Software-update: The Sleuth Kit 4.6.3

Het programma The Sleuth Kit is een collectie forensische tools die gebruikt kunnen worden om de harde schijf nader te bekijken. Daarmee wordt het mogelijk om verwijderde bestanden terug te halen of gedeeltelijk te bekijken. Ondersteuning voor ntfs-, fat-, exfat-, ufs1-, ufs2-, ext2fs-, ext3fs-, etx4-, hfs-, yaffs2- en iso 9660-indelingen is aanwezig. Voor meer informatie verwijzen we naar deze pagina. De ontwikkelaars hebben onlangs versie 4.6.3 uitgebracht, met de volgende veranderingen:

Version 4.6.3
  • C/C++ Code:
    • Hashdb bug fixes for corrupt indexes and 0 hashes
    • New code for testing power of number in ExtX code
  • Java Code:
    • New class that allows generic database access
    • New methods that check for duplicate artifacts
    • Added caches for frequently used content
  • Database Schema:
    • Added Examiner table
    • Tags are now associated with Examiners
    • Changed parent_path for logical files to be consistent with FS files.
Version 4.6.2
  • C/C++ Code:
    • Various compiler warning fixes
    • Added small delay into image writer to not starve other threads
  • Java:
    • Added more locking to ensure that handles were not closed while other threads were using them.
    • Added APIs to support more queries by data source
    • Added memory-based caching when detecting if an object has children or not.
Version 4.6.1
  • C/C++ Code:
    • Lots of bounds checking fixes from Google's fuzzing tests. Thanks Google.
    • Cleanup and fixes from uckelman-sf and others
    • PostgreSQL, libvhdi, & libvmdk are supported for Linux / OS X
    • Fixed display of NTFS GUID in istat - report from Eric Zimmerman.
    • NTFS istat shows details about all FILE_NAME attributes, not just the first. report from Eric Zimmerman.
  • Java:
    • Reports can be URLs
    • Reports are Content
    • Added APIs for graph view of communications
    • JNI library is extracted to name with user name in it to avoid conflicts
  • Database:
    • Version upgraded from to 8.0 because Reports are now Content
Version 4.6.0
  • New Communications related Java classes and database tables.
  • Java build updates for Autopsy Linux build
  • Blackboard artifacts are now Content objects in Java and part of tsk_objects table in database.
  • Increased cache sizes.
  • Lots of bounds checking fixes from Google's fuzzing tests. Thanks Google.
  • HFS fix from uckelman-sf.
Versienummer 4.6.3
Releasestatus Final
Besturingssystemen Windows 7, Linux, BSD, macOS, Solaris, UNIX, Windows Server 2008, Windows Server 2012, Windows 8, Windows 10, Windows Server 2016
Website The Sleuth Kit
Download http://sleuthkit.org/sleuthkit/download.php
Licentietype Voorwaarden (GNU/BSD/etc.)

Door Japke Rosink

Meukposter

31-10-2018 • 16:46

0

Bron: The Sleuth Kit

Reacties

0
0
0
0
0
0
Wijzig sortering

Er zijn nog geen reacties geplaatst

Op dit item kan niet meer gereageerd worden.