Release 2021-09-18

From truxwiki.com
Jump to navigation Jump to search

Truxton 4.1.0.918

<< Released 2021-09-18 >>

Improvements

  1. Added more APIs to the C language
    1. truxton_media_update_paths
    2. truxton_media_update_child_count
    3. truxton_media_update_cache_file_counts
    4. truxton_tag_hash
  2. Added support for new APIs to Python
  3. Better transliteration of Arabic
  4. Truxton now loads VHD disk images
  5. New event types
    1. Disk Mounted
    2. Disk Dismounted
    3. System Boot
  6. Truxton now exploits:
    1. Chrome Web Data
    2. Chrome Local State
  7. Rudimentary password guessing. Windows logon hashes are now tried against well known passwords. If a password is found it will be added as an entity and included in the last field of the pwdump file.
  8. The Media Summary Report now includes the logon password hashes and any passwords found on the media. Geographic coordinates are reported in Latitude/Longitude and MGRS (for those service members who look up to the Air Force)
  9. Pull geographic coordinates out of Google Map View Points
  10. Truxton will now analyze text and tag non-English ones so you can quickly find documents.
  11. New investigation type, Human Trafficking
  12. Memory Swap files are now expanded
  13. A file's origin can now be part of export criteria
  14. Video Contact Sheet creation is now much faster

Bug Fixes

  1. Load stuck at 48% when ETL fails
  2. Windows logon hashes obfuscated with AES are now handled correctly
  3. Temporary file cleanup has been re-architected to be an active process. Temp files from crashed processes were not being cleaned up.
  4. File "readlines" method is now working correctly

New File Types

  1. VHDX
  2. Chrome Local State
  3. Protected Chrome Key
  4. UTMP
  5. Identified Language - This is an "invisible" type. No file will ever be identified with this type nor will it show up in the Analyst Desktop. It is used to route files with non-English text in the to ETLs that want non-English text.