|Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору|
v19.7 was just released. Additional changes since Beta 3:
* When sorting timestamps in one of the many timestamp columns, it may happen that UTC-based time stamps have to be compared to local timestamps with an undefined time zone reference or local timstamps with a user-defined time zone reference (user-defined meaning defined by the examiner), to see which one is earlier and which one is later. That happens for example for file system based timestamps in the case root window if one evidence object has an NTFS file system and the other a FAT file system. It also happens within the same evidence object for example when sorting internal creation timestamps retrieved from file contents, such as ordinary Exif timestamps in JPEG (which are local) and GPS timestamps in JPEG (which are stored in UTC). Sorting all such timestamps now takes into account how these timestamps are displayed (in original local time or in a user-defined display time zone) such that the order is consistent with the displayed values, and not with how the timestamps are internally stored. That means for example that the local Exif timestamp 2017-01-01 14:01 LT is sorted *after* a UTC GPS timestamp 2017-01-01 14:00 +2, which is right if the undefined local time zone is equal to the display time zone, which in this example is UTC +2. That order of course can be wrong, as the unknown time zone of a local Content created timestamp could be somewhere to east of UTC +2. The order could also be wrong if the user-defined time zone reference of timestamps from a FAT file system is wrong.
* The event list's Timestamp column now respects the user-defined reference time zone for timestamps for file systems that store timestamps in local time and translates these timestamps to the current display time zone accordingly.
* Fixed a rare checksum error in Intel Hex conversion output.
* Ability to convert (e.g. search terms) from UTF-16 to various Indian code pages: ISCII Devanagari, Bengali, Tamil, Telugu, Assamese, Oriya, Kannada, Malayalam, Gujarati, Punjabi (Gurmukhi)
* Templates can now display and edit UTF-16 Unicode string variables containing non-Latin characters.
* The search hit context preview in search hit lists can now be turned on and off in the context menu.
* The previous output for .automaticdestinations-ms files in Details mode is now presented in Preview mode, and also for the View command and when copying such jumplist files for inclusion in the report.
* Report thumbnail generation now supported for files of these types: lnk, flnk, TCP/UDP packets, NK2, DBX, Skype chat, WAB, change.log.1, info2, job, IconCache.db, Prefetch, shd, usnjrnl, eiurl, $I*, travellog, chrome1, automaticdestinations-ms, and more.
* The option to omit additional hard links now has an effect even when processing selected or tagged files specifically.
* New volume snapshot option to convert certain RTF-formatted e-mail bodies from Outlook e-mail archives to plain UTF-8 (when extracting e-mails) to better view generated .eml files in external e-mail clients and to allow for the alternative .eml preview.
* When importing hash values from Project Vic, the user is now asked whether US or Canadian standard categories should be preset.
* Solved an import problem with certain surprising whitespace characters in Project Vic JSON files.
* When filling blocks/files/disks with constant hex values, now any number of two-digit hex values up to 16 is allowed.
* The IMEI of some Samsung Galaxy smartphones (high end models) is stored in the SEFT trailing data of JPEG files, depending on the phone's settings, and if so is now presented in Details mode of the SEFT file. The SEFT file is generated by "Uncover embedded data in various file types".
* Protection against a rare kind of NTFS corruption, FILE record displacements within $MFT.
* Fixed a stability issue.
* Several minor improvements.
* User manual and program help updated.