt; 
&lt;p&gt;When the application and database use separate hosts, AIR can show separate disk cards for each. If disk usage becomes high, a warning bar appears at the top of the application and links directly to System Resources for review.&lt;/p&gt; 
&lt;p&gt;Administrators can snooze or dismiss the warning. If severity increases, AIR shows the warning again so teams do not miss a worsening storage condition. This is especially important for investigation environments where disk pressure can affect evidence ingestion, storage, and reporting.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;interACT workflow improvements&lt;/h3&gt; 
&lt;p&gt;interACT now handles asset selections more consistently across the Assets page, case assets, endpoint details, and the Quick Start wizard. When a selection starts from a filtered asset list, AIR hydrates the selected asset details so session tabs show the correct asset name, platform, and IP address.&lt;/p&gt; 
&lt;p&gt;When analysts use Select all items from the Assets page, interACT now resolves the matching eligible assets before starting sessions instead of closing the wizard without creating sessions. AIR also respects the session limit and remains on the wizard if no eligible asset remains.&lt;/p&gt; 
&lt;p&gt;The interACT All tab now clears command results and command history when all sessions are closed. This prevents stale output from appearing in a later, unrelated session set or being included in exported reports.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Administration, Access Control, and Integrations&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Optional SMTP authentication&lt;/h3&gt; 
&lt;p&gt;SMTP username and password fields are now optional. Customers that use internal SMTP relays or unauthenticated SMTP servers can configure email delivery without supplying credentials.&lt;/p&gt; 
&lt;p&gt;When credentials are configured, the UI clearly indicates whether a saved password exists. Administrators can keep the stored password, update it, or clear it explicitly. If the username is empty, AIR does not send SMTP authentication details.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Repository Explorer permission clarity&lt;/h3&gt; 
&lt;p&gt;Repository Explorer access is now aligned with Evidence Repository view permission. Users who can view evidence repositories can browse and download through Repository Explorer without also requiring cloud asset account visibility.&lt;/p&gt; 
&lt;p&gt;Disk image import remains gated by the appropriate asset-creation permission and requires a resolved account context. This improves least-privilege access for teams that need to review repository content without managing cloud asset accounts.&lt;/p&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;Bug Fixes&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;interACT sessions started from asset selections now show asset names correctly.&lt;/strong&gt; Sessions opened from bulk selection, endpoint details, or case assets previously showed blank tabs, missing platform icons, empty IP values, and “Unknown Session” in command results. AIR now hydrates selected asset details before creating sessions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;interACT Select all items now starts sessions instead of silently closing.&lt;/strong&gt; When analysts selected all filtered assets and clicked Connect, no request was sent and no session was created. AIR now resolves the filter to eligible assets, respects exclusions and limits, and keeps the analyst in the wizard if nothing can be started.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;interACT All tab no longer carries results into a new session set.&lt;/strong&gt; Command results and command history are cleared when the final session is closed, preventing stale output from appearing in a later session or in exported reports.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;interACT WebSocket authorization now enforces session ownership.&lt;/strong&gt; The Console now verifies that the connecting user owns the requested interACT session and that the connection asset matches the session asset. This aligns WebSocket behavior with the REST session guard.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder update actions now respect asset eligibility.&lt;/strong&gt; AIR no longer enables Update Responder Version when all selected assets are excluded from updates, in maintenance mode, or already ineligible. Asset detail pages also no longer offer manual updates for assets manually excluded from updates.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Stale version-update badges are cleared more reliably.&lt;/strong&gt; Assets no longer continue to show Waiting or Scheduled after auto-update is disabled or when an update policy blocks the asset. Manual exclusion also clears stale lifecycle status.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Linux responder updates now use the lane declared during the same poll.&lt;/strong&gt; AIR no longer builds an automatic update task from stale lane data loaded before the current heartbeat or visit. This prevents assets from being offered the wrong Linux package on the first lane-aware update.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Deploy Responder for cloud assets now targets only the selected asset.&lt;/strong&gt; A selection containing one AWS cloud asset could previously trigger deployment for multiple devices. AIR now resolves expression filters correctly and intersects them with the selected asset list.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Isolation task failures no longer leave assets stuck in Isolating or Unisolating.&lt;/strong&gt; When an isolation task fails, AIR now reverts the asset state so analysts can retry or initiate the appropriate follow-up action.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Repository Explorer browse now works for view-only evidence repository roles.&lt;/strong&gt; Users with Evidence Repository view permission can browse repository content even if they do not have cloud asset account visibility. Import actions remain controlled by the required asset permissions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Cloud Sync Failed notifications are now readable.&lt;/strong&gt; Notification bodies no longer display raw JSON or literal newline characters. AIR now renders a clean, single-line message in the header popover and notification history.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;On-premise Global Search no longer exposes the SaaS-only Update settings page.&lt;/strong&gt; Deployment-model route metadata is now applied consistently, so SaaS-only settings do not appear in on-premise search results or direct navigation paths.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub DRONE imports no longer race on shared temporary database files.&lt;/strong&gt; Each DRONE import now uses an isolated temporary path, preventing concurrent imports of the same task assignment from corrupting or deleting each other’s input.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub Case.db ingest is safe under concurrent case and task-assignment imports.&lt;/strong&gt; AIR now avoids shared SQLite data-source state that could delete another in-progress import’s database and produce empty or missing evidence tables.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;DRONE import cleanup now releases temporary files and archive handles on all paths.&lt;/strong&gt; Malformed or incomplete archives no longer leave open handles or temporary files behind, reducing the risk of storage and file-handle exhaustion during repeated retries.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;DRONE findings and DRONE analysis imports no longer delete each other’s rows.&lt;/strong&gt; AIR now serializes the overlapping write paths and co-enqueues recovery when needed, reducing the risk of silent finding loss after retries or concurrent imports.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;External evidence import retries no longer duplicate rows or counters.&lt;/strong&gt; Retried imports now clean up prior rows for the same import before re-inserting and recompute counters from stored data instead of incrementing stale values.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Tornado evidence import retries are now idempotent.&lt;/strong&gt; AIR now creates the assignment before marking the import completed or deleting upload records, preventing unrecoverable retries and duplicate imported evidence.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub migration-wait retries no longer create duplicate delayed import jobs.&lt;/strong&gt; AIR now delays the current job instead of adding new jobs with random identifiers while a migration is active.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Refactored osquery ingestion now builds valid evidence queries.&lt;/strong&gt; Triage and acquisition assignments containing osquery results no longer fail with SQL syntax errors when the refactored ingestion path is enabled.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Malformed PST and imported-data feeds now return controlled validation errors.&lt;/strong&gt; Empty, truncated, or wrong-format inputs no longer fall through to generic internal errors in the evidence import pipeline.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Imported-evidence task assignment lookup now uses parameterized values.&lt;/strong&gt; AIR fixed a blind SQL injection path in the Investigation Hub imported-evidence lookup. Unmatched import IDs now return a controlled not-found response instead of an internal error.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fleet-action filters now honor legacy includedIds and excludedIds fields.&lt;/strong&gt; Requests that explicitly target a non-existent asset ID now fail closed instead of widening to every managed asset in the organization.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Evidence repository validation now requires repository management privileges.&lt;/strong&gt; View-only users can no longer use validation routes as outbound connection tests. This better aligns connection validation with repository create and update permissions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;On-premise outbound validation now blocks private network ranges by default.&lt;/strong&gt; Repository and related outbound connection tests now reject RFC1918 private destinations unless administrators explicitly allow the required internal ranges. Customers using private evidence repositories should configure the allowed outbound CIDR ranges before validating those repositories.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Cross-organization Git repository browsing has been blocked.&lt;/strong&gt; AIR now applies organization-scope checks when browsing repository trees or listing branches from stored repository connections.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;SSO provider management now requires Global Admin authority.&lt;/strong&gt; Users with settings-save privileges but without Global Admin authority can no longer create or modify SSO providers. This protects the trust boundary around identity provider configuration.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Organization admins can no longer reset Global Admin 2FA.&lt;/strong&gt; AIR now applies the same target-tier protection to reset 2FA that already existed on neighboring user-management actions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Stored XSS paths were closed across several user-controlled fields.&lt;/strong&gt; AIR now validates or escapes case names, endpoint hostnames, Full Text Search profile keywords, and Slack channel names before they can execute in notification panels, profile editors, or routing dialogs.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;OpenAPI documents are no longer anonymously exposed.&lt;/strong&gt; Swagger JSON and YAML documents are now served through authenticated API paths, and legacy public paths redirect to the protected routes.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Cloud account sync and GCP-related notification rendering was improved.&lt;/strong&gt; Cloud Sync Failed messages now display in a user-readable format and no longer expose raw object payloads in the notification UI.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Quick Start image evidence privilege tests and related UI behavior were stabilized.&lt;/strong&gt; The UI now asserts the correct access contract by disabling the parent action rather than relying on hidden nested menu content.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-5-25" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;What’s New?&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset status notifications improve response readiness.&lt;/strong&gt; AIR can now notify teams when a Responder-backed asset becomes Unreachable or Unmanaged, based on preferences configured in Notification Settings. This helps analysts identify coverage gaps earlier and avoid starting response actions against assets that are no longer ready for investigation tasks.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;System Resources now highlights operational risk before it affects investigations.&lt;/strong&gt; On-premise deployments now have a redesigned System Resources view with CPU, memory, and disk cards, plus an application-wide low-disk warning. This helps administrators detect capacity issues before evidence collection, analysis, or reporting workflows are impacted.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;New Features &amp;amp; Improvements&lt;/h1&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Investigation Hub and Case Workflows&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Improved Investigation Hub reliability during imports&lt;/h3&gt; 
&lt;p&gt;Several Investigation Hub import paths have been strengthened to preserve evidence consistency during concurrent or retried imports. AIR now handles overlapping case and task-assignment imports more safely, isolates temporary evidence databases per import, and avoids shared-state races during DRONE result ingestion.&lt;/p&gt; 
&lt;p&gt;These improvements reduce the risk of missing findings, duplicated imported rows, inflated counters, or incomplete evidence visibility after interruptions. For analysts, this means Investigation Hub results are more dependable during large investigations or when the same task data is opened from more than one workflow.&lt;/p&gt; 
&lt;p&gt;DRONE findings and DRONE analysis imports now coordinate more safely when both write results for the same task assignment. AIR also recovers analysis rows that could previously be removed by a concurrent cleanup path, improving confidence that automated findings remain available after import completion.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Evidence Collection and Responder Operations&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Default Memory Limit is now 4 GiB&lt;/h3&gt; 
&lt;p&gt;The default Memory Limit for responder tasks is now 4 GiB. Previously, a missing memory configuration meant unlimited memory usage. The new default limits the resource exposure of task execution while preserving the option to set unlimited memory deliberately.&lt;/p&gt; 
&lt;p&gt;The 4 GiB default appears in task customization, policy configuration, and interACT shell task options. The Default Policy also converges to 4 GiB during upgrade, so new tasks that follow the Default Policy inherit the safer limit automatically.&lt;/p&gt; 
&lt;p&gt;Entering 0 or clearing the Memory Limit field still means unlimited. Existing custom policies keep their stored values, including explicit unlimited values. This allows administrators to keep intentionally configured exceptions while improving the default posture for the broader fleet.&lt;/p&gt; 
&lt;p&gt;Integration users should note that task callers that omit a memory value now receive the 4 GiB resolved default. To restore unlimited behavior for those callers, create a higher-priority custom policy with Memory Limit cleared or set to 0.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Linux Responder packages for older and newer kernels&lt;/h3&gt; 
&lt;p&gt;AIR now ships two Linux Responder packages so both older and modern Linux assets stay supported:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Legacy&lt;/strong&gt; — for Linux kernel 2.6.32 and above. Use this on older distributions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Edge&lt;/strong&gt; — for Linux kernel 3.2 and above. Use this on modern distributions.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;These kernel ranges follow the Go runtime used to build each package. The Edge package is built with Go 1.26, which requires Linux kernel 3.2 or newer. The Legacy package keeps support for older kernels that cannot run that runtime.&lt;/p&gt; 
&lt;p&gt;When a Linux Responder is downloaded or deployed, the package that matches the asset’s kernel should be chosen. For assets already managed by AIR, later updates use the matching package automatically.&lt;/p&gt; 
&lt;p&gt;&lt;strong style="color: #33485b;"&gt;What happens to existing Linux assets: &lt;/strong&gt;AIR does not yet know which package an already-installed Linux Responder should use. Those assets therefore receive the Legacy package on their first update after this change. After that update, AIR can match the asset’s kernel: hosts running kernel 3.2 or newer move to the Edge package on the next update. Older kernels stay on Legacy.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Responder User-Agent management through CDN records&lt;/h3&gt; 
&lt;p&gt;AIR can now retrieve validated User-Agent records from the Responder CDN and deliver the appropriate value to responders through the existing configuration flow. This allows User-Agent values to be updated without requiring a responder release.&lt;/p&gt; 
&lt;p&gt;The Console periodically refreshes the record set, validates freshness and format, stores the accepted version locally, and recalculates configuration tags only for affected assets. This keeps responder configuration changes targeted and avoids unnecessary updates across unaffected platforms.&lt;/p&gt; 
&lt;p&gt;This improvement helps administrators respond faster when endpoint security controls require updated User-Agent strings for responder communication.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Default-secure deployment commands&lt;/h3&gt; 
&lt;p&gt;Deployment commands now validate TLS certificates by default. For on-premise environments that use self-signed or private certificates, authenticated administrators can explicitly choose the insecure copy option where available, or pass the documented script flag manually.&lt;/p&gt; 
&lt;p&gt;This change improves the default security posture of responder deployment while preserving an operational escape hatch for controlled on-premise environments. SaaS and shareable deployment links do not offer the TLS bypass option.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Asset Visibility, Notifications, and Response&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Asset status change notifications&lt;/h3&gt; 
&lt;p&gt;AIR now generates notifications when responder-backed assets become Unreachable or Unmanaged, based on preferences configured in Notification Settings. Notifications can be delivered through in-app, email, Slack, Teams, and Mattermost channels according to the customer’s notification configuration.&lt;/p&gt; 
&lt;p&gt;These alerts help analysts and administrators detect asset availability or management changes before starting collection or response tasks. For example, if an asset becomes Unreachable, teams can address connectivity or responder readiness before relying on that asset for evidence collection.&lt;/p&gt; 
&lt;p&gt;Notifications are deduplicated by asset and state transition so repeated scans do not create excessive noise for the same condition.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;System Resources visibility and low-disk warning&lt;/h3&gt; 
&lt;p&gt;The System Resources page has been redesigned for on-premise deployments. It now presents CPU, memory, and disk utilization as cards with warning and critical states.&lt;/p&gt; 
&lt;p&gt;When the application and database use separate hosts, AIR can show separate disk cards for each. If disk usage becomes high, a warning bar appears at the top of the application and links directly to System Resources for review.&lt;/p&gt; 
&lt;p&gt;Administrators can snooze or dismiss the warning. If severity increases, AIR shows the warning again so teams do not miss a worsening storage condition. This is especially important for investigation environments where disk pressure can affect evidence ingestion, storage, and reporting.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;interACT workflow improvements&lt;/h3&gt; 
&lt;p&gt;interACT now handles asset selections more consistently across the Assets page, case assets, endpoint details, and the Quick Start wizard. When a selection starts from a filtered asset list, AIR hydrates the selected asset details so session tabs show the correct asset name, platform, and IP address.&lt;/p&gt; 
&lt;p&gt;When analysts use Select all items from the Assets page, interACT now resolves the matching eligible assets before starting sessions instead of closing the wizard without creating sessions. AIR also respects the session limit and remains on the wizard if no eligible asset remains.&lt;/p&gt; 
&lt;p&gt;The interACT All tab now clears command results and command history when all sessions are closed. This prevents stale output from appearing in a later, unrelated session set or being included in exported reports.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Administration, Access Control, and Integrations&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Optional SMTP authentication&lt;/h3&gt; 
&lt;p&gt;SMTP username and password fields are now optional. Customers that use internal SMTP relays or unauthenticated SMTP servers can configure email delivery without supplying credentials.&lt;/p&gt; 
&lt;p&gt;When credentials are configured, the UI clearly indicates whether a saved password exists. Administrators can keep the stored password, update it, or clear it explicitly. If the username is empty, AIR does not send SMTP authentication details.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Repository Explorer permission clarity&lt;/h3&gt; 
&lt;p&gt;Repository Explorer access is now aligned with Evidence Repository view permission. Users who can view evidence repositories can browse and download through Repository Explorer without also requiring cloud asset account visibility.&lt;/p&gt; 
&lt;p&gt;Disk image import remains gated by the appropriate asset-creation permission and requires a resolved account context. This improves least-privilege access for teams that need to review repository content without managing cloud asset accounts.&lt;/p&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;Bug Fixes&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;interACT sessions started from asset selections now show asset names correctly.&lt;/strong&gt; Sessions opened from bulk selection, endpoint details, or case assets previously showed blank tabs, missing platform icons, empty IP values, and “Unknown Session” in command results. AIR now hydrates selected asset details before creating sessions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;interACT Select all items now starts sessions instead of silently closing.&lt;/strong&gt; When analysts selected all filtered assets and clicked Connect, no request was sent and no session was created. AIR now resolves the filter to eligible assets, respects exclusions and limits, and keeps the analyst in the wizard if nothing can be started.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;interACT All tab no longer carries results into a new session set.&lt;/strong&gt; Command results and command history are cleared when the final session is closed, preventing stale output from appearing in a later session or in exported reports.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;interACT WebSocket authorization now enforces session ownership.&lt;/strong&gt; The Console now verifies that the connecting user owns the requested interACT session and that the connection asset matches the session asset. This aligns WebSocket behavior with the REST session guard.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder update actions now respect asset eligibility.&lt;/strong&gt; AIR no longer enables Update Responder Version when all selected assets are excluded from updates, in maintenance mode, or already ineligible. Asset detail pages also no longer offer manual updates for assets manually excluded from updates.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Stale version-update badges are cleared more reliably.&lt;/strong&gt; Assets no longer continue to show Waiting or Scheduled after auto-update is disabled or when an update policy blocks the asset. Manual exclusion also clears stale lifecycle status.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Linux responder updates now use the lane declared during the same poll.&lt;/strong&gt; AIR no longer builds an automatic update task from stale lane data loaded before the current heartbeat or visit. This prevents assets from being offered the wrong Linux package on the first lane-aware update.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Deploy Responder for cloud assets now targets only the selected asset.&lt;/strong&gt; A selection containing one AWS cloud asset could previously trigger deployment for multiple devices. AIR now resolves expression filters correctly and intersects them with the selected asset list.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Isolation task failures no longer leave assets stuck in Isolating or Unisolating.&lt;/strong&gt; When an isolation task fails, AIR now reverts the asset state so analysts can retry or initiate the appropriate follow-up action.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Repository Explorer browse now works for view-only evidence repository roles.&lt;/strong&gt; Users with Evidence Repository view permission can browse repository content even if they do not have cloud asset account visibility. Import actions remain controlled by the required asset permissions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Cloud Sync Failed notifications are now readable.&lt;/strong&gt; Notification bodies no longer display raw JSON or literal newline characters. AIR now renders a clean, single-line message in the header popover and notification history.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;On-premise Global Search no longer exposes the SaaS-only Update settings page.&lt;/strong&gt; Deployment-model route metadata is now applied consistently, so SaaS-only settings do not appear in on-premise search results or direct navigation paths.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub DRONE imports no longer race on shared temporary database files.&lt;/strong&gt; Each DRONE import now uses an isolated temporary path, preventing concurrent imports of the same task assignment from corrupting or deleting each other’s input.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub Case.db ingest is safe under concurrent case and task-assignment imports.&lt;/strong&gt; AIR now avoids shared SQLite data-source state that could delete another in-progress import’s database and produce empty or missing evidence tables.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;DRONE import cleanup now releases temporary files and archive handles on all paths.&lt;/strong&gt; Malformed or incomplete archives no longer leave open handles or temporary files behind, reducing the risk of storage and file-handle exhaustion during repeated retries.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;DRONE findings and DRONE analysis imports no longer delete each other’s rows.&lt;/strong&gt; AIR now serializes the overlapping write paths and co-enqueues recovery when needed, reducing the risk of silent finding loss after retries or concurrent imports.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;External evidence import retries no longer duplicate rows or counters.&lt;/strong&gt; Retried imports now clean up prior rows for the same import before re-inserting and recompute counters from stored data instead of incrementing stale values.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Tornado evidence import retries are now idempotent.&lt;/strong&gt; AIR now creates the assignment before marking the import completed or deleting upload records, preventing unrecoverable retries and duplicate imported evidence.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub migration-wait retries no longer create duplicate delayed import jobs.&lt;/strong&gt; AIR now delays the current job instead of adding new jobs with random identifiers while a migration is active.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Refactored osquery ingestion now builds valid evidence queries.&lt;/strong&gt; Triage and acquisition assignments containing osquery results no longer fail with SQL syntax errors when the refactored ingestion path is enabled.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Malformed PST and imported-data feeds now return controlled validation errors.&lt;/strong&gt; Empty, truncated, or wrong-format inputs no longer fall through to generic internal errors in the evidence import pipeline.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Imported-evidence task assignment lookup now uses parameterized values.&lt;/strong&gt; AIR fixed a blind SQL injection path in the Investigation Hub imported-evidence lookup. Unmatched import IDs now return a controlled not-found response instead of an internal error.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fleet-action filters now honor legacy includedIds and excludedIds fields.&lt;/strong&gt; Requests that explicitly target a non-existent asset ID now fail closed instead of widening to every managed asset in the organization.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Evidence repository validation now requires repository management privileges.&lt;/strong&gt; View-only users can no longer use validation routes as outbound connection tests. This better aligns connection validation with repository create and update permissions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;On-premise outbound validation now blocks private network ranges by default.&lt;/strong&gt; Repository and related outbound connection tests now reject RFC1918 private destinations unless administrators explicitly allow the required internal ranges. Customers using private evidence repositories should configure the allowed outbound CIDR ranges before validating those repositories.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Cross-organization Git repository browsing has been blocked.&lt;/strong&gt; AIR now applies organization-scope checks when browsing repository trees or listing branches from stored repository connections.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;SSO provider management now requires Global Admin authority.&lt;/strong&gt; Users with settings-save privileges but without Global Admin authority can no longer create or modify SSO providers. This protects the trust boundary around identity provider configuration.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Organization admins can no longer reset Global Admin 2FA.&lt;/strong&gt; AIR now applies the same target-tier protection to reset 2FA that already existed on neighboring user-management actions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Stored XSS paths were closed across several user-controlled fields.&lt;/strong&gt; AIR now validates or escapes case names, endpoint hostnames, Full Text Search profile keywords, and Slack channel names before they can execute in notification panels, profile editors, or routing dialogs.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;OpenAPI documents are no longer anonymously exposed.&lt;/strong&gt; Swagger JSON and YAML documents are now served through authenticated API paths, and legacy public paths redirect to the protected routes.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Cloud account sync and GCP-related notification rendering was improved.&lt;/strong&gt; Cloud Sync Failed messages now display in a user-readable format and no longer expose raw object payloads in the notification UI.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Quick Start image evidence privilege tests and related UI behavior were stabilized.&lt;/strong&gt; The UI now asserts the correct access contract by disabling the parent action rather than relying on hidden nested menu content.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6783624&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmarketing.binalyze.com%2Fair-release-notes%2Fbinalyze-air-5-25&amp;amp;bu=https%253A%252F%252Fmarketing.binalyze.com%252Fair-release-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Binalyze AIR</category>
      <category>Release notes</category>
      <pubDate>Tue, 25 Aug 2026 10:37:48 GMT</pubDate>
      <guid>https://marketing.binalyze.com/air-release-notes/binalyze-air-5-25</guid>
      <dc:date>2026-08-25T10:37:48Z</dc:date>
      <dc:creator>Elif Kurt</dc:creator>
    </item>
    <item>
      <title>Binalyze AIR 5.24</title>
