Repository navigation
Releases: TenrootOrg/IntactAI
Release list
intact-20261008
Intact.AI 2026-10-08
Timeframe scopes with a report history, an Evidence tab, optional fast AI estimates (Jev), Volatile Memory rebuilt around kept images and a bundled symbol library, a second masking pass that hides names (Presidio), and a rules catalogue that sets what each detection is worth. Covers everything since 2026-09-15 and replaces 2026-10-05.
New
- Presidio name masking. A second masking pass hides person and company names the pattern masker cannot catch before anything is sent to the AI model. It runs in its own container, starts only while a report is being masked and stops when idle, and works air-gapped. It is on by default and has its own toggle under Mask. The case Log lists what each masker hid (
name = Person1), and the report restores the real names. - Masking is on by default for new cases.
- Scopes. Zoom into a suspicious timeframe and it is kept as its own scope, with its own report, hosts and identities. The whole case is always the widest scope.
- Report history. Every report written for a scope is kept, newest first, and can be viewed or exported again.
- Evidence tab. Attach screenshots, e-mails and logs (or paste a picture), with SHA-256, linked to Timeline events and hosts. Evidence appears in the report, the PDF and a new HTML export, and travels with case export/import. It is never sent to the AI model.
- Jev, optional fast estimates. With its own OpenRouter key, Jev suggests a verdict for unreviewed findings, rates each identity's likelihood of being compromised, scores timeframe cards, and flags report statements the evidence does not support. Every figure is marked "(Jev)" and nothing is decided for you.
- Identities. Mark a person Compromised or Not compromised, switch an account off or back on in place, and see each person's findings, hosts and local accounts.
- Risk tab. Explains what drives each host's score, shows host status, and shows whether Velociraptor has the host in Quarantine.
- Case details. Name, status, owner and description, edited in Case Management. A new case opens in a pop-up.
- Volatile Memory. Keep an acquired image and re-analyse it later, upload a dump resumably, pull another case's memory findings by workflow id, and see or upload symbol tables in a new Symbol tables tab.
- Every release ships the Volatility Windows symbol pack inside the VolWeb asset. An upgrade fetches it only when the pack differs, even when VolWeb itself does not change.
- Force regenerate for a report that looks stuck, Settings → Logs for each container's live log, and Timeline search.
Improved
- What a detection is worth is set in one rules catalogue (
config/fusion_weighting.yaml), by pattern, not by product name:- Self-updating software is one low row, not dozens of high ones.
- A versioned or installer copy of a program is not a renamed binary.
- Web-history hits weigh what their category means.
- People using their own servers every day are not lateral movement.
- Real medium-severity SIGMA techniques now become findings, while noisy PowerShell heuristics are turned down.
- The AI narrative cannot rate a case higher than its evidence.
- Fusion. One bad row costs only that row, never the run. Large cases merge evidence much faster. The Log says which step it is on and how fast it is going.
- Timeline. One row per detection episode. A routine collapses to one row and the days that break it stand out. Same-name files are told apart by hash, phase tags are ATT&CK tactics, and rows can be ordered by severity or time.
- Reports. Every phase is written, with or without a model. Containment follows the Risk ranking. Analyst verdicts, identity decisions and Jev estimates reach the report and the chat. Excluded hosts are removed before analysis.
- Slow AI models are given time. Each report call may take up to 10 minutes and is retried once. A call that is unreachable or rejects the key stops further calls, and the report is written offline.
- Chat receives exactly the findings a question is about, and the model can fetch more on its own.
- Identities link a detection to its account by SID.
- Automatic fusion starts 5 seconds after new data lands, never mid-import.
- Memory analysis waits for every plugin VolWeb is still running, and keeps Volatility's symbol index on the volume.
- Velociraptor. A flow on an offline endpoint says so, and
scripts/velo_tools.shis idempotent and skips offline endpoints. - Upgrades bring new modules. A box older than a module gets it from Online Upgrade, Prepare Package and Import Package with nothing to tick.
- Exports (PDF and HTML) share the application's design.
codex loginworks in the terminal that ran the installer.
Fixed
- Evidence text could act as instructions to the case's AI model.
