Customized CUBE enable prompts
CUBE collection recognizes password-style enable prompts customized by AAA policies, including prompts such as AD Password:, while refusing unrelated privilege challenges.
Releases and project news
What is changing in TranslatorX, why it matters, and where to learn how each new capability works.
Announcement
August 3, 2026
Version 26.1.1 is the first version of the new TranslatorX app. It retains deep protocol evidence while adding a native multi-window investigation workspace, broader import and collection workflows, explainable call and media analysis, and optional evidence-grounded AI assistance.
The release is available as verified packages for macOS, Windows, and Linux. Stable and beta channels remain separate, and every stable build is checked for code vulnerabilities, dependency risk, platform signatures, updater integrity, checksums, and versioned software bills of materials before publication.
Public beta
Beta.19 improves CUBE collection on systems with customized AAA enable-password prompts and refreshes supported dependencies.
CUBE collection recognizes password-style enable prompts customized by AAA policies, including prompts such as AD Password:, while refusing unrelated privilege challenges.
Current supported JavaScript and Rust dependencies replace older build components, including an obsolete frontend build override.
Beta.19 CycloneDX SBOMPublic beta
Beta.18 makes AI analysis easier to configure and follow, gives live traces clearer status and more reliable capture handling, and improves collection and installation recovery.
Custom AI endpoints can use no API key or send the configured key through the authentication header their provider expects, including bearer, Anthropic, LiteLLM, Azure OpenAI, Google, and Azure API Management options.
AI provider documentationTranslatorX enables provider reasoning for recognized models, displays incremental updates when the provider sends them, and retains the complete provider-supplied history in a scrollable view.
AI reasoning documentationA compact status control shows every live source’s connection and capture state with message totals. Buffered-log handling is more reliable when a trace stops.
Live tracing documentationCUBE collection preserves UTF-8 text so international characters remain readable in collected traces.
Remote collection documentationThe Windows installer includes the WebView2 bootstrapper and explains how to recover, including on air-gapped systems, if the required runtime cannot be installed automatically.
Installation documentationThe website retains the CycloneDX and SPDX dependency inventories for each release instead of replacing the previous release’s records.
Beta.18 CycloneDX SBOMPublic beta
Beta.17 makes complex SIP sessions easier to understand by reconstructing their observed call topology, recognizing more signaling devices, and presenting media evidence more clearly.
The Session Inspector follows initial INVITE direction instead of first-seen timestamps, so retries, forks, transfers, and multiple transit hops appear in their observed signaling layers.
Session Inspector documentationThe topology can group a signaling device's interfaces into one card and place each address on the side where it participates.
Multi-interface topology documentationDevice labels use the strongest available product identity while leaving endpoints generic when the signaling evidence is not sufficient.
Device identification documentationMedia reports stay connected to the relevant call path and present quality measurements with clearer labels and units.
Media quality documentationPublic beta
Beta.16 keeps approved collection folders working across app launches and prevents Expressway collections from failing because a saved destination has lost its native authorization.
Collection folders selected through Preferences or a collector remain approved after TranslatorX restarts. The system Downloads folder continues to work without asking for confirmation.
Remote collection documentationWhen an earlier beta saved a custom collection folder without a persistent authorization, TranslatorX opens the native folder picker at that location once and remembers the renewed approval for later launches.
Remote collection documentationPublic beta
Beta.15 prevents duplicate SIP captures from inflating media-quality results.
When separate log records are proven captures of the same SIP wire-message occurrence, matching embedded media reports are grouped into one observation and assessed once.
Media quality documentationEvery source message remains available for inspection. Later SIP retransmissions and similar reports from independent measurements remain separate unless provenance proves they represent the same occurrence.
Media evidence documentationPublic beta
Beta.14 adds explainable media-quality analysis, preserves every device perspective behind deduplicated Call Flow messages, and makes SIP call and session investigation easier.
TranslatorX extracts supported reports from Cisco endpoints, Webex App, CUBE, RFC 6035, and Unified CM CMR data. Established stream directions are graded Good, Bad, or Unknown from the reliable impairment evidence that is present, while Call Flow warns only when poor quality is known.
