github Gadzhovski/TRACE-Forensic-Toolkit v2.1.0
TRACE 2.1.0

6 hours ago

TRACE 2.1.0

New

  • Btrfs (#13) —
    the default file system of Fedora and openSUSE. Every subvolume and
    snapshot, zlib / LZO / zstd compression, sparse files, and one disk of a
    RAID1 read on its own. Tested against fox-it/dissect.btrfs's published
    values and a real Fedora 44 install, where every tree node and data
    sector matched its stored checksum and 22,831 installed files matched
    the RPM database.
  • Each image gets the modules that can find something in it. The
    Analysis Modules dialog lists the case's images with what each holds
    (GPT · FAT16, Btrfs · Linux); one selection for all of them, or one per
    image. A module that cannot find anything in an image is greyed out
    there, with the reason — the NTFS module is no longer run on a Linux
    disk.
  • File system timeline — created, modified, accessed and changed
    times of every file and folder on ext, Btrfs, XFS, HFS+, APFS, FAT and
    exFAT now reach the Timeline (until now only NTFS's did). FAT and exFAT
    times carry no time zone and are shown as local.
  • Linux: the system (release, host name, time zone), user accounts and
    who can use sudo, software installed and removed (dnf, apt), SSH hosts
    and keys. Persistence now reads Linux (systemd, cron, SysV, Upstart,
    rc.local, ld.so.preload, autostart, SSH keys) and macOS (launch agents
    and daemons), graded by what they start.
  • Crash log — a crash now leaves its stack in crash.log, and the next
    start says so in trace.log.

Fixed

  • QCOW2: compressed images (as distributions and qemu-img convert -c
    write them) read about half their data as zeros through libqcow. TRACE
    now reads QCOW2 itself.
  • Carving "unallocated space only" carved live files on APFS, XFS and
    Btrfs and reported them as recovered: free space is now taken from each
    file system's own records. Inside LVM, LUKS and FileVault, where free
    space cannot be told from used, the partition is skipped and the log
    says so.
  • Listing search found nothing on QCOW2, VHD, VMDK, DMG, AFF4, AD1 /
    L01, BitLocker, LVM, APFS, XFS or Btrfs evidence; it now searches every
    image. Search results open on the image they came from, names starting
    with a dot and links are found, and clicking a FAT, exFAT, ext or Btrfs
    partition lists its files.
  • Empty files no longer show as read errors; links on XFS and APFS read as
    their target.

Requirements

  • backports.zstd (Python 3.10–3.13; wheels for every platform) reads
    zstd-compressed data about 45 times faster.

Full Changelog: v2.0.0...v2.1.0

Don't miss a new TRACE-Forensic-Toolkit release

NewReleases is sending notifications on new releases.