🛠Maintenance duration: 2h30
Version: 0.0.4.7_Stable
➤ Added
- Users can now delete their generated reports
- Confirmation step added before deletion
➤ Improvements
- Enhanced RxBot Assistant:
- Added guidance for downloading previous submissions
- Added instructions for deleting generated reports
➤ New Features
- Added new Process Chain section in PDF reports
- Introduced analytical phase-based reading:
- Drop Phase
- Execution Phase
- Persistence Phase
- Reputation Phase
- New JSON fields:
- attack_phases
- process_analysis.process_chain
- process_analysis.process_chain_count
➤ Improvements
- Major improvement in analyst readability with more narrative report structure
- Added compact mode for Process Chain to reduce visual noise on large sessions
- Added PDF bookmark for quick access to Process Chain section
➤ Fixes
- Fixed YARA false positives on legitimate system artifacts (e.g., Defender mpengine.dll)
- YARA matches related to Microsoft/Defender context are now downgraded to informational-only in analyst view
- Raw data remains available for expert investigation and traceability
➤ JSON / Data Model
- Enhanced YARA section with analyst-focused fields:
- analyst_matches
- analyst_matches_count
- analyst_high_confidence_count
- analyst_suspicious_count
- analyst_informational_count
- analyst_filtered_count
- analyst_filtered_reasons
- Backward compatibility maintained with existing fields
- Minor optimizations
- Minor optimizations
- Slight hardening of VLAN rules for VMs
- Minor optimizations (latency caused by VM not fully initialized improved)
- VM video recording feature still in development
- Ongoing work to reduce VirtualBox detection by malware