Autor Thema: Forensic Software diverses  (Gelesen 9118 mal)

0 Mitglieder und 1 Gast betrachten dieses Thema.

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 9.1.1004
« Antwort #135 am: 09 Dezember, 2021, 19:30 »
Changelog

    Case Management:

    Enhanced USB Write Block block more kinds of removable storage devices

    Disk Image and Filesystem Support:

    APFS, added additional file system caching for better performance. Result was up to 30X performance improvement for file searching.
    Support for APFS Sealed Volumes
    APFS, handle compression algorithm 5

    File Viewer:

    Fixed hang when a file system read error occurs when attempting to generate thumbnails

    JSON Viewer:

    Added new feature to parse Google Location History JSON format archive file exported via Google Takeout service, shows a summary of the locations list.
    Selected locations can be exported in KML/GPX/CSV formats for use in applications like Google Earth, Google Maps My Maps and OSForensics Map Viewer.
    Updated right-click menu to view locations on internal Map Viewer.

    Web Capture:

    When downloading large videos the connection to remote server could end with windows error 10060 (connection drop) and/or 10054 (server terminate connection). Previous behaviour: OSForensics reported failed download. Now if OSForensics detects the download is because of above errors, it try attempt to retry the download (the download should continue where it left off). If it fails three (3) times, it will ask user if they want continue to retry or stop.

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 9.1.1005
« Antwort #136 am: 21 Dezember, 2021, 10:00 »
Changelog

    Create / Search Index
        New indexer builds with updated support for APFS
    File Name Search
        Recognizes JSON (*.json) and Event Log (*.evtx) files and open them with internal viewers
    JSON Viewer
        Added support to parse Google Chat record exported from Google Takeout service
        Can parse a single "messages.json" JSON format file or select to parse multiple files at once
        Same as the Hangouts, it shows the conversations in HTML with formatted chatting app-like style
        Fixed right-click Add to case menu, users can choose KML/GPX/CSV formats when adding selected items to case
    Manage Case
        Updated USB write-block message to differentiate when enabling and disabling the setting
    Raw Disk Viewer
        Fix handling of clusters for APFS "cloned" inodes that share clusters with other inodes

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 9.1.1006
« Antwort #137 am: 23 Dezember, 2021, 11:00 »
Changelog
       
    Case Manager
        Added option to "Add to Case" when right click on multiple tagged items. OSForensics will add tagged files but warn and provide a list of tagged items that are references (e.g. artifact found within a database) that could not be added to case.
    Device Manager
        Added support for detecting hidden file systems via on entire disk images. This allows for recovery of deleted partitions (depending on what remnants are left on disk)
    System information
        Updated hardware support to correct report on DDR5 RAM and Intel 12th Gen CPUs with efficiency cores and performance cores
    Password Recovery
        Fixed bug causing columns in list view to disappear after user has configured the active columns, when a new case is loaded
    Misc
        For some modules that allow user to configure columns orders, added a "Defaults" button to allow user to reset the columns to OSF's default settings
        Added the Microsoft DLL, msvcp140_codecvt_ids.dll to installer as it is required by translate.exe, which is in turn used for viewing Word documents. But the DLL is missing in Win 7. The codecvt_ids DLL converts characters between different character sets.

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
Autopsy 4.19.3
« Antwort #138 am: 27 Dezember, 2021, 22:00 »
Autopsy is a graphical interface to The Sleuth Kit and other analysis tools. It was designed to be an extensible platform so that it can be an end-to-end digital forensics solution that incorporates plug-in modules from both open and closed source projects. The application provides users with various analysis features and with the possibility of generating HTML or CSV reports as well.