      <link>https://marketing.binalyze.com/air-release-notes/binalyze-air-5-24</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-5-24" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h1 style="color: #33485b; font-size: 40px; font-weight: bold;"&gt;What’s New?&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Multi-channel operational notifications help teams respond faster.&lt;/strong&gt; AIR now supports notification delivery through email, Slack, Microsoft Teams, and Mattermost in addition to in-app notifications. Analysts and administrators can route important task, case, asset, system, and Investigation Hub events to the channels where response teams already work, reducing the chance that critical updates are missed during an active investigation.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Advanced expression-based filtering improves asset targeting.&lt;/strong&gt; Analysts can now build nested asset filters with AND/OR logic, text matching, date and number comparisons, tag conditions, regular expressions, blank/not blank checks, and CSV-imported values. The same filter logic applies across lists, counts, exports, presets, task assignment, and bulk actions, helping investigation teams target exactly the right asset set with more confidence.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Box is now available as an evidence repository destination.&lt;/strong&gt; AIR can save collected evidence to Box repositories using supported Box authentication methods. This gives teams another managed destination for investigation evidence while preserving the existing repository selection experience in acquisition workflows.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;AI application artifact collection is now available.&lt;/strong&gt; Acquisition profiles now include AI application artifact sources across Windows, Linux, and macOS. A new predefined AI Evidence Collection profile helps analysts collect relevant local AI tooling artifacts without building custom profiles from scratch.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder update visibility gives administrators clear update status across the fleet.&lt;/strong&gt; AIR now records and displays Responder update state, update history, retry status, exclusion status, and the reason an asset is waiting, skipped, or failed. This helps administrators understand update posture without relying on temporary logs or repeated manual checks.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset Tag Catalog enables tag governance before assets are assigned.&lt;/strong&gt; Administrators can now create, rename, delete, and manage asset tags independently from asset assignment. Auto Asset Tag rules also create their catalog tags when saved, so defined tags are visible immediately even before a rule matches an asset.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Breaking change for API users.&lt;/strong&gt; Asset-filter bulk API call now includes an assertions guard: an upper bound on how many assets may be affected. Now assertions is required on filter-based bulk endpoints, which was previously optional. Integrations should be updated accordingly, with setting a threshold that matches safety limits. Details can be found on &lt;a href="http://docs.binalyze.com" style="color: #33485b;"&gt;http://docs.binalyze.com&lt;/a&gt;.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1 style="color: #33485b; font-size: 40px; font-weight: bold;"&gt;New Features &amp;amp; Improvements&lt;/h1&gt; 
&lt;h2 style="color: #33485b; font-size: 30px; font-weight: bold;"&gt;Notifications and Automation&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Breaking change for API users&lt;/h3&gt; 
&lt;p&gt;To improve operational safety for API-driven bulk actions, filter-based asset endpoints now require an assertions guard that sets the maximum number of assets a request may affect.&lt;/p&gt; 
&lt;p&gt;API consumers must include { "assertions": { "failIfNumberOfAssetsGreaterThan": NUMBER } } in requests to supported bulk endpoints; if the filter matches more assets than the specified threshold, the request will fail without executing.&lt;/p&gt; 
&lt;p&gt;This protection applies across operations such as acquisition, triage, full-text search, auto asset tagging, baselining, reboot/shutdown/isolation, log retrieval, version updates, and uninstall/purge actions. &lt;strong style="color: #33485b;"&gt;This is a breaking change for API integrations; UI workflows are unaffected.&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Customers and partners should update their integrations, choose thresholds appropriate to their operational safety limits, and validate changes in a non-production environment before rollout. See the &lt;a href="https://kb.binalyze.com/air/features/api/assertions-field-required-for-filter-based-api-endpoints" style="color: #33485b; font-weight: bold;"&gt;KB article&lt;/a&gt; for the full list of affected endpoints and &lt;a href="http://docs.binalyze.com" style="color: #33485b; font-weight: bold;"&gt;http://docs.binalyze.com&lt;/a&gt; for payload details.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Multi-Channel Notification System&lt;/h3&gt; 
&lt;p&gt;AIR now supports a broader notification model across in-app notifications, email, Slack, Microsoft Teams, and Mattermost. This allows cybersecurity teams to receive operational updates in the communication tools they already monitor, including task status changes, case activity, asset events, Investigation Hub activity, and system notifications.&lt;/p&gt; 
&lt;p&gt;Users can manage their personal channel preferences from Account &amp;gt; Notification Settings. Notification types are grouped by category, and users can choose whether each type is delivered in-app, by email, or only when the event is related to them. Email notifications include structured event details and links back to AIR.&lt;/p&gt; 
&lt;p&gt;Administrators can configure Slack, Microsoft Teams, and Mattermost destinations from Settings. Slack supports both workspace-based channels and incoming webhooks, while Teams and Mattermost use webhook-based delivery. Each destination can be enabled, disabled, tested, and routed to selected notification types.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;API Token Expiration Notifications&lt;/h3&gt; 
&lt;p&gt;AIR now notifies API token owners when a token is close to expiration. The notification includes the token name, description, creation date, last-used date, and expiration date without exposing the token value.&lt;/p&gt; 
&lt;p&gt;This helps administrators and API users rotate credentials before integrations fail, reducing service interruption risk for automated workflows and external tooling.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px; font-weight: bold;"&gt;Asset Management and Filtering&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Advanced Expression-Based Filtering for Assets&lt;/h3&gt; 
&lt;p&gt;AIR now supports recursive expression-based filtering for assets, disk images, and case assets. Analysts can combine nested AND/OR groups and field-specific operators to build precise filters across names, types, status fields, dates, tags, metadata, cloud attributes, and other asset properties.&lt;/p&gt; 
&lt;p&gt;The Advanced Filter experience includes live result counts, CSV import of up to 10,000 values, saved preset support, and consistent behavior across asset lists, exports, statistics, task targeting, and bulk actions. This helps analysts move from investigation hypotheses to targeted action without writing scripts or manually translating filters between product areas.&lt;/p&gt; 
&lt;p&gt;Explicit selections and exclusions are represented as filter expressions, so select-all workflows and deselected assets retain a clear target definition.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;CSV-Based Asset Targeting&lt;/h3&gt; 
&lt;p&gt;Expression filtering supports CSV-imported values for asset identifiers and other supported fields. This is useful when investigation teams receive a list of hostnames, asset names, or other indicators from another tool and need to apply AIR actions to that exact subset.&lt;/p&gt; 
&lt;p&gt;Analysts can import the values into Advanced Filter, review the matching count, and then use the resulting filtered set for exports, tagging, evidence collection, Hunt/Triage, or other bulk actions.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Asset Tag Catalog&lt;/h3&gt; 
&lt;p&gt;AIR now includes an Asset Tag Catalog under Library. Administrators can create, rename, delete, search, and manage organization-scoped asset tags without first assigning them to an asset.&lt;/p&gt; 
&lt;p&gt;This supports tag governance and investigation readiness. Teams can predefine tags such as investigation status, containment state, critical server role, or business ownership before responders are deployed or before assets are available in AIR.&lt;/p&gt; 
&lt;p&gt;The Assets sidebar now supports inline tag creation and rename workflows. Asset tag counts can deep-link back into the Assets view, helping analysts quickly focus on assets assigned to a specific tag.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Auto Asset Tag Rule Tag Creation&lt;/h3&gt; 
&lt;p&gt;When an Auto Asset Tag rule is saved, AIR now creates or updates the related tag in the catalog immediately. The tag no longer remains invisible until the first asset matches the rule.&lt;/p&gt; 
&lt;p&gt;This makes rule configuration easier to validate. Administrators can confirm that a newly defined tag exists, use it in filters, and maintain a consistent taxonomy even before the rule has matched any assets.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Responder Auto Update Visibility&lt;/h3&gt; 
&lt;p&gt;AIR now persists Responder update lifecycle information for each asset. The Assets list includes version status, and the asset detail page shows update status, update reason, and update history for automatic, manual, and retry attempts.&lt;/p&gt; 
&lt;p&gt;Administrators can understand why an asset is waiting, scheduled, excluded, failed, retrying, or blocked by maintenance or running work. This reduces uncertainty during fleet updates and gives Support and operations teams a shared view of update state.&lt;/p&gt; 
&lt;p&gt;Responder Update Policies now include clearer default-policy wording, a count of manually excluded assets, and a searchable modal for reviewing those assets. Administrators can select excluded assets and include them back into update policies directly from the modal.&lt;/p&gt; 
&lt;p&gt;The excluded-assets view also shows which update policy would apply after inclusion. This helps administrators understand the effect of re-enabling updates before making the change.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px; font-weight: bold;"&gt;Evidence Collection and Repository Integrations&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Box Evidence Repository&lt;/h3&gt; 
&lt;p&gt;AIR now supports Box as an evidence repository provider. Administrators can create Box repositories from the Evidence Repositories settings area and configure supported authentication methods, destination folder ID, and optional subfolder paths.&lt;/p&gt; 
&lt;p&gt;Box repositories can be selected in supported evidence collection workflows where upload behavior is compatible with Box. AIR validates Box connectivity and encrypts stored Box credentials.&lt;/p&gt; 
&lt;p&gt;Because Box uploads require the total file size up front, AIR clearly disables unsupported streaming scenarios such as direct collection and interACT transfers for Box. The UI includes guidance explaining these limitations so administrators can choose the correct repository type for the collection workflow.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;AI Evidence Collection Profile and Collectors&lt;/h3&gt; 
&lt;p&gt;AIR now exposes AI application artifact sources in acquisition profiles for Windows, Linux, and macOS. These sources are available through the acquisition profile evidence selection experience and can be included in custom profiles.&lt;/p&gt; 
&lt;p&gt;A new predefined AI Evidence Collection profile includes the available AI artifact sources across supported operating systems. This gives analysts a faster path to collect local AI tooling artifacts during investigations where AI application usage may be relevant.&lt;/p&gt; 
&lt;p&gt;The existing Full and Compromise Assessment predefined profiles continue to include the relevant artifact sources.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Improved Disk Image and Evidence Acquisition Workflows&lt;/h3&gt; 
&lt;p&gt;Quick Start acquisition flows received additional safeguards and consistency improvements. Large asset selections now display typed confirmation before assignment in supported Quick Start workflows, reducing the risk of starting broad tasks unintentionally.&lt;/p&gt; 
&lt;p&gt;Quick Start Acquire Evidence, Acquire Image, Image Evidence Acquisition, Full Text Search, Triage, Auto Asset Tagging, Update Responder, and Comparison workflows now use more consistent selection, validation, scheduling, case selection, and repository confirmation behavior. This helps analysts follow the same task setup pattern across collection and analysis workflows.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px; font-weight: bold;"&gt;Investigation Hub and Analysis Workflows&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Investigation Import Reliability&lt;/h3&gt; 
&lt;p&gt;Investigation Hub import handling is now more resilient when imports are retried, restarted, or reprocessed. AIR now cleans up assignment-specific imported data based on database state rather than relying on retry counters, reducing the risk of duplicated evidence rows after interrupted imports.&lt;/p&gt; 
&lt;p&gt;Drone findings import cleanup now covers the drone-owned evidence tables and related metadata written by the import, not only the findings table. Parent import retry behavior was also adjusted so active child imports are not wiped by a retry of the parent job.&lt;/p&gt; 
&lt;p&gt;These changes help preserve investigation data consistency and reduce the chance that repeated imports create inflated row counts or misleading import statuses.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px; font-weight: bold;"&gt;Threat Intelligence and External Integrations&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;TAXII Feed Duplicate Action and Indicator Labels Filter&lt;/h3&gt; 
&lt;p&gt;TAXII Feeds now include a Duplicate action. Administrators can start a new feed configuration from an existing feed, including the values that can be safely prefilled, and then edit the configuration before saving.&lt;/p&gt; 
&lt;p&gt;TAXII indicators now support filtering by labels. This helps analysts focus on indicators associated with selected STIX labels and makes it easier to explore intelligence feeds by category or source context.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Outpost is Accessible in AIR&lt;/h3&gt; 
&lt;p&gt;AIR now includes Outpost feature. When enabled, administrators can access the Outpost entry point and related product information from the AIR interface.&lt;/p&gt; 
&lt;p&gt;This provides a clearer path for customers evaluating or adopting Outpost capabilities alongside AIR investigation and response workflows.&lt;/p&gt; 
&lt;h1 style="color: #33485b; font-size: 40px; font-weight: bold;"&gt;Bug Fixes&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Restricted off-network package downloads to authorized users.&lt;/strong&gt; AIR now requires assignment privilege and package ownership before serving off-network responder packages through private or public download routes. This prevents organization-scoped users from downloading another organization’s package and accessing repository connection details embedded in that package. Signed share links remain unchanged and still require a valid server-issued signature.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Hardened organization isolation across public APIs, WebSockets, scheduled tasks, and configuration paths.&lt;/strong&gt; AIR now applies missing organization ownership checks to task cancellation by filter, public scheduled Hunt/Triage updates, scheduled Auto Asset Tagging updates, public Auto Asset Tag rule deletion, evidence repository validation by ID, Investigation Hub WebSocket connections, and interACT WebSocket connections. These fixes align WebSocket and public API behavior with the guarded REST routes and prevent cross-organization access to live investigation activity, task control, repository validation, and response sessions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Blocked privilege escalation through role and organization assignment.&lt;/strong&gt; AIR now prevents organization-scoped administrators from granting all-organization access unless they already have that scope. Role assignment now verifies that the caller is authorized to grant the privileges contained in the selected role, preventing a low-privilege user manager from assigning a higher-privileged role to themselves or another user.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Strengthened Investigation Hub SQL query protections.&lt;/strong&gt; The v2 SQL query endpoint now applies stricter read-only safeguards, function and cast allowlists, scope anchoring, and safer error handling. This prevents queries from escaping the selected investigation scope, reaching restricted database metadata, or using unsafe object-reference and XML helper paths.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Closed SQL injection paths in asset sorting and Investigation Hub global search.&lt;/strong&gt; AIR now validates sortable fields and evidence table identifiers before building queries. This prevents crafted sort or evidence category values from influencing database query structure while preserving supported sorting and search behavior.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed AI Assistant output rendering.&lt;/strong&gt; Model-generated HTML is now rendered as inert text instead of live DOM content. This prevents script execution from AI-generated responses while preserving markdown and code display behavior for investigation assistance.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Replaced cleartext temporary passwords with reset links.&lt;/strong&gt; Admin-initiated password reset now returns a time-limited reset URL instead of a temporary password. The user’s current credential is invalidated, the reset token is single-use, and the UI shows a copyable reset link with expiry information.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved cookie security attributes.&lt;/strong&gt; AIR now sets secure cookie attributes for applicable UI and analytics cookies when served over HTTPS, while preserving compatibility for HTTP-based installations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Made license capacity enforcement atomic during Responder registration.&lt;/strong&gt; AIR now serializes slot-consuming registration paths so concurrent registration waves cannot exceed the licensed asset capacity. Existing managed asset re-registrations use a fast path and do not consume additional license slots.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Reduced notification query load on large notification tables.&lt;/strong&gt; Notification count behavior was improved so large notification backlogs do not cause repeated heavy database work for the header badge and notification list. This improves Console reliability during high-volume asset registration or operational event bursts.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed SSL restoration after backup restore.&lt;/strong&gt; On-premises deployments now re-run SSL bootstrap on every application boot and retry if startup dependencies are not ready. This allows restored SSL settings to re-materialize the web configuration files and prevents the web container from staying unhealthy after single-tier to two-tier migration restores.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed disk image and cloud asset detail ID confusion.&lt;/strong&gt; Detail views now validate that route parameters are real asset IDs before calling asset-scoped APIs. This prevents misleading “Asset not found” errors and unnecessary 404 responses when navigation paths carry task IDs or other identifiers.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed case task import retry from the Import Status column.&lt;/strong&gt; Case task tabs now retry failed imports against the case investigation rather than an assignment-level or missing investigation ID. The retry action now sends the correct request and no longer shows a forbidden error for authorized users.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Investigation Hub evidence reload banner placement.&lt;/strong&gt; The “New evidence has been added to the investigation” banner now remains at the top of the page and no longer appears in the center of the screen or blocks import controls.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved Investigation Hub import idempotency.&lt;/strong&gt; Re-importing or retrying the same task assignment no longer duplicates imported evidence rows. Drone findings cleanup now includes related drone-owned evidence tables and metadata, and parent retry behavior no longer wipes active child import work.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Restored task execution log ingestion in the refactored Investigation Hub ingestion pipeline.&lt;/strong&gt; Task execution logs are now populated through the refactored ingestion path, so the Task Execution Logs tree appears when the collected data contains task logs.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Responder update actions for manually excluded assets.&lt;/strong&gt; AIR no longer offers manual Responder update actions for assets excluded from updates. Bulk update actions and asset detail update cards now use the same eligibility rules as the backend assignment filter, preventing zero-assignment tasks and misleading success messages.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Restored large-task confirmation for select-all assignment flows.&lt;/strong&gt; Select-all actions that target large asset sets now display the confirmation dialog based on assignable count, even when the assignable count is a small percentage of the full organization asset count.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed RelayPro manual deployment package naming.&lt;/strong&gt; The RelayPro Linux deployment instructions and downloaded package naming now align so the provided installation command works without manual filename edits.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Acquisition Profile dropdown mouse-wheel scrolling.&lt;/strong&gt; The acquisition profile dropdown now supports mouse-wheel scrolling inside slide panels, improving profile selection when many profiles are available.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved Google Cloud Storage validation messages.&lt;/strong&gt; Billing-disabled and permission-related validation failures now return clearer messages instead of misleading users with an “Invalid Project ID” error when the project ID is correct.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Sanitized evidence repository validation errors.&lt;/strong&gt; AIR no longer returns raw backend error details, internal paths, request configuration, or low-level network codes in evidence repository validation responses. Azure and S3-compatible validation failures now return safer user-facing messages while preserving detailed diagnostics in server logs.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed long-expired license UI gating.&lt;/strong&gt; The UI now remains locked when a license is expired even after the remaining-days value becomes negative. This keeps the Console state aligned with backend license decisions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved GCP account and repository behavior.&lt;/strong&gt; Heavy Google Cloud clients now load only when a GCP workflow is actually used, reducing memory usage for tenants without GCP activity. GCP validation errors are also mapped more accurately.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed GCP account creation metadata failure paths.&lt;/strong&gt; GCP account creation and validation flows were updated so plugin metadata retrieval and related SDK usage behave reliably during account setup.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed backup, disk usage, evidence repository, user management, deploy, and off-network UI reliability issues found during integration coverage work.&lt;/strong&gt; These areas received improved route guarding, loading and error handling, state reset behavior, and consistent navigation while keeping existing customer-facing URLs unchanged.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Quick Start Update Responder conflict preflight ordering.&lt;/strong&gt; Immediate Responder update tasks now always run validation, broad-task confirmation, conflict preflight, and assignment in the correct order, preventing conflict checks from being skipped after large-selection confirmation.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Quick Start Image Evidence Acquisition large-selection confirmation.&lt;/strong&gt; The disk image evidence acquisition wizard now shows the large-selection confirmation dialog before broad assignments, matching other Quick Start task flows.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed task import status display and retry state in case task tabs.&lt;/strong&gt; Failed import rows now read the correct import status field and show Retry when appropriate, including assignments that have not yet populated investigation metadata.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed UI messaging and rendering around Box repository limitations.&lt;/strong&gt; Box setup and disabled-state notices now use clearer copy and better multi-line alert layout, helping administrators understand upload-only behavior and folder selection risks.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Auto Asset Tagging and Responder Update Policy UI consistency issues.&lt;/strong&gt; Auto Asset Tag and Responder Update Policy views now better reflect selected assets, excluded assets, policy matches, and available actions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Investigation Report oversized logo validation.&lt;/strong&gt; Oversized company logos are now rejected consistently during validation instead of sometimes falling through to an internal error.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved service and container hardening.&lt;/strong&gt; Runtime container images and bundled services were updated or adjusted to remove outdated operating system components and resolve reported security findings without changing product workflows.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-5-24" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h1 style="color: #33485b; font-size: 40px; font-weight: bold;"&gt;What’s New?&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Multi-channel operational notifications help teams respond faster.&lt;/strong&gt; AIR now supports notification delivery through email, Slack, Microsoft Teams, and Mattermost in addition to in-app notifications. Analysts and administrators can route important task, case, asset, system, and Investigation Hub events to the channels where response teams already work, reducing the chance that critical updates are missed during an active investigation.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Advanced expression-based filtering improves asset targeting.&lt;/strong&gt; Analysts can now build nested asset filters with AND/OR logic, text matching, date and number comparisons, tag conditions, regular expressions, blank/not blank checks, and CSV-imported values. The same filter logic applies across lists, counts, exports, presets, task assignment, and bulk actions, helping investigation teams target exactly the right asset set with more confidence.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Box is now available as an evidence repository destination.&lt;/strong&gt; AIR can save collected evidence to Box repositories using supported Box authentication methods. This gives teams another managed destination for investigation evidence while preserving the existing repository selection experience in acquisition workflows.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;AI application artifact collection is now available.&lt;/strong&gt; Acquisition profiles now include AI application artifact sources across Windows, Linux, and macOS. A new predefined AI Evidence Collection profile helps analysts collect relevant local AI tooling artifacts without building custom profiles from scratch.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder update visibility gives administrators clear update status across the fleet.&lt;/strong&gt; AIR now records and displays Responder update state, update history, retry status, exclusion status, and the reason an asset is waiting, skipped, or failed. This helps administrators understand update posture without relying on temporary logs or repeated manual checks.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset Tag Catalog enables tag governance before assets are assigned.&lt;/strong&gt; Administrators can now create, rename, delete, and manage asset tags independently from asset assignment. Auto Asset Tag rules also create their catalog tags when saved, so defined tags are visible immediately even before a rule matches an asset.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Breaking change for API users.&lt;/strong&gt; Asset-filter bulk API call now includes an assertions guard: an upper bound on how many assets may be affected. Now assertions is required on filter-based bulk endpoints, which was previously optional. Integrations should be updated accordingly, with setting a threshold that matches safety limits. Details can be found on &lt;a href="http://docs.binalyze.com" style="color: #33485b;"&gt;http://docs.binalyze.com&lt;/a&gt;.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1 style="color: #33485b; font-size: 40px; font-weight: bold;"&gt;New Features &amp;amp; Improvements&lt;/h1&gt; 
&lt;h2 style="color: #33485b; font-size: 30px; font-weight: bold;"&gt;Notifications and Automation&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Breaking change for API users&lt;/h3&gt; 
&lt;p&gt;To improve operational safety for API-driven bulk actions, filter-based asset endpoints now require an assertions guard that sets the maximum number of assets a request may affect.&lt;/p&gt; 
&lt;p&gt;API consumers must include { "assertions": { "failIfNumberOfAssetsGreaterThan": NUMBER } } in requests to supported bulk endpoints; if the filter matches more assets than the specified threshold, the request will fail without executing.&lt;/p&gt; 
&lt;p&gt;This protection applies across operations such as acquisition, triage, full-text search, auto asset tagging, baselining, reboot/shutdown/isolation, log retrieval, version updates, and uninstall/purge actions. &lt;strong style="color: #33485b;"&gt;This is a breaking change for API integrations; UI workflows are unaffected.&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Customers and partners should update their integrations, choose thresholds appropriate to their operational safety limits, and validate changes in a non-production environment before rollout. See the &lt;a href="https://kb.binalyze.com/air/features/api/assertions-field-required-for-filter-based-api-endpoints" style="color: #33485b; font-weight: bold;"&gt;KB article&lt;/a&gt; for the full list of affected endpoints and &lt;a href="http://docs.binalyze.com" style="color: #33485b; font-weight: bold;"&gt;http://docs.binalyze.com&lt;/a&gt; for payload details.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Multi-Channel Notification System&lt;/h3&gt; 
&lt;p&gt;AIR now supports a broader notification model across in-app notifications, email, Slack, Microsoft Teams, and Mattermost. This allows cybersecurity teams to receive operational updates in the communication tools they already monitor, including task status changes, case activity, asset events, Investigation Hub activity, and system notifications.&lt;/p&gt; 
&lt;p&gt;Users can manage their personal channel preferences from Account &amp;gt; Notification Settings. Notification types are grouped by category, and users can choose whether each type is delivered in-app, by email, or only when the event is related to them. Email notifications include structured event details and links back to AIR.&lt;/p&gt; 
&lt;p&gt;Administrators can configure Slack, Microsoft Teams, and Mattermost destinations from Settings. Slack supports both workspace-based channels and incoming webhooks, while Teams and Mattermost use webhook-based delivery. Each destination can be enabled, disabled, tested, and routed to selected notification types.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;API Token Expiration Notifications&lt;/h3&gt; 
&lt;p&gt;AIR now notifies API token owners when a token is close to expiration. The notification includes the token name, description, creation date, last-used date, and expiration date without exposing the token value.&lt;/p&gt; 
&lt;p&gt;This helps administrators and API users rotate credentials before integrations fail, reducing service interruption risk for automated workflows and external tooling.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px; font-weight: bold;"&gt;Asset Management and Filtering&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Advanced Expression-Based Filtering for Assets&lt;/h3&gt; 
&lt;p&gt;AIR now supports recursive expression-based filtering for assets, disk images, and case assets. Analysts can combine nested AND/OR groups and field-specific operators to build precise filters across names, types, status fields, dates, tags, metadata, cloud attributes, and other asset properties.&lt;/p&gt; 
&lt;p&gt;The Advanced Filter experience includes live result counts, CSV import of up to 10,000 values, saved preset support, and consistent behavior across asset lists, exports, statistics, task targeting, and bulk actions. This helps analysts move from investigation hypotheses to targeted action without writing scripts or manually translating filters between product areas.&lt;/p&gt; 
&lt;p&gt;Explicit selections and exclusions are represented as filter expressions, so select-all workflows and deselected assets retain a clear target definition.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;CSV-Based Asset Targeting&lt;/h3&gt; 
&lt;p&gt;Expression filtering supports CSV-imported values for asset identifiers and other supported fields. This is useful when investigation teams receive a list of hostnames, asset names, or other indicators from another tool and need to apply AIR actions to that exact subset.&lt;/p&gt; 
&lt;p&gt;Analysts can import the values into Advanced Filter, review the matching count, and then use the resulting filtered set for exports, tagging, evidence collection, Hunt/Triage, or other bulk actions.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Asset Tag Catalog&lt;/h3&gt; 
&lt;p&gt;AIR now includes an Asset Tag Catalog under Library. Administrators can create, rename, delete, search, and manage organization-scoped asset tags without first assigning them to an asset.&lt;/p&gt; 
