sleuthkit-announce Mailing List for The Sleuth Kit (Page 2)
Brought to you by:
carrier
You can subscribe to this list here.
2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(1) |
Oct
(1) |
Nov
|
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2003 |
Jan
(1) |
Feb
|
Mar
|
Apr
(1) |
May
|
Jun
(2) |
Jul
|
Aug
(3) |
Sep
|
Oct
|
Nov
(1) |
Dec
|
2004 |
Jan
(1) |
Feb
|
Mar
(2) |
Apr
(1) |
May
|
Jun
(1) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
2005 |
Jan
|
Feb
|
Mar
(1) |
Apr
(1) |
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
2006 |
Jan
|
Feb
|
Mar
|
Apr
|
May
(1) |
Jun
|
Jul
(1) |
Aug
|
Sep
(2) |
Oct
|
Nov
|
Dec
(1) |
2007 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
|
Jun
(1) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(1) |
2008 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
(1) |
Oct
(1) |
Nov
|
Dec
|
2009 |
Jan
|
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2010 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
(1) |
Aug
|
Sep
(2) |
Oct
(1) |
Nov
|
Dec
|
2011 |
Jan
|
Feb
|
Mar
(2) |
Apr
|
May
|
Jun
(1) |
Jul
|
Aug
(1) |
Sep
|
Oct
(1) |
Nov
(1) |
Dec
|
2012 |
Jan
|
Feb
|
Mar
|
Apr
|
May
(1) |
Jun
(2) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
(2) |
Nov
(2) |
Dec
(1) |
2013 |
Jan
(2) |
Feb
(1) |
Mar
(1) |
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
|
Sep
(4) |
Oct
(1) |
Nov
|
Dec
|
2014 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
|
Jul
(2) |
Aug
(1) |
Sep
|
Oct
|
Nov
(1) |
Dec
|
2015 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(1) |
Jul
|
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
2016 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(3) |
Aug
(1) |
Sep
|
Oct
|
Nov
|
Dec
|
2017 |
Jan
|
Feb
|
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
|
Aug
(1) |
Sep
|
Oct
(1) |
Nov
|
Dec
|
2018 |
Jan
|
Feb
|
Mar
(3) |
Apr
|
May
(1) |
Jun
|
Jul
|
Aug
(1) |
Sep
|
Oct
|
Nov
(1) |
Dec
|
From: Brian C. <ca...@sl...> - 2013-09-25 22:01:55
|
Long overdue release with new features and bug fixes. New features include: * Multi-select for tagging and extraction * 64-bit Windows installer (has more limited video playback though) * Raw regripper output is available. * Metadata content viewer * Custom tag names persist across cases Bug fixes: * Better error reporting * TSK NTFS bug fix that was showing deleted files in the wrong folder. http://www.sleuthkit.org/autopsy Note to developers: Sorry. We had to make some backward incompatible API changes with this release. It should not effect your module development except that major version of the platform incremented. You'll need to update your module to depend on the new version. Contact me with any questions about this. Don't forget: * 2-day Autopsy user training in November (http://info.basistech.com/blog/bid/317039/Autopsy-Training-Scheduled-for-November-6-7-2013) * 1/2 day Autopsy development training before OSDFCon |
From: Brian C. <ca...@sl...> - 2013-09-25 19:14:56
|
Now compiles on Linux (again)! http://sleuthkit.org/sleuthkit/download.php |
From: Brian C. <ca...@sl...> - 2013-09-25 13:11:39
|
Note that a last minute inclusion of a fiwalk patch means that this will not compile in some cases on Linux (and apparently FreeBSD). We're testing the patch and will likely have a new release soon. Sorry about that. On Sep 24, 2013, at 11:00 PM, Brian Carrier <ca...@sl...> wrote: > New version is on the website. Mostly bug fixes. > > http://www.sleuthkit.org/sleuthkit > > Updates: > • FILE_NAME times in timelines > • Cellebrite disk image auto-detect > • 64-bit windows targets > • Fixed bug with Sqlite code not using NTFS Sequence > • Jar files have native libraries in them > > Corresponding autopsy release will come soon... > > > ------------------------------------------------------------------------------ > October Webinars: Code for Performance > Free Intel webinars can help you accelerate application performance. > Explore tips for MPI, OpenMP, advanced profiling, and more. Get the most from > the latest Intel processors and coprocessors. See abstracts and register > > http://pubads.g.doubleclick.net/gampad/clk?id=60133471&iu=/4140/ostg.clktrk > _______________________________________________ > sleuthkit-announce mailing list > sle...@li... > https://lists.sourceforge.net/lists/listinfo/sleuthkit-announce |
From: Brian C. <ca...@sl...> - 2013-09-25 03:00:15
|
New version is on the website. Mostly bug fixes. http://www.sleuthkit.org/sleuthkit Updates: • FILE_NAME times in timelines • Cellebrite disk image auto-detect • 64-bit windows targets • Fixed bug with Sqlite code not using NTFS Sequence • Jar files have native libraries in them Corresponding autopsy release will come soon... |