Media quality documentationInspect established streams for a SIP call, an entire session, or one call leg; compare compatible transmit and receive counters; follow each observation to its exact source; and open associated CMR records from CDR detail without merging independent measurement viewpoints.
Media evidence documentationWhen duplicate suppression represents several device records with one Call Flow arrow, an observation-count badge identifies the grouped evidence. Message detail can switch among the complete sender, receiver, or observer records while preserving each record’s timestamp, metadata, and source location.
Call Flow documentationSession calls use explicit leg numbers, timeline events retain human-readable timestamps, and Call List search includes participants, endpoints, outcomes, dial peers, and VRFs from every associated call leg.
Calls and sessions documentationPublic beta
Beta.13 adds safe, portable AI analysis results and interactive follow-up questions, improves CUBE collection and call-flow accuracy, and prevents accidental dialog dismissal.
Save a completed analysis as Markdown or as a hardened PDF with portable evidence references and a call-flow ladder when one is available. Exports keep original identifiers by default for local records, offer explicit privacy sanitization for sharing, and always exclude credentials and key material.
AI export documentationAsk concise follow-up questions while retaining the relevant report and evidence context. The model can request additional bounded source data when needed, TranslatorX retries apparently blank responses, and trace or model content is treated as untrusted data rather than instructions.
AI analysis documentationPaired CUBE cover buffers are collected once, SIP header and body boundaries remain intact, and Call Flow collapses the same SIP observation across capture endpoints without hiding legitimate retransmissions.
CUBE and Call Flow documentationAnalysis, collection, preferences, filtering, and related dialogs now close through their explicit controls instead of an outside click, avoiding accidental data loss or interrupted workflows.
Application workflow documentationPublic beta
Beta.12 adds multi-VRF filtering for CUBE traces, improves CUBE endpoint and SIP-session correlation, supports very large historical collections, and makes custom Anthropic analysis reports more reliable.
VRF metadata from CUBE VoIP Trace is retained on SIP messages. Searchable multi-select filters in Display, SIP Calls, and SIP Sessions support multiple VRFs and <none>. Related call legs across VRFs remain visible by default, with an option to restrict them.
Interleaved inside and outside call legs use matching transport evidence so their local and remote endpoints remain distinct. Partial live captures no longer create SIP Sessions unless an INVITE-backed SIP Call exists, keeping both lists consistent.
SIP analysis documentationBusy historical ranges containing hundreds of calls are divided into sequential trace batches and loaded automatically. Individual calls remain intact while avoiding per-file parser and file-access limits.
CUBE collection documentationCustom Anthropic-compatible endpoints now request TranslatorX’s structured report schema, allowing supported models to return complete, schema-conformant analysis reports.
AI analysis documentationPublic beta
Beta.11 improves Expressway trace accuracy, CUBE endpoint recovery, live collection storage, message decoding controls, and application startup.
Live Network Log captures now use canonical line endings and exact persisted line counts. Call Flow also collapses duplicate info/debug observations while retaining legitimate SIP retransmissions.
Call Flow documentationRequest endpoints continue to prefer transport and Via evidence. When prior responses demonstrably reversed header addresses, a later request can use a literal Request-URI address as a constrained fallback, with the advanced recovery behavior remaining configurable.
Trace processing documentationLive CUBE and Expressway captures are stored in per-collection directories under the configured collection location, making retained files easy to find, inspect, and delete.
Live trace documentationA persistent control enables or disables message-decoding explanations directly from message details. Startup now renders immediately and loads collectors, secondary views, and decoder knowledge only when needed.
Trace workflow documentationPublic beta
Beta.10 adds CUBE dial-peer context, corrects absolute-time CUBE collection, and improves performance across large and live trace workflows.
Matched inbound and outbound dial peers now appear with the related INVITE and in the SIP Calls list when that data is present in the trace.
SIP Calls documentationAbsolute-time CUBE VoIP Trace collection now uses the requested local time and timezone so calls in the selected interval are included.
CUBE collection documentationImproved performance for Expressway live traces, archive imports, live sessions, message loading and filtering, and Unified CM log downloads.
Trace workflow documentationPublic beta
Beta.9 expands AI provider compatibility, gives Windows users one adaptive installer, and resolves CUBE live-trace and collection-directory failures found during Windows testing.
