Skip to content

@bcarrier bcarrier released this Oct 14, 2019 · 417 commits to develop since this release


  • Switch from Oracle JDK to OpenJDK.
  • Full command line support (case creation, adding of data sources, running ingest, and generating reports).

Logical Imager:

  • Output can be individual files instead of VHD image (uses less space).
  • More fine grained progress during collection and importing.
  • Log of files and make artifacts.
  • All console messages are saved to a log file too.
  • Improved handling of cancellation when adding results into a case.

Ingest Modules:

  • Added Android support as Python modules for: Android installed apps, Android browser, Facebook Messenger, IMO, LINE, Opera, ORUX Maps, Samsung SBrowser, Skype, ShareIt, TextNow, Viber, WhatsApp, Xender, Zapya.
  • Recycle Bin files are parsed in Recent Activity module, new artifacts are created, and deleted file entries are created at the original location of the deleted files. Code is based on Mark McKinnon’s RecycleBin module (
  • ShellBag registry data is extracted from RegRipper in the Recent Activity module. New artifacts are recreated for the data. Based on Mark McKinnon’s “Parse ShellBags” module (
  • Additional data is extracted about users from SAM hive in Recent Activity module. Data includes password dates, permissions, groups, and full name. Based on Mark McKinnon’s “Parse SAM” module (
  • Email ingest module parses EML files. Based on Mark McKinnon’s “EML Parser” module (
  • Fixed bug in MBOX module that caused attachments to have a “_” in the name.
  • New Plaso ingest module that runs Plaso and generates events for the timeline.
  • Fixed bug in Email module for VCard files to better parse phone number types.
  • Keyword Search module waits longer for Solr to start to prevent incorrectly reporting a problem and disabling the feature.
  • Embedded file extractor module was updated to not report compression bombs for GZIP files.


  • New approach for storing event data. A dedicated events table exists and is populated as files and artifacts are added to the database. No longer requires an explicit step of populating a local events table.
  • Users can create their own events from the Timeline UI.
  • Filtering was simplified based or existence of tag or hash set hit versus a specific name.


  • Fixed bug that hid contact book entries with duplicate numbers.

Image Gallery:

  • Fixed bug in schema that caused errors with very long file names.


  • CASE report is included in a portable case.
  • Image tags are included in portable case.
  • More size options for a packaged portable case.
  • New Infrastructure to support command line-based generation.


  • Developers should use new new Blackboard.postArtifact() method to ensure artifact is indexed and added to the timeline.
  • New classes were created to make it easier to write modules for apps.
Assets 8
You can’t perform that action at this time.