&lt;p&gt;This supports tag governance and investigation readiness. Teams can predefine tags such as investigation status, containment state, critical server role, or business ownership before responders are deployed or before assets are available in AIR.&lt;/p&gt; 
&lt;p&gt;The Assets sidebar now supports inline tag creation and rename workflows. Asset tag counts can deep-link back into the Assets view, helping analysts quickly focus on assets assigned to a specific tag.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Auto Asset Tag Rule Tag Creation&lt;/h3&gt; 
&lt;p&gt;When an Auto Asset Tag rule is saved, AIR now creates or updates the related tag in the catalog immediately. The tag no longer remains invisible until the first asset matches the rule.&lt;/p&gt; 
&lt;p&gt;This makes rule configuration easier to validate. Administrators can confirm that a newly defined tag exists, use it in filters, and maintain a consistent taxonomy even before the rule has matched any assets.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Responder Auto Update Visibility&lt;/h3&gt; 
&lt;p&gt;AIR now persists Responder update lifecycle information for each asset. The Assets list includes version status, and the asset detail page shows update status, update reason, and update history for automatic, manual, and retry attempts.&lt;/p&gt; 
&lt;p&gt;Administrators can understand why an asset is waiting, scheduled, excluded, failed, retrying, or blocked by maintenance or running work. This reduces uncertainty during fleet updates and gives Support and operations teams a shared view of update state.&lt;/p&gt; 
&lt;p&gt;Responder Update Policies now include clearer default-policy wording, a count of manually excluded assets, and a searchable modal for reviewing those assets. Administrators can select excluded assets and include them back into update policies directly from the modal.&lt;/p&gt; 
&lt;p&gt;The excluded-assets view also shows which update policy would apply after inclusion. This helps administrators understand the effect of re-enabling updates before making the change.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px; font-weight: bold;"&gt;Evidence Collection and Repository Integrations&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Box Evidence Repository&lt;/h3&gt; 
&lt;p&gt;AIR now supports Box as an evidence repository provider. Administrators can create Box repositories from the Evidence Repositories settings area and configure supported authentication methods, destination folder ID, and optional subfolder paths.&lt;/p&gt; 
&lt;p&gt;Box repositories can be selected in supported evidence collection workflows where upload behavior is compatible with Box. AIR validates Box connectivity and encrypts stored Box credentials.&lt;/p&gt; 
&lt;p&gt;Because Box uploads require the total file size up front, AIR clearly disables unsupported streaming scenarios such as direct collection and interACT transfers for Box. The UI includes guidance explaining these limitations so administrators can choose the correct repository type for the collection workflow.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;AI Evidence Collection Profile and Collectors&lt;/h3&gt; 
&lt;p&gt;AIR now exposes AI application artifact sources in acquisition profiles for Windows, Linux, and macOS. These sources are available through the acquisition profile evidence selection experience and can be included in custom profiles.&lt;/p&gt; 
&lt;p&gt;A new predefined AI Evidence Collection profile includes the available AI artifact sources across supported operating systems. This gives analysts a faster path to collect local AI tooling artifacts during investigations where AI application usage may be relevant.&lt;/p&gt; 
&lt;p&gt;The existing Full and Compromise Assessment predefined profiles continue to include the relevant artifact sources.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Improved Disk Image and Evidence Acquisition Workflows&lt;/h3&gt; 
&lt;p&gt;Quick Start acquisition flows received additional safeguards and consistency improvements. Large asset selections now display typed confirmation before assignment in supported Quick Start workflows, reducing the risk of starting broad tasks unintentionally.&lt;/p&gt; 
&lt;p&gt;Quick Start Acquire Evidence, Acquire Image, Image Evidence Acquisition, Full Text Search, Triage, Auto Asset Tagging, Update Responder, and Comparison workflows now use more consistent selection, validation, scheduling, case selection, and repository confirmation behavior. This helps analysts follow the same task setup pattern across collection and analysis workflows.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px; font-weight: bold;"&gt;Investigation Hub and Analysis Workflows&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Investigation Import Reliability&lt;/h3&gt; 
&lt;p&gt;Investigation Hub import handling is now more resilient when imports are retried, restarted, or reprocessed. AIR now cleans up assignment-specific imported data based on database state rather than relying on retry counters, reducing the risk of duplicated evidence rows after interrupted imports.&lt;/p&gt; 
&lt;p&gt;Drone findings import cleanup now covers the drone-owned evidence tables and related metadata written by the import, not only the findings table. Parent import retry behavior was also adjusted so active child imports are not wiped by a retry of the parent job.&lt;/p&gt; 
&lt;p&gt;These changes help preserve investigation data consistency and reduce the chance that repeated imports create inflated row counts or misleading import statuses.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px; font-weight: bold;"&gt;Threat Intelligence and External Integrations&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;TAXII Feed Duplicate Action and Indicator Labels Filter&lt;/h3&gt; 
&lt;p&gt;TAXII Feeds now include a Duplicate action. Administrators can start a new feed configuration from an existing feed, including the values that can be safely prefilled, and then edit the configuration before saving.&lt;/p&gt; 
&lt;p&gt;TAXII indicators now support filtering by labels. This helps analysts focus on indicators associated with selected STIX labels and makes it easier to explore intelligence feeds by category or source context.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px; font-weight: bold;"&gt;Outpost is Accessible in AIR&lt;/h3&gt; 
&lt;p&gt;AIR now includes Outpost feature. When enabled, administrators can access the Outpost entry point and related product information from the AIR interface.&lt;/p&gt; 
&lt;p&gt;This provides a clearer path for customers evaluating or adopting Outpost capabilities alongside AIR investigation and response workflows.&lt;/p&gt; 
&lt;h1 style="color: #33485b; font-size: 40px; font-weight: bold;"&gt;Bug Fixes&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Restricted off-network package downloads to authorized users.&lt;/strong&gt; AIR now requires assignment privilege and package ownership before serving off-network responder packages through private or public download routes. This prevents organization-scoped users from downloading another organization’s package and accessing repository connection details embedded in that package. Signed share links remain unchanged and still require a valid server-issued signature.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Hardened organization isolation across public APIs, WebSockets, scheduled tasks, and configuration paths.&lt;/strong&gt; AIR now applies missing organization ownership checks to task cancellation by filter, public scheduled Hunt/Triage updates, scheduled Auto Asset Tagging updates, public Auto Asset Tag rule deletion, evidence repository validation by ID, Investigation Hub WebSocket connections, and interACT WebSocket connections. These fixes align WebSocket and public API behavior with the guarded REST routes and prevent cross-organization access to live investigation activity, task control, repository validation, and response sessions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Blocked privilege escalation through role and organization assignment.&lt;/strong&gt; AIR now prevents organization-scoped administrators from granting all-organization access unless they already have that scope. Role assignment now verifies that the caller is authorized to grant the privileges contained in the selected role, preventing a low-privilege user manager from assigning a higher-privileged role to themselves or another user.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Strengthened Investigation Hub SQL query protections.&lt;/strong&gt; The v2 SQL query endpoint now applies stricter read-only safeguards, function and cast allowlists, scope anchoring, and safer error handling. This prevents queries from escaping the selected investigation scope, reaching restricted database metadata, or using unsafe object-reference and XML helper paths.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Closed SQL injection paths in asset sorting and Investigation Hub global search.&lt;/strong&gt; AIR now validates sortable fields and evidence table identifiers before building queries. This prevents crafted sort or evidence category values from influencing database query structure while preserving supported sorting and search behavior.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed AI Assistant output rendering.&lt;/strong&gt; Model-generated HTML is now rendered as inert text instead of live DOM content. This prevents script execution from AI-generated responses while preserving markdown and code display behavior for investigation assistance.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Replaced cleartext temporary passwords with reset links.&lt;/strong&gt; Admin-initiated password reset now returns a time-limited reset URL instead of a temporary password. The user’s current credential is invalidated, the reset token is single-use, and the UI shows a copyable reset link with expiry information.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved cookie security attributes.&lt;/strong&gt; AIR now sets secure cookie attributes for applicable UI and analytics cookies when served over HTTPS, while preserving compatibility for HTTP-based installations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Made license capacity enforcement atomic during Responder registration.&lt;/strong&gt; AIR now serializes slot-consuming registration paths so concurrent registration waves cannot exceed the licensed asset capacity. Existing managed asset re-registrations use a fast path and do not consume additional license slots.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Reduced notification query load on large notification tables.&lt;/strong&gt; Notification count behavior was improved so large notification backlogs do not cause repeated heavy database work for the header badge and notification list. This improves Console reliability during high-volume asset registration or operational event bursts.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed SSL restoration after backup restore.&lt;/strong&gt; On-premises deployments now re-run SSL bootstrap on every application boot and retry if startup dependencies are not ready. This allows restored SSL settings to re-materialize the web configuration files and prevents the web container from staying unhealthy after single-tier to two-tier migration restores.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed disk image and cloud asset detail ID confusion.&lt;/strong&gt; Detail views now validate that route parameters are real asset IDs before calling asset-scoped APIs. This prevents misleading “Asset not found” errors and unnecessary 404 responses when navigation paths carry task IDs or other identifiers.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed case task import retry from the Import Status column.&lt;/strong&gt; Case task tabs now retry failed imports against the case investigation rather than an assignment-level or missing investigation ID. The retry action now sends the correct request and no longer shows a forbidden error for authorized users.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Investigation Hub evidence reload banner placement.&lt;/strong&gt; The “New evidence has been added to the investigation” banner now remains at the top of the page and no longer appears in the center of the screen or blocks import controls.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved Investigation Hub import idempotency.&lt;/strong&gt; Re-importing or retrying the same task assignment no longer duplicates imported evidence rows. Drone findings cleanup now includes related drone-owned evidence tables and metadata, and parent retry behavior no longer wipes active child import work.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Restored task execution log ingestion in the refactored Investigation Hub ingestion pipeline.&lt;/strong&gt; Task execution logs are now populated through the refactored ingestion path, so the Task Execution Logs tree appears when the collected data contains task logs.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Responder update actions for manually excluded assets.&lt;/strong&gt; AIR no longer offers manual Responder update actions for assets excluded from updates. Bulk update actions and asset detail update cards now use the same eligibility rules as the backend assignment filter, preventing zero-assignment tasks and misleading success messages.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Restored large-task confirmation for select-all assignment flows.&lt;/strong&gt; Select-all actions that target large asset sets now display the confirmation dialog based on assignable count, even when the assignable count is a small percentage of the full organization asset count.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed RelayPro manual deployment package naming.&lt;/strong&gt; The RelayPro Linux deployment instructions and downloaded package naming now align so the provided installation command works without manual filename edits.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Acquisition Profile dropdown mouse-wheel scrolling.&lt;/strong&gt; The acquisition profile dropdown now supports mouse-wheel scrolling inside slide panels, improving profile selection when many profiles are available.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved Google Cloud Storage validation messages.&lt;/strong&gt; Billing-disabled and permission-related validation failures now return clearer messages instead of misleading users with an “Invalid Project ID” error when the project ID is correct.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Sanitized evidence repository validation errors.&lt;/strong&gt; AIR no longer returns raw backend error details, internal paths, request configuration, or low-level network codes in evidence repository validation responses. Azure and S3-compatible validation failures now return safer user-facing messages while preserving detailed diagnostics in server logs.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed long-expired license UI gating.&lt;/strong&gt; The UI now remains locked when a license is expired even after the remaining-days value becomes negative. This keeps the Console state aligned with backend license decisions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved GCP account and repository behavior.&lt;/strong&gt; Heavy Google Cloud clients now load only when a GCP workflow is actually used, reducing memory usage for tenants without GCP activity. GCP validation errors are also mapped more accurately.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed GCP account creation metadata failure paths.&lt;/strong&gt; GCP account creation and validation flows were updated so plugin metadata retrieval and related SDK usage behave reliably during account setup.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed backup, disk usage, evidence repository, user management, deploy, and off-network UI reliability issues found during integration coverage work.&lt;/strong&gt; These areas received improved route guarding, loading and error handling, state reset behavior, and consistent navigation while keeping existing customer-facing URLs unchanged.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Quick Start Update Responder conflict preflight ordering.&lt;/strong&gt; Immediate Responder update tasks now always run validation, broad-task confirmation, conflict preflight, and assignment in the correct order, preventing conflict checks from being skipped after large-selection confirmation.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Quick Start Image Evidence Acquisition large-selection confirmation.&lt;/strong&gt; The disk image evidence acquisition wizard now shows the large-selection confirmation dialog before broad assignments, matching other Quick Start task flows.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed task import status display and retry state in case task tabs.&lt;/strong&gt; Failed import rows now read the correct import status field and show Retry when appropriate, including assignments that have not yet populated investigation metadata.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed UI messaging and rendering around Box repository limitations.&lt;/strong&gt; Box setup and disabled-state notices now use clearer copy and better multi-line alert layout, helping administrators understand upload-only behavior and folder selection risks.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Auto Asset Tagging and Responder Update Policy UI consistency issues.&lt;/strong&gt; Auto Asset Tag and Responder Update Policy views now better reflect selected assets, excluded assets, policy matches, and available actions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fixed Investigation Report oversized logo validation.&lt;/strong&gt; Oversized company logos are now rejected consistently during validation instead of sometimes falling through to an internal error.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved service and container hardening.&lt;/strong&gt; Runtime container images and bundled services were updated or adjusted to remove outdated operating system components and resolve reported security findings without changing product workflows.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6783624&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmarketing.binalyze.com%2Fair-release-notes%2Fbinalyze-air-5-24&amp;amp;bu=https%253A%252F%252Fmarketing.binalyze.com%252Fair-release-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Binalyze AIR</category>
      <category>Release notes</category>
      <pubDate>Tue, 11 Aug 2026 12:02:14 GMT</pubDate>
      <guid>https://marketing.binalyze.com/air-release-notes/binalyze-air-5-24</guid>
      <dc:date>2026-08-11T12:02:14Z</dc:date>
      <dc:creator>Elif Kurt</dc:creator>
    </item>
    <item>
      <title>Binalyze AIR 5.23</title>
      <link>https://marketing.binalyze.com/air-release-notes/binalyze-air-5-23</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-5-23" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;What’s New?&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Cyber Threat Intelligence (STIX/TAXII Feed) Integration for operationalized threat intelligence:&lt;/strong&gt; AIR can now connect to TAXII 2.x threat intelligence sources, pull STIX indicators, parse supported indicator types, and convert them into YARA, Sigma, and osquery Hunt/Triage rules. This helps analysts bring external threat intelligence directly into investigations without manually exporting, converting, and uploading indicators.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder update policies:&lt;/strong&gt; Administrators can manage automatic Responder updates through policy groups and filters, including policy scheduling, asset match counts, and per-asset update status visibility. This helps teams keep Responders current while controlling update rollout for sensitive or operationally constrained assets.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Disk I/O Priority for tasks and policies:&lt;/strong&gt; AIR now supports a Disk I/O Priority resource limit for policy and task configurations. Analysts can tune collection and response activity to reduce performance impact on critical assets during active investigations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Safer Active Directory disable flow:&lt;/strong&gt; Disabling Active Directory integration now includes clearer impact information and an explicit keep-or-remove decision for AD-synced assets. This reduces the risk of unintended Responder uninstall activity and gives administrators better control during directory integration changes.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Expanded Windows SMB event coverage in acquisition profiles:&lt;/strong&gt; Full, Quick, and Compromise Assessment profiles now include additional SMB-related Windows event records. This gives investigation teams stronger visibility into file-sharing, authentication, and SMB-related activity during evidence collection.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;strong&gt;&lt;strong&gt;&lt;span style="color: #33485b;"&gt;PostgreSQL 18 support for on-prem deployments:&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/strong&gt;&lt;/strong&gt;AIR now supports PostgreSQL 18 for on-prem environments with version 5.23. After upgrading AIR, administrators can schedule the PostgreSQL upgrade separately during a planned maintenance window, helping ensure continued compatibility, performance, scalability, and support for future AIR releases.&lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;span style="color: #33485b;"&gt;&lt;strong&gt;Dual Go runtime support for Windows Responders:&lt;/strong&gt; &lt;/span&gt;AIR now automatically delivers a Go 1.26-based Responder to Windows 10 and later devices, while earlier Windows versions continue to receive the Go 1.20 build. Both variants provide the same functionality, improving security scanner compliance without affecting legacy OS support or requiring configuration changes.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;New Features &amp;amp; Improvements&lt;/h1&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Threat Intelligence and Hunt/Triage&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Cyber Threat Intelligence (STIX/TAXII Feed) Integration&lt;/h3&gt; 
&lt;p&gt;AIR now supports TAXII Feed Integration for connecting to TAXII 2.x compliant threat intelligence servers. Teams can configure a feed with a server URL, authentication method, collections, sync interval, and conversion preferences. AIR then pulls STIX indicators and converts supported indicators into investigation-ready Hunt/Triage content.&lt;/p&gt; 
&lt;p&gt;The feature supports public and authenticated feeds, collection discovery, manual and scheduled sync, sync logs, indicator browsing, confidence thresholds, and managed or snapshot ownership modes. Managed feeds regenerate system-owned rules as indicators change, while snapshot feeds allow analysts to capture a point-in-time set of indicators without modifying or deleting previously generated rules.&lt;/p&gt; 
&lt;p&gt;For analysts, this reduces the time between receiving intelligence and using it in an investigation. File hashes, domains, URLs, registry keys, mutexes, process names, direct YARA, and direct Sigma indicators can be transformed into YARA, Sigma, and osquery rules according to the selected conversion configuration.&lt;/p&gt; 
&lt;p&gt;To use the feature, open the Integrations area, create a TAXII feed, test the connection, select collections, choose the rule generation settings, and save the feed. After sync, generated Hunt/Triage rules become available for investigation workflows according to the configured ownership mode and rule settings.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Expanded SMB Event Log Coverage&lt;/h3&gt; 
&lt;p&gt;Windows acquisition profiles now include expanded SMB event coverage. Full, Quick, and Compromise Assessment profiles have been updated with SMB client, SMB server, and Security channel event selections that preserve higher-value SMB investigation signals while limiting noise in faster profiles.&lt;/p&gt; 
&lt;p&gt;This improvement helps analysts review file-sharing, share modification, authentication, and SMB security activity during post-incident investigations. It is especially useful when investigating lateral movement, remote access to shared resources, and suspicious file access patterns.&lt;/p&gt; 
&lt;p&gt;The Full profile includes the broadest researched event coverage, Quick includes a security-focused subset, and Compromise Assessment includes the strongest low-noise indicators. Existing event selections remain unchanged.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Investigation Hub and Case Workflows&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Case Task Import Status Visibility&lt;/h3&gt; 
&lt;p&gt;Case task listings now reflect Investigation Hub import status more accurately. When task data is imported into Investigation Hub, AIR mirrors the status into the task assignment metadata used by case task grids.&lt;/p&gt; 
&lt;p&gt;This gives analysts clearer visibility into whether task results have been imported and are available for review in Investigation Hub, reducing confusion when evidence appears in Investigation Hub but the case task list previously showed the import status as not applicable.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Assets, Responders, and Task Execution&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Responder Update Policies&lt;/h3&gt; 
&lt;p&gt;AIR now provides grouped Responder update policies in Settings. Administrators can configure automatic update behavior through policy cards, filters, schedules, matching asset counts, and a unified save workflow.&lt;/p&gt; 
&lt;p&gt;The asset detail view now shows resolved Responder update status, helping operators understand whether an asset receives automatic updates, which policy applies, and what action may be needed. This improves update governance across large environments where different asset groups require different rollout behavior.&lt;/p&gt; 
&lt;p&gt;A typical use case is to define a policy for a tagged or filtered group of production servers, apply a specific update window, and review matched assets before saving. New assets that match the policy criteria can then inherit the intended update behavior without a manual bulk operation.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Disk I/O Priority for Task Resource Control&lt;/h3&gt; 
&lt;p&gt;Task and policy configuration now includes Disk I/O Priority. The priority can be set from Lowest to Highest, with Medium as the default. AIR passes the selected priority to the Responder for supported task types.&lt;/p&gt; 
&lt;p&gt;This gives analysts and administrators more control over the runtime impact of investigation tasks. During active response, teams can lower priority for business-critical systems or increase priority when rapid evidence collection is more important than background resource usage.&lt;/p&gt; 
&lt;p&gt;The setting is available in task advanced options, policy resource limits, and interACT shell task options. Existing configurations that do not include the field continue to rely on Responder defaults.&lt;/p&gt; 
&lt;h3 style="font-size: 26px;"&gt;&lt;span style="color: #33485b;"&gt;Dual Go Runtime Support for Windows Responders&lt;/span&gt;&lt;/h3&gt; 
&lt;p&gt;To improve security scanner compliance while maintaining compatibility with older Windows operating systems, AIR now delivers Windows Responders with the appropriate Go runtime based on the target OS version.&lt;br&gt;&lt;br&gt;Starting with Responder 3.0.0, Windows 10 and later devices receive a Responder built with Go 1.26, while earlier Windows versions continue to receive a Go 1.20 build. Both variants provide the same Responder package, functionality, and feature set—the only difference is the embedded Go runtime.&lt;br&gt;&lt;br&gt;This enhancement addresses vulnerability scanner findings related to older Go runtime versions (such as VOC-2709) without requiring customers to choose between modern security compliance and legacy operating system support.&lt;br&gt;&lt;br&gt;Responder selection is performed automatically by AIR:&lt;br&gt;&lt;br&gt;Windows 10 and later: Latest Responder (Go 1.26)&lt;br&gt;Earlier than Windows 10: Legacy Responder (Go 1.20)&lt;br&gt;&lt;br&gt;No additional configuration or deployment changes are required. Both Latest and Legacy Responders continue to be fully supported.&lt;br&gt;&lt;br&gt;As part of this change, the Windows MSI installer size increases from approximately 58 MB to 106 MB due to the inclusion of the newer Go runtime. Linux and macOS support for dual runtime delivery will be introduced in a future release.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Administration and Platform Operations&lt;/h2&gt; 
&lt;h3&gt;&lt;span style="font-size: 26px; color: #33485b;"&gt;PostgreSQL 18 Support is Now Available for On-prem Deployments&lt;/span&gt;&lt;/h3&gt; 
&lt;p style="line-height: 1.5;"&gt;After upgrading AIR to v5.23, administrators can upgrade PostgreSQL separately at a time that fits their maintenance schedule by following the PostgreSQL Upgrade Guide. The database upgrade is not performed automatically and requires planned downtime, during which AIR will be temporarily unavailable.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;PostgreSQL 18 will become AIR’s supported database configuration at the end of August, so on-prem customers are strongly encouraged to plan their upgrade accordingly.&lt;br&gt;&lt;br&gt;&lt;span&gt;&lt;strong&gt;Before you begin, we recommend that you:&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;span&gt;Wait at least 24 hours after upgrading AIR.&lt;/span&gt;&lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;span&gt;Close inactive cases.&lt;/span&gt;&lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;span&gt;Create an AIR Backup.&lt;/span&gt;&lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;a href="https://kb.binalyze.com/air/self-hosted/updating/postgresql-15-to-18-upgrade-guide"&gt;&lt;span&gt;Review the PostgreSQL Upgrade Guide.&lt;/span&gt;&lt;/a&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Safer Active Directory Disable Flow&lt;/h3&gt; 
&lt;p&gt;Disabling Active Directory integration now provides a safer and more explicit flow. AIR shows an impact summary, including total affected assets and how many have Responders installed, before the operator chooses whether to keep or remove AD-synced assets.&lt;/p&gt; 
&lt;p&gt;This reduces the operational risk of disabling directory synchronization. Administrators can stop synchronization without unintentionally removing managed assets or uninstalling Responders, and can make a deliberate choice when cleanup is required.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Setup Wizard Proxy and Trusted CA Validation&lt;/h3&gt; 
&lt;p&gt;The setup wizard now supports proxy validation before installation. Proxy and trusted CA checks use the same connectivity validation approach as the post-install Settings experience, helping administrators verify outbound connectivity earlier in the deployment process.&lt;/p&gt; 
&lt;p&gt;This improvement helps reduce setup friction in restricted environments. Administrators can validate proxy settings during installation and correct connectivity issues before completing the AIR deployment.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Backup History Encryption Column&lt;/h3&gt; 
&lt;p&gt;The Backup History table now includes an Encryption column. The column shows whether each backup was encrypted, using the existing backup data already displayed in Backup Details.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Security, Governance, and Authorization Improvements&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Git Repository Organization Scope Enforcement&lt;/h3&gt; 
&lt;p&gt;Git Repository API endpoints now enforce organization scope more consistently. Users and API tokens with Git Repository privileges can only access repositories associated with organizations they are authorized to use.&lt;/p&gt; 
&lt;p&gt;This strengthens governance for customers using Git repositories to import or synchronize investigation content. Filtering, retrieving, creating, updating, deleting, syncing, and viewing logs now apply stricter organization relevance checks.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Privilege Dependency Validation&lt;/h3&gt; 
&lt;p&gt;AIR now validates privilege dependency definitions more strictly. Every catalog privilege must have an explicit dependency entry, even when it has no dependencies.&lt;/p&gt; 
