Difference between revisions of "Release 2024-02-06"
Jump to navigation
Jump to search
| (One intermediate revision by the same user not shown) | |||
| Line 4: | Line 4: | ||
==Improvements== | ==Improvements== | ||
# We pull more information from Apple [[Type_Comm_Center_PList|CommCenter plists]] | # We pull more information from Apple [[Type_Comm_Center_PList|CommCenter plists]] | ||
| − | # Location history is now parsed from Google Takeouts | + | # Location history is now parsed from [[Type_Google_Takeout_Location_History|Google Takeouts]] |
# Media will now have hashes calculated for them | # Media will now have hashes calculated for them | ||
# Investigation Summary report now includes referenced file contents | # Investigation Summary report now includes referenced file contents | ||
| − | # MAC addresses are now extracted from Google Takeout | + | # MAC addresses are now extracted from [[Type_Google_Takeout_Location_History|Google Takeout]] |
# Include <code>[[Load_Validation|ValidateLoad.exe]]</code> for tool validation | # Include <code>[[Load_Validation|ValidateLoad.exe]]</code> for tool validation | ||
# [[Type_KnowledgeC|KnowledgeC]] files are now exploited | # [[Type_KnowledgeC|KnowledgeC]] files are now exploited | ||
# Added [[Type_Mozilla_LZ4_Compressed_Data|LZ4]] compression | # Added [[Type_Mozilla_LZ4_Compressed_Data|LZ4]] compression | ||
| − | # Better Protocol Buffer support | + | # Better [[Type_Protocol_Buffer|Protocol Buffer]] support |
| − | # Better file carving. We now score 100% hash match on [https://www.khyrenz.com/resources Khyrenz] | + | # Better [[Carve#Algorithm|file carving]]. We now score 100% hash match on the especially devious [https://www.khyrenz.com/resources Khyrenz] forensic carving test media. |
# We now write more information to lock files (who wrote it and why) | # We now write more information to lock files (who wrote it and why) | ||
# Added more file types that can be given names to carved files | # Added more file types that can be given names to carved files | ||
| Line 22: | Line 22: | ||
# Consolidated Contact report was missing some email addresses | # Consolidated Contact report was missing some email addresses | ||
# Better rendering of PDF files | # Better rendering of PDF files | ||
| − | # XRY expansion missed some SMS messages | + | # [[Type_XRY_XML_File|XRY]] expansion missed some SMS messages |
# Android SMS was missing messages | # Android SMS was missing messages | ||
# MBOX expansion is now more forgiving about garbage at the beginning | # MBOX expansion is now more forgiving about garbage at the beginning | ||
| Line 28: | Line 28: | ||
# Better temporary file cleanup after errors | # Better temporary file cleanup after errors | ||
# Deleting a Tag now deletes everywhere | # Deleting a Tag now deletes everywhere | ||
| − | # Azure Forensic logging was missing location types | + | # [[Azure_Log_Analytics|Azure Forensic logging]] was missing location types |
# Fixed edge condition when carving files from multiple machines | # Fixed edge condition when carving files from multiple machines | ||
# Better identification of UTF-8 text, JSON and DJI data | # Better identification of UTF-8 text, JSON and DJI data | ||
| Line 34: | Line 34: | ||
==New Types== | ==New Types== | ||
| − | # 11 new file types | + | # 11 new [[File Types Supported|file types]] |
| − | # 2 new Location types (Google Takeout Place visit and Activity Segment) | + | # 2 new [[Location Types|Location types]] (Google Takeout Place visit and Activity Segment) |
| − | # 3 new Event types (Google Takeout Place visit, Activity Segment and Financial Transaction) | + | # 3 new [[Event Types|Event types]] (Google Takeout Place visit, Activity Segment and Financial Transaction) |
| − | # 4 New Entity types | + | # 4 New [[Entity Types|Entity types]] |
# There is now a Microsoft Documents file group | # There is now a Microsoft Documents file group | ||
Latest revision as of 10:53, 8 June 2024
Truxton 4.3.1
Improvements
- We pull more information from Apple CommCenter plists
- Location history is now parsed from Google Takeouts
- Media will now have hashes calculated for them
- Investigation Summary report now includes referenced file contents
- MAC addresses are now extracted from Google Takeout
- Include
ValidateLoad.exefor tool validation - KnowledgeC files are now exploited
- Added LZ4 compression
- Better Protocol Buffer support
- Better file carving. We now score 100% hash match on the especially devious Khyrenz forensic carving test media.
- We now write more information to lock files (who wrote it and why)
- Added more file types that can be given names to carved files
- Support Python 3.12
- You can now specify a database password when installing Truxton
Bug Fixes
- Accounts are now added as part of Android contacts
- Consolidated Contact report was missing some email addresses
- Better rendering of PDF files
- XRY expansion missed some SMS messages
- Android SMS was missing messages
- MBOX expansion is now more forgiving about garbage at the beginning
- Fixed Chinese text appearing in log files
- Better temporary file cleanup after errors
- Deleting a Tag now deletes everywhere
- Azure Forensic logging was missing location types
- Fixed edge condition when carving files from multiple machines
- Better identification of UTF-8 text, JSON and DJI data
- Searching text in the desktop's hex view had wrong highlight length
New Types
- 11 new file types
- 2 new Location types (Google Takeout Place visit and Activity Segment)
- 3 new Event types (Google Takeout Place visit, Activity Segment and Financial Transaction)
- 4 New Entity types
- There is now a Microsoft Documents file group