Difference between revisions of "Next Release"

From truxwiki.com
Jump to navigation Jump to search
Line 8: Line 8:
 
* Updated to SQLite 3.51.1
 
* Updated to SQLite 3.51.1
 
* Updated default hashset to <code>Truxton20251201.hashset</code> with 251,384,600 hashes.
 
* Updated default hashset to <code>Truxton20251201.hashset</code> with 251,384,600 hashes.
 +
* New <code>globaldedupe</code> option causes only unique files to be stored in depots. Loads will slow but file contents will not be duplicated anywhere. You save storage at the cost of load speed.
 
* We now scan text for Bitcoin accounts and seed phrases
 
* We now scan text for Bitcoin accounts and seed phrases
 
* Improved the quality of parsing [[Type_Cellebrite_2|Cellebrite reports]] to clean up deleted entries and pull more contact information.
 
* Improved the quality of parsing [[Type_Cellebrite_2|Cellebrite reports]] to clean up deleted entries and pull more contact information.

Revision as of 05:32, 20 March 2026

This is a place holder for what is being put into the next release of Truxton.

Truxton Next

<< Released 2025-?

Improvements

Bug Fixes

  • Consolidated contacts reports where phone numbers showed up as email addresses.
  • The loader now processes APFS filesystems correctly.
  • The enumeration API wasn't scoping media and investigation enumeration.
  • KTX conversion now handles uncompressed payloads.
  • Parquet files were not being identified.
  • Truxton.ETL assembly was not sourcing relationships properly.
  • Fixed a bug in the C API that caused Notes to not be associated with contacts.
  • Notes now appear in the Consolidated Contact reports.
  • Added missing EVENT_TYPE constants to Python.
  • Consolidated Contacts now does a better job of consolidating contacts.
  • Valid file details are now produced from DPAPI blobs that don't start at the beginning of a file.
  • Duplicate entries were showing up in the Visual Media display when Unique was specified.

New Types

File

  1. Type_EBTS - Electronic Biometric Transmission Specification (fingerprints, biometric information, etc.)
  2. Type_OBB - Android opaque binary blobs
  3. Type_Volley_Cache - Android library for applications to cache web data
  4. Type_Glide_Disk_Cache - Something really similar to Volley cache
  5. Type_Wwise_SoundBank - A bundle of sounds for an application
  6. Type_Roblox_Cache - Cache used by Roblox application
  7. Type_Android_Binary_XML - Yet another XML compression scheme (different from the other Android Binary XML format)
  8. Type_Apple_Spotlight_String_Map - String maps used by Apple's Spotlight system
  9. Type_Visio - Visio drawings
  10. Type_Envelope_Index - Apple Envelope Index SQLite database
  11. Type_XAR - Extensible Archive
  12. Type_Apple_Logdata_Statistics - Apple Logdata Statistics
  13. Type_Apple_Shutdown_Log - Apple shutdown log
  14. Type_WiFi_Network_Store_Model - Apple WiFi Network Store database
  15. Type_Notepad_Tabstate - Microsoft Notepad Tab State
  16. Type_Android_Snapchat_Core - Android Snapchat Core
  17. Type_Android_Snapchat_Main - Android Snapchat Main
  18. Type_Android_WiFi_Config_Store - Android WiFi Configuration Store
  19. Type_Android_Bluetooth_Share_Database - Android Bluetooth File Sharing Database
  20. Type_Samsung_Smart_Tethering - Samsung Smart Tethering Database
  21. Type_Android_WiFi_QTables - Android WiFI Q Tables
  22. Type_Samsung_Q_Image - Samsung image format used during boot and shutdown
  23. Type_eDiscovery_Concordance - A concordance file from an eDiscovery dump
  24. Type_Notepad_Plus_Plus_Session - Notepad++ session information
  25. Type_ProcMon_Log - ProcMon tracing logs
  26. Type_IDA_Type_Library - IDA Pro Disassembler Type Information Library
  27. Type_Firefox_Key_Database - Firefox Key Database
  28. Type_Firefox_Web_App_Store - Firefox Web App Storage
  29. Type_Firefox_Favicons - Firefox Web Page Icons
  30. Type_Firefox_Cache - Firefox Cache
  31. Type_Firefox_Storage - Firefox Website Storage
  32. Type_Firefox_Object_Data - Firefox Object Data
  33. Type_Firefox_Object_Key - Firefox Object Key
  34. Type_Apple_Resource - Apple Double Resource
  35. Type_Bink_Video - Bink Video
  36. Type_BSON - Binary JSON
  37. Type_DirectX_Object - DirectX Object File (XOF)
  38. Type_Apple_Aggregated_Preferences - Yet another Plist
  39. Type_Kaspersky_Virus_Definitions - Kaspersky definitions
  40. Type_Koan_Pro_Composition - Koan Pro Composition
  41. Type_Photoshop_Action - Photoshop action
  42. Type_Intel_Hex - Firmware programming file
  43. Type_iOS_Processing_Pipeline - iOS PencilKit pipeline
  44. Type_iOS_Keyboard_Image - iOS Keyboard
  45. Type_iOS_Locationsd_Tiles - Locationds Tiles
  46. Type_iOS_Voice_Services_Cache - iOS Voice Services Cache
  47. Type_iOS_Shortcut_Plist - iOS Shortcuts

Entity Types

  1. ENTITY_TYPE_BITCOIN - A bitcoin account
  2. ENTITY_TYPE_BITCOIN_SEED - A bitcoin seed phrase

Event Types

  1. EVENT_TYPE_COOKIE_CREATED - A browser cookie was created.
  2. EVENT_TYPE_COOKIE_USED - A browser cookie was used.
  3. EVENT_TYPE_FILE_TRANSFER - A file was transferred.

Location Type

Message Type

URL Types

  1. URL_TYPE_VOLLEY_CACHE - A URL used by Android's Volley caching system to retrieve a file from the internet
  2. URL_TYPE_APPLICATION - A URL used by an application to retrieve a file from the internet