&lt;p&gt;This helps administrators configure roles more consistently. When a privilege requires a related view or supporting privilege, role configuration can auto-select or validate the required dependency instead of leaving users with incomplete access that causes screens or actions to fail.&lt;/p&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;Bug Fixes&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Expired task assignments now finalize parent task status.&lt;/strong&gt; When assignments expired after remaining in Assigned or Processing for an extended period, parent tasks could stay stuck in Assigned or Processing even though no active assignments remained. AIR now treats expired assignments as settled for task completion accounting, recalculates the parent task, and includes a self-heal sweep for historical stuck tasks. This helps administrators and SOC teams identify whether investigation work is actually active.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Retry Upload now preserves custom evidence repository folder naming.&lt;/strong&gt; Retried uploads no longer land at the root of the evidence repository when custom evidence collection naming is configured. AIR now uses the original acquisition context so retried evidence follows the expected folder hierarchy.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Evidence repository validation delay reduced in acquisition workflows.&lt;/strong&gt; Selecting an unreachable repository in the acquisition customization step now times out faster and shows the existing inaccessible-repository warning instead of pausing for about 10 seconds or advancing without feedback.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Global Search and Grid Search consistency improved.&lt;/strong&gt; Grid search behavior has been corrected so users are less likely to miss records that are returned by Global Search for the same keyword.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Case task import status now reflects imported Investigation Hub data.&lt;/strong&gt; Case task pages no longer show imported task data as not applicable when the data is available in Investigation Hub.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset resource usage no longer shows misleading zero-based values while metrics are pending.&lt;/strong&gt; Newly registered assets now show a pending usage state until CPU, memory, and disk metrics arrive, instead of displaying values such as 100% CPU free or 0 B memory free.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Production UI blank page after build upgrade fixed.&lt;/strong&gt; A loading issue that could cause the AIR Console UI to display a blank page in production and staging builds has been resolved.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;All export functions now work behind proxied environments.&lt;/strong&gt; Export preflight handling now uses a standard success response instead of a non-standard status code that could be rewritten by edge infrastructure. The UI now starts downloads on standard successful preflight responses and shows an error when export preflight fails.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;GCP account creation and verification now work with proxy and trusted CA configurations.&lt;/strong&gt; AIR corrected the GCP client transport behavior that could fail with plugin metadata or response parsing errors during account creation.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Azure remote command errors now show the real service message.&lt;/strong&gt; Azure VM command failures no longer surface JSON parsing errors when the cloud service returns a plain-text error. Operators now see the actionable Azure error message, such as when a VM must be running before a command can execute.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Full Text Search task flow now validates mandatory case selection consistently.&lt;/strong&gt; AIR now shows the required case warning when progressing through the Full Text Search task flow without selecting a case, matching the Start action behavior.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder update default schedule drawer now respects disabled time frames.&lt;/strong&gt; The Default policy schedule drawer no longer shows “Set Time Frame” enabled when the backend explicitly has the time frame disabled.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Forward proxy handling for internal processor traffic corrected.&lt;/strong&gt; When a forward proxy is enabled, trusted Console-to-processor traffic for internal infrastructure now bypasses the proxy for private network targets. This prevents processors from appearing offline and disk image actions from being disabled when the proxy cannot resolve internal processor hostnames.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Push-type task assignments now fail correctly when processor delivery fails.&lt;/strong&gt; Disk image and DRONE-related assignments no longer remain in Assigned indefinitely after all processor assignment retries fail. AIR now marks affected assignments as Failed and rolls up the parent task status.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Processor-side cleanup during asset deletion now reaches trusted internal processors.&lt;/strong&gt; Asset deletion cleanup calls now use the trusted private-network path, preventing orphaned processor-side files when internal processor hosts were blocked by outbound safeguards.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;PST evidence import no longer blocks the main application event loop.&lt;/strong&gt; PST import now runs asynchronously with streaming and bounded processing. This prevents long event-loop stalls, Redis connection storms, and health check failures in shared SaaS environments while still surfacing import failures to the UI.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Worker processes now initialize white-labeling configuration.&lt;/strong&gt; Task delivery failures caused by missing white-labeling configuration in worker processes have been resolved.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset and case association lists now handle empty scopes correctly.&lt;/strong&gt; Asset or Responder case tabs no longer show all organization cases when the asset has no related case assignments. AIR now returns an empty list when the related case scope is explicitly empty.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;interACT command-result downloads now require read permission.&lt;/strong&gt; AIR now enforces the appropriate interACT read privilege before users can download persisted command output files. Enumerate-only users can no longer reach command-output resolution paths.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Git Repository organization access tightened.&lt;/strong&gt; Git Repository operations now reject access to repositories or organization scopes outside the caller’s assigned organizations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Gaps in case, task, and assignment counts were reduced for large environments.&lt;/strong&gt; Task visibility queries and count retrieval were optimized to reduce expensive repeated list and count calls, especially for scheduled task views in large tenants.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-5-23" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;What’s New?&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Cyber Threat Intelligence (STIX/TAXII Feed) Integration for operationalized threat intelligence:&lt;/strong&gt; AIR can now connect to TAXII 2.x threat intelligence sources, pull STIX indicators, parse supported indicator types, and convert them into YARA, Sigma, and osquery Hunt/Triage rules. This helps analysts bring external threat intelligence directly into investigations without manually exporting, converting, and uploading indicators.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder update policies:&lt;/strong&gt; Administrators can manage automatic Responder updates through policy groups and filters, including policy scheduling, asset match counts, and per-asset update status visibility. This helps teams keep Responders current while controlling update rollout for sensitive or operationally constrained assets.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Disk I/O Priority for tasks and policies:&lt;/strong&gt; AIR now supports a Disk I/O Priority resource limit for policy and task configurations. Analysts can tune collection and response activity to reduce performance impact on critical assets during active investigations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Safer Active Directory disable flow:&lt;/strong&gt; Disabling Active Directory integration now includes clearer impact information and an explicit keep-or-remove decision for AD-synced assets. This reduces the risk of unintended Responder uninstall activity and gives administrators better control during directory integration changes.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Expanded Windows SMB event coverage in acquisition profiles:&lt;/strong&gt; Full, Quick, and Compromise Assessment profiles now include additional SMB-related Windows event records. This gives investigation teams stronger visibility into file-sharing, authentication, and SMB-related activity during evidence collection.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;strong&gt;&lt;strong&gt;&lt;span style="color: #33485b;"&gt;PostgreSQL 18 support for on-prem deployments:&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/strong&gt;&lt;/strong&gt;AIR now supports PostgreSQL 18 for on-prem environments with version 5.23. After upgrading AIR, administrators can schedule the PostgreSQL upgrade separately during a planned maintenance window, helping ensure continued compatibility, performance, scalability, and support for future AIR releases.&lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;span style="color: #33485b;"&gt;&lt;strong&gt;Dual Go runtime support for Windows Responders:&lt;/strong&gt; &lt;/span&gt;AIR now automatically delivers a Go 1.26-based Responder to Windows 10 and later devices, while earlier Windows versions continue to receive the Go 1.20 build. Both variants provide the same functionality, improving security scanner compliance without affecting legacy OS support or requiring configuration changes.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;New Features &amp;amp; Improvements&lt;/h1&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Threat Intelligence and Hunt/Triage&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Cyber Threat Intelligence (STIX/TAXII Feed) Integration&lt;/h3&gt; 
&lt;p&gt;AIR now supports TAXII Feed Integration for connecting to TAXII 2.x compliant threat intelligence servers. Teams can configure a feed with a server URL, authentication method, collections, sync interval, and conversion preferences. AIR then pulls STIX indicators and converts supported indicators into investigation-ready Hunt/Triage content.&lt;/p&gt; 
&lt;p&gt;The feature supports public and authenticated feeds, collection discovery, manual and scheduled sync, sync logs, indicator browsing, confidence thresholds, and managed or snapshot ownership modes. Managed feeds regenerate system-owned rules as indicators change, while snapshot feeds allow analysts to capture a point-in-time set of indicators without modifying or deleting previously generated rules.&lt;/p&gt; 
&lt;p&gt;For analysts, this reduces the time between receiving intelligence and using it in an investigation. File hashes, domains, URLs, registry keys, mutexes, process names, direct YARA, and direct Sigma indicators can be transformed into YARA, Sigma, and osquery rules according to the selected conversion configuration.&lt;/p&gt; 
&lt;p&gt;To use the feature, open the Integrations area, create a TAXII feed, test the connection, select collections, choose the rule generation settings, and save the feed. After sync, generated Hunt/Triage rules become available for investigation workflows according to the configured ownership mode and rule settings.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Expanded SMB Event Log Coverage&lt;/h3&gt; 
&lt;p&gt;Windows acquisition profiles now include expanded SMB event coverage. Full, Quick, and Compromise Assessment profiles have been updated with SMB client, SMB server, and Security channel event selections that preserve higher-value SMB investigation signals while limiting noise in faster profiles.&lt;/p&gt; 
&lt;p&gt;This improvement helps analysts review file-sharing, share modification, authentication, and SMB security activity during post-incident investigations. It is especially useful when investigating lateral movement, remote access to shared resources, and suspicious file access patterns.&lt;/p&gt; 
&lt;p&gt;The Full profile includes the broadest researched event coverage, Quick includes a security-focused subset, and Compromise Assessment includes the strongest low-noise indicators. Existing event selections remain unchanged.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Investigation Hub and Case Workflows&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Case Task Import Status Visibility&lt;/h3&gt; 
&lt;p&gt;Case task listings now reflect Investigation Hub import status more accurately. When task data is imported into Investigation Hub, AIR mirrors the status into the task assignment metadata used by case task grids.&lt;/p&gt; 
&lt;p&gt;This gives analysts clearer visibility into whether task results have been imported and are available for review in Investigation Hub, reducing confusion when evidence appears in Investigation Hub but the case task list previously showed the import status as not applicable.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Assets, Responders, and Task Execution&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Responder Update Policies&lt;/h3&gt; 
&lt;p&gt;AIR now provides grouped Responder update policies in Settings. Administrators can configure automatic update behavior through policy cards, filters, schedules, matching asset counts, and a unified save workflow.&lt;/p&gt; 
&lt;p&gt;The asset detail view now shows resolved Responder update status, helping operators understand whether an asset receives automatic updates, which policy applies, and what action may be needed. This improves update governance across large environments where different asset groups require different rollout behavior.&lt;/p&gt; 
&lt;p&gt;A typical use case is to define a policy for a tagged or filtered group of production servers, apply a specific update window, and review matched assets before saving. New assets that match the policy criteria can then inherit the intended update behavior without a manual bulk operation.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Disk I/O Priority for Task Resource Control&lt;/h3&gt; 
&lt;p&gt;Task and policy configuration now includes Disk I/O Priority. The priority can be set from Lowest to Highest, with Medium as the default. AIR passes the selected priority to the Responder for supported task types.&lt;/p&gt; 
&lt;p&gt;This gives analysts and administrators more control over the runtime impact of investigation tasks. During active response, teams can lower priority for business-critical systems or increase priority when rapid evidence collection is more important than background resource usage.&lt;/p&gt; 
&lt;p&gt;The setting is available in task advanced options, policy resource limits, and interACT shell task options. Existing configurations that do not include the field continue to rely on Responder defaults.&lt;/p&gt; 
&lt;h3 style="font-size: 26px;"&gt;&lt;span style="color: #33485b;"&gt;Dual Go Runtime Support for Windows Responders&lt;/span&gt;&lt;/h3&gt; 
&lt;p&gt;To improve security scanner compliance while maintaining compatibility with older Windows operating systems, AIR now delivers Windows Responders with the appropriate Go runtime based on the target OS version.&lt;br&gt;&lt;br&gt;Starting with Responder 3.0.0, Windows 10 and later devices receive a Responder built with Go 1.26, while earlier Windows versions continue to receive a Go 1.20 build. Both variants provide the same Responder package, functionality, and feature set—the only difference is the embedded Go runtime.&lt;br&gt;&lt;br&gt;This enhancement addresses vulnerability scanner findings related to older Go runtime versions (such as VOC-2709) without requiring customers to choose between modern security compliance and legacy operating system support.&lt;br&gt;&lt;br&gt;Responder selection is performed automatically by AIR:&lt;br&gt;&lt;br&gt;Windows 10 and later: Latest Responder (Go 1.26)&lt;br&gt;Earlier than Windows 10: Legacy Responder (Go 1.20)&lt;br&gt;&lt;br&gt;No additional configuration or deployment changes are required. Both Latest and Legacy Responders continue to be fully supported.&lt;br&gt;&lt;br&gt;As part of this change, the Windows MSI installer size increases from approximately 58 MB to 106 MB due to the inclusion of the newer Go runtime. Linux and macOS support for dual runtime delivery will be introduced in a future release.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Administration and Platform Operations&lt;/h2&gt; 
&lt;h3&gt;&lt;span style="font-size: 26px; color: #33485b;"&gt;PostgreSQL 18 Support is Now Available for On-prem Deployments&lt;/span&gt;&lt;/h3&gt; 
&lt;p style="line-height: 1.5;"&gt;After upgrading AIR to v5.23, administrators can upgrade PostgreSQL separately at a time that fits their maintenance schedule by following the PostgreSQL Upgrade Guide. The database upgrade is not performed automatically and requires planned downtime, during which AIR will be temporarily unavailable.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;PostgreSQL 18 will become AIR’s supported database configuration at the end of August, so on-prem customers are strongly encouraged to plan their upgrade accordingly.&lt;br&gt;&lt;br&gt;&lt;span&gt;&lt;strong&gt;Before you begin, we recommend that you:&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;span&gt;Wait at least 24 hours after upgrading AIR.&lt;/span&gt;&lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;span&gt;Close inactive cases.&lt;/span&gt;&lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;span&gt;Create an AIR Backup.&lt;/span&gt;&lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt;&lt;a href="https://kb.binalyze.com/air/self-hosted/updating/postgresql-15-to-18-upgrade-guide"&gt;&lt;span&gt;Review the PostgreSQL Upgrade Guide.&lt;/span&gt;&lt;/a&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Safer Active Directory Disable Flow&lt;/h3&gt; 
&lt;p&gt;Disabling Active Directory integration now provides a safer and more explicit flow. AIR shows an impact summary, including total affected assets and how many have Responders installed, before the operator chooses whether to keep or remove AD-synced assets.&lt;/p&gt; 
&lt;p&gt;This reduces the operational risk of disabling directory synchronization. Administrators can stop synchronization without unintentionally removing managed assets or uninstalling Responders, and can make a deliberate choice when cleanup is required.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Setup Wizard Proxy and Trusted CA Validation&lt;/h3&gt; 
&lt;p&gt;The setup wizard now supports proxy validation before installation. Proxy and trusted CA checks use the same connectivity validation approach as the post-install Settings experience, helping administrators verify outbound connectivity earlier in the deployment process.&lt;/p&gt; 
&lt;p&gt;This improvement helps reduce setup friction in restricted environments. Administrators can validate proxy settings during installation and correct connectivity issues before completing the AIR deployment.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Backup History Encryption Column&lt;/h3&gt; 
&lt;p&gt;The Backup History table now includes an Encryption column. The column shows whether each backup was encrypted, using the existing backup data already displayed in Backup Details.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Security, Governance, and Authorization Improvements&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Git Repository Organization Scope Enforcement&lt;/h3&gt; 
&lt;p&gt;Git Repository API endpoints now enforce organization scope more consistently. Users and API tokens with Git Repository privileges can only access repositories associated with organizations they are authorized to use.&lt;/p&gt; 
&lt;p&gt;This strengthens governance for customers using Git repositories to import or synchronize investigation content. Filtering, retrieving, creating, updating, deleting, syncing, and viewing logs now apply stricter organization relevance checks.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Privilege Dependency Validation&lt;/h3&gt; 
&lt;p&gt;AIR now validates privilege dependency definitions more strictly. Every catalog privilege must have an explicit dependency entry, even when it has no dependencies.&lt;/p&gt; 
&lt;p&gt;This helps administrators configure roles more consistently. When a privilege requires a related view or supporting privilege, role configuration can auto-select or validate the required dependency instead of leaving users with incomplete access that causes screens or actions to fail.&lt;/p&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;Bug Fixes&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Expired task assignments now finalize parent task status.&lt;/strong&gt; When assignments expired after remaining in Assigned or Processing for an extended period, parent tasks could stay stuck in Assigned or Processing even though no active assignments remained. AIR now treats expired assignments as settled for task completion accounting, recalculates the parent task, and includes a self-heal sweep for historical stuck tasks. This helps administrators and SOC teams identify whether investigation work is actually active.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Retry Upload now preserves custom evidence repository folder naming.&lt;/strong&gt; Retried uploads no longer land at the root of the evidence repository when custom evidence collection naming is configured. AIR now uses the original acquisition context so retried evidence follows the expected folder hierarchy.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Evidence repository validation delay reduced in acquisition workflows.&lt;/strong&gt; Selecting an unreachable repository in the acquisition customization step now times out faster and shows the existing inaccessible-repository warning instead of pausing for about 10 seconds or advancing without feedback.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Global Search and Grid Search consistency improved.&lt;/strong&gt; Grid search behavior has been corrected so users are less likely to miss records that are returned by Global Search for the same keyword.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Case task import status now reflects imported Investigation Hub data.&lt;/strong&gt; Case task pages no longer show imported task data as not applicable when the data is available in Investigation Hub.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset resource usage no longer shows misleading zero-based values while metrics are pending.&lt;/strong&gt; Newly registered assets now show a pending usage state until CPU, memory, and disk metrics arrive, instead of displaying values such as 100% CPU free or 0 B memory free.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Production UI blank page after build upgrade fixed.&lt;/strong&gt; A loading issue that could cause the AIR Console UI to display a blank page in production and staging builds has been resolved.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;All export functions now work behind proxied environments.&lt;/strong&gt; Export preflight handling now uses a standard success response instead of a non-standard status code that could be rewritten by edge infrastructure. The UI now starts downloads on standard successful preflight responses and shows an error when export preflight fails.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;GCP account creation and verification now work with proxy and trusted CA configurations.&lt;/strong&gt; AIR corrected the GCP client transport behavior that could fail with plugin metadata or response parsing errors during account creation.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Azure remote command errors now show the real service message.&lt;/strong&gt; Azure VM command failures no longer surface JSON parsing errors when the cloud service returns a plain-text error. Operators now see the actionable Azure error message, such as when a VM must be running before a command can execute.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Full Text Search task flow now validates mandatory case selection consistently.&lt;/strong&gt; AIR now shows the required case warning when progressing through the Full Text Search task flow without selecting a case, matching the Start action behavior.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder update default schedule drawer now respects disabled time frames.&lt;/strong&gt; The Default policy schedule drawer no longer shows “Set Time Frame” enabled when the backend explicitly has the time frame disabled.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Forward proxy handling for internal processor traffic corrected.&lt;/strong&gt; When a forward proxy is enabled, trusted Console-to-processor traffic for internal infrastructure now bypasses the proxy for private network targets. This prevents processors from appearing offline and disk image actions from being disabled when the proxy cannot resolve internal processor hostnames.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Push-type task assignments now fail correctly when processor delivery fails.&lt;/strong&gt; Disk image and DRONE-related assignments no longer remain in Assigned indefinitely after all processor assignment retries fail. AIR now marks affected assignments as Failed and rolls up the parent task status.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Processor-side cleanup during asset deletion now reaches trusted internal processors.&lt;/strong&gt; Asset deletion cleanup calls now use the trusted private-network path, preventing orphaned processor-side files when internal processor hosts were blocked by outbound safeguards.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;PST evidence import no longer blocks the main application event loop.&lt;/strong&gt; PST import now runs asynchronously with streaming and bounded processing. This prevents long event-loop stalls, Redis connection storms, and health check failures in shared SaaS environments while still surfacing import failures to the UI.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Worker processes now initialize white-labeling configuration.&lt;/strong&gt; Task delivery failures caused by missing white-labeling configuration in worker processes have been resolved.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset and case association lists now handle empty scopes correctly.&lt;/strong&gt; Asset or Responder case tabs no longer show all organization cases when the asset has no related case assignments. AIR now returns an empty list when the related case scope is explicitly empty.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;interACT command-result downloads now require read permission.&lt;/strong&gt; AIR now enforces the appropriate interACT read privilege before users can download persisted command output files. Enumerate-only users can no longer reach command-output resolution paths.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Git Repository organization access tightened.&lt;/strong&gt; Git Repository operations now reject access to repositories or organization scopes outside the caller’s assigned organizations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Gaps in case, task, and assignment counts were reduced for large environments.&lt;/strong&gt; Task visibility queries and count retrieval were optimized to reduce expensive repeated list and count calls, especially for scheduled task views in large tenants.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6783624&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmarketing.binalyze.com%2Fair-release-notes%2Fbinalyze-air-5-23&amp;amp;bu=https%253A%252F%252Fmarketing.binalyze.com%252Fair-release-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Binalyze AIR</category>
      <category>Release notes</category>
      <pubDate>Tue, 28 Jul 2026 07:43:42 GMT</pubDate>
      <guid>https://marketing.binalyze.com/air-release-notes/binalyze-air-5-23</guid>
      <dc:date>2026-07-28T07:43:42Z</dc:date>
      <dc:creator>Elif Kurt</dc:creator>
    </item>
    <item>
      <title>Binalyze AIR v5.21</title>
      <link>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-21</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-21" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;What’s New?&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Automatic Responder update exclusion rules help protect critical assets during maintenance windows.&lt;/strong&gt; Administrators can now define named, policy-style rules that automatically exclude matching assets from automatic Responder updates. This is especially valuable for production systems such as messaging clusters, infrastructure services, and other sensitive assets where an unscheduled Responder restart could disrupt investigation readiness or business operations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Expanded macOS artifact coverage improves visibility into user activity.&lt;/strong&gt; AIR now expands KnowledgeC collection coverage with additional macOS activity streams, including application focus, web usage, lock and power state indicators, audio output, media activity, and modern macOS activity streams. This gives analysts broader context when reconstructing user activity during security investigations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Task memory-limit configuration is available across acquisition, Hunt/Triage, and Full Text Search workflows.&lt;/strong&gt; Memory-limit settings are now available in task advanced options and policy configuration. This helps administrators control task impact on production assets while preserving the ability to collect and analyze evidence at scale.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Linux file system enumeration now includes mounted local filesystems.&lt;/strong&gt; File System Enumeration on Linux assets now covers eligible local mounted disks and volumes, not only the root filesystem. Virtual, pseudo, volatile, container, and network filesystems remain excluded by default to avoid unstable runtime trees and performance issues.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;New Features &amp;amp; Improvements&lt;/h1&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;AIR Console — Asset and Responder Administration&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Automatic Responder Update Exclusion Rules&lt;/h3&gt; 
&lt;p&gt;AIR now supports automatic Responder update exclusion based on saved asset filter rules. Administrators can define one or more named rules under asset update settings, and any asset that matches an enabled rule is automatically excluded from automatic Responder updates.&lt;/p&gt; 
&lt;p&gt;This improvement is designed for environments where critical systems must be updated only during approved maintenance windows. For example, an administrator can create a rule that matches assets tagged as production infrastructure or sensitive Linux servers. Newly registered assets or assets that receive matching tags later are handled automatically, without requiring manual bulk updates.&lt;/p&gt; 
&lt;p&gt;The rule-based exclusion is additive with the existing per-asset manual exclusion flag. Manual Responder update actions remain available, so administrators can still update excluded assets deliberately when they are ready.&lt;/p&gt; 
&lt;p&gt;The asset detail page now also shows which update exclusion rules match the selected asset. This gives administrators a clear explanation of why an asset is being skipped by the automatic update workflow.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Safer Bulk Uninstall and Purge Operations&lt;/h3&gt; 
&lt;p&gt;Bulk uninstall, purge, and uninstall-with-purge operations now support an optional maximum matched-asset assertion. If the filter matches more assets than the configured threshold, AIR stops the operation before making changes.&lt;/p&gt; 
&lt;p&gt;This is useful for cleanup scripts and scheduled administration workflows where filters may evolve over time. Administrators can use the assertion as a guardrail to prevent accidental removal of more assets than intended.&lt;/p&gt; 
&lt;p&gt;When no assets match the filter, AIR now returns a clearer not-found response instead of silently proceeding. This helps administrators identify filter mistakes before they rely on automation.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Policy-Based Memory Limit Configuration for Tasks&lt;/h3&gt; 
&lt;p&gt;Memory limit configuration is now available in task advanced options and policy configuration. AIR also passes resource-limit fields through Hunt/Triage and Full Text Search task flows so the configured limits are preserved when tasks are submitted.&lt;/p&gt; 
&lt;p&gt;This improvement helps administrators control resource consumption on production assets. For investigation teams, it supports safer evidence collection and analysis by reducing the chance that long-running or high-volume tasks consume more memory than expected.&lt;/p&gt; 
&lt;p&gt;Administrators can configure these limits as part of task or policy settings, depending on the workflow. Existing task behavior remains unchanged when no limit is configured.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Improved First Responder Deployment Experience&lt;/h3&gt; 
&lt;p&gt;The empty asset page now updates the “Deploy your first Responder” action correctly when license capabilities or permissions are available. This improves the onboarding experience for newly deployed AIR tenants and reduces confusion for administrators who have the required access but previously saw the action disabled.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Updated AIR For Chrome Extension Store Link&lt;/h3&gt; 
&lt;p&gt;The Deploy &amp;gt; Chrome package page now points to the updated official Chrome Web Store listing for the AIR For Chrome extension. Quick Deployment actions such as &lt;strong style="color: #33485b;"&gt;Copy Link to Chrome Store&lt;/strong&gt; and &lt;strong style="color: #33485b;"&gt;Add to Chrome&lt;/strong&gt; now open the updated extension URL.&lt;/p&gt; 
&lt;p&gt;This ensures administrators and analysts are directed to the current official AIR For Chrome extension when deploying the standalone collector.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Settings and Administration&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Additional Month-First Date Formats&lt;/h3&gt; 
&lt;p&gt;User date and time preferences now include additional month-first date format options. These formats better support users in regions where month-first dates are the standard.&lt;/p&gt; 
&lt;p&gt;Users can select these formats from Profile &amp;gt; Date &amp;amp; Time Preferences. This improves readability in investigation timelines, reports, and operational views for teams that use month-first date conventions.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Improved License Validation Feedback&lt;/h3&gt; 
&lt;p&gt;License validation now preserves the license server’s response more accurately when the license key is invalid or not found. AIR now distinguishes invalid-license scenarios from license server connectivity issues more clearly.&lt;/p&gt; 
&lt;p&gt;This reduces troubleshooting time for administrators and support teams by pointing them toward the correct root cause, such as an invalid key or capacity condition, instead of suggesting a network issue.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Improved Console Address Certificate Import Flow&lt;/h3&gt; 
