Talk to a Binalyzer
Get a free trial
Administrators can now define named, policy-style rules that automatically exclude matching assets from automatic Responder updates.
AIR v5.18 focuses on faster investigation workflows, stronger large-environment scalability, improved responder communication, expanded MITRE ATT&CK database management, and more flexible isolation controls.
What’s New? Structured Data Viewer for JSON, XML, and YAML: AIR automatically identifies structured content within evidence and opens it in a dedicated viewer.
What's New? AIR File Explorer XFS Partition Support: Added support for recognizing and parsing XFS partitions in disk images. Analysts can now browse and analyze evidence from XFS-based assets directly within AIR File Explorer.
What's New? Enhanced interACT Session Visibility: When reviewing historical interACT sessions, the session header now displays the specific task name, helping analysts quickly identify which live-response session they are reviewing—especially when multiple sessions are open in separate tabs. This enhancement improves investigation context and analyst efficiency.
What's New? Git-Managed Triage Rules: Security and investigation teams can now connect their organization’s Git repositories (GitHub, GitLab, Azure DevOps, or Bitbucket) directly to AIR to manage YARA, Sigma, and osquery triage rules as their single source of truth.
New Features & Improvements. AIR Console. MITRE ATT&CK Rules Download Optimization and Resilience.
What's New? Advanced Time Display and Copy Options – The DateTime component within AIR Console now allows analysts to view and copy timestamps in multiple formats including UTC, ISO, local, and relative time.
What's New? Google Cloud Storage support – AIR now supports evidence upload and archival to Google Cloud Storage. This provides analysts and investigation teams with greater flexibility in selecting secure cloud repositories for collected evidence, improving integration with multi-cloud environments and accelerating post-incident data availability for review.
What's New? Google Cloud Platform (GCP) Support: AIR now extends its cloud forensics and asset management capabilities to Google Cloud Platform.
Evidence Collection in Windows Recovery Environment – AIR Windows off‑network responders can now collect evidence while operating inside the Windows Recovery Environment (WinRE).
What's New? Maintenance Mode for Device Assets: Analysts can now place assets into Maintenance Mode to safely prevent task execution while performing diagnostics or hardware maintenance.
What's New? Investigation Hub Live Collaboration and Activity Sync: Analysts can now observe real-time user presence, comment updates, and evidence flag changes within the Investigation Hub.
What's New? DRONE analysis on previously or newly collected evidence files — Analysts can now initiate DRONE analysis directly from the Investigation Hub on any existing evidence file, whether or not it was previously analyzed by a responder.
What's New? Command Snippets in interACT Terminal: Investigators and response teams can customize, execute, and reuse predefined or custom command snippets from within the interACT terminal – streamlining repetitive response operations, improving accuracy, and saving time.
What's New? Redesigned Timeline in Investigation Hub: The Timeline has been rebuilt for speed, precision, and interactivity. Analysts can now run high-performance attribute-based searches, apply advanced evidence-specific filters, and visualize events, findings, and flags in zoomable charts.