License: GPL

Changelog

    Bug Fixes:

    Updates for log4j vulnerabilities.
    Solr 8.11.0 Upgrade
    Manual update of log4j to 2.16.0

[close]

http://www.sleuthkit.org/autopsy

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 9.1.1007
« Antwort #139 am: 24 Januar, 2022, 19:00 »
Whats new:>>

    Case Manager:

    Support for adding recovered partitions to case

    Misc:

    Refresh physical disk info only when there is device change notification, to reduce costly re-scanning of physical disks
    ?Keep single instance of physical disk info shared between all modules

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 9.1.1008
« Antwort #140 am: 27 Januar, 2022, 11:01 »
Whats new:>>

    Disk Image and Filesystem Support
    Fixed HFS+ partitions being incorrectly identified as ext2

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 9.1.1009
« Antwort #141 am: 03 Februar, 2022, 11:00 »
Changelog


    Case Management:

    Fixed possible crash (crash was due to uncaught exception from MoveFile failure) when changing the case location in the Edit Case Details dialog when paths are longer than MAX_PATH

    Deleted Files:

    Cleaned up text/message for the Save Checked Deleted Files confirmation dialog
    Direct Image Access / Filesystem support
    NTFS, fixed bug in traversing $I30 entries in directories spanning multiple MFT records

    File Name Search:

    Enabled "Show $FILE_NAME Dates (NTFS)" configuration option automatically if any of the $FILE_NAME columns are selected when configuring displayed columns
    Fixed bug where the custom case directories a user can specify in the config settings did not get reset when switching between cases

    File System Browser:

    Fixed issue of FSB starting in extremely minimized state. Issue was caused if previous instance of FSB was minimized when closed. Now if closed while minimized, FSB will not save existing dimensions and reuse the last saved values

    File Viewer:

    Fixed bug where OSF crashed when trying to retrieve file info from a file that does not exist
    Fixed bug where if 'save file' option is used on a HFS file system and with 2 or more files selected, the saved file name was incorrectly output

    Mismatch Files Search:

    Updated help file to add more detail on how 'Filter Types' is used
    Fixed Chrome/Firefox Cache image exclusions (caches were in different places than expected, e.g. for Firefox, it is different based on OS)

    Search Index:

    Fixed bug where displayed sort options did not match function (email + attachments)

    Signatures:

    Will now clear create signature config (output type, hashes, etc) each time a new case is loaded

    User Activity:

    Fixed bug where all USB entries weren't displayed unless the "event log" option was selected as well
    Will now clear user activity config (date range etc) each time a new case is loaded

    Misc:

    Decreased the size of the Deleted Icon (X) overlay over image thumbnails
    Added .emlx to email pre-sets where used

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 9.1.1010
« Antwort #142 am: 24 März, 2022, 09:00 »
Changelog


    Boot VM

        Added more verbose debug logging when obtaining privileges to mount a registry hive
        Added check for whether VirtualBox extension pack is installed if USB 2.0 or USB 3.0 controller is selected

    Disk Image and Filesystem Support

        Fixed reading of volume bitmap failure due to sector unaligned access
        APFS, fixed bug causing buffer overflow when reading extended attributes (eg. compressed files)
        APFS, fixed reading compressed file data for files with hard links
        APFS, fixed bug in decompressing zlib-compressed file data
        APFS, fixed reading of lzvn-compressed file data with updated implementation
        HFS+, fixed bug in decompressing zlib-compressed file data
        HFS+, support for reading lzvn-compressed file data stored in resource fork

    File Hashing

        NSRL import, the latest hash set (2.75 Dec 2021) contains an invalid character that was stopping the import from running correctly, this has now been fixed

    Help

        Added the FireFox/Chrome cache directories that are excluded when using the Chrome/Firefox exclude image cache file options in the Files Mismatch module

    Password Recovery

        Fixed issue with browse dialog not accepting multiple files correctly

    Screen Capture

        Fixed GDI handle leak when drawing button. This caused a leak when drawing windows containing the Screen Capture button (eg. internal viewer)

    Search Index

        Fixed file handle leak
        Fixed GDI handle leak
        Fixed a bug that could occur on the off-chance that system time is the same for two searches