&lt;p&gt;The Console Address certificate import flow now handles custom PFX imports more reliably when the Console Address itself is unchanged. The import modal also prevents the PFX password from appearing in the browser URL.&lt;/p&gt; 
&lt;p&gt;This improves both usability and credential handling for administrators configuring Console Address certificates under Settings &amp;gt; General &amp;gt; Connection &amp;gt; Console Address.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Responder and Evidence Collection&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Expanded macOS KnowledgeC Artifact Coverage&lt;/h3&gt; 
&lt;p&gt;AIR expands macOS KnowledgeC parsing with additional high-value activity streams. New parsed streams include application focus, web usage, device lock state, power connection state, battery percentage, audio output route, media now-playing activity, application media usage, and application intents where present on the asset.&lt;/p&gt; 
&lt;p&gt;These artifacts help analysts build a more complete timeline of user activity and system state during an investigation. For example, application focus and media usage can help confirm whether a user was active, which applications were in use, and how activity correlates with other evidence.&lt;/p&gt; 
&lt;p&gt;Raw KnowledgeC data collection remains available, while the expanded parsed coverage makes more of the data directly searchable and usable inside AIR workflows.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Linux Shell History Collection for Domain and NSS Users&lt;/h3&gt; 
&lt;p&gt;Linux shell history collection now accounts for user home directories that exist under &lt;code style="color: #33485b;"&gt;/home&lt;/code&gt; even when the user is not listed in the local password file. This improves coverage for environments that resolve users through directory services or similar identity integrations.&lt;/p&gt; 
&lt;p&gt;For investigation teams, this reduces the chance of missing command history from domain or externally managed users whose home directories are present on disk. The collector keeps discovery bounded by scanning immediate home directories rather than recursively walking the entire filesystem.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Linux File System Enumeration Now Includes Mounted Local Filesystems&lt;/h3&gt; 
&lt;p&gt;Linux File System Enumeration now enumerates the root filesystem plus eligible local mounted filesystems. Previously, mount points such as &lt;code style="color: #33485b;"&gt;/mnt&lt;/code&gt;, &lt;code style="color: #33485b;"&gt;/media&lt;/code&gt;, &lt;code style="color: #33485b;"&gt;/srv&lt;/code&gt;, and &lt;code style="color: #33485b;"&gt;/afs&lt;/code&gt; could appear as single directory entries while their mounted contents were absent from &lt;code style="color: #33485b;"&gt;FileSystemEnumeration.csv&lt;/code&gt;.&lt;/p&gt; 
&lt;p&gt;AIR applies a Linux-specific traversal policy for eligible local mounts while continuing to exclude virtual, pseudo, volatile, container, and network filesystems by default. Darwin and AIX root-device behavior is unchanged.&lt;/p&gt; 
&lt;p&gt;For investigation teams, this improves filesystem visibility on Linux assets where evidence is spread across multiple mounted disks or volumes, without expanding collection into unstable runtime or network-backed trees.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Responder Upgrade Safety on Linux Hosts&lt;/h3&gt; 
&lt;p&gt;Linux Responders no longer flush the full connection tracking table on every service start. The cleanup now runs only when isolation artifacts are present and cleanup is actually required.&lt;/p&gt; 
&lt;p&gt;This change prevents brief network disruptions on NAT-dependent production workloads during Responder updates. It is especially relevant for customers running clustered infrastructure where even a sub-second connection reset can cause service impact.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;DRONE Event Classification Improvement&lt;/h3&gt; 
&lt;p&gt;DRONE now classifies Windows Event ID 104 as “Event Log Cleared” only when the provider matches the Windows event log provider. This prevents unrelated USB or smart card driver events from being reported as event log clearing activity.&lt;/p&gt; 
&lt;p&gt;This reduces false positives and helps analysts focus on activity that is more likely to be relevant during an investigation.&lt;/p&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;Bug Fixes&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Audit log event filtering now behaves more consistently across Console processes.&lt;/strong&gt; Customer-reported issues where event filter settings appeared stale or inconsistent after changes have been addressed. Saved audit log event filter settings are now invalidated across running processes, and the settings read path reflects the latest saved configuration more reliably. This improves confidence when administrators use “Log only selected events” or “Log all except selected events” to reduce audit log noise.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Audit log filtering controls now better preserve administrator intent.&lt;/strong&gt; AIR improves handling around audit event selection modes so administrators can switch between logging modes with less risk of losing or misapplying selected event filters.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Outbound connector validation has been hardened across AIR Console integrations.&lt;/strong&gt; AIR now applies a secure-by-default outbound destination validator to Console-initiated requests, including Git repository validation, event subscriptions, evidence repository validation, directory services validation, syslog validation, proxy validation, and related connector checks. SaaS deployments block non-public and cloud-metadata destinations, while on-premise deployments preserve legitimate internal connectivity with configurable allow-list controls.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub query handling has been secured and parameterized.&lt;/strong&gt; Time-based and second-order query injection paths in Investigation Hub timeline count and finding exclusion-rule workflows have been fixed. Stored values are treated as untrusted at use time, and affected query paths now use safer parameter handling.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub object-scope checks have been tightened.&lt;/strong&gt; AIR now enforces authorization more consistently when listing, creating, or applying Investigation Hub exclusion rules and when building asset summary data. This prevents users from expanding results or writing exclusion rules outside their permitted investigation scope.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Stored script execution in Investigation Hub asset filters has been fixed.&lt;/strong&gt; Asset and assignment names displayed in the Evidence Assets filter are now escaped before highlighting. Server-side validation was also added to prevent unsafe asset-name input in section creation workflows. This protects analysts from stored script execution when viewing investigation report-generation filters.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub search results now open records more reliably on large datasets.&lt;/strong&gt; AIR optimized the search-to-grid path so selecting artifact search hits is less likely to result in a timeout or an empty records view when matching data exists.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;The “New evidence has been added” toast no longer appears incorrectly for task-assignment investigations.&lt;/strong&gt; AIR now suppresses this notification for investigations that are permanently scoped to a single task assignment, avoiding confusion when the initial import completes while an analyst is already viewing the Investigation Hub.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Findings CSV export no longer duplicates the “Flags” column.&lt;/strong&gt; Exported findings now contain a single human-readable Flags column, allowing the CSV to be re-imported without duplicate-header errors.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;The Platform “Add to Filter” action in finding details now creates a valid advanced filter.&lt;/strong&gt; AIR now falls back to an allowed operation when the requested filter operation is not supported by the selected field.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Remote repository browsing no longer shows stale results during rapid search or navigation.&lt;/strong&gt; AIR now ignores superseded repository list responses so slow responses from earlier requests do not overwrite newer search results.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Date pattern changes no longer fail because of unchanged profile name fields.&lt;/strong&gt; Date and time preference saves now submit only the relevant preference data, so users with identity-provider-managed names containing restricted characters can still update date formatting.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Additional month-first date formats are now available.&lt;/strong&gt; Users can choose formats such as month/day/year and month-day-year variants from Date &amp;amp; Time Preferences.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Invalid license keys now produce clearer validation messages.&lt;/strong&gt; AIR no longer reports a license server connectivity problem when the server is reachable and the actual issue is an invalid or missing license key.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;PFX import no longer exposes the PFX password in the URL.&lt;/strong&gt; The certificate import modal prevents native form submission and keeps sensitive certificate passwords out of client-visible locations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;The “Deploy your first Responder” button now updates correctly on new tenants.&lt;/strong&gt; The empty asset page now reflects current permissions and license features reactively, so eligible administrators can start deployment without refreshing or navigating away.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder reinstall handling on Linux has been improved.&lt;/strong&gt; AIR addresses a scenario where an older Responder process could remain running after uninstall and block the newly installed service from starting because the previous process still held the runtime lock.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder updates are safer for NAT-dependent Linux workloads.&lt;/strong&gt; A startup cleanup path that could briefly reset established network flows on certain Linux hosts has been fixed. Customers running affected Responder versions should upgrade to the fixed Responder release before resuming automatic updates on sensitive clustered workloads.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;DRONE no longer reports unrelated USB or smart card driver events as event log clearing.&lt;/strong&gt; Event classification now checks the provider, reducing false positives in Windows event analysis.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;A restrictive Permissions-Policy response header has been added.&lt;/strong&gt; AIR now explicitly disables access to browser features such as geolocation, camera, microphone, payment, USB, and motion sensors unless they are intentionally enabled in the future.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Console-initiated outbound requests now sanitize failure behavior more consistently.&lt;/strong&gt; Connector validation paths no longer rely on inconsistent destination filtering, reducing internal reachability exposure in SaaS environments.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;API token metadata visibility has been improved for integrations.&lt;/strong&gt; External consumers can retrieve token details such as expiration date, enabling better token renewal warnings and reducing failed automation caused by expired credentials.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Background worker consistency for audit logging has been improved.&lt;/strong&gt; Multiple Console containers and workers now receive audit log setting changes more reliably, reducing discrepancies between saved settings and logged events.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-21" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;What’s New?&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Automatic Responder update exclusion rules help protect critical assets during maintenance windows.&lt;/strong&gt; Administrators can now define named, policy-style rules that automatically exclude matching assets from automatic Responder updates. This is especially valuable for production systems such as messaging clusters, infrastructure services, and other sensitive assets where an unscheduled Responder restart could disrupt investigation readiness or business operations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Expanded macOS artifact coverage improves visibility into user activity.&lt;/strong&gt; AIR now expands KnowledgeC collection coverage with additional macOS activity streams, including application focus, web usage, lock and power state indicators, audio output, media activity, and modern macOS activity streams. This gives analysts broader context when reconstructing user activity during security investigations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Task memory-limit configuration is available across acquisition, Hunt/Triage, and Full Text Search workflows.&lt;/strong&gt; Memory-limit settings are now available in task advanced options and policy configuration. This helps administrators control task impact on production assets while preserving the ability to collect and analyze evidence at scale.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Linux file system enumeration now includes mounted local filesystems.&lt;/strong&gt; File System Enumeration on Linux assets now covers eligible local mounted disks and volumes, not only the root filesystem. Virtual, pseudo, volatile, container, and network filesystems remain excluded by default to avoid unstable runtime trees and performance issues.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;New Features &amp;amp; Improvements&lt;/h1&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;AIR Console — Asset and Responder Administration&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Automatic Responder Update Exclusion Rules&lt;/h3&gt; 
&lt;p&gt;AIR now supports automatic Responder update exclusion based on saved asset filter rules. Administrators can define one or more named rules under asset update settings, and any asset that matches an enabled rule is automatically excluded from automatic Responder updates.&lt;/p&gt; 
&lt;p&gt;This improvement is designed for environments where critical systems must be updated only during approved maintenance windows. For example, an administrator can create a rule that matches assets tagged as production infrastructure or sensitive Linux servers. Newly registered assets or assets that receive matching tags later are handled automatically, without requiring manual bulk updates.&lt;/p&gt; 
&lt;p&gt;The rule-based exclusion is additive with the existing per-asset manual exclusion flag. Manual Responder update actions remain available, so administrators can still update excluded assets deliberately when they are ready.&lt;/p&gt; 
&lt;p&gt;The asset detail page now also shows which update exclusion rules match the selected asset. This gives administrators a clear explanation of why an asset is being skipped by the automatic update workflow.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Safer Bulk Uninstall and Purge Operations&lt;/h3&gt; 
&lt;p&gt;Bulk uninstall, purge, and uninstall-with-purge operations now support an optional maximum matched-asset assertion. If the filter matches more assets than the configured threshold, AIR stops the operation before making changes.&lt;/p&gt; 
&lt;p&gt;This is useful for cleanup scripts and scheduled administration workflows where filters may evolve over time. Administrators can use the assertion as a guardrail to prevent accidental removal of more assets than intended.&lt;/p&gt; 
&lt;p&gt;When no assets match the filter, AIR now returns a clearer not-found response instead of silently proceeding. This helps administrators identify filter mistakes before they rely on automation.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Policy-Based Memory Limit Configuration for Tasks&lt;/h3&gt; 
&lt;p&gt;Memory limit configuration is now available in task advanced options and policy configuration. AIR also passes resource-limit fields through Hunt/Triage and Full Text Search task flows so the configured limits are preserved when tasks are submitted.&lt;/p&gt; 
&lt;p&gt;This improvement helps administrators control resource consumption on production assets. For investigation teams, it supports safer evidence collection and analysis by reducing the chance that long-running or high-volume tasks consume more memory than expected.&lt;/p&gt; 
&lt;p&gt;Administrators can configure these limits as part of task or policy settings, depending on the workflow. Existing task behavior remains unchanged when no limit is configured.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Improved First Responder Deployment Experience&lt;/h3&gt; 
&lt;p&gt;The empty asset page now updates the “Deploy your first Responder” action correctly when license capabilities or permissions are available. This improves the onboarding experience for newly deployed AIR tenants and reduces confusion for administrators who have the required access but previously saw the action disabled.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Updated AIR For Chrome Extension Store Link&lt;/h3&gt; 
&lt;p&gt;The Deploy &amp;gt; Chrome package page now points to the updated official Chrome Web Store listing for the AIR For Chrome extension. Quick Deployment actions such as &lt;strong style="color: #33485b;"&gt;Copy Link to Chrome Store&lt;/strong&gt; and &lt;strong style="color: #33485b;"&gt;Add to Chrome&lt;/strong&gt; now open the updated extension URL.&lt;/p&gt; 
&lt;p&gt;This ensures administrators and analysts are directed to the current official AIR For Chrome extension when deploying the standalone collector.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Settings and Administration&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Additional Month-First Date Formats&lt;/h3&gt; 
&lt;p&gt;User date and time preferences now include additional month-first date format options. These formats better support users in regions where month-first dates are the standard.&lt;/p&gt; 
&lt;p&gt;Users can select these formats from Profile &amp;gt; Date &amp;amp; Time Preferences. This improves readability in investigation timelines, reports, and operational views for teams that use month-first date conventions.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Improved License Validation Feedback&lt;/h3&gt; 
&lt;p&gt;License validation now preserves the license server’s response more accurately when the license key is invalid or not found. AIR now distinguishes invalid-license scenarios from license server connectivity issues more clearly.&lt;/p&gt; 
&lt;p&gt;This reduces troubleshooting time for administrators and support teams by pointing them toward the correct root cause, such as an invalid key or capacity condition, instead of suggesting a network issue.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Improved Console Address Certificate Import Flow&lt;/h3&gt; 
&lt;p&gt;The Console Address certificate import flow now handles custom PFX imports more reliably when the Console Address itself is unchanged. The import modal also prevents the PFX password from appearing in the browser URL.&lt;/p&gt; 
&lt;p&gt;This improves both usability and credential handling for administrators configuring Console Address certificates under Settings &amp;gt; General &amp;gt; Connection &amp;gt; Console Address.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Responder and Evidence Collection&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Expanded macOS KnowledgeC Artifact Coverage&lt;/h3&gt; 
&lt;p&gt;AIR expands macOS KnowledgeC parsing with additional high-value activity streams. New parsed streams include application focus, web usage, device lock state, power connection state, battery percentage, audio output route, media now-playing activity, application media usage, and application intents where present on the asset.&lt;/p&gt; 
&lt;p&gt;These artifacts help analysts build a more complete timeline of user activity and system state during an investigation. For example, application focus and media usage can help confirm whether a user was active, which applications were in use, and how activity correlates with other evidence.&lt;/p&gt; 
&lt;p&gt;Raw KnowledgeC data collection remains available, while the expanded parsed coverage makes more of the data directly searchable and usable inside AIR workflows.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Linux Shell History Collection for Domain and NSS Users&lt;/h3&gt; 
&lt;p&gt;Linux shell history collection now accounts for user home directories that exist under &lt;code style="color: #33485b;"&gt;/home&lt;/code&gt; even when the user is not listed in the local password file. This improves coverage for environments that resolve users through directory services or similar identity integrations.&lt;/p&gt; 
&lt;p&gt;For investigation teams, this reduces the chance of missing command history from domain or externally managed users whose home directories are present on disk. The collector keeps discovery bounded by scanning immediate home directories rather than recursively walking the entire filesystem.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Linux File System Enumeration Now Includes Mounted Local Filesystems&lt;/h3&gt; 
&lt;p&gt;Linux File System Enumeration now enumerates the root filesystem plus eligible local mounted filesystems. Previously, mount points such as &lt;code style="color: #33485b;"&gt;/mnt&lt;/code&gt;, &lt;code style="color: #33485b;"&gt;/media&lt;/code&gt;, &lt;code style="color: #33485b;"&gt;/srv&lt;/code&gt;, and &lt;code style="color: #33485b;"&gt;/afs&lt;/code&gt; could appear as single directory entries while their mounted contents were absent from &lt;code style="color: #33485b;"&gt;FileSystemEnumeration.csv&lt;/code&gt;.&lt;/p&gt; 
&lt;p&gt;AIR applies a Linux-specific traversal policy for eligible local mounts while continuing to exclude virtual, pseudo, volatile, container, and network filesystems by default. Darwin and AIX root-device behavior is unchanged.&lt;/p&gt; 
&lt;p&gt;For investigation teams, this improves filesystem visibility on Linux assets where evidence is spread across multiple mounted disks or volumes, without expanding collection into unstable runtime or network-backed trees.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Responder Upgrade Safety on Linux Hosts&lt;/h3&gt; 
&lt;p&gt;Linux Responders no longer flush the full connection tracking table on every service start. The cleanup now runs only when isolation artifacts are present and cleanup is actually required.&lt;/p&gt; 
&lt;p&gt;This change prevents brief network disruptions on NAT-dependent production workloads during Responder updates. It is especially relevant for customers running clustered infrastructure where even a sub-second connection reset can cause service impact.&lt;/p&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;DRONE Event Classification Improvement&lt;/h3&gt; 
&lt;p&gt;DRONE now classifies Windows Event ID 104 as “Event Log Cleared” only when the provider matches the Windows event log provider. This prevents unrelated USB or smart card driver events from being reported as event log clearing activity.&lt;/p&gt; 
&lt;p&gt;This reduces false positives and helps analysts focus on activity that is more likely to be relevant during an investigation.&lt;/p&gt; 
&lt;h1 style="color: #33485b; font-size: 40px;"&gt;Bug Fixes&lt;/h1&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Audit log event filtering now behaves more consistently across Console processes.&lt;/strong&gt; Customer-reported issues where event filter settings appeared stale or inconsistent after changes have been addressed. Saved audit log event filter settings are now invalidated across running processes, and the settings read path reflects the latest saved configuration more reliably. This improves confidence when administrators use “Log only selected events” or “Log all except selected events” to reduce audit log noise.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Audit log filtering controls now better preserve administrator intent.&lt;/strong&gt; AIR improves handling around audit event selection modes so administrators can switch between logging modes with less risk of losing or misapplying selected event filters.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Outbound connector validation has been hardened across AIR Console integrations.&lt;/strong&gt; AIR now applies a secure-by-default outbound destination validator to Console-initiated requests, including Git repository validation, event subscriptions, evidence repository validation, directory services validation, syslog validation, proxy validation, and related connector checks. SaaS deployments block non-public and cloud-metadata destinations, while on-premise deployments preserve legitimate internal connectivity with configurable allow-list controls.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub query handling has been secured and parameterized.&lt;/strong&gt; Time-based and second-order query injection paths in Investigation Hub timeline count and finding exclusion-rule workflows have been fixed. Stored values are treated as untrusted at use time, and affected query paths now use safer parameter handling.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub object-scope checks have been tightened.&lt;/strong&gt; AIR now enforces authorization more consistently when listing, creating, or applying Investigation Hub exclusion rules and when building asset summary data. This prevents users from expanding results or writing exclusion rules outside their permitted investigation scope.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Stored script execution in Investigation Hub asset filters has been fixed.&lt;/strong&gt; Asset and assignment names displayed in the Evidence Assets filter are now escaped before highlighting. Server-side validation was also added to prevent unsafe asset-name input in section creation workflows. This protects analysts from stored script execution when viewing investigation report-generation filters.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub search results now open records more reliably on large datasets.&lt;/strong&gt; AIR optimized the search-to-grid path so selecting artifact search hits is less likely to result in a timeout or an empty records view when matching data exists.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;The “New evidence has been added” toast no longer appears incorrectly for task-assignment investigations.&lt;/strong&gt; AIR now suppresses this notification for investigations that are permanently scoped to a single task assignment, avoiding confusion when the initial import completes while an analyst is already viewing the Investigation Hub.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Findings CSV export no longer duplicates the “Flags” column.&lt;/strong&gt; Exported findings now contain a single human-readable Flags column, allowing the CSV to be re-imported without duplicate-header errors.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;The Platform “Add to Filter” action in finding details now creates a valid advanced filter.&lt;/strong&gt; AIR now falls back to an allowed operation when the requested filter operation is not supported by the selected field.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Remote repository browsing no longer shows stale results during rapid search or navigation.&lt;/strong&gt; AIR now ignores superseded repository list responses so slow responses from earlier requests do not overwrite newer search results.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Date pattern changes no longer fail because of unchanged profile name fields.&lt;/strong&gt; Date and time preference saves now submit only the relevant preference data, so users with identity-provider-managed names containing restricted characters can still update date formatting.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Additional month-first date formats are now available.&lt;/strong&gt; Users can choose formats such as month/day/year and month-day-year variants from Date &amp;amp; Time Preferences.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Invalid license keys now produce clearer validation messages.&lt;/strong&gt; AIR no longer reports a license server connectivity problem when the server is reachable and the actual issue is an invalid or missing license key.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;PFX import no longer exposes the PFX password in the URL.&lt;/strong&gt; The certificate import modal prevents native form submission and keeps sensitive certificate passwords out of client-visible locations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;The “Deploy your first Responder” button now updates correctly on new tenants.&lt;/strong&gt; The empty asset page now reflects current permissions and license features reactively, so eligible administrators can start deployment without refreshing or navigating away.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder reinstall handling on Linux has been improved.&lt;/strong&gt; AIR addresses a scenario where an older Responder process could remain running after uninstall and block the newly installed service from starting because the previous process still held the runtime lock.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder updates are safer for NAT-dependent Linux workloads.&lt;/strong&gt; A startup cleanup path that could briefly reset established network flows on certain Linux hosts has been fixed. Customers running affected Responder versions should upgrade to the fixed Responder release before resuming automatic updates on sensitive clustered workloads.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;DRONE no longer reports unrelated USB or smart card driver events as event log clearing.&lt;/strong&gt; Event classification now checks the provider, reducing false positives in Windows event analysis.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;A restrictive Permissions-Policy response header has been added.&lt;/strong&gt; AIR now explicitly disables access to browser features such as geolocation, camera, microphone, payment, USB, and motion sensors unless they are intentionally enabled in the future.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Console-initiated outbound requests now sanitize failure behavior more consistently.&lt;/strong&gt; Connector validation paths no longer rely on inconsistent destination filtering, reducing internal reachability exposure in SaaS environments.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;API token metadata visibility has been improved for integrations.&lt;/strong&gt; External consumers can retrieve token details such as expiration date, enabling better token renewal warnings and reducing failed automation caused by expired credentials.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Background worker consistency for audit logging has been improved.&lt;/strong&gt; Multiple Console containers and workers now receive audit log setting changes more reliably, reducing discrepancies between saved settings and logged events.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6783624&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmarketing.binalyze.com%2Fair-release-notes%2Fbinalyze-air-v5-21&amp;amp;bu=https%253A%252F%252Fmarketing.binalyze.com%252Fair-release-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Binalyze AIR</category>
      <category>Release notes</category>
      <pubDate>Tue, 30 Jun 2026 13:34:01 GMT</pubDate>
      <guid>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-21</guid>
      <dc:date>2026-06-30T13:34:01Z</dc:date>
      <dc:creator>Elif Kurt</dc:creator>
    </item>
    <item>
      <title>Binalyze AIR v5.20</title>
      <link>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-20</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-20" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;What’s New?&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Expanded Windows event collection coverage:&lt;/strong&gt; Acquisition profiles now include additional relevant Windows Event IDs. This increases visibility into activity that may be important during security investigations and retrospective analysis..&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved interACT file download experience:&lt;/strong&gt; interACT command result downloads now include file size information, enabling progress indication for larger files and improving the experience for analysts and external integrations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub usability improvements:&lt;/strong&gt; A Toolbox button is now available in the Investigation Hub header, making related investigation actions easier to access during active case review.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;New Features &amp;amp; Improvements&lt;/h2&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Responder and Task Execution&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Expanded Windows Event Collection Coverage&lt;/h3&gt; 
&lt;p&gt;AIR acquisition profiles now include additional Windows Event IDs that are relevant to security investigations. These additions improve coverage for event-based review and help analysts identify activity that may otherwise require manual profile updates.&lt;/p&gt; 
&lt;p&gt;Administrators can use the updated acquisition configuration as part of standard evidence collection workflows. The expanded event coverage supports stronger timeline reconstruction and better evidence-backed decisions during post-incident investigation.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Investigation Hub&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Toolbox Access from the Investigation Hub Header&lt;/h3&gt; 