Custom AI providers can now use either Anthropic Messages or OpenAI Chat Completions compatibility. Local loopback endpoints may use HTTP, model discovery understands common provider response formats, and token accounting includes compatible cache-read usage when reported.
AI analysis documentationThe Windows beta now ships as one NSIS installer that offers a per-user installation without elevation or an all-users installation with administrator approval. Switching scope removes the prior registration and installation files so migrations do not leave duplicate applications behind.
Installation documentationLive-trace startup failures remain visible per device, the first logging poll begins immediately, and cursor verification falls back to the complete IOS logging buffer. An explicit manual stop no longer turns an in-flight or final cursor miss into a false data-loss error, while gaps detected during an active trace still stop collection.
Live trace documentationTranslatorX now initializes a default Downloads location, exposes it under Preferences > Files, and applies it consistently to remote and coordinated collection. Windows disk-space checks resolve collection files to valid directories instead of failing with an invalid-directory warning.
Collection documentationPublic beta
Beta.8 makes CUBE live tracing resilient to dropped terminal-monitor output, adds SOCKS5 routing for HTTPS and SSH, restores packaged FIDO2 support on every production platform, and strengthens collection safety.
CUBE live traces now read sequenced SIP debugs from the IOS logging buffer every five seconds instead of relying on terminal-monitor delivery. Polls never overlap, a final read runs during stop, and a missing or discontinuous sequence stops the trace with an explicit gap error rather than silently omitting messages.
Live trace documentationA readiness window identifies the logging level, buffer size, sequence-number, and filter requirements for each CUBE. TranslatorX can prepare a buffer of at least 10 MB, optionally save the change to startup configuration, and remember the choice on a saved profile. Connection failures are reported separately and never offer a configuration action.
CUBE readiness documentationReusable proxy profiles now use separate type, host, and port fields. HTTP or SOCKS5 can route supported HTTPS connections, while SOCKS5 can also route CUBE and Expressway SSH directly or before a jump host with proxy-side destination DNS. Connection errors distinguish an unavailable proxy from a destination failure.
Proxy documentationThe production OpenSSH clients for macOS, Windows, and Linux now include and validate the FIDO2 provider and security-key helper required for *_sk private keys.
Native file operations are limited to files and folders selected in an operating-system dialog, SSH host-key approval is bound to the exact inspected identity, and collection warns about low disk space before stopping at a critical reserve.
Collection safety documentationTroubleshooting collection now reports queued, active, completed, and failed targets independently. Message Filters closes correctly, routine-traffic checkboxes consistently mean checked traffic is shown, and message selection remains anchored when filters reposition rows.
Collection documentationPublic beta
Beta.7 makes secure remote connectivity consistent across platforms, exposes the SSH protection actually negotiated, adds reusable HTTP proxy routing, and provides actionable CUBE readiness checks.
SSH connections now support a wider range of current key exchange, host-key, and cipher algorithms across macOS and Windows, prefer hybrid post-quantum key exchange when the device supports it, and exclude legacy algorithms.
SSH security documentationConnection tests open an immediate progress dialog and finish with per-host results that show the negotiated key exchange, host-key algorithm, cipher, and message authentication details.
Connection-test documentationTrusted host identities remain valid when a server negotiates another already-known host-key type, while genuinely changed or revoked keys are still rejected and require explicit review.
SSH trust documentationCUBE tests identify disabled VoIP Trace and insufficient monitor logging, then offer the permitted running-configuration changes directly with the result instead of hiding them behind a second dialog.
CUBE collection documentationUse system proxy settings, connect directly, or select a reusable proxy profile for Unified CM, Expressway HTTPS, and signed software updates. Optional proxy credentials remain in the operating system credential manager.
Proxy and connection documentationWhen a selected file contains no supported signaling messages, TranslatorX now explains the result and points to diagnostic details instead of leaving the workspace unchanged without context.
Trace import documentationPublic beta
Beta.6 improves SDP analysis, keeps historical collections focused on the requested incident window, and corrects Webex App session and media reconstruction.
