AIL Framework v7.1 brings a wide range of new features and improvements across forum collection, interactive crawling, image analysis, trackers, APIs, PDF processing, and analyst workflows.
This release expands AIL's forum and crawler capabilities, introduces new image-similarity features, improves tracker management and filtering, adds new APIs, and includes numerous usability, performance, and security fixes.
Interactive crawler
AIL v7.1 introduces and expands interactive browser sessions for crawler workflows.
Instead of relying only on automated crawling, an analyst can open a live browser session and interact directly with the target website before continuing collection.
Interactive sessions can be used to:
- Manually navigate a website or domain to reach the content that should be collected.
- Log in manually when authentication cannot or should not be fully automated.
- Complete CAPTCHA or other interactive challenges presented by the website.
- Navigate multi-step authentication or access workflows.
- Create and preserve a cookiejar from the authenticated browser session.
- Use the resulting authenticated session for subsequent forum and crawler tasks.
- Repair a forum account while keeping and updating its existing cookiejar.
- Enable JavaScript when required by a target.
- Capture content from the interactive browser session.
- Cancel an interactive session when it is no longer needed.
- Track browser and crawler errors more clearly.
- Generate commands for local browser login workflows.
This is particularly useful for websites that require analyst interaction before automated collection can continue, such as authenticated forums, sites protected by CAPTCHA, or applications where the crawler must first navigate through several pages to establish the correct session state.
Forum collection and analysis
Forum support receives another major set of improvements in v7.1.
Forum Explorer
Forum-related improvements include:
- Dedicated forum post views.
- Forum, subforum, thread, and post translation.
- Subforum categories.
- Improved forum-account management.
- Account crawling availability information.
- Stale-account detection and recovery.
- Interactive account repair.
- Manual thread recrawling.
- Improved crawler queue readability.
- Better thread pagination.
- Improved forum status and date display.
- Support for forums changing domains.
- Updating thread/subforum relationships when forum structures change.
- Improved forum crawler performance through caching.
- Post and user image extraction.
- Image extraction from HAR captures.
- Improved forum user-account support and correlations.
Forum posts are also better integrated into trackers and retro-hunt workflows.
Image similarity
AIL v7.1 introduces new image-similarity capabilities based on perceptual hashes.
Highlights include:
- A dedicated database for image-similarity data.
- Multi-index matching for pHash searches.
- Core pHash indexing support.
- UI and configuration integration for pHash processing.
- Additional pHash tests.
- Improved image-similarity dashboard integration.
These features make it easier to identify visually similar images across collected datasets.
Image descriptions
Image-description workflows have also been improved:
- Support for configuring multiple image-description models.
- Ability to select the model used to describe images.
- Markdown rendering for image descriptions.
- Improved description templates and tooltips.
- Removal of unnecessary model reasoning output.
Trackers and retro hunts
Tracker workflows receive several improvements:
- Added tracker status display.
- Administrators can disable trackers.
- Users can pause and resume trackers.
- Added forum-post filters.
- Improved tracker match heatmaps.
- Clicking a month in the heatmap can directly filter matching results.
- Added anchors for quickly jumping to match tables.
- Fixed tracker filters for source, subtype, and MIME type.
- Empty source filters are no longer incorrectly applied to trackers and retro hunts.
TempoLocus
AIL v7.1 introduces TempoLocus for chat and user-account analysis.
TempoLocus analyses message activity to estimate contextual information such as:
- Likely time zones.
- Possible countries based on timezone offsets.
- Holiday-region patterns.
This adds another source of temporal context when analysing accounts and messaging activity.
API improvements
AIL v7.1 extends the API with:
- Support for the
X-AIL-AUTHheader for API keys, improving compatibility with reverse proxies. - API access to chat instances.
- API access to chats within a chat instance.
- API access to chat, subchannel, and thread messages.
PDF and Markdown
PDF and Markdown handling receives several improvements:
- PDF content can now be rendered as Markdown.
- Added a Markdown viewer.
- Administrators can manually trigger PDF-to-Markdown extraction.
- A warning is displayed when PDF content could not be extracted.
- Disabled
pymupdf4llmOCR. - Fixed Markdown handling when a PDF has no generated Markdown.
- Fixed PDF translation overflow errors.
Cookiejar and crawler improvements
Cookiejar management has been expanded with:
- JSON import and export.
- Copy/paste JSON import.
- Additional metadata.
- Last-used and last-edited timestamps.
- Improved ACL checks.
Crawler-related improvements also include better task handling, JavaScript support, interactive capture workflows, and additional validation.
Other notable improvements
- Migrated URL parsing to faup-rs.
- Updated Pivotick.
- Improved MISP investigation export.
- Improved search behavior for same-date filters.
- Added handling for Meilisearch connection errors.
- Updated CodeMirror.
- Improved chat and participant image lazy loading.
- Improved crawler and forum status interfaces.
- Improved forum logging and debugging.
- Improved image-description rendering.
- Added extracted/matched content display in post views.
Security fixes
AIL v7.1 also includes several security fixes and hardening improvements.
The following vulnerabilities are addressed in this release:
- GCVE-1-2026-20292 (CVE-2026-100190)
- GCVE-1-2026-20276 (CVE-2026-100187)
- GCVE-1-2026-20183 (CVE-2026-100177)
- GCVE-1-2026-20279 (CVE-2026-100176)
- GCVE-1-2026-20269 (CVE-2026-100174)
- GCVE-1-2026-20239 (CVE-2026-100172)
Security-related changes include fixes and hardening around:
- Stored and reflected XSS.
- Tag rendering and unsafe HTML handling.
- Username timeline tooltips.
- Extracted-content popovers.
- Domain and crawler metadata rendering.
- Login handling and redirects.
- Cookiejar access controls.
- Onion crawler target validation.
- Access-log injection.
- SQL injection detection regex handling.
- PDF path traversal.
Bug fixes
AIL v7.1 includes numerous additional fixes across the framework, including:
- Tracker filter handling.
- Passive SSH settings.
- MISP export behavior.
- Forum scheduling and account recovery.
- Cookiejar handling.
- Forum URL handling.
- XenForo thread URLs.
- Onion lookup responses.
- Search and Redis compatibility.
- Interactive crawler task handling.
- Image-description UI issues.
- I2P address validation.
Acknowledgements
Thanks to everyone who contributed code, testing, bug reports, and security reports for this release.
Special thanks to Jeroen Pinoy for reporting several issues fixed in v7.1.
Thanks also to Cormac Doherty, David Curran, Wachizungu, and all other contributors.
Funding
AIL is developed and maintained with the support of the European Union as part of the HOPLITE European Project.
HOPLITE supports the improvement of tools such as AIL and MISP to help law enforcement authorities collect, analyse, and share intelligence.
- More information: https://hoplite-project.eu/
Law enforcement agencies can request access to the operated MISP/AIL-LEA platforms through: