Release 2022-09-12
Jump to navigation
Jump to search
Truxton 4.2.1.21013
Improvements
- EXIF parsing can now handle unsorted fields
- New Media type of "Vehicle"
- Exploit the following file types:
- Android ID Settings
- Android PCW Device Settings
- Generic Logs
- Android Settings
- Android Bookmarks
- Samsung Notes
- Better labeling of Android call events
- Python API now supports id parameters being string or UUIDs
- Triage loads have been rewritten. Filenames and patterns now come from the "TriageFile" table in the database so users can add their own.
- Triage loads will now have the word "Triage" in their description
- New artifact type of "Device Identifier"
- Better exploitation of Android Contacts
- Depot files marked as "ToBeDeleted" will be deleted during Depot Consolidation if the disk becomes full before continuing. A disk full situation will not stop consolidation.
- New event type of "Vehicle" for door-open, door-closed type events.
- New relationship types:
- Profile Photo
- Member Of
- Associated With
- In Contact With
- New Python and C APIs for parsing time (yes, it is a thing), black box debugging, carving a single file for child files, and adding investigator notes.
Bug Fixes
- Message priority was not being passed along. This caused media to backup up at certain stages.
- Events are now extracted from Android Calendars
- Better checking for duplicate messages
- Better checking for duplicate locations
- Apple DSID's were being tagged as Apple Authentication IDs
New File Types
- 15 new file types