AshES CTI - Changelog
Last updated: April 7th, 2026
Version 1.3.1: Performance Refinement
Changes
- Improved application startup performance for a smoother launch experience
- Cleaner IOCs view with reduced low-signal noise
Version 1.3: IOC Visibility, Detection Support & UI Enhancements
Highlights
- Dedicated IOCs view with enrichment and filtering
- SNORT rule ingestion and export support
- Customizable UI with themes and settings
Features
- New IOCs tab for browsing extracted indicators
- Displays IOC value, type, observed timestamp, and enrichment data
- IOC enrichment fields include VirusTotal hits, first seen, and last enriched timestamp
- Filtering support in the IOCs view (by IOC value and type)
- Clickable IOCs open corresponding VirusTotal pages (hashes, IPs, domains)
- Search support for keywords and IOCs in the Items view
- Adjustable display counts for the IOCs view (50 / 100 / 250)
- Added Settings menu for UI configuration and utility actions
- Introduced 6 UI themes with persistent selection stored in the local SQLite database
- Manual in-app update checking via Settings (opens download in browser)
- SNORT rule ingestion and export
Version 1.2 : Intelligence Ingestion & Multilingual Support
Highlights
- Expanded intelligence ingestion capabilities
- Multilingual threat intelligence support
- Improved indicator extraction from threat reports
Features
- Chinese (CJK) UI rendering support for multilingual threat intelligence sources
- STIX bundle ingestion via CLI
- Bulk IOC import from CSV files
- PDF intelligence ingestion with automated artifact extraction
- Enhanced IOC extraction including domains and URLs
- Automatic normalization of defanged indicators (e.g. hxxp → http, [.] → .)
- Chinese-aware summarization improvements for multilingual reports
- Enhanced summary readability using a custom text layouter
- Minor UI typography improvements
Version 1.1
User Interface
- Added UI buttons to display 50, 100, and 250 items from the DB.
- Implemented Export YARA button in the UI.
- Artifact table entries can be exported as:
- Individual YARA rule files
- A consolidated YARA bundle for SIEM ingestion
Ingestion & Processing
Version 1.0.0 : Release
Highlights
- Stable production release
- Improved ingestion reliability
- Refined summarizer accuracy across multiple sources
Changes
- Reduced false positive rate during TAXII ingest.
- Improved Sophos summary output.
- Added CISA and additional government intelligence feeds.
- Added CLI option to manually enter new IOCs.
- Minor UI improvements and stability fixes.
Version 1.0.0-beta : Closed Beta
Highlights
- Initial closed beta release
- Full UI + CLI support
- Offline-focused workflow
Features
- OSINT feed ingestion
- Offline IOC enrichment
- MITRE ATT&CK mapping
- STIX/TAXII export
- Windows-native UI
- Lightweight, self-contained installation
- No telemetry; fully offline workflows