- An uploaded memory dump's file name was passed to a shell.
- Deleting a case could delete another case's evidence.
- A slow model's report was cut off after 5 minutes, and a paused virtual machine timed out a report call on resume.
- A failed overview discarded the phase analyses already written.
- Cancelling a memory run left VolWeb running, and a memory run gave up on plugins that were still running.
- The "Keep image" tick reset on every return to the Memory tab.
upgrade.sh --velo-refreshwrote to a second server, so nothing it registered took effect.- Stopping an upload did not stop the transfer.
- A run could take the id of a stored run.
- Saving Agentic settings started report generation.
Versions
New module: Presidio 2.2.364, with the spaCy en_core_web_lg model built in. Its asset is about 0.9 GB and is downloaded only when its version changes. Every other module is unchanged from 2026-09-15.
The VolWeb asset is about 1.4 GB because it carries the symbol pack.
Known issues
- Presidio can mistake technical words for names (for example
SAMorCritical). The report restores them, but the model reads a placeholder in their place. Turn Presidio off for that case if it gets in the way. - The bundled Volatility pack has no Windows 10 20H2+ or Windows 11 kernels. A connected appliance downloads them from Microsoft on first use. An air-gapped one needs them uploaded in Memory → Symbol tables.
- On Windows 11, Volatility's NetScan finds no connections and NetStat fails (an upstream limitation). Use the Velociraptor collection for that host's network activity.
- The bulk tool download (
options.download_tools) does not verify pinned hashes and covers only part of the tools. Usescripts/velo_tools.shfor the rest.
intact-20260915
Intact.AI 2026-09-15
Fusion that cannot lose a case, Case Analysis that opens instantly and says one clear thing about the AI model, and a supported way to add Velociraptor tools to an air-gapped appliance.
New
- Add any Velociraptor tool to an air-gapped appliance.
scripts/velo_tools.shlists what the installed artifacts are missing, installs a tool by name on a connected box, or registers files you carry in — including vendor installers and your own binaries. Seedocs/VELOCIRAPTOR_TOOLS_AIRGAP.md. - Collection limits are adjustable per run. Expiry, timeout and CPU are pre-filled from the blueprint and can be changed for a single collection or hunt.
- Refresh the client list in every module, without reloading the page.
- Migrate a risx-mssp Velociraptor fleet onto an installed appliance, with an operator runbook.
Improved
- Case Analysis opens at once. A heavy case shows its previous view while it loads instead of a blank "pick a case" screen.
- One message, one fix. The air-gap and report banners each state a single problem and a single action, and a connected Codex subscription with a blank model field is recognised as available.
- A template report regenerates by itself as soon as a model becomes reachable, or when different AI settings wrote it — immediately, for the case you are viewing.
- A renamed machine is one host. Activity recorded under an earlier computer name is attributed to the current host and labelled as such.
- Collections read correctly. Detections from the same moment form one finding, links point where they should, and hosts match what was collected.
Fixed
- Fusion could fail an entire case with
unhashable type: 'list', leaving no graph. - A Codex subscription with no model selected was reported as "No AI model is selected".
- A failed Gemini model-list refresh could write the API key to the backend log. Rotate any Gemini key that was configured.
- Regenerating a report that reused its previous narrative returned an error.
upgrade.sh --velo-refreshregistered tools under their file names, which no artifact looks up, so re-registered tools were never found.- An uploaded AWS or Azure run was not tied to the active workspace, and Azure did not always report a rules count.
Versions
All module versions are unchanged from 2026-09-03.
Known issues
- The bulk tool download (
options.download_tools) does not verify the hash an artifact pins, and covers only part of the tools artifacts ask for. Usescripts/velo_tools.shfor the rest. - An air-gapped install still ships only the tools the default blueprints use; everything else is added with that script.
intact-20260903
Intact.AI 2026-09-03
A clearer, more accurate incident report, faster Velociraptor collection, and fusion that stays stable on large cases.
New
- Phase-based incident report. Broad incidents are split into timeframes, each analysed on its own; narrow incidents get a detailed, focused report.
- Use your own Codex subscription for AI analysis.