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 9.1.1011
« Antwort #143 am: 04 April, 2022, 06:00 »
Changelog


    Device Manager:

    Scan up to a maximum number of sectors when looking for recovered partitions. This prevents unbounded scanning of disks with large amount of unpartitioned space

    Subscription:

    Fixed crash when checking subscription validity

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 9.1.1012
« Antwort #144 am: 06 April, 2022, 09:22 »
Changelog


    File system support:

    exFAt, removed check for volume attribute bit when traversing file entries, which appears to be set in macOS created volumes (which casued file sizes to appear as 0 and some directories to be hidden)

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSFClone 1.3.1001
« Antwort #145 am: 12 April, 2022, 10:30 »
OSFClone is a free, self-booting solution which enables you to create or clone exact raw disk images quickly and independent of the installed operating system.

In addition to raw disk images, OSFClone also supports imaging drives to the open Advance Forensics Format (AFF). AFF is an open and extensible format to store disk images and associated metadata. An open standard enables investigators to use quickly and efficiently their preferred tools for drive analysis. After creating or cloning a disk image, you can mount the image with PassMark OSFMount before conducting analysis with PassMark OSForensics™.

OSFClone creates a forensic image of a disk, preserving any unused sectors, slack space, file fragmentation and undeleted file records from the original hard drive. Boot into OSFClone and create disk clones of FAT, NTFS, and USB-connected drives! OSFClone can be booted from CD/DVD drives, or from USB flash drives.

Freeware

Whats new:>>

Updated Porteus Linux to V4.0 (Base Image, Porteus-XFCE-v4.0-x86_64.iso)

http://osforensics.com/tools/create-disk-images.html

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 10.0 Beta 1
« Antwort #146 am: 10 Juni, 2022, 19:00 »
Changelog


    Boot VM:

    Will now display a proper error message when booting from VirtualBox failed (eg. when Intel VT-x/AMD-V is not enabled)
    Added check for whether VirtualBox extension pack is installed if USB 2.0 or USB 3.0 controller is selected
    Added check and display error for partition-only images without a supported OS before mounting as physical disk
    Added support for password bypass for Win 10/Server 2016 Builds 17763 and 19041 (via PEPassPass v1.2.3)

    Case Manager:

    Support for adding recovered partitions to case
    Added ability to save and load custom templates for evidence categories
    Added ability to rename case devices after they have been added
    Add Device, changed the default display name to include the date the shadow copy was taken.
    Report Generation, separated the HTML and PDF report options into different templates, no longer need to generate a HTML report to get a PDF copy
    Report Generation, added the details of OSFOrensics digital signature to generated reports
    Report Generation, updated "Link to case files" and "Copy files to report location" options to "Create Redacted Report" and "Create Full Length Report" to be more descriptive
    Report Generation, added ability to toggle the inclusion of signature certificate verification information in report generation dialog
    Report Generation, Added "Software Verification" link in report sidebar
    Report Generation, Added certificate verification information to non HTML reports
    Clipboard Viewer / ThumbCache Viewer:
    Will now draw checkerboard background for improved display of transparent images
    Improved drawing of images to reduce flickering

    Deleted Files:

    Updated to allow selecting of carving of MFT Only, MFT and Carving, or Carving Only
    MFT and Carving now enabled by default
    Added minimum size requirement for carved JPGs (126 bytes), GIFs (43 Bytes), PNGs (68 bytes)
    Changed name Plist to Binary Plist and improved detection to limit false positives
    File carving, fixed possible crash when carving MP3 files
    File carving, improved MP3/JPG detection to cut down on the number of false positive results returned
    Added secondary sorting on second column (via dropdown and/or control click on details tab)
    Disabled sorting while deleted file scan is in progress
    Lowered priority level of carving threads to improve response from computer when carving is in progress
    Thumbnail Tab, added a quality level indicator to the thumbnails preview
    Added support for carving MFT file records on non-NTFS quick formatted volumes
    Added support for recovering files from carved MFT records. This enables recovery of files from a quick-formatted volume
    Added new scan method to config window, changed dropdown box to checkboxes.
    Prepend "Carved MFT" to 'Source String' of files recovered from carved MFT records to differentiate from normal deleted files
    Added check for large buffer sizes before allocating memory when detecting faces
    Background LED indicator fixed, indicator would incorrectly reset after "Saving Delete File to Disk" while scan is running.
    File carving, optimization, improved efficiency of pattern matching code. This change roughly doubles the speed of file carving.
    File carving, optimization, updated extensions with header signature. Changed empty buffer detection to faster implementation to detect empty or repeating blocks read from disk. Scanning empty sectors is now 6 times faster
    File carving, optimization, improved the responsiveness for OSForensics when carving is running
    File carving, optimization, increased the number of carving threads to 75% of available logical processors, up to a max of 32
    File carving, improved carving of HTML files
    File carving, reduced false positives for FLV files
    File carving, changed the naming of file to be more informative, new format "Carved .JPG file found at 310GB - byte offset 0x482D709C00.jpg"
    File carving, better handling of .eml files (will verify that both "From:" and "Date:" field are present
    File carving, reduced repeated carving for file signatures with the same headers (e.g. TIFF family, ZIP family).
    File carving, ensure recovered carved file will not exceed the max file size specified by extension (or 100 MB, whichever is less)
    Opening internal viewer for Plist Files from within the deleted files module should now work
    Further optimizations to file carving. Improved accuracy for JPG files and overall performance. Compared to final V9 release, current file carving code is over 6x faster (benchmarked with an Mac E01 disk image with default carving config)

    Device Manager:

    Scan up to a maximum number of sectors when looking for recovered partitions. This prevents unbounded scanning of disks with large amount of unpartitioned space

    Disk Image and Filesystem Support:

    HFS+, preliminary support for compressed files
    HFS+, fixed bug in decompressing zlib-compressed file data
    HFS+, support for reading lzvn-compressed file data stored in resource fork
    APFS, fixed bug causing buffer overflow when reading extended attributes (eg. compressed files)
    APFS, fixed reading compressed file data for files with hard links
    APFS, fixed bug in decompressing zlib-compressed file data

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 10.0.1000
« Antwort #147 am: 14 Juli, 2022, 13:00 »
Changelog

