New and updated
- The AXIOM Process CLI is now set to process using 32 threads (when available), conducts de-duping of artifact hits and generates logs for all search types by default.
- You can now add a Stop for merge element to your workflows. If the workflow is used in conjunction with a merge workflow, the current branch of execution exits at the stop point and proceeds with the merge workflow. This feature allows you to reuse the same base workflows for single and multi-item cases, reducing duplication.
- Added support for AXIOM post-processing tasks, including Connections, CPS matching, Chat thread building, and Timeline. you can add this functionality to your workflows using the AXIOM Post-processing element.
- The behavior for copying and canceling case outputs has changed. Previously, after each step in a workflow, the output for that step would be copied to the final output location. Now, AUTOMATE waits until all steps are completed to do any copying. This change has also impacted what happens when you cancel a case. Previously, when you cancelled a case, the case cancelled immediately as any case files that had been created were already copied to the final output location. Now, if you click cancel, AUTOMATE will begin copying files to the output location. Clicking cancel a second time skips the copying step and any completed workflow outputs get discarded.
Bug fixes
- In cases that processed FAT or APFS filesystems, exports created using AXIOM Exporter would be missing file attachments for live/allocated files in all export types (VICS JSON, HTML, PDF, etc). A new log file has been added (exporter.log) to identify any missed/dropped file attachments. -AUTO-1321
- VICS exports had source path and filename information mixed up or sometimes missing for live or allocated files. -AXE-7546
- If you created a case, but communication with the back end service had failed, you might have cases display on the dashboard that don't actually exist. Requesting logs for those cases would result in errors. Now, the request completes without errors but doesn't contain logs. -AUTO-1275
- Using an artifact template with the AXIOM Process CLI was yielding different results than using the same template with the UI.
- AXIOM Process was not creating logs while searching some image types.
- The My cases only filter was not filtering out other cases. -AUTO-1281
- The Completed cases section of the dashboard wasn't showing the correct number of cases as per the user's selection. -AUTO-1297
- When you expanded cases on the Dashboard, the names of the nodes that were running a case would disappear. -AUTO-1280
- The duration of a run was being calculated from the time the user initiated the run, rather than when the run actually started processing. -AUTO-1282
- Retrying a case wasn't clearing all the case files from the initial attempt before it started, resulting in the same piece of evidence being scanned into a single case file multiple times -AUTO-1210
- AXIOM Exporter would sometimes fail if more than one user initiated runs on a single case. -AUTO-1208
- Merging cases that include an IP address in their case paths would cause the case merge CLI to crash and lock the case files. -AUTO-1295
Tips
- You can create media categorization summary reports and chat thread visualization reports by adding AXIOM Exporter as a custom app and specifying the appropriate command line arguments
- You can set a timezone to be used for reports by adding the exporter as a custom app and specifying the appropriate command line arguments.
- You can use an all content keyword search by adding AXIOM Process as a custom app and specifying the appropriate command line arguments.