What's new in Mobius Forensic Toolkit 1.16

Oct 16, 2019
  • Turing: Retrieves old password hashes from CREDHIST files (up to Win 8.1)
  • Turing: Retrieves passwords from Chromium based browsers (Chrome, Opera, ...) (up
  • to Win 8.1)
  • Turing: Retrieves passwords from Windows Credentials (up to Win 8.1)
  • Turing: Retrieves passwords from IE Intelliforms (up to Win 8.1)
  • Spider: Added support for 7 Star
  • Spider: Added support for AliExpress Browser
  • Spider: Added support for Amigo
  • Spider: Added support for Avast Browser
  • Spider: Added support for BoBrowser
  • Spider: Added support for Brave
  • Spider: Added support for CentBrowser
  • Spider: Added support for Chedot
  • Spider: Added support for Chrome Canary
  • Spider: Added support for Chromium
  • Spider: Added support for Coccoc
  • Spider: Added support for Comodo Dragon
  • Spider: Added support for Elements Browser
  • Spider: Added support for Epic Privacy Browser
  • Spider: Added support for Kometa
  • Spider: Added support for Orbitum
  • Spider: Added support for PlutoTV
  • Spider: Added support for Spotify Browser
  • Spider: Added support for Sputnik
  • Spider: Added support for Torch
  • Spider: Added support for Uran
  • Spider: Added support for Vivaldi
  • Libmobius: Upgraded to C++14
  • Libmobius: New class mobius::crypt::cipher_rc2
  • Libmobius: New function turing::hash_ie_entropy
  • Python API: Releases GIL when calling C++ intensive tasks
  • Python API: Added support for cipher RC2

New in Mobius Forensic Toolkit 1.15 (Aug 16, 2019)

  • DPAPI decryption implemented
  • Turing: Automatically decrypts DPAPI system master keys
  • Turing: Automatically decrypts Win WiFi passwords

New in Mobius Forensic Toolkit 1.14 (Jul 6, 2019)

  • Added native support for .vhd image files
  • Spider: Added support for Opera
  • Spider: Added support for GeckoFX
  • Case Model: New class application
  • Case Model: New class profile
  • Case Model: New class cookie

New in Mobius Forensic Toolkit 1.13 (Jun 10, 2019)

  • Case Model: New class password
  • Case Model: New class password_hash
  • Turing: Export .hashcat hash files
  • Turing: Export .john with RID, GID and GECOS fields filled
  • Turing: Using persistence layer from Case Model
  • Libmobius: Turing API implements on demand connection to database

New in Mobius Forensic Toolkit 1.12 (Mar 25, 2019)

  • Chat Viewer: Added support for Skype
  • app.skype: Added support for Skype v8 and newer ones
  • app.chrome: Handles Web Data.version = 52
  • Libmobius: New function mobius::crypt::pbkdf1
  • Libmobius: New function mobius::crypt::pbkdf2_hmac
  • Python API: New module mobius.evidence.chats

New in Mobius Forensic Toolkit 1.8 (Sep 17, 2018)

  • Added support for Emule and EmuleTorrent.
  • p2p.ares: Retrieves data from TorrentH.dat evidence files
  • p2p.ares: Retrieves data from PHashIdx.dat evidence files
  • p2p.ares: Retrieves data from PHashIdxTemp.dat evidence files
  • p2p.ares: Retrieves data from TempPHash.dat evidence files
  • p2p.ares: Retrieves data from PHash_*.dat evidence files
  • p2p.ares: Retrieves data from PBTHash_*.dat evidence files
  • p2p.ares: Retrieves data from ___ARESTRA___* downloading files

New in Mobius Forensic Toolkit 1.7 (Aug 11, 2018)

  • Report Wizard: Two new graphic commands "while" and "exec"
  • Libmobius: ED2K cryptographic hash function implemented
  • Libmobius: New module mobius::model
  • Libmobius: Hash functions preserve state on get_digest ()
  • Python API: New module pymobius.p2p.ares
  • Python API: New module mobius.model

New in Mobius Forensic Toolkit 0.5.19 (Oct 10, 2013)

  • The partition-agent extension automatically adds partitions to case when a data source is set. New registry report: "Shared Folders".
  • Minor improvements have been made.