       
    Auto Triage
        Added option to enable running auto triage automatically on startup, which can be enabled in the install to usb dialog and use settings last set
        Added splash screen and progress bar when running auto triage as a standalone option
    Analyze Shadow Copy
        Added ability to find shadow copies from analyze dialog without adding to case first
    Boot VM
        Will now display a proper error message when booting from VirtualBox failed (eg. when Intel VT-x/AMD-V is not enabled)
        Added check for whether VirtualBox extension pack is installed if USB 2.0 or USB 3.0 controller is selected
        Added check and display error for partition-only images without a supported OS before mounting as physical disk
        Added support for password bypass for Win 10/Server 2016 Builds 17763 and 19041 (via PEPassPass v1.2.3)
    Case Manager
        Support for adding recovered partitions to case
        Added ability to save and load custom templates for evidence categories
        Added ability to rename case devices after they have been added
        Add Device, changed the default display name to include the date the shadow copy was taken
        Added time zone names to time zone drop down and case report
        Report Generation, separated the HTML and PDF report options into different templates, no longer need to generate a HTML report to get a PDF copy
        Report Generation, added the details of OSFOrensics digital signature to generated reports
        Report Generation, updated "Link to case files" and "Copy files to report location" options to "Create Redacted Report" and "Create Full Length Report" to be more descriptive
        Report Generation, added ability to toggle the inclusion of signature certificate verification information in report generation dialog
        Report Generation, Added "Software Verification" link in report sidebar
        Report Generation, Added certificate verification information to non HTML reports
    Clipboard Viewer / ThumbCache Viewer
        Will now draw checkerboard background for improved display of transparent images
        Improved drawing of images to reduce flickering
    Deleted Files
        File carving, optimization. Improved accuracy for JPG files and overall performance. Compared to final V9 release, current file carving code is over 6x faster (benchmarked with an Mac E01 disk image with default carving config)
        File carving, optimization, updated extensions with header signature ????ftyp to \x00\x00\x00?ftyp instead. Changed empty buffer detection to faster implementation to detect empty or repeating blocks read from disk. Scanning empty sectors is now 6 times faster
        File carving, optimization, improved efficiency of pattern matching code. This change roughly doubles the speed of file carving
        File carving, optimization, improved the responsiveness for OSForensics when carving is running
        File carving, optimization, increased the number of carving threads to 75% of available logical processors, up to a max of 32
        For FAT and NTFS files systems, added option to carve only Allocated sectors
        Updated to allow selecting of carving of MFT Only, MFT and Carving, or Carving Only
        MFT and Carving now enabled by default
        Added minimum size requirement for carved JPGs (126 bytes), GIFs (43 Bytes), PNGs (68 bytes)
        Changed name Plist to Binary Plist and improved detection to limit false positives
        File carving, fixed possible crash when carving MP3 files
        File carving, improved MP3/JPG detection to cut down on the number of false positive results returned
        Added secondary sorting on second column (via dropdown and/or control click on details tab)
        Disabled sorting while deleted file scan is in progress
        Lowered priority level of carving threads to improve response from computer when carving is in progress
        Thumbnail Tab, added a quality level indicator to the thumbnails preview
        Added support for carving MFT file records on non-NTFS quick formatted volumes
        Added support for recovering files from carved MFT records. This enables recovery of files from a quick-formatted volume
        Added new scan method to config window, changed dropdown box to checkboxes
        Prepend "Carved MFT" to 'Source String' of files recovered from carved MFT records to differentiate from normal deleted files
        Added check for large buffer sizes before allocating memory when detecting faces
        Background LED indicator fixed, indicator would incorrectly reset after "Saving Delete File to Disk" while scan is running
        File carving, improved carving of HTML files
        File carving, reduced false positives for FLV files
        File carving, changed the naming of file to be more informative, new format "Carved .JPG file found at 310GB - byte offset 0x482D709C00.jpg"
        File carving, better handling of .eml files (will verify that both "From:" and "Date:" field are present
        File carving, reduced repeated carving for file signatures with the same headers (e.g. TIFF family, ZIP family)
        File carving, ensure recovered carved file will not exceed the max file size specified by extension (or 100 MB, whichever is less)
        Opening internal viewer for Plist Files from within the deleted files module should now work
        NTFS, fixed potential memory issue when restoring deleted files
        NTFS, added more debug verbosity when restoring deleted files to disk
    Device Manager
        Scan up to a maximum number of sectors when looking for recovered partitions. This prevents unbounded scanning of disks with large amount of unpartitioned space
    Disk Image and Filesystem Support
        HFS+, preliminary support for compressed files
        HFS+, fixed bug in decompressing zlib-compressed file data
        HFS+, support for reading lzvn-compressed file data stored in resource fork
        APFS, fixed bug causing buffer overflow when reading extended attributes (eg. compressed files)
        APFS, fixed reading compressed file data for files with hard links
        APFS, fixed bug in decompressing zlib-compressed file data
        NTFS, fixed bug in incorrect file being opened due to hash collision
    E-mail Viewer
        Message body containing inline content (eg. base64-encoded jpgs) now displayed as attachments
        Thumbnail preview for supported image attachments on mouse over
    ESEDB Viewer
        Viewer now displays when binary data has been found
        Search now looks for ASCII strings present in binary data fields
    Event Log Viewer
        Added "Device Connected/Disconnected" option to the filter preset list
    File Name Search
        Added Hash Set column which identifies which hash set the file was located in
        Fixed $FILE_NAME dates not being displayed for entire disk images added to case
        Added a reset button to config dialog which sets all changes made by user back to their defaults
        Made several popup dialogs to close when 'esc' is pressed
