github Gadzhovski/TRACE-Forensic-Toolkit v2.2.0
TRACE 2.2.0

6 hours ago

TRACE 2.2.0

New

  • RAID and multi-disk volumes — Linux md arrays (RAID 0/1/4/5/6/10,
    every superblock, one missing member rebuilt), multi-disk Btrfs,
    Windows dynamic disks (simple, spanned, striped, mirrored, RAID5) and
    hardware RAID rebuilt from its parameters, with automatic detection of
    level, disk order and stripe size. File ▸ Assemble RAID or Multi-Disk
    Volume.
  • LUKS2 unlocked (PBKDF2 and Argon2), and LVM inside LUKS — the
    default encrypted Ubuntu and Fedora install — read and carved.
  • Lost partitions — file systems no partition table points at (a
    wiped table, a broken extended chain, a deleted GPT entry) are found and
    opened. A partition formatted twice shows both file systems.
  • Deleted files recovered further: Btrfs deleted files, proved by the
    file system's own checksums; exFAT files followed through their FAT
    chain; ext3/ext4 files whose inode was emptied, rebuilt from the
    journal; NTFS files whose MFT entry was reused, named from $LogFile.
    Each one is graded — recoverable, start only, possibly or partly
    overwritten — and none is called recoverable when it is not (checked
    against NIST's Deleted File Recovery answer key: 0 wrong on ext, FAT,
    exFAT and NTFS).
  • Deleted registry keys and values, recovered from a hive's free
    cells, in the Registry tab.
  • More evidence: Outlook .msg, Office macros (VBA source and what it
    does), password-protected Office documents (opened with the password),
    network captures (hosts, DNS, HTTP, TLS server names), Parallels disks,
    Apple Core Storage, CPIO, LZMA / zlib streams, damaged gzip read as far
    as it goes, and legacy archives — CAB, LHA, ALZip, uuencode, Unix .Z.
  • macOS: the unified log (logons, sudo, screen locks, USB storage) and
    login items. Linux: rotated logs, dpkg and yum history,
    NetworkManager networks, Docker and Podman containers.
  • Search finds Greek, Cyrillic, Hebrew, Arabic and other non-Latin
    text stored as UTF-16, and searches unallocated space (a case setting).
  • Chain of custody: evidence is hashed in full or not at all, every
    E01 chunk's checksum is checked, and the audit trail is chained — an
    edited case database is detected. An E01 set with a segment missing says
    so instead of reading zeros.
  • Analysis profile "None" — create a case and only browse; modules can
    run later.
  • The tree's Findings node has a group for every Triage tab with
    something in it
    (deleted files by state, NTFS sections, the map,
    thumbnail caches, similar pictures), in Triage's order.

Fixed

  • A folder of an image's segments (x.E01, x.E02… with the
    imager's log or report) added as evidence opened as a folder of files;
    it now opens as the one disk they make.
  • Volume names now agree everywhere: the tree, Image Information's
    disk map and its volume table name every partition, table and free run
    alike, in disk order. Free space no longer overlaps the partition
    tables — clicking it read table sectors as free space.
  • Clicking Unallocated Space could crash TRACE (a running thread freed).
  • Hex search results could crash on macOS.
  • Partitions are named as forensic tools name them, and unnamed GPT
    partitions (Fedora's EFI, /boot and Btrfs) are no longer dropped.

Cases

Cases are upgraded to schema 18 (the chained audit trail) when opened.
TRACE 2.1.0 cannot open a case that 2.2.0 has opened.

Requirements

  • libphdi-python (Parallels disks), msoffcrypto-tool (encrypted
    Office), dpkt (network captures) and pefile (imphash and Rich
    hashes) — wheels or pure Python on every platform.

Full Changelog: v2.1.0...v2.2.0

Don't miss a new TRACE-Forensic-Toolkit release

NewReleases is sending notifications on new releases.