Talk to a Binalyzer
Get a free trial
Administrators can now define named, policy-style rules that automatically exclude matching assets from automatic Responder updates.
Binalyze Announces Strategic Technical Services Partnership with DIFOSE to Strengthen Capabilities in Türkiye
AIR v5.18 focuses on faster investigation workflows, stronger large-environment scalability, improved responder communication, expanded MITRE ATT&CK database management, and more flexible isolation controls.
A follow-up to: "Handala and the New Face of Iranian Cyber Warfare" If you read the last post, you already know where I land on Handala. I don't buy the idea that this is just a loose hacktivist crew freelancing online. It looks a lot more like a state-backed Iranian operation wearing a hacktivist mask.
The shot came at 3:30 a.m. Eastern. While most of the U.S. was asleep, more than 200,000 devices across 79 countries went dark. Laptops. Mobile phones. Medical workstations. On the Entra login page for one of the world's largest medical technology companies, employees were greeted by a symbol: the cartoon of a barefoot Palestinian child, arms crossed behind his back, staring at the horizon.
What’s New? Structured Data Viewer for JSON, XML, and YAML: AIR automatically identifies structured content within evidence and opens it in a dedicated viewer.
What's New? AIR File Explorer XFS Partition Support: Added support for recognizing and parsing XFS partitions in disk images. Analysts can now browse and analyze evidence from XFS-based assets directly within AIR File Explorer.
What's New? Enhanced interACT Session Visibility: When reviewing historical interACT sessions, the session header now displays the specific task name, helping analysts quickly identify which live-response session they are reviewing—especially when multiple sessions are open in separate tabs. This enhancement improves investigation context and analyst efficiency.
New capability enables security teams to proactively search file contents across endpoints, whilst also enabling faster, more accurate investigation and response
What's New? Git-Managed Triage Rules: Security and investigation teams can now connect their organization’s Git repositories (GitHub, GitLab, Azure DevOps, or Bitbucket) directly to AIR to manage YARA, Sigma, and osquery triage rules as their single source of truth.
The quiet problem we’ve accepted Let’s be honest about how most investigations actually work today.
If you’ve ever been in a security operations center (SOC), you know the feeling. It’s like trying to drink from a firehose. Thousands of alerts pour in every day, and your team is overwhelmed, trying to figure out which ones are real fires and which are just false alarms.