&lt;p&gt;The Investigation Hub header now includes a Toolbox button. This makes supporting actions more accessible while analysts are reviewing evidence, findings, and artifacts inside a case.&lt;/p&gt; 
&lt;p&gt;By reducing navigation friction, the change helps analysts stay focused on the active investigation context and move more quickly between review and response actions.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;interACT&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Improved Command Result Downloads&lt;/h3&gt; 
&lt;p&gt;interACT command result downloads now include the content length in the response. This allows browsers and integrations to display accurate progress for larger downloads.&lt;/p&gt; 
&lt;p&gt;The improvement is useful when analysts retrieve larger command outputs or files through interACT. It reduces uncertainty during downloads and provides a clearer indication that the file transfer is progressing.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Bug Fixes&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder startup no longer disrupts Linux connection tracking when isolation was not used.&lt;/strong&gt; A Linux Responder startup path could clear host connection tracking during upgrade or service restart, even on assets where network isolation had never been used. This could briefly disrupt NAT-dependent clustered workloads. The cleanup now runs only when isolation artifacts are present, preserving normal network state during routine Responder updates.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Acquisition now stops immediately on disk-full write errors.&lt;/strong&gt; When a collector encounters a no-space-left condition during evidence collection, AIR now cancels the acquisition pipeline immediately instead of allowing additional collectors to continue failing and generating excessive logs. This reduces wasted processing and improves clarity when an asset lacks sufficient disk space.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Console proxy settings are now applied to license validation in on-premise deployments.&lt;/strong&gt; License validation now respects the configured Console proxy. This resolves failures in environments where outbound internet access must pass through a proxy and avoids misleading situations where proxy verification succeeds but license validation bypasses the proxy.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;RelayPro registration now works correctly in multiport Console configurations.&lt;/strong&gt; RelayPro agent-facing registration and communication endpoints are now accepted through the supported Responder communication path. This resolves 403 “Console Port Forbidden” errors that prevented RelayPro from registering in affected on-premise configurations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fresh installations now create the required File Explorer processor configuration.&lt;/strong&gt; AIR now creates the required File Explorer processor during installation. This resolves Repository Explorer failures where the supporting service was healthy but AIR reported that the processor was not configured.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub export URLs now resolve correctly.&lt;/strong&gt; The Investigation Evidence Export Request API now returns a usable download URL. API users can create an export request and retrieve the generated CSV instead of receiving a 404 response from the returned URL.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub filtering has been improved for large findings datasets.&lt;/strong&gt; The Flag “Is blank” advanced filter has been optimized so large findings views do not become unresponsive or fail because of long-running queries. This improves review workflows for cases containing a high volume of findings.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Artifact data now remains visible when filtering by affected assets.&lt;/strong&gt; AIR fixed an Investigation Hub issue where artifact data could disappear from the left-side panel after applying certain asset filters. Clearing filters is no longer required to restore the artifact view.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub evidence relationship handling has been corrected.&lt;/strong&gt; AIR fixed an issue that affected evidence relationship display and correlation inside Investigation Hub, improving consistency when analysts review linked artifacts and findings.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Advanced filter value lists now show expected available values.&lt;/strong&gt; AIR fixed an issue where some valid filter values did not appear in Advanced Filter controls across areas such as Assets and Tasks. Analysts and administrators can now select available environment values more reliably.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset selection now matches the task scope for Triage tasks.&lt;/strong&gt; AIR fixed an issue where the selection count could include assets selected across multiple filtered views, while the resulting Triage task only processed assets from the latest filter view. Task creation now better reflects the intended asset selection.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Disk Image and Repository Explorer search behavior has been corrected.&lt;/strong&gt; Search filtering now works more reliably when selecting repositories or browsing disk image lists, helping analysts locate relevant evidence sources faster.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;PFX certificate import messaging and trust handling have been improved.&lt;/strong&gt; AIR now handles PKCS12 certificate conversion and certificate chain validation more reliably, with clearer guidance when certificate trust issues are detected.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;License error messages now better reflect the actual condition.&lt;/strong&gt; AIR now provides more accurate license validation feedback, reducing confusion between capacity-related conditions and connectivity problems.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;MITRE notification formatting has been corrected.&lt;/strong&gt; Analyzer database change notifications now render more cleanly, improving readability for administrators reviewing update information.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Bulk case closure now reduces load on cache services.&lt;/strong&gt; AIR no longer proactively scans and removes large numbers of investigation jobs when a case is closed. Job processors now check case state when processing and skip work for closed cases, reducing load during bulk closure operations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Task assignment reads no longer include large response payloads by default.&lt;/strong&gt; AIR avoids loading large task assignment response data unless needed. This improves performance in environments where task responses contain large JSON bodies, such as auto asset tag responses.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Auto-tag organization isolation has been corrected.&lt;/strong&gt; Auto asset tags are now filtered by organization during assignment and scheduled processing. This prevents tags configured for one organization from appearing in another organization’s cases or assets.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Security and authorization hardening has been applied across tenant-scoped workflows.&lt;/strong&gt; AIR corrected cross-organization authorization gaps in Investigation Hub advanced filters, finding exclusion rules, and asset tag deletion. These fixes strengthen tenant boundaries and prevent unauthorized cross-organization modification of saved searches, exclusion rules, and tags.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Audit log filtering has been hardened.&lt;/strong&gt; AIR now safely handles user-supplied audit log filter keys, preventing unsafe query construction while preserving existing filtering behavior.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;SSO provider data remains current after configuration changes.&lt;/strong&gt; AIR now invalidates cached SSO provider data when providers are created, updated, or deleted, ensuring administrators see current authentication configuration.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Integration settings load more efficiently.&lt;/strong&gt; AIR improved integration settings retrieval performance, reducing delays for administrators working with cloud and repository integrations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Setup and role seeding reliability has been improved.&lt;/strong&gt; AIR fixed a race condition between setup and predefined role seeding, improving reliability during installation and provisioning.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-20" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;What’s New?&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Expanded Windows event collection coverage:&lt;/strong&gt; Acquisition profiles now include additional relevant Windows Event IDs. This increases visibility into activity that may be important during security investigations and retrospective analysis..&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Improved interACT file download experience:&lt;/strong&gt; interACT command result downloads now include file size information, enabling progress indication for larger files and improving the experience for analysts and external integrations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub usability improvements:&lt;/strong&gt; A Toolbox button is now available in the Investigation Hub header, making related investigation actions easier to access during active case review.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;New Features &amp;amp; Improvements&lt;/h2&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Responder and Task Execution&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Expanded Windows Event Collection Coverage&lt;/h3&gt; 
&lt;p&gt;AIR acquisition profiles now include additional Windows Event IDs that are relevant to security investigations. These additions improve coverage for event-based review and help analysts identify activity that may otherwise require manual profile updates.&lt;/p&gt; 
&lt;p&gt;Administrators can use the updated acquisition configuration as part of standard evidence collection workflows. The expanded event coverage supports stronger timeline reconstruction and better evidence-backed decisions during post-incident investigation.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Investigation Hub&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Toolbox Access from the Investigation Hub Header&lt;/h3&gt; 
&lt;p&gt;The Investigation Hub header now includes a Toolbox button. This makes supporting actions more accessible while analysts are reviewing evidence, findings, and artifacts inside a case.&lt;/p&gt; 
&lt;p&gt;By reducing navigation friction, the change helps analysts stay focused on the active investigation context and move more quickly between review and response actions.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;interACT&lt;/h2&gt; 
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Improved Command Result Downloads&lt;/h3&gt; 
&lt;p&gt;interACT command result downloads now include the content length in the response. This allows browsers and integrations to display accurate progress for larger downloads.&lt;/p&gt; 
&lt;p&gt;The improvement is useful when analysts retrieve larger command outputs or files through interACT. It reduces uncertainty during downloads and provides a clearer indication that the file transfer is progressing.&lt;/p&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Bug Fixes&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Responder startup no longer disrupts Linux connection tracking when isolation was not used.&lt;/strong&gt; A Linux Responder startup path could clear host connection tracking during upgrade or service restart, even on assets where network isolation had never been used. This could briefly disrupt NAT-dependent clustered workloads. The cleanup now runs only when isolation artifacts are present, preserving normal network state during routine Responder updates.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Acquisition now stops immediately on disk-full write errors.&lt;/strong&gt; When a collector encounters a no-space-left condition during evidence collection, AIR now cancels the acquisition pipeline immediately instead of allowing additional collectors to continue failing and generating excessive logs. This reduces wasted processing and improves clarity when an asset lacks sufficient disk space.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Console proxy settings are now applied to license validation in on-premise deployments.&lt;/strong&gt; License validation now respects the configured Console proxy. This resolves failures in environments where outbound internet access must pass through a proxy and avoids misleading situations where proxy verification succeeds but license validation bypasses the proxy.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;RelayPro registration now works correctly in multiport Console configurations.&lt;/strong&gt; RelayPro agent-facing registration and communication endpoints are now accepted through the supported Responder communication path. This resolves 403 “Console Port Forbidden” errors that prevented RelayPro from registering in affected on-premise configurations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Fresh installations now create the required File Explorer processor configuration.&lt;/strong&gt; AIR now creates the required File Explorer processor during installation. This resolves Repository Explorer failures where the supporting service was healthy but AIR reported that the processor was not configured.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub export URLs now resolve correctly.&lt;/strong&gt; The Investigation Evidence Export Request API now returns a usable download URL. API users can create an export request and retrieve the generated CSV instead of receiving a 404 response from the returned URL.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub filtering has been improved for large findings datasets.&lt;/strong&gt; The Flag “Is blank” advanced filter has been optimized so large findings views do not become unresponsive or fail because of long-running queries. This improves review workflows for cases containing a high volume of findings.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Artifact data now remains visible when filtering by affected assets.&lt;/strong&gt; AIR fixed an Investigation Hub issue where artifact data could disappear from the left-side panel after applying certain asset filters. Clearing filters is no longer required to restore the artifact view.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Investigation Hub evidence relationship handling has been corrected.&lt;/strong&gt; AIR fixed an issue that affected evidence relationship display and correlation inside Investigation Hub, improving consistency when analysts review linked artifacts and findings.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Advanced filter value lists now show expected available values.&lt;/strong&gt; AIR fixed an issue where some valid filter values did not appear in Advanced Filter controls across areas such as Assets and Tasks. Analysts and administrators can now select available environment values more reliably.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset selection now matches the task scope for Triage tasks.&lt;/strong&gt; AIR fixed an issue where the selection count could include assets selected across multiple filtered views, while the resulting Triage task only processed assets from the latest filter view. Task creation now better reflects the intended asset selection.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Disk Image and Repository Explorer search behavior has been corrected.&lt;/strong&gt; Search filtering now works more reliably when selecting repositories or browsing disk image lists, helping analysts locate relevant evidence sources faster.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;PFX certificate import messaging and trust handling have been improved.&lt;/strong&gt; AIR now handles PKCS12 certificate conversion and certificate chain validation more reliably, with clearer guidance when certificate trust issues are detected.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;License error messages now better reflect the actual condition.&lt;/strong&gt; AIR now provides more accurate license validation feedback, reducing confusion between capacity-related conditions and connectivity problems.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;MITRE notification formatting has been corrected.&lt;/strong&gt; Analyzer database change notifications now render more cleanly, improving readability for administrators reviewing update information.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Bulk case closure now reduces load on cache services.&lt;/strong&gt; AIR no longer proactively scans and removes large numbers of investigation jobs when a case is closed. Job processors now check case state when processing and skip work for closed cases, reducing load during bulk closure operations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Task assignment reads no longer include large response payloads by default.&lt;/strong&gt; AIR avoids loading large task assignment response data unless needed. This improves performance in environments where task responses contain large JSON bodies, such as auto asset tag responses.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Auto-tag organization isolation has been corrected.&lt;/strong&gt; Auto asset tags are now filtered by organization during assignment and scheduled processing. This prevents tags configured for one organization from appearing in another organization’s cases or assets.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Security and authorization hardening has been applied across tenant-scoped workflows.&lt;/strong&gt; AIR corrected cross-organization authorization gaps in Investigation Hub advanced filters, finding exclusion rules, and asset tag deletion. These fixes strengthen tenant boundaries and prevent unauthorized cross-organization modification of saved searches, exclusion rules, and tags.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Audit log filtering has been hardened.&lt;/strong&gt; AIR now safely handles user-supplied audit log filter keys, preventing unsafe query construction while preserving existing filtering behavior.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;SSO provider data remains current after configuration changes.&lt;/strong&gt; AIR now invalidates cached SSO provider data when providers are created, updated, or deleted, ensuring administrators see current authentication configuration.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Integration settings load more efficiently.&lt;/strong&gt; AIR improved integration settings retrieval performance, reducing delays for administrators working with cloud and repository integrations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Setup and role seeding reliability has been improved.&lt;/strong&gt; AIR fixed a race condition between setup and predefined role seeding, improving reliability during installation and provisioning.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6783624&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmarketing.binalyze.com%2Fair-release-notes%2Fbinalyze-air-v5-20&amp;amp;bu=https%253A%252F%252Fmarketing.binalyze.com%252Fair-release-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Binalyze AIR</category>
      <category>Release notes</category>
      <pubDate>Thu, 18 Jun 2026 11:54:21 GMT</pubDate>
      <guid>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-20</guid>
      <dc:date>2026-06-18T11:54:21Z</dc:date>
      <dc:creator>Elif Kurt</dc:creator>
    </item>
    <item>
      <title>Binalyze AIR v5.19</title>
      <link>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-19</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-19" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;What’s New?&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Expanded Windows Clipboard History visibility:&lt;/strong&gt; AIR now surfaces Clipboard History and Clipboard Activity artifacts in Investigation Hub. This helps analysts review copied text activity, user workflow context, and clipboard-related evidence when investigating suspicious behavior on Windows assets.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;S3-compatible evidence repository support:&lt;/strong&gt; AIR now supports custom S3-compatible storage providers, including common object storage platforms that use S3-compatible APIs. This gives security teams more flexibility when storing collected evidence in restricted, hybrid, or customer-managed environments.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Improved export workflows for reporting and correlation:&lt;/strong&gt; Export behavior has been expanded with configurable CSV delimiters, UTF-8 BOM support, timezone options, and column-selection-aware exports. Analysts can now generate cleaner, locale-compatible outputs that better match what they see in AIR.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Configurable audit logging:&lt;/strong&gt; Administrators can now control which audit events are written to the Audit Log. This helps reduce noise, focus on high-value security events, and support compliance-driven monitoring requirements.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;More controlled auto asset tagging:&lt;/strong&gt; Auto Asset Tagging can now be managed more selectively, allowing teams to enable or disable specific tagging rules. This helps SOC and MSSP teams apply automation more precisely across different customer or organizational environments.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;New Features &amp;amp; Improvements&lt;/h2&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Investigation Hub&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Investigator Toolbox for In-Hub Analysis&lt;/h3&gt; 
&lt;p style=""&gt;Investigation Hub now includes entry points for an Investigator Toolbox from evidence detail views. Analysts can open selected field values in the toolbox directly from the evidence context, reducing the need to copy values into external utilities during an investigation.&lt;/p&gt; 
&lt;p style=""&gt;This improvement supports faster evidence review by keeping common analysis actions close to the data. Values such as encoded strings, timestamps, hashes, IP addresses, domains, registry paths, and other artifacts can be reviewed with less context switching.&lt;/p&gt; 
&lt;p style=""&gt;For investigation teams, this improves continuity during evidence-based investigations. Analysts can move from observation to enrichment more quickly while preserving the context of the case and the original evidence item.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Export Options for Investigation Reporting&lt;/h3&gt; 
&lt;p style=""&gt;AIR export workflows now provide more flexibility for teams that rely on CSV outputs for reporting, correlation, and downstream analysis. Exports can be configured with delimiter options such as comma, semicolon, tab, or pipe, and can include UTF-8 BOM support for improved compatibility with regional spreadsheet settings.&lt;/p&gt; 
&lt;p style=""&gt;This is valuable for organizations using Turkish or European locale settings, where spreadsheet tools may expect semicolon-separated files. Analysts can produce files that open correctly without manual conversion steps.&lt;/p&gt; 
&lt;p style=""&gt;Export workflows also include timezone-related controls for Investigation Hub flag exports, helping analysts generate outputs that match investigation and reporting requirements across different operating regions.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Exports Now Respect Visible Column Selection&lt;/h3&gt; 
&lt;p style=""&gt;Non-Investigation Hub exports now support exporting the columns currently visible in the UI. When analysts hide columns through column selection, exported CSV files can now reflect that visible selection instead of always exporting every available column.&lt;/p&gt; 
&lt;p style=""&gt;This improves data minimization and reporting accuracy. Analysts can export only the fields needed for a report or handoff, reducing unnecessary internal identifiers, sensitive values, or irrelevant operational data in exported files.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Evidence Collection&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Windows Clipboard History Evidence&lt;/h3&gt; 
&lt;p style=""&gt;AIR now integrates Windows Clipboard History evidence into the acquisition profile and Investigation Hub. Clipboard History and Clipboard Activity are available as Windows artifact sources, with parsed activity status values displayed in a readable format.&lt;/p&gt; 
&lt;p style=""&gt;This helps analysts review clipboard-related user activity when Clipboard History is available on the asset. Clipboard evidence can support investigations involving copied commands, copied URLs, copied identifiers, or other text values that may be relevant to adversary techniques or unauthorized activity.&lt;/p&gt; 
&lt;p style=""&gt;The new evidence appears in Investigation Hub under the Windows evidence navigation structure and uses the standard evidence grid experience. Analysts can review, filter, and correlate clipboard-related records with other collected evidence in the same case.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Evidence Repository and Storage&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;S3-Compatible Evidence Repositories&lt;/h3&gt; 
&lt;p style=""&gt;AIR now supports a dedicated S3-compatible evidence repository type. Administrators can configure a custom endpoint, provider name, and region for object storage platforms that use S3-compatible APIs.&lt;/p&gt; 
&lt;p style=""&gt;This expands evidence repository options beyond standard cloud storage configurations. Organizations using providers such as Backblaze B2, Pure Storage, MinIO, Wasabi, Cloudflare R2, or similar S3-compatible services can configure evidence upload destinations more directly.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Custom Azure Blob Storage Domains&lt;/h3&gt; 
&lt;p style=""&gt;AIR now supports custom Azure Blob Storage domains in evidence repository configuration. This addresses environments that use custom storage domains instead of the standard public Azure Blob Storage domain format.&lt;/p&gt; 
&lt;p style=""&gt;This is important for organizations operating in restricted or contained network environments. Administrators can configure storage destinations that match their network architecture, allowing acquisition workflows to upload evidence without requiring workarounds.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Evidence Repository Filtering, Sorting, and Last-Used Details&lt;/h3&gt; 
&lt;p style=""&gt;Evidence repository lists now provide improved filtering and sorting for S3-compatible providers. Repository type and provider values are handled more consistently, including provider names entered as free text.&lt;/p&gt; 
&lt;p style=""&gt;Repositories can also be sorted by last-used information, helping administrators quickly identify active storage destinations and review repository usage patterns. This is useful in environments with multiple organizations, storage providers, or regional evidence destinations.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Access, Authentication, and Governance&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;SSO Custom Claim Mapping&lt;/h3&gt; 
&lt;p style=""&gt;Administrators can now define custom claim mappings for SSO providers. AIR supports mapping identity provider attributes to expected AIR fields such as email, first name, last name, and groups.&lt;/p&gt; 
&lt;p style=""&gt;This improves compatibility with identity providers that use different claim or attribute names. Administrators can adapt AIR to existing identity configurations without requiring custom changes or provider-specific workarounds.&lt;/p&gt; 
&lt;p style=""&gt;The improvement supports both OIDC and SAML-based SSO configurations and helps enterprise teams integrate AIR into established authentication environments more efficiently.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Self-Service 2FA Device Change&lt;/h3&gt; 
&lt;p style=""&gt;Users can now change their authenticator device through a guided self-service flow. The user verifies the current authenticator code, scans a new authenticator secret, and confirms the new code before the old secret is replaced.&lt;/p&gt; 
&lt;p style=""&gt;This provides a graceful transition when users replace a phone, move to a new authenticator application, or update corporate devices. The old authenticator remains valid until the new one is verified, so the account does not lose 2FA protection during the change.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Personal Access Token Access Control&lt;/h3&gt; 
&lt;p style=""&gt;AIR now includes a dedicated privilege for managing personal access tokens. Administrators can control whether users can view, create, edit, or delete personal access tokens.&lt;/p&gt; 
&lt;p style=""&gt;This gives security teams more precise control over API access and automation credentials. Organizations can limit token management to approved roles while preserving existing operational workflows for users who require token-based integrations.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Configurable Audit Logging&lt;/h3&gt; 
&lt;p style=""&gt;Administrators can now configure which event types are written to the Audit Log. The new event filter supports logging all events, logging only selected events, or logging all events except selected events.&lt;/p&gt; 
&lt;p style=""&gt;This helps teams reduce audit noise and focus on activity that matters most to their governance, compliance, and security monitoring requirements. Changes to audit logging configuration are themselves recorded, helping maintain traceability over audit policy changes.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;License Usage Banners&lt;/h3&gt; 
&lt;p style=""&gt;AIR now provides clearer license usage notifications through visible banners at higher usage thresholds. These banners help administrators understand when asset usage is approaching important license limits.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Asset and Task Management&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Selective Auto Asset Tagging Rules&lt;/h3&gt; 
&lt;p style=""&gt;Auto Asset Tagging can now be controlled at the rule level. Administrators can enable or disable individual rules instead of relying only on a global auto-tagging switch.&lt;/p&gt; 
&lt;p style=""&gt;This helps teams run only the tagging rules that are relevant to a specific environment, organization, or customer. MSSP teams can reduce noisy tagging behavior and test new rules without activating every rule in the library.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Bug Fixes&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Investigation Hub advanced filters:&lt;/strong&gt; Fixed an issue where invalid filter options could appear for some columns in the advanced filter panel.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Investigation Hub exclusion activity:&lt;/strong&gt; Fixed an issue where exclusion rule creation activity was displayed incorrectly and was not clickable in the Activity view.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Investigation Hub flags after organization changes:&lt;/strong&gt; Fixed an issue where incorrect flags could be shown or assigned after changing an investigation organization.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;DRONE analysis rerun at scale:&lt;/strong&gt; Fixed a case-level DRONE re-analysis workflow that generated one request and one toast per asset assignment. The workflow now batches the action more effectively and shows a single summary notification, improving usability in large cases.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Exclusion rule modal usability:&lt;/strong&gt; Improved the Exclusion Rule modal layout so action controls remain accessible on common screen sizes and users do not need to search for the submit action inside the scroll area.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Exclusion toast behavior:&lt;/strong&gt; Exclusion confirmation toasts now auto-dismiss after a short duration instead of remaining on screen indefinitely.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Export timestamp precision:&lt;/strong&gt; Fixed an issue where some exported date and time formats did not include seconds. Exported timestamps now provide consistent precision across supported timezone options.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Matched policies after isolation actions:&lt;/strong&gt; Fixed an issue where the Matched Policies section disappeared after isolate or unisolate actions until the page was refreshed.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Policy search:&lt;/strong&gt; Fixed an issue where searching on the Policies page did not filter the displayed policy list.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Cases page search field:&lt;/strong&gt; Fixed a UI issue where the search input on the Cases page was too narrow, making typed text difficult to see.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Task Details table spacing:&lt;/strong&gt; Adjusted default table spacing on the Task Details page to improve readability and screen usage.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;interACT REST polling:&lt;/strong&gt; Fixed an issue where public interACT REST API polling could continue returning an in-progress state after the command had already completed.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;MITRE ATT&amp;amp;CK database version validation:&lt;/strong&gt; Fixed an issue where the API accepted a non-existent MITRE ATT&amp;amp;CK database version before task creation. Invalid versions are now validated earlier.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Backup restore completeness:&lt;/strong&gt; Fixed an issue where a backup archive could miss the primary database dump in larger environments, causing restore results to appear incomplete in the UI.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Backup creation options:&lt;/strong&gt; Removed a misleading unused database option from the backup creation workflow to reduce confusion and avoid unnecessary backup size growth.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Application health after install or upgrade:&lt;/strong&gt; Fixed a health check validation issue that could cause an application container to be reported as unhealthy after a fresh installation or upgrade.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Evidence repository configuration:&lt;/strong&gt; Fixed and refined S3-compatible repository form behavior, provider display, and save handling for repository configuration workflows.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Custom Azure Blob Storage validation:&lt;/strong&gt; Fixed validation so custom Azure Blob Storage domains can be used where supported by the evidence repository configuration.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-19" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;What’s New?&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Expanded Windows Clipboard History visibility:&lt;/strong&gt; AIR now surfaces Clipboard History and Clipboard Activity artifacts in Investigation Hub. This helps analysts review copied text activity, user workflow context, and clipboard-related evidence when investigating suspicious behavior on Windows assets.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;S3-compatible evidence repository support:&lt;/strong&gt; AIR now supports custom S3-compatible storage providers, including common object storage platforms that use S3-compatible APIs. This gives security teams more flexibility when storing collected evidence in restricted, hybrid, or customer-managed environments.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Improved export workflows for reporting and correlation:&lt;/strong&gt; Export behavior has been expanded with configurable CSV delimiters, UTF-8 BOM support, timezone options, and column-selection-aware exports. Analysts can now generate cleaner, locale-compatible outputs that better match what they see in AIR.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Configurable audit logging:&lt;/strong&gt; Administrators can now control which audit events are written to the Audit Log. This helps reduce noise, focus on high-value security events, and support compliance-driven monitoring requirements.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;More controlled auto asset tagging:&lt;/strong&gt; Auto Asset Tagging can now be managed more selectively, allowing teams to enable or disable specific tagging rules. This helps SOC and MSSP teams apply automation more precisely across different customer or organizational environments.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;New Features &amp;amp; Improvements&lt;/h2&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Investigation Hub&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Investigator Toolbox for In-Hub Analysis&lt;/h3&gt; 
