Policies
Policies serve to define how evidence is collected and managed, providing fine-grained control over resources and processes.
Policies in AIR provide central configuration management and support global configurations that can be overridden at the Organisation level when required.
This overriding is only possible when the user has the “Override Policy” privilege allocated to their role.
Enabling and Disabling Policies
Section titled “Enabling and Disabling Policies”Policies can be enabled or disabled for the whole Console under Settings > Policies.
| State | Behavior when creating a task |
|---|---|
| Policies enabled | Tasks use the policies assigned to the asset’s organization, merged in priority order, with the read-only Default Policy filling in any value left unset. Operators with the Override Policy privilege can still switch a single task to Use Custom Options. |
| Policies disabled | The policy-based option is no longer offered, so every task is configured with Use Custom Options. |
The 4 GiB Memory Limit default is sent in the same way, on the task types that support it.
See Resource Limits for each limit, its default value, and how the Responder enforces it.
Key Components:
Section titled “Key Components:”- Name & Organization: Policies must have a unique name and be assigned to a specific organization.
- Evidence Storage: Configures where evidence is stored—either locally (default paths:
Binalyze\AIR\on Windows,/opt/binalyze/air/on Linux/macOS) or in defined repositories like SMB or SFTP.
- Resource Limits: Caps the Responder’s resource usage while it executes tasks on an asset, so collections cannot disrupt in-use systems. See Resource Limits for every available limit, its default value, enforcement behavior per operating system, and tuning guidance.
- Compression & Encryption: Enables optional compression and encryption of the collected evidence, with a password for added security.
- Scan Scope: You can opt to restrict scans to local drives only, excluding network and external drives.
- Isolation Settings: Policies can include IP/Port and process allow lists for isolation tasks, ensuring that specific communication channels remain open during an asset’s isolation. Allow-list behavior is applied bidirectionally (inbound and outbound), and DNS/DHCP behavior during isolation can be configured based on operational needs.
Use Case Example:
Section titled “Use Case Example:”When creating a policy for a specific investigation, you could configure it to save evidence in an AWS S3 bucket, limit the CPU to 50%, compress the evidence for efficient storage, and ensure network drives are excluded from the scan. You could also configure the policy to allow communication with critical servers even if the asset is isolated.