TRACE 2.2.0
New
- RAID and multi-disk volumes — Linux md arrays (RAID 0/1/4/5/6/10,
every superblock, one missing member rebuilt), multi-disk Btrfs,
Windows dynamic disks (simple, spanned, striped, mirrored, RAID5) and
hardware RAID rebuilt from its parameters, with automatic detection of
level, disk order and stripe size. File ▸ Assemble RAID or Multi-Disk
Volume. - LUKS2 unlocked (PBKDF2 and Argon2), and LVM inside LUKS — the
default encrypted Ubuntu and Fedora install — read and carved. - Lost partitions — file systems no partition table points at (a
wiped table, a broken extended chain, a deleted GPT entry) are found and
opened. A partition formatted twice shows both file systems. - Deleted files recovered further: Btrfs deleted files, proved by the
file system's own checksums; exFAT files followed through their FAT
chain; ext3/ext4 files whose inode was emptied, rebuilt from the
journal; NTFS files whose MFT entry was reused, named from$LogFile.
Each one is graded — recoverable, start only, possibly or partly
overwritten — and none is called recoverable when it is not (checked
against NIST's Deleted File Recovery answer key: 0 wrong on ext, FAT,
exFAT and NTFS). - Deleted registry keys and values, recovered from a hive's free
cells, in the Registry tab. - More evidence: Outlook
.msg, Office macros (VBA source and what it
does), password-protected Office documents (opened with the password),
network captures (hosts, DNS, HTTP, TLS server names), Parallels disks,
Apple Core Storage, CPIO, LZMA / zlib streams, damaged gzip read as far
as it goes, and legacy archives — CAB, LHA, ALZip, uuencode, Unix.Z. - macOS: the unified log (logons, sudo, screen locks, USB storage) and
login items. Linux: rotated logs, dpkg and yum history,
NetworkManager networks, Docker and Podman containers. - Search finds Greek, Cyrillic, Hebrew, Arabic and other non-Latin
text stored as UTF-16, and searches unallocated space (a case setting). - Chain of custody: evidence is hashed in full or not at all, every
E01 chunk's checksum is checked, and the audit trail is chained — an
edited case database is detected. An E01 set with a segment missing says
so instead of reading zeros. - Analysis profile "None" — create a case and only browse; modules can
run later. - The tree's Findings node has a group for every Triage tab with
something in it (deleted files by state, NTFS sections, the map,
thumbnail caches, similar pictures), in Triage's order.
Fixed
- A folder of an image's segments (
x.E01,x.E02… with the
imager's log or report) added as evidence opened as a folder of files;
it now opens as the one disk they make. - Volume names now agree everywhere: the tree, Image Information's
disk map and its volume table name every partition, table and free run
alike, in disk order. Free space no longer overlaps the partition
tables — clicking it read table sectors as free space. - Clicking Unallocated Space could crash TRACE (a running thread freed).
- Hex search results could crash on macOS.
- Partitions are named as forensic tools name them, and unnamed GPT
partitions (Fedora's EFI, /boot and Btrfs) are no longer dropped.
Cases
Cases are upgraded to schema 18 (the chained audit trail) when opened.
TRACE 2.1.0 cannot open a case that 2.2.0 has opened.
Requirements
libphdi-python(Parallels disks),msoffcrypto-tool(encrypted
Office),dpkt(network captures) andpefile(imphash and Rich
hashes) — wheels or pure Python on every platform.
Full Changelog: v2.1.0...v2.2.0