- Fetch without re-collecting. Retrieve data Velociraptor already holds, including from stopped collections, without touching the endpoint.
- Automatic retention of Velociraptor monitoring data.
Improved
- More accurate reports. Every severe finding is covered, invented hashes are flagged, and command lines appear in full. Validated against 41 simulated attack scenarios.
- ATT&CK techniques are mapped for many more findings.
- Live progress. Case Analysis shows which analysis step is running and displays the report as soon as it is ready.
- Reports refresh automatically when new data arrives.
- Collections are lighter. Blueprints use at most 50% of an endpoint's CPU, and only data that analysis uses is retrieved.
- More detections reach the analyst, including memory YARA, webshells and MFT anti-forensics.
- Purge accurately reports and frees disk space. The branded PDF has cleaner typesetting.
Fixed
- Fusion could exhaust memory and take the appliance down on large cases.
- Detections could be lost on some Windows event records.
- A failed Velociraptor collection was treated as finished.
- An air-gapped upgrade using a package directory could silently run online.
Versions
All module versions are unchanged from 2026-08-25.
Known issues (fixed in the next release)
- Fusion can fail with
unhashable type: 'list'on some combinations of collected data. - A Codex subscription with no model selected is shown as "No AI model is selected".
- A failed Gemini model-list refresh can write the API key to the backend log. Rotate any Gemini key that was configured.
intact-20260825
Intact.AI 2026-08-25
Upgrade straight to any newer release, install and upgrade reliably without internet, and a Case Analysis that writes the report for you and keeps it current.
New
- Upgrade to any newer release in one step, online or air-gapped. The new release's own engine performs the upgrade.
- Portable cases. Export a case with its evidence, and import it on another appliance.
- Automatic fusion. New data joins its case by itself, and the report explains when it has no narrative.
Improved
- Case Analysis reports are written by the configured AI model by default and cover every host.
- Model settings show the real cost of the selected model, list subscription models, and explain connection problems clearly.
- Configuration is preserved across upgrades.
Fixed
- 13 issues found in air-gapped installation.
- An upgrade could replace the Velociraptor certificate authority, disconnecting enrolled endpoints. A recovery tool is included for affected appliances.
- A second fusion running at the same time could overwrite analyst work.
- Changing a finding's triage status failed.
- The same account written two ways appeared as two identities.
Versions
Velociraptor 0.77.2 · IRIS v2.4.29 · Portainer 2.39.6 · nginx 1.31.3
Known issues
- On very large cases, fusion can exhaust memory. Fixed in 2026-09-03.
- Fusion can fail with
unhashable type: 'list'on some combinations of collected data. Fixed in the next release.
intact-20260811
This release replaces the appliance's authentication, closes a broad set of security findings, and rebuilds the upgrade system from the ground up.
Authentication
nginx Basic Auth is gone, replaced by a real session login. The dashboard now has its own login page backed by a proper auth service, with the operator choosing the dashboard password in config.yaml — or setting it on first launch, instead of the appliance inventing one nobody can find. Sessions survive a backend restart, and the "configured but no credential" state that could lock an operator out of their own box now repairs itself at boot.
Security
Multiple hardening passes across the platform:
- Network exposure — Velociraptor and Logstash management ports are no longer published on every interface. The Timesketch data stores and the Portainer agent were taken off the shared network, and the Portainer agent is now authenticated.
- Credentials — Timesketch moved off its shipped default database credential. Secrets no longer reach logs that leave the box, the installer's config summary, built images, or git. World-readable secret files are corrected on both the install and upgrade paths.
- Input handling — closed a host-picker XSS, stopped rendering uploaded filenames as HTML, put a single admission policy on operator-supplied archives, locked the PDF report renderer to embedded resources, and added client-ID validation at the VQL sinks.
- Supply chain — the installer records what it actually ran, packages can be anchored by an operator, and CI is hardened against ever shipping key material.
New upgrade engine
The in-container Python upgrader (~25,900 lines) has been replaced by a host-side engine roughly a fifth the size. It runs from the shell and talks only to Docker and the checkout — so it works when the backend is stopped, crash-looping, or was never installed, which is exactly when upgrades matter.
