Blackbird is missing a glaringly obvious feature that all malware analysis tools must have. Network analysis!
To be integrated:
- HTTP callout/connections
- DNS resolution
- Connections, endpoint, operations, bytes sent/received
- Blocking and masking controls that are safe for Community builds
- Public threat detection rows from local telemetry
Public migration notes
Current validation work maps to Community as local network-analysis QA only. This public lane should stay focused on the driver, sensor, controller, runner, and WPF interface surfaces that exist in Community.
Acceptance criteria
- Live and replayed captures populate HTTP, DNS, connection, and threat rows correctly.
- Network rows preserve endpoint, host, PID, source, and evidence fields in copy/details flows.
- Counts and history survive process/session switching.
- Public UI text stays focused on Community capabilities and does not advertise private orchestration features.

Blackbird is missing a glaringly obvious feature that all malware analysis tools must have. Network analysis!
To be integrated:
Public migration notes
Current validation work maps to Community as local network-analysis QA only. This public lane should stay focused on the driver, sensor, controller, runner, and WPF interface surfaces that exist in Community.
Acceptance criteria