SDP fields and attributes now include more complete contextual descriptions, with related payload types and attributes highlighted together for faster inspection.
SDP analysis documentationHistorical and coordinated collection defaults to importing only messages inside the requested interval, preventing unrelated calls from broad Unified CM call-log files from entering analysis.
Historical collection documentationLowercase SIP headers are decoded correctly so Webex App call legs participate in Session-ID filtering and multi-leg call analysis.
SIP session documentationDetached Webex App SDP blocks are paired with the correct SIP message, and final responses can update media first established by provisional responses.
Call Flow media documentationPublic CycloneDX and SPDX software bills of materials document the application dependency inventory without exposing private source-repository locations.
Beta.6 CycloneDX SBOMPublic beta
Beta.5 strengthens release packaging and cross-platform verification while incorporating the latest documentation refinements.
Public beta
Beta.4 focuses on SIP fidelity and call-flow clarity, with parser hardening for real-world packet captures and Unified CM normalization traces.
Changed messages now show a normalization indicator and an inbound or outbound comparison with before, after, and highlighted difference views. Unchanged normalization events stay out of the way.
SIP normalization documentationPCAP and PCAPNG handling is more tolerant of fragmented, retransmitted, out-of-order, and segmented SIP traffic, including message bodies split across packets.
Open traces documentationSDP offer and answer tracking now follows the terminal media endpoints across intermediary call-control legs and avoids inventing media streams to Unified CM.
Call Flow and media documentationCall bands use a restrained legacy-inspired order, media labels are easier to read, and signaling rows no longer alternate between light and dark variants within one call.
Call Flow documentationWhen a SIP BYE carries Reason or Warning headers, the Call Flow arrow includes that context. BYEs without either header retain the compact label.
Call Flow message-label documentationStable release
Version 26.1.1 is the first version of the new TranslatorX app. This cumulative catalog covers features that are new or substantially expanded since TranslatorX Classic 15.0(3), with links to the current user documentation.
The legacy application has been completely rebuilt using modern frameworks, creating a maintainable cross-platform foundation for faster ongoing development.
Modern application documentationCall List, Call Flow, filters, source traces, CDR details, preferences, and inspectors open as reusable native desktop windows with platform menus and shortcuts.
Windows, menus, and shortcuts documentationThe interface can follow the operating system or use an explicit light or dark appearance while retaining protocol and call correlation colors.
Preferences documentationLarge folder imports, parsing, correlation, and call analysis remain responsive and report clear progress for each phase of the work.
Loading and progress documentationUniversal macOS, 64-bit Windows, and 64-bit Linux packages use platform or updater signatures, notarization or Authenticode where applicable, and per-platform SHA-256 manifests.
Software update documentationChoose a current-user or all-users installation from one signed package, with integrated WebView2 setup and clear recovery guidance for restricted or offline systems.
Windows installation documentationChoose an update channel, check automatically or manually, and receive verified releases through the application’s signed updater. A deliberate rollback to Stable is permitted only after native confirmation and a compatibility check of application-owned data.
Update-channel documentationEach release retains CycloneDX and SPDX software bills of materials with independent checksums, alongside platform checksums and signed updater metadata.
26.1.1 CycloneDX SBOMOpen files, recursive folders, drag-and-drop selections, or clipboard text and choose whether new evidence appends to or replaces the current session.
Trace import documentationRead gzip logs, ZIP bundles, and ZIP files nested to a controlled depth while reporting unsupported or unsafe entries instead of silently skipping them.
Archive import documentationSupport common link layers, VLANs, IPv4 and IPv6 fragments, nanosecond timestamps, TCP reassembly, retransmissions, compact headers, and SIP bodies spanning packets.
Open traces documentationDecode current and legacy Unified CM, CUBE, Expressway, Webex, endpoint, CUSP, BroadWorks, IOS binary, H.323, Q.931, SCCP, MGCP, SIP, and SDP sources.
Supported data documentationRe-import source-neutral .txtrace evidence with normalized metadata instead of depending on the original vendor wrapper or source path.
Use Unified CM calllogs to fill missing events, then replace a matching summary with the full SDL message if richer evidence is loaded later.