        Now using ffmpeg library instead of exiftool for counting video tracks for better performance
    Forensic and Cloud Imaging
        Rebuild RAID Disk, added support for detecting and rebuilding Linux mdadm RAID using superblock v1.X
        Forensics Copy, added ability to export forensic image as zip file
    Internal Viewer
        Perform initialization/shutdown of Media Foundation once rather than for every internal viewer instance
        Fixed issue that prevented deleted files opened from File System Browser from showing in the File Viewer
        Fixed incorrect thumbnail being draw for current item, after the list is updated
        Migrated library for media playback from Windows Media Foundation to ffmpeg
        Added support for playing media from memory buffer sources (eg. deleted files)
        Will now display a specific error message when attempting to open media file with corrupted attributes (duration, video pixel format, etc)
        Fixed flickering from redrawing thumbnails from deleted search result
        Automatically rotate videos if rotation metadata available
        Added a check to only redraw thumbnails if the items changed
        Metadata, display an error message if exiftool executable was not found
        Fixed multithreading bug causing media playback issues when opening multiple instances of the same file
        Fixed video paint issues when resizing window
        Fixed first video frame occasionally being displayed immediately after loading preview thumbnail images
        File viewer support, added opening deleted files (image, video/audio, android backup, compressed archive, office files)
        Added right-click menu support for deleted files
    Install to USB
        Fixed bug, files required by the web browser module were not being copied
    Localisation
        Added localisation support for Korean, Chinese (simplified and traditional), Japanese, Spanish, German and French
    Mismatch File Search
        Separated default and user-created filters, removed "built-in" text
    OSForensics Digital Signature Verification
        Added button to start screen (in housekeeping section) that verifies the integrity the program and displays a dialog with the information. Equivalent to going to the properties for the OSF executable, going to the digital signatures tab and clicking the details of the signature to verify the digital certificate is valid
    Password Recovery
        Fixed decrypting of wifi passwords on some machines due to a bug in PBKDF2 algorithm
        Updated common passwords dictionary with passwords obtained from more recent data breaches, increased number of unique passwords from ~10,000 to ~2.3 Million
        Fixed password recovery issue with the records in "Windows.old" folder
        Fixed crash in ZIP password recovery when testing a single password
    Search Index
        Fixed GDI handle leak
    SQLite Browser
        New Tab to shown Unallocated Space (Free Pages/Blocks) within SQLite database file
        Fixed bug to address possible circular reference/offset when parsing corrupted/bad free blocks
        Added Run SQL tab, allows users to write their own SQL statements
        Updated sqlite source files from 3.8.11.1 to V3.38.0
    Start Window
        Added settings option to allow for selecting language in use
    System Information
        Added partition selection dialog when scanning whole disk image with multiple partitions
        Added category for basic system information collection from non Windows machines
    Thumbnail Cache / Viewer
        Attempt to generate video file thumbnails if file extension is a known video type
        Attempt to load thumbnails only if the filename has a known file extension
        Set maximum thumbnail cache size of 2000 to prevent exceeding GDI handle limit
        Fixed multithreaded handling of video thumbnail generation using Media Foundation
        Fixed thumbnail icons not appearing in thumbnail view
        Added check for large buffer sizes before allocating memory for displaying thumbnails
        Migrated library used for video thumbnail generation from Windows Media Foundation to ffmpeg
        Fixed pixelated play icon for video thumbnails
    User Activity
        Added Cortana history category. Finds reminders, events, contacts and search history as well as location at time of creation
        Added "Create Super Timeline" button that performs a complete scan of all activity sub-categories
        USB timeline, added support to collect USB Artifacts of USB storage device connection and disconnection history. This feature is achieved by analyzing event ID 1006 (from Microsoft-Windows-Partition%4Diagnostic.evtx) and event IDs 2003 and 2012 (Microsoft-Windows-DriverFrameworks-UserMode/Operational channel). Event logging of the later channel is not enabled by default, users / system administrators need to have enabled it in the past in order for OSF to collect the relevant events
        Added parsing for Linux log files located in the /var/log directory
        Passwords, added an option to scan "Windows.old" folder which stores the backups of the previously installed Windows, this option is enabled by default and can be disabled from the Config dialog
        Fixed an issue where Moved Downloads not recognizing the system drive on live acquisition mode
        Added browser artifact support for some modern versions of Linux
        MRU, shortcut Files, will prompt users if they would like to open the .lnk file itself if the target file/directory is no longer available
        Added warning when attempting to scan a drive image that does not exist
        Shellbag, fixed possible heap corruption crash when parsing (corrupted) URI shell item
        Added check and warning message for missing case device when starting scan
    Web Server Log Viewer
        Added menu for filtering for common web exploits such as SQL injections
    Misc
        Refresh physical disk info only when there is device change notification, to reduce costly re-scanning of physical disks
        Keep single instance of physical disk info shared between all modules
        Fixed bugs with some MessageBoxes opening to wrong handle
        Changed some dialogs to close when 'esc' is pressed and centred others
        Installer, added language selection when running installer
        Rearranged some ok/cancel buttons for consistency, fixed up some out of place buttons/controls
        GPUSupport DLLs, changed the runtime library for them to /MT instead of /MD to avoid a missing VC runtime error on older Windows systems
        Centred some dialogs to main window for consistency
        Help file, updated file carving config info + images
        UI adjustments, centred additional dialogs
        Installer, updated OSFMount to v3.1.1001
        Installer, added Japanese language selection option
        Removed "Selected items" option from the right-click menu for consistency. Affected modules include JSON Viewer, ThumbCache Viewer, Web Server Log Viewer
        Updated DirectIO driver used for system information collection to work with Win11 22H2 release