From: Brian C. <ca...@sl...> - 2013-06-19 17:50:23
|
3.0.6 is available for download! New Features: • Logical files and folders support • New file views in directory tree to view: deleted, executable, archive files and files by size • ext4 and yaffs2 support (via TSK 4.1.0) • Improvements to tagging of files and keyword search results • Any file and folder can be selectively ingested using the directory tree view And a bunch of bug fixes. http://sleuthkit.org/autopsy/download.php Thanks to Adam, Tim, and Sean for the dev work. We have two Autopsy courses planned in Northern VA. One in Aug and one right after OSDFCon in Nov. See the Basis site for details: http://www.basistech.com/digital-forensics/training/ Also, this year, we are not going to have a 1-day hack-a-thon at the Open Source Digital Forensics Conference (OSDFCon), but we are instead going to have a 4+ month-long module building contest. The basic idea is that you write a really neat, open source module, present it at the conference in 5 minutes (in person or via video), the attendees vote, and you can win cash (up to $1500). Details are on the site: http://www.basistech.com/about-us/events/open-source-forensics-conference/contest/ brian |
From: Brian C. <ca...@sl...> - 2013-06-17 21:57:41
|
Version 4.1.0 of The Sleuth Kit is finally available. It adds many commonly requested features: - YAFFS2 and Ext4 support (from viaForensics and Kevin Fairbanks) - Framework runs on Linux and OS X. - Lots of other less minor things in comparison (see http://sleuthkit.org/sleuthkit/history.php for details) http://sleuthkit.org/sleuthkit/download.php A note on YAFFS2, though I'm sure I'll be responding to many questions like this in the future. The layout of the flash memory spare area is not defined in the YAFFS2 spec. The viaForensics patch had a format that they commonly saw and we (Basis Technology) updated it with some layouts that we also came across. Ideally, TSK would allow the caller to specify the layout, but that feature does not yet exist. See some notes here on the topic: http://wiki.sleuthkit.org/index.php?title=YAFFS2_Implementation_Notes I've cc:ed sleuthkit-developers on this because this version made some development environment changes. Previously, include paths were '/usr/local/include/tsk3'...' Well, it's no longer TSK3. The number was removed so that it does not need to be updated with major version changes. So, update your code to remove the '3'. thanks, brian |
From: Brian C. <ca...@sl...> - 2013-03-29 01:29:05
|
Autopsy 3.0.5 is available on the website with new features and bug fixes. New Features / Improvements: • New ingest module that opens ZIP and other archive formats. • Timeline (Beta) -- access it from the Tools menu. • improved image loading in Media View and Thumbnail View (faster loading, handles large files better) • Uses more signatures instead of extensions (keyword search and exif modules) • Updated Ingest Message Inbox Bug Fixes: • fixed memory leaks in "Add Image" • The "media view" tab is inactive for deleted files (#165) • fixed directory tree history being reset when tree is refreshed. http://www.sleuthkit.org/autopsy/ Nearly all of the work done by Basis Technology with a few patches submitted by users. Thanks! brian |
From: Brian C. <ca...@sl...> - 2013-02-04 18:27:53
|
Sleuth Kit 4.0.2 is now available. http://www.sleuthkit.org/sleuthkit/ We're working on 4.1.0, which will have the submitted patches for YAFFS2 and Ext4, our support for Linux/OS X support of the framework, hash database support in SQLite databases and more. brian New Features in Core: • fiwalk is now included. Bug Fixes in Core: • Fixed fcat to work on NTFS files (still doesn't support ADS though). • Fixed HFS+ support in tsk_loaddb / SQLite -- root directory was not added. • NTFS code now looks at all MFT entries when listing directory contents. It used to only look at unallocated entries for orphan files. This fixes an image that had allocated files missing from the directory b-tree. • NTFS code uses sequence number when searching MFT entries for all files. • Libewf detection code change to support v2 API more reliably (ID: 3596212). • NTFS $SII code could crash in rare cases if $SDS was multiple of block size. Framework: • Added new API to TskImgDB that returns the base name of an image. • Numerous performance improvements to framework. • Removed requirement in framework to specify module extension in pipeline configuration file. • Added blackboard artifacts to represent both operating system and network service user accounts. Java Bindings • More methods to query files • Methods to get current directory when being added to DB. • Modified class structure a bit • More lazy loading for children / parents. • Better exception throwing from C++ |
