github sleuthkit/sleuthkit sleuthkit-4.8.0
The Sleuth Kit 4.8.0

latest releases: sleuthkit-4.12.1, sleuthkit-4.12.0, sleuthkit-4.11.1...
4 years ago

[NOTE: The .tar.gz file was updated after the initial release to fix some compiler errors related to maven and APFS on OS X. No logic changes were made though. Hashes are at the bottom of this note]

C/C++

  • Pool layer was added to support APFS. NOTE: API is likely to change.
  • Limited APFS support added in libtsk and some of the command line tools.
    -- Encryption support is not complete.
    -- Black Bag Technologies submitted the initial PR. Basis Technology did some minor refactoring.
  • Refactoring and minor fixes to logical imager
  • Various bug fixes from Google fuzzing efforts and Jonathan B from Afarsec
  • Fixed infinite NTFS loop from cyclical attribute lists. Reported by X.
  • File system bug fixes from uckelman-sf on github

Database:

  • DB schema was updated to support pools
  • Added concept of JSON in Blackboard Attributes
  • Schema supports cascading deletes to enable data source deletion

Java:

  • Added Pool class and associated infrastructure
  • Added methods to support deleting data sources from database
  • Removed JavaFX as a dependency by refactoring the recently introduced timeline filtering classes.
  • Added attachment support to the blackboard helper package.

Hash of .tar.gz that would not compile on all systems: b5c081eb2cc92d2e56b8c470de37f890
Hash of fixed version: c7f9431bceae9b421b337d3c44af4ea9

Don't miss a new sleuthkit release

NewReleases is sending notifications on new releases.