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 10.0.1001
« Antwort #148 am: 22 Juli, 2022, 09:15 »
Changelog

       
    Localisation
        UI adjustments for localisation
        Added some missing strings to localisation
    OSFMount
        Updated OSFMount files to fix driver and program version mismatch
    User Activity
        Increased event info string size to avoid overflow
    Volatility Workbench
        Updated Volatility tool from "3 1.0.1 - beta" to "3 2.0.1"
        Added new volatility commands to volatility workbench

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )

Offline SiLæncer

  • Cheff-Cubie
  • *****
  • Beiträge: 190065
  • Ohne Input kein Output
    • DVB-Cube
OSForensics 10.0.1002
« Antwort #149 am: 05 August, 2022, 13:00 »
Changelog

       
    Create / Search Index:

    Fixed crash when saving and loading index configurations

    File System Browser:

    Fixed file entries not appearing in Details/List View in Win 7

    Install to USB:

    Added config link to adjust auto triage options in USB install window

    Localisation:

    Further UI adjustments for localisation

    Start Window:

    Fixed filename bug when opening a file directly from the start window (registry, email, etc) where the filename could be random text or not open correctly

    ThumbCache Viewer:

    Fixed thumbnails not appearing in List View in Win 7

[close]

http://www.osforensics.com/

Arbeits.- Testrechner :

Intel® Core™ i7-6700 (4 x 3.40 GHz / 4.00 GHz)
16 GB (2 x 8 GB) DDR4 SDRAM 2133 MHz
250 GB SSD Samsung 750 EVO / 1 TB HDD
ZOTAC Geforce GTX 1080TI AMPExtreme Core Edition 11GB GDDR5
MSI Z170A PC Mate Mainboard
DVD-Brenner Laufwerk
Microsoft Windows 10 Home 64Bit

TT S2 3200 ( BDA Treiber 5.0.1.8 ) + Terratec Cinergy 1200 C ( BDA Treiber 4.8.3.1.8 )