- Per-module transactions that roll back on failure, with data protected explicitly: Velociraptor's CA is verified unchanged, Timesketch takes a
pg_dumpand refuses a Postgres major migration if that dump failed. - A health gate that separates degraded from broken, so a normally-yellow single-node cluster no longer triggers a false rollback.
- Packages are checksum- and tar-slip-verified before anything is applied; downgrades are refused rather than half-attempted.
- Stop/Ctrl-C now unwinds the in-flight module and reclaims its extraction scratch instead of abandoning the run.
The dashboard upgrade cards remain. They launch a detached helper that runs the same engine, so there is one upgrade implementation — not two.
intact-20260726
Intact.AI — 2026-07-26
Cut from main. 392 commits since intact-20260615
(2026-06-17 → 2026-07-26). The headline is Case Analysis / Entity Fusion: a
cross-module, cross-host correlation engine built from scratch this cycle, plus a
second wave of upgrade hardening (Full-mode backend image, resumable two-phase
upgrades, CI-built packages) and a full frontend/backend decomposition.
Case Analysis & Entity Fusion (new)
A deterministic graph engine fusing every module's output — Velociraptor
collections/hunts/offline imports, AWS/Azure scans, CVE findings, TimeSketch
timelines — into one cross-host case graph with a report, attack-story synthesis,
and chat.
- Ontology + mappers — per-module mappers, hash-identity bridge (same binary
across hash algorithms → one node), auth/Kerberos + lateral-movement
enrichment, Hayabusa detection linking. - Correlation — baseline subtraction (environment-normal noise suppression,
extended to all detections, not just SIGMA), corroboration, cross-host and
coordinated-activity findings, spawn chains, WMI persistence (T1546.003), and
fleet-relative host risk scoring (0–100, p95-based). - Identities tab — the same real-world person/account resolved across
endpoint, AWS and Azure. Norm clustering with an accuracy harness,
evidence-corroborated auto-merge, one row per logical relationship (was O(n²)
pairwise noise), confidence scores, same-name dedup with a "stale" hint.
Analyst confirm/decline persists across every re-fusion. - Reporting — a DFIR-grade rewrite, decoupled from the fuse step. The case is
now the only reporting surface (dead per-run LLM/report code removed from
AWS, Azure, agentic and memory). Adds an Attack Assessment prose synthesis,
a single flat timeline, one consolidated IOC appendix, andreport_detail
(Auto/Explicit/Summary) controlling evidence volume per finding.
Masking: dynamic identity masking with a revert path, stable per-identity
numbering, identifier-boundary-aware matching, a complete pre-LLM audit log
(was truncated at 500 chars), a closed leak (AWS IAM principals reaching the
LLM unmasked), and a 233s → 3.6s mask-build fix that unblocked large cases. - Operator workflow — unified Timeline with reversible 4-state triage, Case
Analysis Log tab, chat over the fused graph, and a cross-case knowledge base
(Elasticsearch-backed, enrichment-only). - Fixes — a degenerate time window (start == end) silently dropped every
timestamped entity, leaving a graph with entities but zero relationships; the
offline-import hunt-id parser lost the id on multi-client imports and silently
skipped fusion; refusion now streams live per-phase%instead of a silent wait.
Decomposition
Frontend (Phase A–F): DaisyUI 4 + a de-neon professional dark theme, all 14
tabs extracted into partials/*.html, app.js (1,692 lines) split per-store, and
a local build replacing the CDN-loaded downloads page.
Backend (Phase G): six 1,100–2,000-line monoliths split into sub-packages —
the entire agentic/ package plus iris_service.py (1,971 lines).
Collect-only pivot: every module is now a collector; automation_type: agentic → velociraptor_collection.
