February 28, 2026 in activity reports by Esther Onfroy4 minutes
Real-time threat intelligence is now live in Colander, with network flows and Suricata alerts streaming directly from PiRogue devices, plus Threatr queries and flow imports straight into cases. We also enabled PiRogue as an emergency VPN server for supporting at-risk individuals without physical device access. On the maintenance side, we tightened up the UX across the board, better status monitoring, quick system version checks, simpler team access management, and a leaner device monitoring workflow.
PiRogue Tool Suite (PTS) provides a platform combining analysis tools, knowledge management, incident response management and artifact management, which allows civil society organizations with limited resources to equip themselves at a low cost. The project consists of an open source tool suite that provides a comprehensive mobile device forensics and digital investigations platform.
hello [at] pts-project.org🚀️ PTS Community Meeting on Friday, March 27 · 2:00 – 3:00pm CEST. We are looking forward to hear from you join us on Google Meet
You can find more details about the different activities in the project roadmap.
Documenting the project is key in its usability. We are continuously documenting the different tools and features we develop and build new learning materials to facilitate skills development.
We have started restructuring our documentation. In the coming month you will oversee changes on the documentation structure.
We manufacture PiRogues to supply organizations, while taking care of its maintenance. We will include OS upgrades, improvement of the documentation and fixing bugs. Regarding Colander and Threatr, we maintain the public Colander server, upgrade dependencies, improve the documentation and fix bugs.
We enhanced the display and the expiration of PiRogue statues.
A PiRogue owner can quickly check system updates.
A PiRogue owner can now easily create and share accesses to Colander teams. Colander operators assigned to these teams will be able to use the access granted to them for their investigations.
We have simplified the configuration and start-up of device monitoring. A Colander operator can now launch profiling with fewer fields and clicks.
We will continue the maintenance of the tools, Debian packages we maintain and Colander ecosystem.
Given the success of events, webinars and demos with members of the civil society, NGOs and security researchers, we continue with our outreach plan. We organize trainings and demonstration sessions as well as creating spaces for the community to share feedback and request new features via our mailing list, GitHub issues or Discord server. We analyze one Android app that has received the community’s interest (ex COP28 app) per month. The application to be analyzed is chosen by the community. The analysis report is first privately shared with the community and one month later it is publicly released.
We organize monthly calls open to all members of the community to share project updates and get the community’s feedback.
We will continue with our recurring activities.