Follow the development of Malware INFO, including major feature additions, interface improvements, compatibility changes, and verified bug fixes.
1.2.1
Version 1.2.1 — Major UI/UX Refresh
In Development
Release date
To be announced
Release type
Major user-interface and workflow update
Version 1.2.1 begins a major redesign of the Malware INFO user interface and user experience. The objective is to make complex investigation tools easier to discover, understand, and operate while preserving the evidence-focused workflow of Malware INFO.
Improved
Reorganized navigation for faster access to scanning, investigation, monitoring, and administration tools.
Redesigned major screens to improve readability, spacing, visual consistency, and workflow clarity.
Improved the presentation of scan results, evidence, warnings, and recommended next actions.
Improved feature discovery so users can more easily understand which tools are available in their edition.
Improved consistency between the application interface, built-in Help, Website documentation, and public feature information.
Documentation
Added a public Release History for tracking version changes.
Added Version & Build History to the built-in Help system.
Updated product terminology across Help Center, Website, and GitHub documentation to match the redesigned interface.
Standardized public screenshot names around the current Command Center, Scan Studio, Protection Matrix, Threat Lookup, Advanced Analysis, Administration, and Help Center workspaces.
Bug fixes
Verified fixes will be listed before the public release. Only issues confirmed as resolved in the released build will be included.
1.3
Version 1.3 — Offline Windows Memory Forensics
Future Plan
Release date
Not scheduled
Release type
Planned offline forensic-analysis expansion
Version 1.3 is planned to introduce an independently engineered, Windows-only offline memory-forensics subsystem for Malware INFO. The planned subsystem will examine supported Windows physical-memory images and crash dumps without executing recovered content and without requiring a live target, Live Protection, ETW, Sysmon, or a third-party memory-forensics engine.
Planned investigation areas
Read-only analysis of supported Windows 10 and Windows 11 x64 raw physical-memory images.
Analysis of eligible Windows full crash dumps and kernel crash dumps when the required memory pages are present.
Identification and correlation of processes, threads, loaded modules, user sessions, memory regions, and related system evidence.
Review of private or executable memory, reconstructed in-memory PE evidence, recovered payload candidates, and supported YARA or static-analysis findings.
Examination of validated registry, service, persistence, handle, file-object, and network-endpoint artifacts.
Review of supported kernel modules, drivers, callbacks, timers, devices, and pointer-ownership evidence.
Evidence-based correlation for possible process injection, hollowing, manual mapping, module inconsistencies, and other memory-resident activity.
Core memory parsing, hashing, correlation, extraction, YARA scanning, and reporting are planned to run locally on the analyst's workstation or an organization-controlled system.
Memory images, recovered pages, files, strings, host information, and case evidence will not be uploaded automatically.
Recovered content will be treated as untrusted evidence and will never be executed by the memory-forensics subsystem.
Validation and support boundary
Support will be Windows-build-specific and will be published only after exact symbol identity, parser behavior, and representative fixtures pass validation.
Incomplete, truncated, corrupted, smeared, or missing-page images may produce explicit Partial, Unsupported, Corrupt Input, or Missing Memory results.
Unavailable structure layouts or missing evidence will not be guessed or silently replaced with invented values.
Not included in the initial plan
Live-memory acquisition, malware execution, and credential, password, secret, hash, or key extraction.
x86 or ARM64 memory images, Linux or macOS memory analysis, and hibernation-file decompression.
Proprietary Hyper-V, VMware, or VirtualBox saved-state and snapshot parsing.
Before 1.2.1
Legacy Foundation — Before 1.2.1
Historical Baseline
Release date
Before the Version 1.2.1 redesign
Release type
Pre-1.2.1 product foundation
Before the Version 1.2.1 UI/UX redesign, Malware INFO already provided a local-first investigation environment for examining suspicious files, system activity, indicators, memory evidence, and endpoint artifacts.
Established capability areas
Threat Lookup and indicator investigation.
Rapid Scan, Deep Signature Scan, and Zero-Day Analysis.
Live Protection monitoring for file, registry, process, network, timeline, and memory-related evidence.
Quarantine Vault, Reports & Evidence, Detection Library, and Update Center workflows.
Threat Intelligence, Threat Briefing, Vulnerability Alerts, and licensed-provider intelligence workflows.
Ransomware Shield, Security Connectors, and Startup & Persistence Manager.