From: Brian C. <ca...@sl...> - 2013-01-23 17:32:17
|
New version on the website. http://www.sleuthkit.org/autopsy/download.php Improvements: • File tagging. • Error notification in lower right. Bug Fixes: • DLL installation issues fixed. • Out of memory configuration changed. • Issue that caused duplicate keyword search results fixed. • Crash when generating HTML and Excel reports with special characters. • MS Office text extraction • EXIF data not being extracted All work in this release was done by Basis Technology with debugging help from various people. Thanks! thanks, brian |
From: Brian C. <ca...@sl...> - 2013-01-08 15:22:05
|
It has a big bug fix with keyword search, so all users should upgrade. As a result of the fix, all cases indexed with 3.0.2 and before should be re-indexed -- sorry. It also has a much improved reporting infrastructure thanks to one of our interns, Devin, who finished in Dec. The timeline work of our other intern, Nick, who finished in Dec. The timeline feature will be in a near-term release. http://sleuthkit.org/autopsy/download.php brian |
From: Brian C. <ca...@sl...> - 2012-12-20 22:31:13
|
A new version is on the website. Lots of features from user requests. http://www.sleuthkit.org/autopsy/ Improvements: • New feature to extract unallocated space as a single file. • Hashkeeper database support • Can add comments to bookmarks and bookmarks are reported. • Queuing time is reduced during ingest. • Jump to arbitrary pages in thumbnail view. • Changed flow of add image wizard to configure modules while database is being populated. • Changed HTML report layout. Bug Fixes: • Fixed keyword search interval (did not run until end) • Fixed domain type in Web Downloads adata. • Added hash and keyword search results to report. • Fixed UI issue whereby NSRL was always being looked up. |
From: Brian C. <ca...@sl...> - 2012-11-15 23:12:18
|
Autopsy 3.0.1 is available on the website. http://www.sleuthkit.org/autopsy/download.php Improvements: • Significant performance improvements when adding images. • Slight improvements in UI performance for large number of results. • Improved stability when running ingest on multiple images. • Removed limit on number of results displayed. • Thumbnail viewer - added paging and removed limit of images. • Better HTML report navigation, handling large reports better. • Updated Add image wizard to support local devices. Bug Fixes: • Fixed reading content from multiple file attributes (NTFS, HFS). • Added ability to extract contents of the unalloc files. • Enable user to select any image file extension when opening image. • Thunderbird parser module fixes. • Reporting fixes: added missing artifacts (keyword search, hash hits, file bookmarks). |
From: Brian C. <ca...@sl...> - 2012-11-15 15:17:06
|
TSK 4.0.1 is available on the website: http://www.sleuthkit.org/sleuthkit/download.php New Features: - Some tools are now much faster (tsk_loaddb, blkcalc, blkstat, blkls -l) - new fcat tool that outputs contents given a file name (ifind and icat put together) - General NTFS and FAT performance improvements Bug Fixes: - mactime timezone fix - memory leaks and physical drive size fixes from ADF - Size of alternate data streams in database of tsk_loaddb and framework. |
From: Brian C. <ca...@sl...> - 2012-10-16 19:16:48
|
Autopsy 3.0 was posted to the site yesterday. Since the last beta release, we fixed a few bugs that we found during the workshop at the open source forensics conference. Autopsy 3 is a complete rewrite from Autopsy 2. It is Windows-only and easier to use. We are currently working on adding more features and making it easier to install on nom-windows platforms. We'll also be posting more docs and tutorials on using it and writing modules for it. http://www.sleuthkit.org/autopsy/ Thanks to everyone who has been involved in building this. It has been in the works for almost 2 years with varying levels of effort at Basis Technology. The US Army Intelligence Center of Excellence funded some of the development this past year and 42Six Solutions joined us for that effort. thanks, brian |
From: Brian C. <ca...@sl...> - 2012-10-02 13:11:09
|
