Release 2018-03-08
Jump to navigation
Jump to search
Truxton 2.1.17.0
Improvements
- Automatic tagging of malware infection points
- New entity type of Cryptographic Key ID
TuneDatabase.ps1script now includes settings suggestions from http://pgtune.leopard.in.ua/- PGP ASCII Public Keys are now exploited
- BMP file identification is loosened. We now account for BMPs that have an invalid format yet they still work.
- We now have Credit Card and Phone Number specialized entity search
- New Artifact Types report to tell you about all of the possible artifacts Truxton can process.
- Global Artifact Correlation report. This report lists artifacts that exist in multiple sources in Truxton regardless of the investigation.
- New Administrative Reports:
Depot Audit - This checks to see if there's any missing depot files and attempts to locate and add them to the database.
Optimize Database - This report will tell the database to update all statistics to make queries go faster. - Numerous improvements to the user interface.
New File Types
- USPS Database
- Android Resources
- Microsoft Defender Scans
- Inno ZLib
- PGP Public Keyring
- Apple System Statistics
- Apple Application Bookmark
Bug Fixes
- DatabaseTableName table was being double initialized.
- Some JPGs were being missed in carving due to the identifier being too strict.
- Serious bug where partitions in the middle of a disk that had no file system was processing more freespace than bytes in the partition.
- Dashboard display no longer gets crowded when more than 50 investigations are added in a single day.
- More credit card false-positive work done.
- We now process the "long link name" variant of a TAR entry as well as handle filenames longer than 260 characters. The new limit is 32,768 characters.