&lt;p style=""&gt;Investigation Hub now includes entry points for an Investigator Toolbox from evidence detail views. Analysts can open selected field values in the toolbox directly from the evidence context, reducing the need to copy values into external utilities during an investigation.&lt;/p&gt; 
&lt;p style=""&gt;This improvement supports faster evidence review by keeping common analysis actions close to the data. Values such as encoded strings, timestamps, hashes, IP addresses, domains, registry paths, and other artifacts can be reviewed with less context switching.&lt;/p&gt; 
&lt;p style=""&gt;For investigation teams, this improves continuity during evidence-based investigations. Analysts can move from observation to enrichment more quickly while preserving the context of the case and the original evidence item.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Export Options for Investigation Reporting&lt;/h3&gt; 
&lt;p style=""&gt;AIR export workflows now provide more flexibility for teams that rely on CSV outputs for reporting, correlation, and downstream analysis. Exports can be configured with delimiter options such as comma, semicolon, tab, or pipe, and can include UTF-8 BOM support for improved compatibility with regional spreadsheet settings.&lt;/p&gt; 
&lt;p style=""&gt;This is valuable for organizations using Turkish or European locale settings, where spreadsheet tools may expect semicolon-separated files. Analysts can produce files that open correctly without manual conversion steps.&lt;/p&gt; 
&lt;p style=""&gt;Export workflows also include timezone-related controls for Investigation Hub flag exports, helping analysts generate outputs that match investigation and reporting requirements across different operating regions.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Exports Now Respect Visible Column Selection&lt;/h3&gt; 
&lt;p style=""&gt;Non-Investigation Hub exports now support exporting the columns currently visible in the UI. When analysts hide columns through column selection, exported CSV files can now reflect that visible selection instead of always exporting every available column.&lt;/p&gt; 
&lt;p style=""&gt;This improves data minimization and reporting accuracy. Analysts can export only the fields needed for a report or handoff, reducing unnecessary internal identifiers, sensitive values, or irrelevant operational data in exported files.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Evidence Collection&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Windows Clipboard History Evidence&lt;/h3&gt; 
&lt;p style=""&gt;AIR now integrates Windows Clipboard History evidence into the acquisition profile and Investigation Hub. Clipboard History and Clipboard Activity are available as Windows artifact sources, with parsed activity status values displayed in a readable format.&lt;/p&gt; 
&lt;p style=""&gt;This helps analysts review clipboard-related user activity when Clipboard History is available on the asset. Clipboard evidence can support investigations involving copied commands, copied URLs, copied identifiers, or other text values that may be relevant to adversary techniques or unauthorized activity.&lt;/p&gt; 
&lt;p style=""&gt;The new evidence appears in Investigation Hub under the Windows evidence navigation structure and uses the standard evidence grid experience. Analysts can review, filter, and correlate clipboard-related records with other collected evidence in the same case.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Evidence Repository and Storage&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;S3-Compatible Evidence Repositories&lt;/h3&gt; 
&lt;p style=""&gt;AIR now supports a dedicated S3-compatible evidence repository type. Administrators can configure a custom endpoint, provider name, and region for object storage platforms that use S3-compatible APIs.&lt;/p&gt; 
&lt;p style=""&gt;This expands evidence repository options beyond standard cloud storage configurations. Organizations using providers such as Backblaze B2, Pure Storage, MinIO, Wasabi, Cloudflare R2, or similar S3-compatible services can configure evidence upload destinations more directly.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Custom Azure Blob Storage Domains&lt;/h3&gt; 
&lt;p style=""&gt;AIR now supports custom Azure Blob Storage domains in evidence repository configuration. This addresses environments that use custom storage domains instead of the standard public Azure Blob Storage domain format.&lt;/p&gt; 
&lt;p style=""&gt;This is important for organizations operating in restricted or contained network environments. Administrators can configure storage destinations that match their network architecture, allowing acquisition workflows to upload evidence without requiring workarounds.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Evidence Repository Filtering, Sorting, and Last-Used Details&lt;/h3&gt; 
&lt;p style=""&gt;Evidence repository lists now provide improved filtering and sorting for S3-compatible providers. Repository type and provider values are handled more consistently, including provider names entered as free text.&lt;/p&gt; 
&lt;p style=""&gt;Repositories can also be sorted by last-used information, helping administrators quickly identify active storage destinations and review repository usage patterns. This is useful in environments with multiple organizations, storage providers, or regional evidence destinations.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Access, Authentication, and Governance&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;SSO Custom Claim Mapping&lt;/h3&gt; 
&lt;p style=""&gt;Administrators can now define custom claim mappings for SSO providers. AIR supports mapping identity provider attributes to expected AIR fields such as email, first name, last name, and groups.&lt;/p&gt; 
&lt;p style=""&gt;This improves compatibility with identity providers that use different claim or attribute names. Administrators can adapt AIR to existing identity configurations without requiring custom changes or provider-specific workarounds.&lt;/p&gt; 
&lt;p style=""&gt;The improvement supports both OIDC and SAML-based SSO configurations and helps enterprise teams integrate AIR into established authentication environments more efficiently.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Self-Service 2FA Device Change&lt;/h3&gt; 
&lt;p style=""&gt;Users can now change their authenticator device through a guided self-service flow. The user verifies the current authenticator code, scans a new authenticator secret, and confirms the new code before the old secret is replaced.&lt;/p&gt; 
&lt;p style=""&gt;This provides a graceful transition when users replace a phone, move to a new authenticator application, or update corporate devices. The old authenticator remains valid until the new one is verified, so the account does not lose 2FA protection during the change.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Personal Access Token Access Control&lt;/h3&gt; 
&lt;p style=""&gt;AIR now includes a dedicated privilege for managing personal access tokens. Administrators can control whether users can view, create, edit, or delete personal access tokens.&lt;/p&gt; 
&lt;p style=""&gt;This gives security teams more precise control over API access and automation credentials. Organizations can limit token management to approved roles while preserving existing operational workflows for users who require token-based integrations.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Configurable Audit Logging&lt;/h3&gt; 
&lt;p style=""&gt;Administrators can now configure which event types are written to the Audit Log. The new event filter supports logging all events, logging only selected events, or logging all events except selected events.&lt;/p&gt; 
&lt;p style=""&gt;This helps teams reduce audit noise and focus on activity that matters most to their governance, compliance, and security monitoring requirements. Changes to audit logging configuration are themselves recorded, helping maintain traceability over audit policy changes.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;License Usage Banners&lt;/h3&gt; 
&lt;p style=""&gt;AIR now provides clearer license usage notifications through visible banners at higher usage thresholds. These banners help administrators understand when asset usage is approaching important license limits.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Asset and Task Management&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Selective Auto Asset Tagging Rules&lt;/h3&gt; 
&lt;p style=""&gt;Auto Asset Tagging can now be controlled at the rule level. Administrators can enable or disable individual rules instead of relying only on a global auto-tagging switch.&lt;/p&gt; 
&lt;p style=""&gt;This helps teams run only the tagging rules that are relevant to a specific environment, organization, or customer. MSSP teams can reduce noisy tagging behavior and test new rules without activating every rule in the library.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Bug Fixes&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Investigation Hub advanced filters:&lt;/strong&gt; Fixed an issue where invalid filter options could appear for some columns in the advanced filter panel.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Investigation Hub exclusion activity:&lt;/strong&gt; Fixed an issue where exclusion rule creation activity was displayed incorrectly and was not clickable in the Activity view.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Investigation Hub flags after organization changes:&lt;/strong&gt; Fixed an issue where incorrect flags could be shown or assigned after changing an investigation organization.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;DRONE analysis rerun at scale:&lt;/strong&gt; Fixed a case-level DRONE re-analysis workflow that generated one request and one toast per asset assignment. The workflow now batches the action more effectively and shows a single summary notification, improving usability in large cases.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Exclusion rule modal usability:&lt;/strong&gt; Improved the Exclusion Rule modal layout so action controls remain accessible on common screen sizes and users do not need to search for the submit action inside the scroll area.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Exclusion toast behavior:&lt;/strong&gt; Exclusion confirmation toasts now auto-dismiss after a short duration instead of remaining on screen indefinitely.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Export timestamp precision:&lt;/strong&gt; Fixed an issue where some exported date and time formats did not include seconds. Exported timestamps now provide consistent precision across supported timezone options.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Matched policies after isolation actions:&lt;/strong&gt; Fixed an issue where the Matched Policies section disappeared after isolate or unisolate actions until the page was refreshed.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Policy search:&lt;/strong&gt; Fixed an issue where searching on the Policies page did not filter the displayed policy list.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Cases page search field:&lt;/strong&gt; Fixed a UI issue where the search input on the Cases page was too narrow, making typed text difficult to see.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Task Details table spacing:&lt;/strong&gt; Adjusted default table spacing on the Task Details page to improve readability and screen usage.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;interACT REST polling:&lt;/strong&gt; Fixed an issue where public interACT REST API polling could continue returning an in-progress state after the command had already completed.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;MITRE ATT&amp;amp;CK database version validation:&lt;/strong&gt; Fixed an issue where the API accepted a non-existent MITRE ATT&amp;amp;CK database version before task creation. Invalid versions are now validated earlier.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Backup restore completeness:&lt;/strong&gt; Fixed an issue where a backup archive could miss the primary database dump in larger environments, causing restore results to appear incomplete in the UI.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Backup creation options:&lt;/strong&gt; Removed a misleading unused database option from the backup creation workflow to reduce confusion and avoid unnecessary backup size growth.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Application health after install or upgrade:&lt;/strong&gt; Fixed a health check validation issue that could cause an application container to be reported as unhealthy after a fresh installation or upgrade.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Evidence repository configuration:&lt;/strong&gt; Fixed and refined S3-compatible repository form behavior, provider display, and save handling for repository configuration workflows.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Custom Azure Blob Storage validation:&lt;/strong&gt; Fixed validation so custom Azure Blob Storage domains can be used where supported by the evidence repository configuration.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6783624&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmarketing.binalyze.com%2Fair-release-notes%2Fbinalyze-air-v5-19&amp;amp;bu=https%253A%252F%252Fmarketing.binalyze.com%252Fair-release-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Binalyze AIR</category>
      <category>Release notes</category>
      <pubDate>Wed, 03 Jun 2026 10:06:18 GMT</pubDate>
      <guid>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-19</guid>
      <dc:date>2026-06-03T10:06:18Z</dc:date>
      <dc:creator>Elif Kurt</dc:creator>
    </item>
    <item>
      <title>Binalyze AIR v5.18</title>
      <link>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-18</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-18" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;AIR v5.18 focuses on faster investigation workflows, stronger large-environment scalability, improved responder communication, expanded MITRE ATT&amp;amp;CK database management, and more flexible isolation controls. This release helps cybersecurity and investigation teams work across large asset estates with greater confidence, while giving administrators more control over authentication, evidence repositories, policies, and operational visibility.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-18" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;AIR v5.18 focuses on faster investigation workflows, stronger large-environment scalability, improved responder communication, expanded MITRE ATT&amp;amp;CK database management, and more flexible isolation controls. This release helps cybersecurity and investigation teams work across large asset estates with greater confidence, while giving administrators more control over authentication, evidence repositories, policies, and operational visibility.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6783624&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmarketing.binalyze.com%2Fair-release-notes%2Fbinalyze-air-v5-18&amp;amp;bu=https%253A%252F%252Fmarketing.binalyze.com%252Fair-release-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Binalyze AIR</category>
      <category>Release notes</category>
      <pubDate>Tue, 12 May 2026 09:55:10 GMT</pubDate>
      <guid>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-18</guid>
      <dc:date>2026-05-12T09:55:10Z</dc:date>
      <dc:creator>Elif Kurt</dc:creator>
    </item>
    <item>
      <title>Binalyze AIR v5.17</title>
      <link>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-17</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-17" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;What’s New?&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Structured Data Viewer for JSON, XML, and YAML:&lt;/strong&gt; AIR automatically identifies structured content within evidence and opens it in a dedicated viewer. Analysts can collapse, search, and format data for clearer insight into complex artifacts like system logs or Tornado data.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Policy Cloning:&lt;/strong&gt; Users can now duplicate any existing isolation or acquisition policy. This streamlines the creation of consistent policies across organizations or investigation scenarios, reducing configuration errors and setup time during critical incident response actions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Bulk Import for Isolation Policy Allow Lists:&lt;/strong&gt; Analysts can now import IP/Port or process allow lists in bulk through text or CSV input, expediting creation of large-scale isolation rules for controlled response actions.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;New Features &amp;amp; Improvements&lt;/h2&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Investigation Hub&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Structured Data Viewer – JSON, XML, and YAML&lt;/h4&gt; 
&lt;p&gt;Evidence items that contain structured content can now be examined through a dedicated viewer. When AIR detects JSON, XML, or YAML, users can click &lt;em style="color: #33485b;"&gt;View&lt;/em&gt; to open a read-only panel that uses syntax highlighting, search, wrapping, and toggling between raw and formatted modes.&lt;/p&gt; 
&lt;p&gt;This improves readability of system logs, Event Viewer exports, or Tornado-acquired data, helping analysts to interpret data formats natively rather than extracting them externally. The viewer maintains forensic integrity while improving interpretability for complex datasets.&lt;/p&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Settings&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;User Visibility Enhancements&lt;/h4&gt; 
&lt;p&gt;The Users table now contains fields for &lt;strong style="color: #33485b;"&gt;Created&lt;/strong&gt; (user registration date) and &lt;strong style="color: #33485b;"&gt;Last Active&lt;/strong&gt; (last console interaction). These additions clarify differences between login time and real-time console presence. Analysts and administrators can now see both authentication events and continuous activity, supporting audit and compliance tracking.&lt;/p&gt; 
&lt;p&gt;The “Created” column is sortable, which helps identify new or potentially unauthorized accounts swiftly. “Last Active” reflects the last heartbeat signal received from a user’s browser session, providing insight into actual system usage.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Syslog Configuration Persistence&lt;/h4&gt; 
&lt;p&gt;Syslog configuration updates now apply dynamically without restarting the console. This ensures uninterrupted log forwarding when updating integrations with SIEM or log management platforms during active operations.&lt;/p&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Policies&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Policy Duplication&lt;/h4&gt; 
&lt;p&gt;Policy creation has been simplified with a new &lt;strong style="color: #33485b;"&gt;Duplicate&lt;/strong&gt; action, allowing analysts to clone existing policies, including all filters, allow-list entries, and organization assignments. This is particularly valuable for large enterprises with complex, standardized configurations across multiple operational units.&lt;/p&gt; 
&lt;p&gt;To use this feature, open the Policies view, select a policy row, and choose &lt;em style="color: #33485b;"&gt;Duplicate&lt;/em&gt;. The new policy opens prefilled with the selected configuration, ready for minor adjustments. It significantly reduces preparation overhead when adapting response templates across environments.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Bulk Import for Isolation Allow Lists&lt;/h4&gt; 
&lt;p&gt;Isolation policy configuration now supports bulk entry for IP/Port and process allow lists. Investigators can paste or import multiple rows directly into the configuration dialog, where AIR validates and structures the entries automatically. This improves efficiency for incident containment planning, allowing immediate deployment of network or process restrictions at scale.&lt;/p&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Assets &amp;amp; Task Management&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Asset List and Tagging Stability&lt;/h4&gt; 
&lt;p&gt;Asset list rendering performance has been optimized for high-scale environments with hundreds of online assets. Tag updates, search, and filtering now remain consistent during background polling, ensuring dependable management of large connected fleets.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Creation Date Filters for Tasks&lt;/h4&gt; 
&lt;p&gt;A new “Created At” filter enables analysts to view tasks executed within a specific date or time range. This is useful when correlating console performance or task behavior across simultaneous acquisitions or hunts, particularly during post-incident review.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;DRONE Analyzer State Synchronization&lt;/h4&gt; 
&lt;p&gt;When DRONE’s global toggle is disabled during task configuration, all individual analyzers are now correctly deselected. This clarifies configuration state and prevents unintentional analyzer execution.&lt;/p&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Responder and Evidence Collection&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Disk Space Validation Improvements&lt;/h4&gt; 
&lt;p&gt;The Acquisition Task behavior for disk space thresholds has been updated to ensure decimal input values are handled safely. Analysts can now enter size limits more intuitively without risking misinterpretation during collection jobs.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Enhanced Failure Feedback in Acquisition Tasks&lt;/h4&gt; 
&lt;p&gt;Failure messages during partially completed acquisitions now include clear context about missing or inaccessible evidence, aiding interpretation of collection outcomes and simplifying troubleshooting during live operations.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;macOS Deployment Guidance&lt;/h4&gt; 
&lt;p&gt;The macOS deployment instructions now include a “Do Not Change Filename” advisory, aligning with Windows packaging consistency to prevent deployment misconfiguration for responders installed in secure macOS environments.&lt;/p&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Investigation Management&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Improved Data Export Performance&lt;/h4&gt; 
&lt;p&gt;Exports from the Investigation Hub now cache JSON keys, improve view materialization, and reduce redundant lookups, dramatically enhancing performance when exporting findings from large-scale investigations. Analysts working with hundreds of assets and thousands of findings will experience significant speed gains during CSV export.&lt;/p&gt;  
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Bug Fixes&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Evidence Repository Validation:&lt;/strong&gt; The system no longer performs repository connection checks during interACT task setup when no repository is selected, ensuring consistent and logical validation behavior.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset Polling Instability:&lt;/strong&gt; Asset tags, filters, and column selections now remain stable during polling cycles with hundreds of online assets, preventing data flicker or loss of user selections.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Syslog Configuration:&lt;/strong&gt; Configuration updates are now applied immediately without requiring a restart, ensuring uninterrupted event forwarding.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;DRONE Analyzer Toggle:&lt;/strong&gt; Disabling the master DRONE analyzer now correctly resets each individual analyzer switch in the task creation form.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Decimal Disk Space in Policy:&lt;/strong&gt; Acquisition tasks accept fractional disk space entries and standardize size representation across the UI and backend.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Windows DNS Evidence:&lt;/strong&gt; Evidence collection for Windows DNS Server is restored to return expected results, improving visibility during network infrastructure investigations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;User Interface Corrections:&lt;/strong&gt; Search results no longer display disabled configuration options, and column selections persist as expected when navigating between asset views.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Partial Task Status Clarity:&lt;/strong&gt; Improved error messaging now differentiates between fully failed acquisitions and partially completed evidence collections to reduce confusion in investigation reports.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-17" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;What’s New?&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Structured Data Viewer for JSON, XML, and YAML:&lt;/strong&gt; AIR automatically identifies structured content within evidence and opens it in a dedicated viewer. Analysts can collapse, search, and format data for clearer insight into complex artifacts like system logs or Tornado data.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Policy Cloning:&lt;/strong&gt; Users can now duplicate any existing isolation or acquisition policy. This streamlines the creation of consistent policies across organizations or investigation scenarios, reducing configuration errors and setup time during critical incident response actions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Bulk Import for Isolation Policy Allow Lists:&lt;/strong&gt; Analysts can now import IP/Port or process allow lists in bulk through text or CSV input, expediting creation of large-scale isolation rules for controlled response actions.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;New Features &amp;amp; Improvements&lt;/h2&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Investigation Hub&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Structured Data Viewer – JSON, XML, and YAML&lt;/h4&gt; 
&lt;p&gt;Evidence items that contain structured content can now be examined through a dedicated viewer. When AIR detects JSON, XML, or YAML, users can click &lt;em style="color: #33485b;"&gt;View&lt;/em&gt; to open a read-only panel that uses syntax highlighting, search, wrapping, and toggling between raw and formatted modes.&lt;/p&gt; 
&lt;p&gt;This improves readability of system logs, Event Viewer exports, or Tornado-acquired data, helping analysts to interpret data formats natively rather than extracting them externally. The viewer maintains forensic integrity while improving interpretability for complex datasets.&lt;/p&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Settings&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;User Visibility Enhancements&lt;/h4&gt; 
&lt;p&gt;The Users table now contains fields for &lt;strong style="color: #33485b;"&gt;Created&lt;/strong&gt; (user registration date) and &lt;strong style="color: #33485b;"&gt;Last Active&lt;/strong&gt; (last console interaction). These additions clarify differences between login time and real-time console presence. Analysts and administrators can now see both authentication events and continuous activity, supporting audit and compliance tracking.&lt;/p&gt; 
&lt;p&gt;The “Created” column is sortable, which helps identify new or potentially unauthorized accounts swiftly. “Last Active” reflects the last heartbeat signal received from a user’s browser session, providing insight into actual system usage.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Syslog Configuration Persistence&lt;/h4&gt; 
&lt;p&gt;Syslog configuration updates now apply dynamically without restarting the console. This ensures uninterrupted log forwarding when updating integrations with SIEM or log management platforms during active operations.&lt;/p&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Policies&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Policy Duplication&lt;/h4&gt; 
&lt;p&gt;Policy creation has been simplified with a new &lt;strong style="color: #33485b;"&gt;Duplicate&lt;/strong&gt; action, allowing analysts to clone existing policies, including all filters, allow-list entries, and organization assignments. This is particularly valuable for large enterprises with complex, standardized configurations across multiple operational units.&lt;/p&gt; 
&lt;p&gt;To use this feature, open the Policies view, select a policy row, and choose &lt;em style="color: #33485b;"&gt;Duplicate&lt;/em&gt;. The new policy opens prefilled with the selected configuration, ready for minor adjustments. It significantly reduces preparation overhead when adapting response templates across environments.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Bulk Import for Isolation Allow Lists&lt;/h4&gt; 
&lt;p&gt;Isolation policy configuration now supports bulk entry for IP/Port and process allow lists. Investigators can paste or import multiple rows directly into the configuration dialog, where AIR validates and structures the entries automatically. This improves efficiency for incident containment planning, allowing immediate deployment of network or process restrictions at scale.&lt;/p&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Assets &amp;amp; Task Management&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Asset List and Tagging Stability&lt;/h4&gt; 
&lt;p&gt;Asset list rendering performance has been optimized for high-scale environments with hundreds of online assets. Tag updates, search, and filtering now remain consistent during background polling, ensuring dependable management of large connected fleets.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Creation Date Filters for Tasks&lt;/h4&gt; 
&lt;p&gt;A new “Created At” filter enables analysts to view tasks executed within a specific date or time range. This is useful when correlating console performance or task behavior across simultaneous acquisitions or hunts, particularly during post-incident review.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;DRONE Analyzer State Synchronization&lt;/h4&gt; 
&lt;p&gt;When DRONE’s global toggle is disabled during task configuration, all individual analyzers are now correctly deselected. This clarifies configuration state and prevents unintentional analyzer execution.&lt;/p&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Responder and Evidence Collection&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Disk Space Validation Improvements&lt;/h4&gt; 
&lt;p&gt;The Acquisition Task behavior for disk space thresholds has been updated to ensure decimal input values are handled safely. Analysts can now enter size limits more intuitively without risking misinterpretation during collection jobs.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Enhanced Failure Feedback in Acquisition Tasks&lt;/h4&gt; 