After many claims that it was coming soon, the open source conference has forced us to make that a reality. Version 4.0 is now on the website: http://sleuthkit.org/sleuthkit/index.php What's new since the last beta: - The Framework is now officially released on Windows. New features since the last beta include a new Exif module and tsk_analyzeimg will also run scalpel and process the carved files in the pipelines. - Better FAT orphan file finding. - Better HFS+ support (ATC-NY) - mactime -y flag for ISO8601 format Other things that are notable and were in the last beta release: - Support for libewf v2 - Only need to specify first file in E01 series. - C++ classes and Java bindings - Lots of minor bug fixes... brian |
From: Brian C. <ca...@sl...> - 2012-09-14 14:47:07
|
Beta 5 of Autopsy 3 (and likely the last beta before the full release) is on the website: http://www.sleuthkit.org/autopsy Autopsy 3 is still Windows-only and a complete rewrite from Autopsy 2. If you haven't checked out the screen shots yet, I'd recommend it: http://sleuthkit.org/autopsy/desc3.php http://sleuthkit.org/autopsy/images/v3/overview.png We have a hands-on workshop before the OSDF Conference on Oct 2 that focuses on using Autopsy 3. We'll also have a presentation at the conference on it. http://www.osdfcon.org/ Updates with this beta: • Extract non-English strings from unknown file types. • Extract more data from HTML files. • Extract EXIF data • Basic bookmark support • Body file report module Bug Fixes: • Better memory footprint of keyword search • Media player occasionaly crashes All development in this release was from Basis Technology. brian |
From: Brian C. <ca...@sl...> - 2012-07-05 14:49:39
|
I forgot to announce this on the 3rd. Beta 4 is available. The Windows installer is available for download. http://www.sleuthkit.org/autopsy/download.php New Features: • MBOX / Thunderbird parsing module • Better lnk file parsing Bug Fixes: • Included needed jar file for Recent Activity (Issue #52). • Fixed error handling from ingest (Issue #53) Development since the last beta was done by Basis Technology and 42Six Solutions. It was funded by the US Army Intelligence Center of Excellence (USAICoE). No significant development has occurred on the front of making this easy to distribute on non-Windows platforms. Though, you can now download Autopsy source and build it w/out NetBeans since the ant target will pull down the needed jar files. The BUILDING.txt file has been updated. brian |
From: Brian C. <ca...@sl...> - 2012-06-15 04:17:11
|
Looks like I uploaded a corrupt installer that was missing some bytes. Updated version is now up there (MD5: c50a0cc7572d6f984d53195a338819a8). Sorry about that. On Jun 14, 2012, at 5:58 PM, Brian Carrier wrote: > This is an exciting beta release. Lots of new features. Still Windows-only, but it now comes with an installer that includes Java. > > High-level list of new features includes: > • Ingest manager that runs triage/ingest task after disk is added. > • Keyword search (indexed via SOLR) > • Recent activity extract (web artifacts, recent documents, devices, etc.) > • Improved UI > > Full description, screen shots, and list of known limitations at: > http://www.sleuthkit.org/autopsy/desc3.php > > Download from: > http://www.sleuthkit.org/autopsy/download.php > > > Development since the last beta was done by Basis Technology and 42Six Solutions. It was funded by the US Army Intelligence Center of Excellence (USAICoE). > > brian |
From: Brian C. <ca...@sl...> - 2012-06-14 21:58:52
|
This is an exciting beta release. Lots of new features. Still Windows-only, but it now comes with an installer that includes Java. High-level list of new features includes: • Ingest manager that runs triage/ingest task after disk is added. • Keyword search (indexed via SOLR) • Recent activity extract (web artifacts, recent documents, devices, etc.) • Improved UI Full description, screen shots, and list of known limitations at: http://www.sleuthkit.org/autopsy/desc3.php Download from: http://www.sleuthkit.org/autopsy/download.php Development since the last beta was done by Basis Technology and 42Six Solutions. It was funded by the US Army Intelligence Center of Excellence (USAICoE). brian |
From: Brian C. <ca...@sl...> - 2012-05-30 14:15:14
|
