Repository navigation
·
428 commits
to main
since this release
Intact.AI 2026-09-15
Fusion that cannot lose a case, Case Analysis that opens instantly and says one clear thing about the AI model, and a supported way to add Velociraptor tools to an air-gapped appliance.
New
- Add any Velociraptor tool to an air-gapped appliance.
scripts/velo_tools.shlists what the installed artifacts are missing, installs a tool by name on a connected box, or registers files you carry in — including vendor installers and your own binaries. Seedocs/VELOCIRAPTOR_TOOLS_AIRGAP.md. - Collection limits are adjustable per run. Expiry, timeout and CPU are pre-filled from the blueprint and can be changed for a single collection or hunt.
- Refresh the client list in every module, without reloading the page.
- Migrate a risx-mssp Velociraptor fleet onto an installed appliance, with an operator runbook.
Improved
- Case Analysis opens at once. A heavy case shows its previous view while it loads instead of a blank "pick a case" screen.
- One message, one fix. The air-gap and report banners each state a single problem and a single action, and a connected Codex subscription with a blank model field is recognised as available.
- A template report regenerates by itself as soon as a model becomes reachable, or when different AI settings wrote it — immediately, for the case you are viewing.
- A renamed machine is one host. Activity recorded under an earlier computer name is attributed to the current host and labelled as such.
- Collections read correctly. Detections from the same moment form one finding, links point where they should, and hosts match what was collected.
Fixed
- Fusion could fail an entire case with
unhashable type: 'list', leaving no graph. - A Codex subscription with no model selected was reported as "No AI model is selected".
- A failed Gemini model-list refresh could write the API key to the backend log. Rotate any Gemini key that was configured.
- Regenerating a report that reused its previous narrative returned an error.
upgrade.sh --velo-refreshregistered tools under their file names, which no artifact looks up, so re-registered tools were never found.- An uploaded AWS or Azure run was not tied to the active workspace, and Azure did not always report a rules count.
Versions
All module versions are unchanged from 2026-09-03.
Known issues
- The bulk tool download (
options.download_tools) does not verify the hash an artifact pins, and covers only part of the tools artifacts ask for. Usescripts/velo_tools.shfor the rest. - An air-gapped install still ships only the tools the default blueprints use; everything else is added with that script.