Difference between revisions of "Release 2024-02-06"

From truxwiki.com
Jump to navigation Jump to search
 
(One intermediate revision by the same user not shown)
Line 4: Line 4:
 
==Improvements==
 
==Improvements==
 
# We pull more information from Apple [[Type_Comm_Center_PList|CommCenter plists]]
 
# We pull more information from Apple [[Type_Comm_Center_PList|CommCenter plists]]
# Location history is now parsed from Google Takeouts
+
# Location history is now parsed from [[Type_Google_Takeout_Location_History|Google Takeouts]]
 
# Media will now have hashes calculated for them
 
# Media will now have hashes calculated for them
 
# Investigation Summary report now includes referenced file contents
 
# Investigation Summary report now includes referenced file contents
# MAC addresses are now extracted from Google Takeout
+
# MAC addresses are now extracted from [[Type_Google_Takeout_Location_History|Google Takeout]]
 
# Include <code>[[Load_Validation|ValidateLoad.exe]]</code> for tool validation
 
# Include <code>[[Load_Validation|ValidateLoad.exe]]</code> for tool validation
 
# [[Type_KnowledgeC|KnowledgeC]] files are now exploited
 
# [[Type_KnowledgeC|KnowledgeC]] files are now exploited
 
# Added [[Type_Mozilla_LZ4_Compressed_Data|LZ4]] compression
 
# Added [[Type_Mozilla_LZ4_Compressed_Data|LZ4]] compression
# Better Protocol Buffer support
+
# Better [[Type_Protocol_Buffer|Protocol Buffer]] support
# Better file carving. We now score 100% hash match on [https://www.khyrenz.com/resources Khyrenz]
+
# Better [[Carve#Algorithm|file carving]]. We now score 100% hash match on the especially devious [https://www.khyrenz.com/resources Khyrenz] forensic carving test media.
 
# We now write more information to lock files (who wrote it and why)
 
# We now write more information to lock files (who wrote it and why)
 
# Added more file types that can be given names to carved files
 
# Added more file types that can be given names to carved files
Line 22: Line 22:
 
# Consolidated Contact report was missing some email addresses
 
# Consolidated Contact report was missing some email addresses
 
# Better rendering of PDF files
 
# Better rendering of PDF files
# XRY expansion missed some SMS messages
+
# [[Type_XRY_XML_File|XRY]] expansion missed some SMS messages
 
# Android SMS was missing messages
 
# Android SMS was missing messages
 
# MBOX expansion is now more forgiving about garbage at the beginning
 
# MBOX expansion is now more forgiving about garbage at the beginning
Line 28: Line 28:
 
# Better temporary file cleanup after errors
 
# Better temporary file cleanup after errors
 
# Deleting a Tag now deletes everywhere
 
# Deleting a Tag now deletes everywhere
# Azure Forensic logging was missing location types
+
# [[Azure_Log_Analytics|Azure Forensic logging]] was missing location types
 
# Fixed edge condition when carving files from multiple machines
 
# Fixed edge condition when carving files from multiple machines
 
# Better identification of UTF-8 text, JSON and DJI data
 
# Better identification of UTF-8 text, JSON and DJI data
Line 34: Line 34:
  
 
==New Types==
 
==New Types==
# 11 new file types
+
# 11 new [[File Types Supported|file types]]
# 2 new Location types (Google Takeout Place visit and Activity Segment)
+
# 2 new [[Location Types|Location types]] (Google Takeout Place visit and Activity Segment)
# 3 new Event types (Google Takeout Place visit, Activity Segment and Financial Transaction)
+
# 3 new [[Event Types|Event types]] (Google Takeout Place visit, Activity Segment and Financial Transaction)
# 4 New Entity types
+
# 4 New [[Entity Types|Entity types]]
 
# There is now a Microsoft Documents file group
 
# There is now a Microsoft Documents file group

Latest revision as of 10:53, 8 June 2024

Truxton 4.3.1

<< Released 2024-02-06 >>

Improvements

  1. We pull more information from Apple CommCenter plists
  2. Location history is now parsed from Google Takeouts
  3. Media will now have hashes calculated for them
  4. Investigation Summary report now includes referenced file contents
  5. MAC addresses are now extracted from Google Takeout
  6. Include ValidateLoad.exe for tool validation
  7. KnowledgeC files are now exploited
  8. Added LZ4 compression
  9. Better Protocol Buffer support
  10. Better file carving. We now score 100% hash match on the especially devious Khyrenz forensic carving test media.
  11. We now write more information to lock files (who wrote it and why)
  12. Added more file types that can be given names to carved files
  13. Support Python 3.12
  14. You can now specify a database password when installing Truxton

Bug Fixes

  1. Accounts are now added as part of Android contacts
  2. Consolidated Contact report was missing some email addresses
  3. Better rendering of PDF files
  4. XRY expansion missed some SMS messages
  5. Android SMS was missing messages
  6. MBOX expansion is now more forgiving about garbage at the beginning
  7. Fixed Chinese text appearing in log files
  8. Better temporary file cleanup after errors
  9. Deleting a Tag now deletes everywhere
  10. Azure Forensic logging was missing location types
  11. Fixed edge condition when carving files from multiple machines
  12. Better identification of UTF-8 text, JSON and DJI data
  13. Searching text in the desktop's hex view had wrong highlight length

New Types

  1. 11 new file types
  2. 2 new Location types (Google Takeout Place visit and Activity Segment)
  3. 3 new Event types (Google Takeout Place visit, Activity Segment and Financial Transaction)
  4. 4 New Entity types
  5. There is now a Microsoft Documents file group