New in Mobius Forensic Toolkit 0.5.18 (Apr 24, 2013)

  • This version features the new Gigatribe Agent extension, an extension to browse Gigatribe chat files.
  • Five new registry reports have been added to the hive-report extension: Gigatribe accounts, Gigatribe download folders, Gigatribe requested passwords, Ares Search History, and Wifi Network List.
  • Minor improvements and bugfixes have been made.

New in Mobius Forensic Toolkit 0.5.17 (Mar 25, 2013)

  • This version adds support for physical device's datasources.
  • Minor improvements were made.
  • Bugs were fixed.

New in Mobius Forensic Toolkit 0.5.16 (Jan 18, 2013)

  • This version features the Turing extension, an extension to handle cryptographic services.
  • It is fully integrated to the Hive (registry) extension, so that when registry files are opened, it automatically records the user account password hashes and tests keywords such as LSA secrets, e-mail passwords, and Internet Explorer Autocomplete, among others. All hashes and passwords found are stored in an SQLite database.
  • The Turing extension exports and imports to/from John The Ripper .pot files and to John The Ripper hash files.

New in Mobius Forensic Toolkit 0.5.15 (Nov 2, 2012)

  • The Partition Viewer extension provides a viewer for partition tables.
  • The GTK-UI Treeview extension implements a treeview based on treenodes.
  • Minor improvements have been made.

New in Mobius Forensic Toolkit 0.5.14 (Aug 20, 2012)

  • This version supports reading multiple segment EWF files.
  • Minor improvements and bugfixes have been made.

New in Mobius Forensic Toolkit 0.5.12 (Apr 21, 2012)

  • This version features the Skype Agent extension, an extension to browse Skype log files and show calls, chats, contacts, profiles, file transfers, SMS, and voicemails.

New in Mobius Forensic Toolkit 0.5.11 (Jan 26, 2012)

  • This version features 14 new registry reports: autorun, services, IE download folder, IE typed URLs, MRU files opened/saved, MRU files executed, search assistant, printer ports, processors, all devices, enumerated devices, HID devices, network devices, and stream devices.
  • Minor improvements were made.

New in Mobius Forensic Toolkit 0.5.10 (Dec 21, 2011)

  • This version introduces the Integrated Case Environment (ICE) extension, which replaces the Case Viewer extension.
  • A new and improved data representation of the case model was developed.
  • Several minor improvements were made.

New in Mobius Forensic Toolkit 0.5.5 (Oct 5, 2010)

  • The Hive extension assembles the registry's logical structure, akin to that viewed with regedit.
  • The new extension Hive Report adds report capabilities to the Hive extension.
  • Three registry reports were added: OS information, user accounts and user profiles.
  • The Report Viewer extension shows generated reports.

New in Mobius Forensic Toolkit 0.5.4 (Aug 15, 2010)

  • Extensions are now deployed in .mobius files.
  • This version features three new extensions: Datasource SCSI, for drag'n'drop of /dev/sd* files directly into case, Data Viewer, a hexviewer for case items, and Extension Manager.
  • Floppy Imager has been improved and uses direct I/O only.
  • Minor improvements were made.

New in Mobius Forensic Toolkit 0.4.8 (Sep 21, 2009)

  • Support for services was implemented.
  • Extension Builder was extended to edit services.
  • A new section about Extension Builder was added to Mobius Tutorial.