Modules
- AWS — off Prowler entirely to native CloudTrail detection via a pinned
SigmaHQ pack (aws_sigma). Custom SIGMA rule management for AWS and Azure;
the shared SigmaHQ clone moved offHEAD(unreproducible — two installs got
different rules on the same pin) onto a monthly release tag. Module IDs migrated
live, carrying enable flags forward. - IRIS — ships disabled by default; self-heal rotates its web TLS cert on
every bring-up;config.yamlis authoritative for the admin password. - VolWeb / Memory — the daphne OOM under YARA serialization is closed at the
source (worker recycling + arena cap) after threemem_limitbumps. Adds a
severity-ranked findings report, per-blueprint YARA scoping, plugin row cap
80 → 250, and drops YARA-Forge. YaraScan results now survive both a timeout and
an auto-purge. - Scheduler / clients — Collector and Hunt scheduling split apart, interval
units (days→years) anchored to a start date, every picker unified onto one
facetedClientManager. - Velociraptor — label-targeted hunts, OS-aware collection (real Linux
support), artifact bundle baked into the image.
Upgrade pipeline
- Full image-per-release backend (Wave F) — the backend runs from a baked
intact-backend:<release>image with zero code bind-mounts, swapped atomically
on upgrade instead of rebuilt from source on the box. - Waves A–E — host preflight, tusd version-pinning + recreate-on-bump,
floating image tags pinned, SIGMA content clone pinned. - Two-phase hardening (~10 iterations) — single-writer lock, restart handoff,
CA guard, package integrity, a source snapshot + compile gate before restart
(anti-brick), a resumable Phase 2, a boot watchdog, and a health gate that
checks the backend image, not just liveness. - CI builds the version-pinned release package, replacing on-box building.
Packages are diff-scoped (only modules changed since the previous release),
carry a byte-size manifest, and size the disk preflight from the real package. - Self-heal drift detection now compares a source content fingerprint (image IDs
aren't reproducible across separate builds). - Fixed: a
run_command()deadlock on >64 KB of stdout; a catastrophic-regex spin
that could hang an upgrade indefinitely (+ afaulthandlerSIGUSR1 hook); the
health gate counting run metadata as modules; andStopcancelling the UI's
view of a run rather than the upgrade itself.
Workspaces
Strict per-case runs — every module run, TUS upload and memory-dump XHR is tagged
to the active workspace. Case Management and Case Analysis split into dedicated
surfaces with a System workspace carved out from real cases; launching a
system feature switches into it, and a module launched while System is active
auto-redirects to Default. Full workspace export/import. Purge no longer wipes
client installers or corrupts installer state, preserves cases, cleans
Velociraptor clients, and gains an orphaned-containerd-images category.
Security & install
Pre-commit secret guard blocking tokens before they enter git history; a shipped
Slack webhook scrubbed from the Velociraptor bundle; options.github_token for
authenticated API calls (60 → 5,000 req/hr). Tools inventory gated by
options.download_tools (off by default). change_ip is now force +
non-interactive, rotates the TLS cert in place, reloads every consumer, and runs
fully air-gapped. The test suite is consolidated into intact/tests/ behind one
runner (+74 tests, plus an API-validation contract suite);
docs/UPGRADE_CONTRACT.md is enforced by tests, not just documented; and CI
checks that tests/ never ships in a release tarball.
Version pins
versions:
elk: 9.4.2 # unchanged
iris: v2.4.27 # unchanged
plaso: '20260512' # unchanged
portainer: 2.39.5 # was 2.39.1
timesketch: '20260630' # was 20260611
velociraptor: '0.77.1' # was 0.76.6
aws_sigma: '2026.04' # replaces prowler: 5.28.1 (module migration)
sigma_rules: 'r2026-07-01' # NEW — pins the full SigmaHQ clone
o365rc: 'latest' # unchanged
velociraptor_legacy: '0.7.1' # unchanged
volweb: '3.16.0' # unchanged
backend: '<release-name>' # Full-mode (Wave F) — was a static 1.0.0Source
intact-20260615
Intact.AI release — 2026-06-15
Cut from the main branch. Everything from
intact-20260609 plus ~110 commits. This is a
pipeline-hardening release focused on upgrade correctness and air-gap
completeness: transitive container pins become a single source of truth in
config.yaml, the upgrade flow merges the new release's pins into the operator's
config, and VolWeb YARA + Velociraptor tooling ship inside the package for offline
installs.
