Release 2019-12-19
Jump to navigation
Jump to search
Truxton 3.1.0.0
Improvements
- Added file origin to file type breakdown report.
- Output more feedback when using the automated installer.
- Improved client dashboard load speed.
- Client previewbox wraps to the next row when being viewed on smaller screen resolutions.
- Improved accuracy of RTF carver for file types and author.
- Improved extracted details of ELF executables.
- User can now quickly hide directories from UI search results (on by default).
- Increased support for windows event log messages.
- 1001 & 1002 Microsoft-Windows-Storsvc/Diagnostic - Microsoft USB storage device insertions.
- 2104 Microsoft-Windows-WebAuthN/Operational - Two Factor Authentication USB Devices.
- Improved Unicode HTML identification.
- Type colors start out as a random color instead of grey.
- Reduced load memory consumption for some E01 configurations.
- Improved empty detection used when carving.
- Improved output for reports.
- Display notes for referenced files and findings in the My Findings report.
- User can choose to omit notes and referenced binaries when downloading the my findings report.
- User can now quickly hide Truxton generated files from UI search results (on by default).
- Better identification and exploitation of Android Telephony DB.
- Can now copy the string or byte text from the hex viewer via ctrl-c.
- More SQLite WAL consolidation.
- Improved Android MMS SMS identification.
- Improved Android Signal identification.
- User can now choose encoding for text content view.
- Improved MMS attachment extraction.
- Updated NSRL to 2.66.
- Users now manage connections to instances of Truxton via a unified interface for both metadata (database) and content (depots).
- Pressing the escape key now closes dialogs in the UI.
- New Alerts are now added when a media is reprocessed.
- The order for sorting options in the search UI is now alphabetical
- Improved ETL startup time.
- Added ability for a user to force media being loaded to the next phase if it appears to be stuck.
Bug Fixes
- Fix Android Bug Report offsets not being correct for machine name and serial number
- Fix issue where Postgres db connections requiring SSL did not work
- Fix issue when expanding SQL Lite file summaries missing information like name, hash, time, etc.
- Fix memory leaks when rendering some reports
- Fix the alpha channel for customized colors not being output correctly for HTML reports
- Fix memory leaks in ETLs when streaming depot file content
- Fix crash when initializing a new instance of Truxton without a locally installed database
- Fix race condition when changing search result categories
- Fix issues where SOLR based etls ran out of memory due to large differences in memory vs cpu cores
- Fix corrupted name paths when analyzing prefetch files
- Fix issue where new findings wouldn't be displayed in some certain circumstances
- Normalize timestamps to zulu across forensic time displays
- Fix issues when parsing certain EVTX files
- Fix issue where filtering by location or time didn't navigate back to the search page as expected
- Fix issue when parsing certain Android Binary XML files. Additionally improved the identification of these files
- Fixed paging issue when view websites in the domain visualization
- Fixed some cases where the size of the file as reported by the operating wasn't being set.
- Fixed bug where notes for website visits weren't being saved
- Fixed bug where displaying artifact correlation categories were duplicated
- Fixed issue where you couldn't navigate to a correlated rapid review in progress
- Fixed bug where performing bulk actions in the visual media display didn't always persist correctly
- Fixed bug when exporting timeline didn't work due to invalid timestamps
- Fixed certain MKV files not being identified
- Fixed issue where real media videos weren't being displayed in the UI
- Fixed email attachments occasionally not having a filename
- Improved MOV file identification accuracy
- Reduced false positives for base64 identification
- Fix crash if user navigated away from load media page before it finished initializing
- Fix bug where files extracted from RARs and 7zips were not being identified
- Fix issue where application occasionally does not fully shut down
- Fix issue where a website findings wasn't being added correctly
- Fix bug where the
TruxtonSettings.xmlconfig file was being reset between installations. - SQLite sample files now have an origin of expanded instead of generated
- Fixed Google Hangouts Messages not having their threads IDs calculated
- Fixed some text files not being identified as javascript
- Fixed Apple Partition Maps not being expanded
- Fixed bug in SQLite schema identification, table.column names can now belong to multiple types of SQLite databases.
- Fixed issue where duplicate properties can be written to settings file
- Fixed issue where Truxton service events being written to the windows event log were not being quoted correctly
- Fixed several issues with Unicode vCard parsing
- Fixed issue where content/depots would not be cleared correctly when purging and instance of Truxton.
- Fixed issue where docx files were not being displayed correctly in the preview window.
- Fixed some images in the KMZ reports not displaying.
- Fixed media reprocessing not working as expected. Including bulk reprocessing.
- Fixed issue where more ETLs than specified would run on service startup.
- Fixed issue where information being cached wasn't being updated in the UI. This was mostly apparent when viewing media while it was loading.
- Fixed sorting arrows on search columns occasionally not being representative of the order which was being sorted.
- Fixed issues where toggling offensive in certain areas was not persisting and updating the display correctly.
- Fixed GIMP XCF identification.
- Fixed issue where filtering by byte sizes was not working as expected due to rounding issues.
- Fixed issue where the finding button was not highlighted accordingly for events in the timeline.
- Fixed issue where volume serial number alerts weren't triggering.
- Fixed issue where viewing XLSX spreadsheets in non compact search results would crash the UI in certain cases.