Calllog documentationCompare time, endpoints, direction, protocol, message name, handles, tags, and call identifiers across vendor formats with resizable and content-aware columns.
Message workspace documentationResolve payloads and codecs across media sections; decode common FMTP, transport, security, feedback, ICE, BFCP, and Cisco multistream values; highlight related SDP lines on hover or keyboard focus; and provide plain-language explanations and standards references without altering selectable message text. The SDP interpretation builds in part on SDPlorer, created by Rob Hanton. We thank Rob for sharing the code.
Decoded content documentationReview wire, before, after, and highlighted semantic differences for changed inbound or outbound SIP normalization events without duplicate rows.
SIP normalization documentationCombine protocol, direction, endpoint, message, identifiers, correlation, text, and time criteria using AND within rows and OR across rows, then save them as .txf.
Search message content and independently hide protocol families or routine traffic without deleting evidence from the active session.
Search and display documentationJump from a decoded message or AI citation to exact raw lines with line numbers, horizontal scrolling, previous/next search, and matches-only mode.
Source viewer documentationNormalize to GMT using explicit zones, device identity, matching SIP messages, missing-year inference, sub-minute skew correction, evidence confidence, and user overrides.
Source-time documentationReview parsing warnings, collection status, inferred values, remote connection events, and cleanup results in one support-oriented window.
Event Log documentationEdit discovered device names once, use them throughout the workspace and diagrams, and import or export alias sets as JSON.
Device alias documentationSeparate Unified CM CDR records, trace-derived SIP calls, and explicitly correlated multi-leg SIP sessions instead of treating every investigation as one flat list.
Call List documentationConnect call legs through Session-ID, remote-cc, Cisco-Guid, and related identifiers without relying on phone-number or timing guesses.
SIP session documentationDistinguish connected, completed, cancelled, redirected, rejected, failed, and incomplete calls, then inspect route, legs, endpoint history, evidence, and key events chronologically.
Call analysis documentationRetain matched inbound and outbound dial peers with their calls, preserve CUBE VRF metadata, and filter messages, calls, or sessions by one or more VRFs without hiding related cross-VRF legs by default.
CUBE call-context documentationReconstruct retries, forks, transfers, transit hops, and multi-interface signaling devices from the direction and identifiers actually present in the trace.
Session topology documentationKeep timestamps visible, suppress duplicate SIP retransmissions when desired, select any arrow for detail, and retain a dense chronological ladder.
Call Flow documentationReorder or combine lanes, apply persistent aliases, keep media-only endpoints adjacent, and use restrained per-call band colors without alternating row shades.
Call Flow lane documentationFollow SDP offer and answer endpoints across intermediary signaling legs and show audio, video, direction, hold, rejection, resume, port, and transport changes without duplicate streams.
Media stream documentationExtract endpoint, Webex App, CUBE, RFC 6035, and Unified CM CMR reports; grade each established stream direction as Good, Bad, or Unknown; warn on Call Flow only when poor media is known; compare compatible TX and RX counters; preserve independent viewpoints and copied source representations; and browse complete evidence from established Media Streams or compact CDR-to-CMR links.
Media quality documentationShow SIP Reason and Warning values directly on BYE arrows when present while leaving ordinary BYE labels compact.
Call Flow label documentationOpen standalone or embedded records, search grouped and raw fields, decode disconnect causes, create trace filters, and launch related Call Flow views.
CDR and CMR documentationDecode Q.931 and Q.SIG Facility information in the message where it occurred rather than requiring a separate developer utility.
Protocol support documentationManage and test Unified CM, CUBE, and Expressway connections once, then use the same profiles across historical, coordinated, troubleshooting, and live workflows.
Profile documentationKeep passwords and key passphrases in the operating system credential manager rather than serializing secrets into profile or settings files.
Credential storage documentationUse passwords, OpenSSH keys, hardware-backed FIDO2 keys, keyboard-interactive MFA, enable passwords, and independently authenticated jump hosts. Bundled production clients include validated FIDO2 support on macOS, Windows, and Linux.
SSH authentication documentationSupport a wider range of current SSH algorithms consistently across macOS and Windows, prefer hybrid post-quantum key exchange, exclude legacy algorithms, and review the exact security negotiated with every host.