A way overdue Sleuth Kit 4.0.0b1 (b1 is for beta 1) release is on the site. It has a lot of new features, including: • Framework with first set of basic modules (hash calculation, hash lookup, entropy calculation, RegRipper, ZIP file extraction, extraction via name signatures, etc.) -- Windows-only • Multithreaded support • C++ wrapper classes • JNI bindings and data model classes • All non-set times are displayed as 0 instead of 1970. • Support for libewf v2 • Only first file in split or E01 needs to be specified. • EnCase Hashset support in hash tools. • New table schema for loaddb database that supports more data types (carved, local files, etc.). • ... I'm really excited about the new framework (http://sleuthkit.org/sleuthkit/framework.php), but we still need some more modules for it. We're going to have some workshops at the open source conference in Oct (www.osdfcon.org) to help developers make modules for it. New version can be downloaded here: http://sleuthkit.org/sleuthkit/download.php thanks, brian |
From: Brian C. <ca...@sl...> - 2011-11-15 15:06:03
|
The second beta of Autopsy 3 is now available. The new major feature is hash database support. There were a lot of other behind the scene changes, including a new database design and other performance improvements. This is still a Windows-only release. It can run on other platforms, but we still need to do some work on packaging so that all of the libraries are found on other platforms when it is installed (i.e. if you know Java/JNI you can manually do it, but it doesn't work out of the box). http://www.sleuthkit.org/autopsy/download.php Thanks to Peter Martel for his work on getting these improvements in there. thanks, brian |
From: Brian C. <ca...@sl...> - 2011-10-07 20:37:39
|
TSK 3.2.3 is up. This will probably be the last release in the 3.2 branch. Lots of new stuff on the 'trunk' that will be released as 3.3.0 in the near future. http://sleuthkit.org/sleuthkit/download.php This release has some minor bug fixes and features. New features include: • Only need to specify first E01 file in a set of files • Added -d option to tsk_recover • DOS partitions are loaded even if an extended partition fails Bug fixes include: • Cleanup of corrupt orphan FAT names • RAW CD Support See http://svn.sleuthkit.org/repos/sleuthkit/tags/sleuthkit-3.2.3/NEWS.txt for more details. thanks, brian |
From: Brian C. <ca...@sl...> - 2011-08-16 17:44:57
|
The website now has a link to the first beta release of 3.0.0. For those who have not heard a quick presentation on 3.0.0 yet, it is a complete rewrite using the NetBeans Platform in Java. NetBeans allows Autopsy to have a modular framework that will make it easy to incorporate lots of other open source forensics tools. Here are some of the milestones that we are planning: • Aug 2011: First Betas: Windows only. Provides ability to browse directory hierarchy and do basic file searching. • Oct 2011: First stable release: New database design, allows local files to be imported (not just disk images), adds bookmarks, save search results, supports hash databases, and can identify file types. • Jan 2012: Adds more analysis modules (i.e. keyword search, timeline, carving). Version 2 provides more core features than the version 3 beta currently has (i.e. keyword searching, timelines), but we are throwing this out there to get some early feedback. Please send any issues to the sleuthkit-users list. If you want to get involved and write modules, let me know. I think we'll be moving the source to github and that can happen sooner than later if there is interest from others who want to play with the source. Thanks to Anthony Lawrence, James Antonius, and Peter Martel for their work in developing what we have so far. http://sleuthkit.org/autopsy/download.php thanks, brian |
From: Brian C. <ca...@sl...> - 2011-06-13 16:07:12
|
Sleuth Kit 3.2.2 has been released. It has some minor bug fixes and enhancements. http://www.sleuthkit.org/sleuthkit/ New Features include: • Support for RAW CDs Bug fixes include: • ISO9660 directory processing • FAT deleted file detection • FAT deleted name cleanup thanks, brian |
From: Brian C. <ca...@sl...> - 2011-03-01 03:44:18
|
Version 3.2.1 is on the website: http://sleuthkit.org/sleuthkit/download.php It has some minor bug fixes and a few minor feature additions. thanks, brian Bug Fixes - 3108272: fls arguments for -d and -u - 3105539: compile error issues because of SQlite and pthreads - 3173095: missing FAT files because of invalid dates. - 3184419: mingew compile errors. - 3191391: surround file name in quotes in mactime -d csv output New Features: - A single dummy entry is added to the SQlite DB if no volume exists so that all programs can assume that there will be at least one volume in the table. - 3184455: allow srcdir != builddir |