New in Mobius Forensic Toolkit 0.4.6 (Jun 22, 2009)

  • Service item.expand-initvalues renamed to item.expand-value-masks
  • Service category.attribute.set-init-value renamed to category.attribute.set-value-mask
  • attribute-viewer: attributes with value_mask are not editable
  • report-wizard: text and verbatim use multiline text
  • report-wizard: ${} option in verbatim
  • Extension Mobius Forensic Toolkit App created
  • Module mobius.ui.main_window removed
  • Module mobius.ui.extension_manager_dialog removed
  • Program mobius_icq.py eliminated
  • Service calls are now isolated by try...except
  • Service app.start created
  • Service app.get-data-path created
  • Service toolbox.add moved to Mobius Forensic Toolkit App extension
  • Service toolbox.remove created
  • Module mobius.model.extension created
  • Extensions are coded in XML
  • Service extension.new created
  • Service extension.open created
  • Service extension.save created

New in Mobius Forensic Toolkit 0.4.5 (May 5, 2009)

  • category-manager: scrolling in attribute up/down
  • Service category.new created
  • Service category.set created
  • Service category.remove created
  • Service category.iter-attributes created
  • Service category.list.iter created
  • Service category.list.save created
  • Service category.attribute.remove created
  • Service category.get-list eliminated
  • Service category.set-list eliminated
  • Service category.get-attribute-list eliminated
  • Service item.expand-attributes created
  • Service item.expand-initvalues created
  • category-model extension created
  • category_manager extension renamed to category-manager
  • Service item.expand-attributes created
  • case-viewer: add item now sets attributes

New in Mobius Forensic Toolkit 0.4.3.1 (Mar 12, 2009)

  • A workaround was made for the GTK/SVG SIGFPE exception while rendering the Report Wizard icon.
  • A bug in setup.py was fixed.

New in Mobius Forensic Toolkit 0.4.3 (Mar 11, 2009)

  • This release introduces the Floppy Imager extension, an extension for Linux featuring direct I/O, disk info retrieval, and multi-pass copy.
  • You can eject and re-insert a disk and try to retrieve only bad sectors.
  • This release also features the Mobius Tutorial.
  • Windows' states are now persistent.

New in Mobius Forensic Toolkit 0.4.2 (Feb 14, 2009)

  • This release features a Report Wizard extension, a graphical IDE to build report templates, compile them on demand, and run them against data models given by other extensions.

New in Mobius Forensic Toolkit 0.4.1 (Jan 26, 2009)

  • The Case Viewer extension replaces the case manager module.
  • The case_treeview, case_window, and add_item_dialog modules were eliminated.
  • The XML Pickle extension was created to persist Python objects into XML files, using xml.pickle and xml.unpickle services.
  • Minor bugs were fixed.

New in Mobius Forensic Toolkit 0.4 (Dec 14, 2008)

  • The Spider Data Center extension handles datasources.
  • This release supports raw image files.
  • The Case Model extension abstracts case, case items, and datasources operations.
  • Some minor bugfixes were made.

New in Mobius Forensic Toolkit 0.3.5 (Nov 24, 2008)

  • Default value evaluation was corrected in AttributeViewer.
  • Mediator emits events in chronological order.
  • Better clean-up code when de-registering from mediator events.
  • The SDI extension implements a Single Document Interface.
  • Extensions use ui.working-area.new advertised by the SDI extension.

New in Mobius Forensic Toolkit 0.3.4 (Nov 12, 2008)

  • Two new extensions have been created.
  • The GtkUI extension abstracts UI coding, and the Date Code extension translates the hard disk's datecode to date format. Icon renderization codes have been unified.

New in Mobius Forensic Toolkit 0.3.3 (Nov 2, 2008)

  • The new PartCatalogue extension manages parts and part-numbers, setting other item's attributes based solely on part-number.
  • CaseTreeview changes case and item names on modification.
  • Events now accept keyword parameters.
  • AttributeViewer columns are now resizable.
  • The on_delete event was fixed in AttributeViewer.Window.
  • Attributes can be moved up and down in CategoryManager.

New in Mobius Forensic Toolkit 0.3.2 (Oct 12, 2008)

  • This release features a Category Manager extension.
  • Extensions now run in isolated namespaces. Support for SVG icons has been added.

New in Mobius Forensic Toolkit 0.3.1 (Sep 15, 2008)

  • An Attribute Viewer extension has been created.
  • Mediator implements signals and loose coupled function calls.

New in Mobius Forensic Toolkit 0.3 (Aug 31, 2008)

  • A case manager has been implemented.
  • Support for extensions has been added.