The forensic discovery cockpit is live.
DBSCAN and K-Means views now help analysts explore real scanned file observations as feature vectors, with linked findings, a 3D map, evidence drawers, and adjustable tuning.
This release moves VersionGopher from evidence collection toward evidence discovery. The new ML/AI Insights workbench maps real scanned files into forensic feature space so analysts can see clusters, odd files, rare markers, hash identity clues, package context, and PE or ELF structure without reading millions of rows by hand.
DBSCAN and K-Means views now help analysts explore real scanned file observations as feature vectors, with linked findings, a 3D map, evidence drawers, and adjustable tuning.
VersionGopher now preserves richer PE section, import, export, overlay, Rich Header, compiler, and structural clues so unusual DLLs and executables are easier to separate from routine software.
Evidence-gated CVE lanes are now current. Component scope, vendor/platform context, weak-version handling, and visible rationale reduce noisy matches without hiding real exposure.
Reviewed default presets guide analysts toward promising lanes such as ELF path/package oddities, PE path/signature evidence, co-location anomalies, package dependencies, and hash identity mismatches.
Ubuntu, Debian, GitHub Advisory, Red Hat-family, and Microsoft MSRC source-truth labels now feed repeatable regression gates that catch false positives and protect real product findings.
ML findings are grouped around the file, package, hash, path, or cluster that matters, then separate model reasons from CVE, KEV, malware-hash, and advisory context.
Staged 0.7.6 collectors cover enterprise systems plus Linux ARM, Linux ARM64, OpenWrt MIPS, PowerPC, macOS, Linux, and Windows targets for messy field environments.
Teams can correlate SHA-256 evidence, trusted malware-hash hits, package-risk advisories, and Miasma-response scans without live reputation lookups per file.
CVE exposure, package risk, private-key and wallet exposure metadata, archive evidence, drift, and scan provenance can be packaged for review.
VersionGopher 0.7.6 helps responders, security leaders, diligence teams, and mission owners move from raw file lists to evidence-backed action: what is present, what is risky, what changed, what deserves follow-up, and what can be shown to stakeholders without pretending the environment was cleaner than it really was.
ML/AI Insights is built around that same practical question: what should the analyst look at first? The model map is not a replacement for human review. It is a fast way to surface files that behave differently from their peers and attach the exact evidence needed to confirm or dismiss the concern.
The CVE workflow now favors defensible decisions over broad matches: generic filename collisions, child-file version overreach, ABI/SONAME confusion, and vendor/platform mismatches are gated before they become visible remediation work.
Accuracy work is now tested against labeled advisory sources instead of local examples alone. The regression suite uses package and vendor truth from Ubuntu, Debian, Red Hat-family sources, GitHub Advisory Database, and Microsoft MSRC data to improve precision while keeping positive-control findings visible.
The release keeps the collector lightweight and moves deeper analysis into the hosted workflow: ML/AI Insights, file cards, CVE panels, package-risk views, binary forensic signals, search, drift, and assessment reports.
Learn the ML/AI Insights workbench Read the binary forensics guide Read the CVE evidence decision guide Open help and setup notes
Start with one endpoint group, firmware image, storage estate, inherited environment, or embedded platform.