This tag intentionally pins to an older module baseline (see Version pins) so it
can be installed first and upgraded forward into a newer tag to exercise the upgrade
flow end-to-end.
Transitive sidecar pins → config.yaml (headline)
The old live-scrape of each module's upstream docker-compose (via
transitive_resolver.py + an in-memory/disk cache + a defaults table) is gone. It
produced silent install-vs-upgrade drift — an operator hit it on 2026-06-14 when
install used postgres:15 (compose default) while upgrade scraped upstream's
postgres:13.0-alpine, and postgres-13 then refused to start against postgres-15 data.
- Single source of truth: every sidecar (
postgres/opensearch/redis/
nginx/rabbitmq) is now pinned explicitly underversions:inconfig.yaml
with a<module>_<sidecar>naming convention. - Both online and offline (air-gap) paths read the SAME entries via the bundled
manifest; pins are stamped into each module's.envbefore itsdocker compose up. - Prepare-time scraping + the obsolete drift-detection CI workflow were removed.
Config-aware upgrade
- The upgrade now merges the new release's
versions:block into the operator's
config.yamlbefore prepare reads it, with per-module backup/revert, smart
insertion, and safety assertions — so a box picks up new pins without clobbering
operator edits. - Prepare reads the target release's
config.yamlfor transitive pins (not the
build host's).
Air-gap completeness
- VolWeb YARA rulesets are bundled and auto-seeded on install and upgrade;
YARA-Forge is pulled from the release asset, not the source tree. - Bundle Velociraptor tools, backfill artifacts, and enable installed modules
so an offline box comes up complete.
Velociraptor
- Pre-stage the
velociraptor-collectorbinary for Hunt-collector generation. - Collector serves locally (no runtime internet round-trip); VolWeb compose-up race
gets a retry. - Refresh offline-collector downloads on upgrade (fixes the greyed-out musl
installer button).
Install resilience
- Wait for the dpkg lock before apt steps; Dockerfile build retries.
- Preflight + compose-up retry + skip-already-installed + journal dump on failure.
install_*_offlinebootstraps.envfrom scratch (fixes UI-driven fresh
install); timesketch postgres compose default aligned with the upstream pin.- Memory pipeline survives a VolWeb restart.
Upgrade pipeline fixes
- Pre-load all bundled images before the Phase-2 module loop; timesketch + volweb
offline upgrade load their sidecar image tars. - Always restart the backend after an intact upgrade (fixes a split-run footgun);
intactnever no-ops — prepare/online allow an intact-only refresh. - Stamp transitive pins in the Phase-2 resume (fixes a missed
redis:7-alpine). - Add VolWeb to
resume_upgrade_workflow's upgrade order.
UI
- The apply-package modal shows current vs target versions and filters downgrade
references; the online-upgrade / prepare-package modal flow is streamlined. - Null-safe the upgrade-modal
x-textexpressions (silences Alpine console errors);
drop the noisy "use the Apply card" hint from the upgrade-package upload log.
Module id cleanup
aws_prowler→prowler,azure_dfir_o365rc→o365rc(config keys).
Version pins
This tag pins to an older module baseline (install-then-upgrade testing):
versions:
elk: 9.4.2 # was 9.3.3
iris: v2.4.26 # was v2.4.27 (baseline)
velociraptor: '0.76.1' # was 0.76.5 (baseline)
prowler: '5.28.1' # renamed from aws_prowler
o365rc: 'latest' # renamed from azure_dfir_o365rc
# NEW — external sidecar pins now live here (single source of truth):
timesketch_opensearch: '2.11.0'
timesketch_postgres: '13.0-alpine'
timesketch_redis: '7-alpine'
timesketch_nginx: 'alpine'
iris_rabbitmq: '3-management-alpine'
volweb_postgres: '14.1'
volweb_redis: '7'Backend/module compose files now enforce a stamped .env via ${VAR:?} — stamp
.env before docker compose down.
Known issues
- Carried over: velociraptor downgrade crash, legacy v0.7.x post-upgrade disable,
run_command>64 KB stdout deadlock. docker compose downrequires a stamped.env(from the${VAR:?}enforcement
introduced this release).