SSH security documentationRequire TLS 1.2+, review untrusted certificate identity before credentials are sent, pin accepted certificates by origin, accept alternate already-trusted SSH key types, and reject genuinely changed keys.
Connection trust documentationUse system proxy settings, direct connections, or independently managed HTTP and SOCKS5 profiles for supported HTTPS traffic. SOCKS5 can also route CUBE and Expressway SSH, including connections that continue through a jump host.
Proxy documentationSee active progress, authentication and negotiated-security results, CUBE VoIP Trace state, and buffered-logging readiness, then apply permitted running-configuration fixes and optionally save logging changes to startup configuration.
Connection-test documentationDiscover every node from a publisher profile and collect the requested SDL, SDI, calllog, CDR, or related timeframe across the cluster.
Unified CM collection documentationDiscard messages outside a selected collection interval before call reconciliation and analysis while preserving the complete downloaded source files on disk.
Historical import-boundary documentationInspect trace state and coverage, offer to enable VoIP trace when privileges permit, collect bounded evidence, interpret router clock information, and divide busy ranges into sequential batches without splitting individual calls.
CUBE collection documentationCollect historical signaling, discover supported diagnostic operations, coordinate captures, and handle current and legacy Network Log formats.
Expressway collection documentationApply one absolute or relative timeframe to several products and open their independently collected evidence as one correlated timeline.
Multi-device collection documentationFolders selected through native controls remain approved across launches, while every collection stays contained within the chosen destination.
Collection destination documentationSelect participating systems, record the exact reproduction interval, coordinate Expressway capture state, stop cleanly, and collect one combined session.
Troubleshooting session documentationTrace one or more CUBE and Expressway sources while filters, calls, sessions, and open diagrams update incrementally. CUBE uses sequenced five-second logging-buffer polls with gap detection and guided readiness checks.
Live trace documentationEnable only the required signaling and transport debugs, strip shell noise safely, and report any stop or cleanup state that cannot be confirmed.
Live CUBE cleanup documentationConfigure Ollama, Anthropic, AWS Bedrock, Google Gemini, or custom endpoints compatible with Anthropic Messages or OpenAI Chat Completions, including flexible provider-specific authentication.
AI provider documentationStart analysis from a SIP call, correlated session, or filtered trace with deterministic observations and a bounded catalog of exact source ranges.
AI evidence documentationAllow the model to request validated literal or regular-expression searches and exact surrounding lines without granting arbitrary filesystem access.
Context retrieval documentationReview probable cause, confidence, findings, alternatives, recommendations, limitations, and citations that open the supporting message or source lines.
AI report documentationAsk follow-up questions against the same frozen evidence case, retain the conversation and provider-supplied reasoning history, and keep every supported citation linked to source evidence.
AI follow-up documentationExport the complete evidence-grounded analysis as Markdown or a paginated PDF with findings, recommendations, limitations, usage, and source links.
AI export documentationAlways remove credentials and SDP keys, anonymize telephone numbers, IP addresses, and hostnames by default, and keep local Ollama traffic on loopback.
AI privacy documentationAccumulate input, output, cache-read, and cache-write usage across context rounds when the selected provider reports it.
AI usage documentationExport the full session or only the current search, filter, protocol, and routine-traffic result as normalized readable text.
Readable export documentationShare a portable trace containing protocol content and structured analysis metadata without original local paths or vendor wrappers.
TranslatorX trace documentationSave the signaling and visible media diagram with its current labels and lane arrangement as a scalable vector image.
Call Flow export documentationShare evidence-grounded AI results as Markdown or PDF without changing the underlying trace, while preserving supported source links and report context.
Analysis export documentationPerform normal parsing, filtering, correlation, call analysis, diagram generation, and export locally without requiring a cloud service.
Security and privacy documentationProtect temporary trace data, limit archive and network content, validate remote destinations, and restrict sensitive application operations.
Application security documentationCheck every release for quality, vulnerabilities, and dependency freshness; sign platform packages and updater files; and publish checksums plus reproducible CycloneDX and SPDX inventories.
Release integrity documentationGitHub retains versioned installers, checksums, updater manifests, and earlier release entries.