Week 28 – 2016

SOFTWARE UPDATES A couple weeks ago Guidance released EnCase 7.13. This is the last update for encase 7. It mainly contained bug fixes. . Exiftool was updated to version 10.23 (development release). This update added some new tags and file support, as well as a new commandline option, and the “ability to geotag only GPS […]

Week 27 – 2016

SOFTWARE UPDATES ExfiTool was updated to version 10.22. This update adds read support for BPG images, minor changes to a few of the new Nikon tags and updated the Windows version to include all 10.21 updates. ExifTool 10.22 Andrilla updated to version 2.6.0.1, adding support for several WhatsApp backup databases, GUI improvements, and various bug […]

Week 26 – 2016

SOFTWARE UPDATES Cellebrite updated UFED Physical Analyzer to version 5.1.2. This update adds support for the crypt12 WhatsApp backup database and addresses various bug fixes. UFED Physical Analyzer Version 5.1.2 Maintenance Release Oxygen Forensics released an update to their Detective product, now at version 8.4.2, improving support for newer versions of various apps and numerous […]

Week 25 – 2016

SOFTWARE UPDATES Belkasoft updated their Evidence Center suite to version 7.5. In this update the user interface has been revamped, encrypted iTunes backups are now supported, Outlook 2016 Outlook 2016 support has been improved, as well as updates to usability. A more extensive set of release notes can be found here. New Update: Evidence Center […]

Week 24 – 2016

SOFTWARE UPDATES Didier stevens updated oledump to version 0.0.24. This update adds the ability to decompress macro streams before calculating the md5 of the stream. This allows users to take two different samples and determine that the internal macro code is similar or different. Update:oledump.py Version 0.0.24 MSAB updated XRY to version 7.0.1 and XAMN […]

Week 23 – 2016

SOFTWARE UPDATES DME Forensics’ DVR Examiner has been updated to version 1.22.0. This update adds support for PAVS_264, IFLY_264 and IFS_M file systems, improving support for IXDVRDISK, hikfat,  KSF_RSF, and KSF_dc file systems as well as some bug fixes. DVR Examiner 1.22.0 Paraben’s DS has been updated to version 7.5. The update adds acquisition of […]

Week 22 – 2016

SOFTWARE UPDATES Didier Stevens updated his python script zipdump to version 0.0.3. This update added in a number of different command line arguments such as -dumpall which dumps all files rather than just the first, allows for inputting a password, support for YARA rules and decoders, among others. (I could only compare to 0.0.1, so […]

Week 21 – 2016

SOFTWARE UPDATES Last week I mentioned that Magnet updated IEF to version 6.7.8. From the release notes this update is mainly bug fixes. . CRU has updated their WriteBlocking Validation Utility to version 1.1.0.3. The new version reformats the test reports, updates the help file, allows for pausing tests, adds support for drives larger than 2.2TB […]

Week 20 – 2016

SOFTWARE UPDATES Magnet released IEF version 6.7.8 however I wasn’t able to get a copy of the release notes to summarise them. . Didier Stevens has published a new YARA rule for identifying portable executables created with pyinstaller. This post here explains the impetus for the rule and what it looks for. New YARA Rule: PE_File_pyinstaller […]

Week 19 – 2016

Week 19! Trying a slightly different format this week to divide thing up a bit better. SOFTWARE UPDATES Cellebrite have released a maintenance release for UFED Physical and Logical Analyzer, now at version 5.0.2. The main feature of this update is decryption of the new Whatsapp Crypt9 backup databases. (If you don’t have a copy […]