&lt;p&gt;Failure messages during partially completed acquisitions now include clear context about missing or inaccessible evidence, aiding interpretation of collection outcomes and simplifying troubleshooting during live operations.&lt;/p&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;macOS Deployment Guidance&lt;/h4&gt; 
&lt;p&gt;The macOS deployment instructions now include a “Do Not Change Filename” advisory, aligning with Windows packaging consistency to prevent deployment misconfiguration for responders installed in secure macOS environments.&lt;/p&gt;  
&lt;h3 style="color: #33485b; font-size: 26px;"&gt;Investigation Management&lt;/h3&gt; 
&lt;h4 style="color: #33485b; font-size: 22px;"&gt;Improved Data Export Performance&lt;/h4&gt; 
&lt;p&gt;Exports from the Investigation Hub now cache JSON keys, improve view materialization, and reduce redundant lookups, dramatically enhancing performance when exporting findings from large-scale investigations. Analysts working with hundreds of assets and thousands of findings will experience significant speed gains during CSV export.&lt;/p&gt;  
&lt;h2 style="color: #33485b; font-size: 30px;"&gt;Bug Fixes&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Evidence Repository Validation:&lt;/strong&gt; The system no longer performs repository connection checks during interACT task setup when no repository is selected, ensuring consistent and logical validation behavior.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Asset Polling Instability:&lt;/strong&gt; Asset tags, filters, and column selections now remain stable during polling cycles with hundreds of online assets, preventing data flicker or loss of user selections.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Syslog Configuration:&lt;/strong&gt; Configuration updates are now applied immediately without requiring a restart, ensuring uninterrupted event forwarding.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;DRONE Analyzer Toggle:&lt;/strong&gt; Disabling the master DRONE analyzer now correctly resets each individual analyzer switch in the task creation form.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Decimal Disk Space in Policy:&lt;/strong&gt; Acquisition tasks accept fractional disk space entries and standardize size representation across the UI and backend.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Windows DNS Evidence:&lt;/strong&gt; Evidence collection for Windows DNS Server is restored to return expected results, improving visibility during network infrastructure investigations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;User Interface Corrections:&lt;/strong&gt; Search results no longer display disabled configuration options, and column selections persist as expected when navigating between asset views.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong style="color: #33485b;"&gt;Partial Task Status Clarity:&lt;/strong&gt; Improved error messaging now differentiates between fully failed acquisitions and partially completed evidence collections to reduce confusion in investigation reports.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;    
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6783624&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmarketing.binalyze.com%2Fair-release-notes%2Fbinalyze-air-v5-17&amp;amp;bu=https%253A%252F%252Fmarketing.binalyze.com%252Fair-release-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Binalyze AIR</category>
      <category>Release notes</category>
      <pubDate>Wed, 29 Apr 2026 10:41:15 GMT</pubDate>
      <guid>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-17</guid>
      <dc:date>2026-04-29T10:41:15Z</dc:date>
      <dc:creator>Elif Kurt</dc:creator>
    </item>
    <item>
      <title>Binalyze AIR v5.16</title>
      <link>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-16</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-16" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;What’s New?&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;  AIR File Explorer XFS Partition Support: &lt;/strong&gt;  Added support for recognizing and parsing XFS partitions in disk images. Analysts can now browse and analyze evidence from XFS-based assets directly within AIR File Explorer. &lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Expanded Windows evidence coverage in Baseline Comparison: &lt;/strong&gt;Baseline Comparison is enhanced with support for 40+ new Windows evidence sources, along with new section constants and table-to-section mappings to extend comparison coverage across file system activity, registry artifacts, system and network data, SRUM, and other forensic evidence sources. macOS section constants and mappings were also reformatted for improved consistency.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Enhanced RelayPro:&lt;/strong&gt; Upgraded RelayPro with a new toolchain and dependency improvements enhances responder–console communication security and reliability. This ensures uninterrupted evidence transfers and more resilient responder connectivity during large-scale, distributed investigations.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;New Features &amp;amp; Improvements&lt;/h2&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Expanded Windows evidence coverage in Baseline Comparison &lt;/h2&gt; 
&lt;p style=""&gt;Baseline Comparision coverage was significantly expanded through the addition of more than 40 new  Windows evidence items with appropriate identifier fields and ignore fields mappings introduced to support accurate comparison behavior across a broader set of artifacts. To enable these new evidence types throughout the comparison pipeline, 12 new Windows section constants and related table-to-section mappings were also added. In addition, macOS section constants and table mappings were reformatted for more consistent alignment and improved maintainability. &lt;/p&gt; 
&lt;p style=""&gt;The newly supported Windows evidence sources were added across multiple investigation areas, including file system and user activity artifacts such as crash dumps, recycle bin, system restore, downloads, shell bags, LNK files, and jump list data; registry artifacts such as AppCompatCache, UserAssist, Recent Docs, Typed URLs, Office MRU, and Open/Save MRU; system and network data including processes, TCP/UDP tables, ARP table, and volumes; SRUM-based usage artifacts covering application, network, timeline, energy, and connectivity data; and other high-value sources such as Amcache, browser downloads, dependency manifests, PowerShell ConsoleHost history, and user access logs. Through this expansion, broader visibility into Windows activity and configuration data was enabled, allowing change analysis to be performed with greater depth and consistency.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;&lt;strong style="color:#33485b;"&gt;AIR File Explorer XFS Partition Support&lt;/strong&gt; Improvements&lt;/h2&gt; 
&lt;p style=""&gt;Full disk images containing XFS partitions can now be opened in AIR File Explorer, and file types within those partitions are displayed correctly. This improvement was implemented to address cases where XFS-based evidence could be accessed, but file type information was not visible, limiting file review and triage during investigations. With this enhancement, evidence stored on XFS partitions can be examined more effectively, enabling faster validation of file contents and improving confidence in incident analysis for security analysts.&lt;/p&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Responder Communication Optimization&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;RelayPro Dependency and Toolchain Upgrades&lt;/h3&gt; 
&lt;p style=""&gt;This release introduces an updated RelayPro component version that enhances responder–console communication reliability and strengthens encryption handling. The updated communication stack ensures secure transmission during live-response operations and improves failover handling for responders working through restrictive networks.&lt;/p&gt; 
&lt;p style=""&gt;For investigation teams, this means greater confidence in evidence integrity and session reliability during real-time analysis or containment workflows. RelayPro’s enhanced dependency security reduces the risk of communication errors, ensuring uninterrupted connectivity between distributed responders and the AIR Console.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Prevent Avoidable HTTP Requests from Responder&lt;/h3&gt; 
&lt;p style=""&gt;Optimizations have been added to reduce redundant responder–console communication. Responders now suppress duplicate status reports and disable unnecessary retry attempts when a request fails with permanent error conditions (for example, 404, 403, 401 responses). This improvement reduces network overhead during widespread deployments and speeds up recovery during transient connectivity disruptions.&lt;/p&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Bug Fixes&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Incorrect Task Status Display:&lt;/strong&gt; Resolved an issue where task statuses under &lt;em style="color:#33485b;"&gt;Cases → Tasks&lt;/em&gt; appeared inconsistent when the main task was cancelled. Statuses now correctly reflect task outcomes across all views.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Proxy Configuration Not Applied to External Services:&lt;/strong&gt; Corrected a defect where AIR Console’s proxy settings did not apply to outbound traffic for feature management and analytics services. Proxy enforcement is now consistent across all external integrations.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Investigation Hub Report Generation:&lt;/strong&gt; Fixed a failure that prevented report generation from evidence sources while reports from findings succeeded. Evidence-based reports now generate reliably.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Acquisition Task Report Loading:&lt;/strong&gt; Addressed an issue where the Investigation Hub report for certain acquisition tasks remained in a loading state. Reports now open consistently within the console.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Chrome History Acquisition Integrity:&lt;/strong&gt; Improved file copy process for the Chrome History database to reduce the risk of corrupted SQLite files, ensuring analysts can examine browser activity with full integrity preservation.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-16" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;What’s New?&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;  AIR File Explorer XFS Partition Support: &lt;/strong&gt;  Added support for recognizing and parsing XFS partitions in disk images. Analysts can now browse and analyze evidence from XFS-based assets directly within AIR File Explorer. &lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Expanded Windows evidence coverage in Baseline Comparison: &lt;/strong&gt;Baseline Comparison is enhanced with support for 40+ new Windows evidence sources, along with new section constants and table-to-section mappings to extend comparison coverage across file system activity, registry artifacts, system and network data, SRUM, and other forensic evidence sources. macOS section constants and mappings were also reformatted for improved consistency.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Enhanced RelayPro:&lt;/strong&gt; Upgraded RelayPro with a new toolchain and dependency improvements enhances responder–console communication security and reliability. This ensures uninterrupted evidence transfers and more resilient responder connectivity during large-scale, distributed investigations.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;New Features &amp;amp; Improvements&lt;/h2&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Expanded Windows evidence coverage in Baseline Comparison &lt;/h2&gt; 
&lt;p style=""&gt;Baseline Comparision coverage was significantly expanded through the addition of more than 40 new  Windows evidence items with appropriate identifier fields and ignore fields mappings introduced to support accurate comparison behavior across a broader set of artifacts. To enable these new evidence types throughout the comparison pipeline, 12 new Windows section constants and related table-to-section mappings were also added. In addition, macOS section constants and table mappings were reformatted for more consistent alignment and improved maintainability. &lt;/p&gt; 
&lt;p style=""&gt;The newly supported Windows evidence sources were added across multiple investigation areas, including file system and user activity artifacts such as crash dumps, recycle bin, system restore, downloads, shell bags, LNK files, and jump list data; registry artifacts such as AppCompatCache, UserAssist, Recent Docs, Typed URLs, Office MRU, and Open/Save MRU; system and network data including processes, TCP/UDP tables, ARP table, and volumes; SRUM-based usage artifacts covering application, network, timeline, energy, and connectivity data; and other high-value sources such as Amcache, browser downloads, dependency manifests, PowerShell ConsoleHost history, and user access logs. Through this expansion, broader visibility into Windows activity and configuration data was enabled, allowing change analysis to be performed with greater depth and consistency.&lt;/p&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;&lt;strong style="color:#33485b;"&gt;AIR File Explorer XFS Partition Support&lt;/strong&gt; Improvements&lt;/h2&gt; 
&lt;p style=""&gt;Full disk images containing XFS partitions can now be opened in AIR File Explorer, and file types within those partitions are displayed correctly. This improvement was implemented to address cases where XFS-based evidence could be accessed, but file type information was not visible, limiting file review and triage during investigations. With this enhancement, evidence stored on XFS partitions can be examined more effectively, enabling faster validation of file contents and improving confidence in incident analysis for security analysts.&lt;/p&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Responder Communication Optimization&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;RelayPro Dependency and Toolchain Upgrades&lt;/h3&gt; 
&lt;p style=""&gt;This release introduces an updated RelayPro component version that enhances responder–console communication reliability and strengthens encryption handling. The updated communication stack ensures secure transmission during live-response operations and improves failover handling for responders working through restrictive networks.&lt;/p&gt; 
&lt;p style=""&gt;For investigation teams, this means greater confidence in evidence integrity and session reliability during real-time analysis or containment workflows. RelayPro’s enhanced dependency security reduces the risk of communication errors, ensuring uninterrupted connectivity between distributed responders and the AIR Console.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Prevent Avoidable HTTP Requests from Responder&lt;/h3&gt; 
&lt;p style=""&gt;Optimizations have been added to reduce redundant responder–console communication. Responders now suppress duplicate status reports and disable unnecessary retry attempts when a request fails with permanent error conditions (for example, 404, 403, 401 responses). This improvement reduces network overhead during widespread deployments and speeds up recovery during transient connectivity disruptions.&lt;/p&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Bug Fixes&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Incorrect Task Status Display:&lt;/strong&gt; Resolved an issue where task statuses under &lt;em style="color:#33485b;"&gt;Cases → Tasks&lt;/em&gt; appeared inconsistent when the main task was cancelled. Statuses now correctly reflect task outcomes across all views.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Proxy Configuration Not Applied to External Services:&lt;/strong&gt; Corrected a defect where AIR Console’s proxy settings did not apply to outbound traffic for feature management and analytics services. Proxy enforcement is now consistent across all external integrations.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Investigation Hub Report Generation:&lt;/strong&gt; Fixed a failure that prevented report generation from evidence sources while reports from findings succeeded. Evidence-based reports now generate reliably.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Acquisition Task Report Loading:&lt;/strong&gt; Addressed an issue where the Investigation Hub report for certain acquisition tasks remained in a loading state. Reports now open consistently within the console.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Chrome History Acquisition Integrity:&lt;/strong&gt; Improved file copy process for the Chrome History database to reduce the risk of corrupted SQLite files, ensuring analysts can examine browser activity with full integrity preservation.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt;    
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6783624&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmarketing.binalyze.com%2Fair-release-notes%2Fbinalyze-air-v5-16&amp;amp;bu=https%253A%252F%252Fmarketing.binalyze.com%252Fair-release-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Binalyze AIR</category>
      <category>Release notes</category>
      <pubDate>Wed, 15 Apr 2026 07:39:31 GMT</pubDate>
      <guid>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-16</guid>
      <dc:date>2026-04-15T07:39:31Z</dc:date>
      <dc:creator>Elif Kurt</dc:creator>
    </item>
    <item>
      <title>Binalyze AIR v5.15</title>
      <link>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-15</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-15" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;What’s New?&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Enhanced interACT Session Visibility:&lt;/strong&gt; When reviewing historical interACT sessions, the session header now displays the specific task name, helping analysts quickly identify which live-response session they are reviewing—especially when multiple sessions are open in separate tabs. This enhancement improves investigation context and analyst efficiency.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;New Features &amp;amp; Improvements&lt;/h2&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;AIR Settings&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Independent Universal Trusted Certificate Store&lt;/h3&gt; 
&lt;p style=""&gt;Analysts and administrators can now securely add and manage Trusted Certificate Authorities directly within the AIR Console. Previously, this capability was restricted under proxy configuration, limiting flexibility for enterprises performing SSL inspection without proxies or those utilizing self-signed certificates. The new implementation introduces a certificate store independent of proxy settings, ensuring forensically sound authentication and minimizing reliance on manual container-level changes.&lt;/p&gt; 
&lt;p style=""&gt;With this enhancement, organizations using strict SSL inspection or network monitoring can now deploy AIR without interruptions to licensing or updates. This proactive measure enhances compliance and operational continuity in high-security environments.&lt;/p&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;interACT&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Display interACT Task Name in Historic Session Headers&lt;/h3&gt; 
&lt;p style=""&gt;In multi-session environments where analysts review past interACT activities, identifying the correct investigation session can be challenging. AIR now surfaces the task name (for example, “AX-Day2.2”) directly in the session header and browser tab. This improvement enhances visibility and supports faster navigation between concurrent evidence reviews.&lt;/p&gt; 
&lt;p style=""&gt;For investigation workflows, this means analysts can immediately differentiate and correlate live-response sessions without confusion, improving auditability and speed during case validation or retrospective analysis.&lt;/p&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;  Asset Management &lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Expanded Asset Filter Options&lt;/h3&gt; 
&lt;p style=""&gt;The &lt;em style="color:#33485b;"&gt;Registered At&lt;/em&gt; field has been added to the Advanced Filters of the Assets page. Analysts can now filter assets based on their registration timestamp, allowing time-based scoping for both live and historical analysis. This feature streamlines investigation scoping, particularly useful when identifying assets registered during or after a known incident window.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Enhanced Auto Asset Tag Search&lt;/h3&gt; 
&lt;p style=""&gt;Tag search capabilities have been extended to include the content of tags rather than only their names. This improvement increases flexibility when classifying or correlating assets, especially in environments with rich tagging datasets. Analysts can quickly locate assets linked by contextual tag descriptions, enabling faster triage and focused response workflows.&lt;/p&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Bug Fixes&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Large Dataset Upload Timeout:&lt;/strong&gt; Resolved an issue where large acquisition datasets exceeded timeout thresholds during upload or manual PPC processing. Upload stability and dataset handling within Investigation Hub have been improved to maintain continuity across extended acquisitions.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Windows Volume Imaging Issue:&lt;/strong&gt; Fixed a Windows-specific image acquisition bug that caused unexpected failures during remote imaging tasks, ensuring consistent evidence capture across platforms.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;“Key Not Found” and Authorization Errors in Console UI:&lt;/strong&gt; Addressed errors occurring after version upgrades and during access to the &lt;em style="color:#33485b;"&gt;Assets &amp;gt; Disk Images&lt;/em&gt; menu, affecting console usability and access control verification. Global Admin accounts now have consistent authorization visibility.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Git Repository Fork Mode Configuration:&lt;/strong&gt; Resolved a configuration issue preventing edits to repositories in Fork mode where the system incorrectly enforced sync interval parameters.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;AWS Integration Regional Limitation:&lt;/strong&gt; Corrected the synchronization behavior that was prematurely terminating global scans if a single AWS region returned an explicit deny response. AIR now continues enumeration across other regions unaffected.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Investigation Hub Data Handling Errors:&lt;/strong&gt; Fixed the reported null property and missing field exceptions in task processing and data publishing services. These stability fixes ensure that investigation data imports and evidence processing continue without interruption.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Audit Log Performance Enhancements:&lt;/strong&gt; Improved the search and pagination performance for audit logs in environments with very large asset counts. Query execution and caching have been optimized to reduce latency and prevent timeout errors.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Responder Unisolation Feedback:&lt;/strong&gt; Enhanced feedback visibility during asset unisolation attempts. Responders now display clear status information when unisolation fails or is incomplete, improving clarity during containment and recovery operations.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt;   
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Binalyze MITRE ATT&amp;amp;CK Analyzer is now at version 13.0.1&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Microsoft 365 Detection Enhancements&lt;/h3&gt; 
&lt;p style=""&gt;The DRONE Tornado Analyzer now includes new detections focused on Microsoft 365 event telemetry. Analysts can identify unauthorized configuration changes such as modifications to audit log settings, narrowing of cmdlet auditing, external sharing misconfigurations, and reduced retention policies. These detections are critical for identifying unauthorized administrative activity and potential configuration weakening tactics observed in cloud investigations.&lt;/p&gt; 
&lt;p style=""&gt;Additional correlation improvements flag brute-force login attempts, missed MFA flows, suspicious OAuth consent grants, and mailbox permission changes commonly associated with persistence techniques in business email compromise incidents.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Sigma Rule Updates&lt;/h3&gt; 
&lt;p style=""&gt;The integrated Sigma detection library has been synchronized with the latest rule updates from the SigmaHQ and Hayabusa repositories. This alignment expands coverage across both endpoint and cloud telemetry sources, bringing enhanced detection insight into unauthorized script execution, privilege escalation, and registry modification behaviors.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;MITRE ATT&amp;amp;CK Analyzer / YARA Enhancements&lt;/h3&gt; 
&lt;p style=""&gt;Version 13.0.1 introduces YARA-based detection for Covenant C2 Grunt HTTP stager and implant activities. These additional signatures support early identification of adversary-controlled command-and-control frameworks during evidence analysis, increasing the confidence and precision of post-incident findings.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-15" title="" class="hs-featured-image-link"&gt; &lt;img src="https://marketing.binalyze.com/hubfs/Blog/Blog%20Post%20Featured%20Images/Product%20Release.png" alt="Binalyze AIR Release notes" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;What’s New?&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Enhanced interACT Session Visibility:&lt;/strong&gt; When reviewing historical interACT sessions, the session header now displays the specific task name, helping analysts quickly identify which live-response session they are reviewing—especially when multiple sessions are open in separate tabs. This enhancement improves investigation context and analyst efficiency.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="color:#33485b;font-size:30px;"&gt;New Features &amp;amp; Improvements&lt;/h2&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;AIR Settings&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Independent Universal Trusted Certificate Store&lt;/h3&gt; 
&lt;p style=""&gt;Analysts and administrators can now securely add and manage Trusted Certificate Authorities directly within the AIR Console. Previously, this capability was restricted under proxy configuration, limiting flexibility for enterprises performing SSL inspection without proxies or those utilizing self-signed certificates. The new implementation introduces a certificate store independent of proxy settings, ensuring forensically sound authentication and minimizing reliance on manual container-level changes.&lt;/p&gt; 
&lt;p style=""&gt;With this enhancement, organizations using strict SSL inspection or network monitoring can now deploy AIR without interruptions to licensing or updates. This proactive measure enhances compliance and operational continuity in high-security environments.&lt;/p&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;interACT&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Display interACT Task Name in Historic Session Headers&lt;/h3&gt; 
&lt;p style=""&gt;In multi-session environments where analysts review past interACT activities, identifying the correct investigation session can be challenging. AIR now surfaces the task name (for example, “AX-Day2.2”) directly in the session header and browser tab. This improvement enhances visibility and supports faster navigation between concurrent evidence reviews.&lt;/p&gt; 
&lt;p style=""&gt;For investigation workflows, this means analysts can immediately differentiate and correlate live-response sessions without confusion, improving auditability and speed during case validation or retrospective analysis.&lt;/p&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;  Asset Management &lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Expanded Asset Filter Options&lt;/h3&gt; 
&lt;p style=""&gt;The &lt;em style="color:#33485b;"&gt;Registered At&lt;/em&gt; field has been added to the Advanced Filters of the Assets page. Analysts can now filter assets based on their registration timestamp, allowing time-based scoping for both live and historical analysis. This feature streamlines investigation scoping, particularly useful when identifying assets registered during or after a known incident window.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Enhanced Auto Asset Tag Search&lt;/h3&gt; 
&lt;p style=""&gt;Tag search capabilities have been extended to include the content of tags rather than only their names. This improvement increases flexibility when classifying or correlating assets, especially in environments with rich tagging datasets. Analysts can quickly locate assets linked by contextual tag descriptions, enabling faster triage and focused response workflows.&lt;/p&gt;  
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Bug Fixes&lt;/h2&gt; 
&lt;ul style=""&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Large Dataset Upload Timeout:&lt;/strong&gt; Resolved an issue where large acquisition datasets exceeded timeout thresholds during upload or manual PPC processing. Upload stability and dataset handling within Investigation Hub have been improved to maintain continuity across extended acquisitions.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Windows Volume Imaging Issue:&lt;/strong&gt; Fixed a Windows-specific image acquisition bug that caused unexpected failures during remote imaging tasks, ensuring consistent evidence capture across platforms.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;“Key Not Found” and Authorization Errors in Console UI:&lt;/strong&gt; Addressed errors occurring after version upgrades and during access to the &lt;em style="color:#33485b;"&gt;Assets &amp;gt; Disk Images&lt;/em&gt; menu, affecting console usability and access control verification. Global Admin accounts now have consistent authorization visibility.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Git Repository Fork Mode Configuration:&lt;/strong&gt; Resolved a configuration issue preventing edits to repositories in Fork mode where the system incorrectly enforced sync interval parameters.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;AWS Integration Regional Limitation:&lt;/strong&gt; Corrected the synchronization behavior that was prematurely terminating global scans if a single AWS region returned an explicit deny response. AIR now continues enumeration across other regions unaffected.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Investigation Hub Data Handling Errors:&lt;/strong&gt; Fixed the reported null property and missing field exceptions in task processing and data publishing services. These stability fixes ensure that investigation data imports and evidence processing continue without interruption.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Audit Log Performance Enhancements:&lt;/strong&gt; Improved the search and pagination performance for audit logs in environments with very large asset counts. Query execution and caching have been optimized to reduce latency and prevent timeout errors.&lt;/p&gt;&lt;/li&gt; 
 &lt;li style=""&gt;&lt;p style=""&gt;&lt;strong style="color:#33485b;"&gt;Responder Unisolation Feedback:&lt;/strong&gt; Enhanced feedback visibility during asset unisolation attempts. Responders now display clear status information when unisolation fails or is incomplete, improving clarity during containment and recovery operations.&lt;/p&gt;&lt;/li&gt; 
&lt;/ul&gt;   
&lt;h2 style="color:#33485b;font-size:30px;"&gt;Binalyze MITRE ATT&amp;amp;CK Analyzer is now at version 13.0.1&lt;/h2&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Microsoft 365 Detection Enhancements&lt;/h3&gt; 
&lt;p style=""&gt;The DRONE Tornado Analyzer now includes new detections focused on Microsoft 365 event telemetry. Analysts can identify unauthorized configuration changes such as modifications to audit log settings, narrowing of cmdlet auditing, external sharing misconfigurations, and reduced retention policies. These detections are critical for identifying unauthorized administrative activity and potential configuration weakening tactics observed in cloud investigations.&lt;/p&gt; 
&lt;p style=""&gt;Additional correlation improvements flag brute-force login attempts, missed MFA flows, suspicious OAuth consent grants, and mailbox permission changes commonly associated with persistence techniques in business email compromise incidents.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;Sigma Rule Updates&lt;/h3&gt; 
&lt;p style=""&gt;The integrated Sigma detection library has been synchronized with the latest rule updates from the SigmaHQ and Hayabusa repositories. This alignment expands coverage across both endpoint and cloud telemetry sources, bringing enhanced detection insight into unauthorized script execution, privilege escalation, and registry modification behaviors.&lt;/p&gt; 
&lt;h3 style="color:#33485b;font-size:26px;"&gt;MITRE ATT&amp;amp;CK Analyzer / YARA Enhancements&lt;/h3&gt; 
&lt;p style=""&gt;Version 13.0.1 introduces YARA-based detection for Covenant C2 Grunt HTTP stager and implant activities. These additional signatures support early identification of adversary-controlled command-and-control frameworks during evidence analysis, increasing the confidence and precision of post-incident findings.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6783624&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fmarketing.binalyze.com%2Fair-release-notes%2Fbinalyze-air-v5-15&amp;amp;bu=https%253A%252F%252Fmarketing.binalyze.com%252Fair-release-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Binalyze AIR</category>
      <category>Release notes</category>
      <pubDate>Wed, 01 Apr 2026 15:09:37 GMT</pubDate>
      <guid>https://marketing.binalyze.com/air-release-notes/binalyze-air-v5-15</guid>
      <dc:date>2026-04-01T15:09:37Z</dc:date>
      <dc:creator>Elif Kurt</dc:creator>
    </item>
  </channel>
</rss>
