Elcomsoft Quick Triage 2.2 is out. The release adds a timeline that merges events from different artifacts into a single chronology, rebuilds artifact support around a new plugin architecture, and introduces a file system snapshot as a new artifact. Password recovery, full-text search, and BitLocker key extraction were extended as well.
Timeline
The timeline is the main addition in Elcomsoft Quick Triage 2.2. The timeline enables investigators to know what happened on the computer in what order, correlating records that from numerous different places against a time range. The timeline does the correlation and presents the result as one chronology.
Events are collected into several groups. Browser activity covers visit history and downloads. Network activity covers network data usage from SRUM and the list of networks the computer connected to, based on registry records. Recent files covers recent files and folders by last access time, while Jump Lists cover user interactions with applications and documents. Device activity covers USB connections from the registry, microphone and webcam use, and Bluetooth, and, finally, Program execution covers the BAM registry branch and Prefetch.
The view has a table and a histogram with event grouping. Filtering is fast and works the moment you start typing, event cards open directly from the timeline, and any event links back to the artifact it came from. You can export the timeline exports to PDF and XLS.
Plugin system and new artifacts
Artifact types are now plugins. This is an internal change that, in future, will allow new formats and artifacts to appear much faster. Thanks to this new plugin system, we’ve implemented six new artifact type plugins in this release: Microsoft Defender logs, Windows Update Store, the Capability Access Manager (CAM) database, Jump Lists, the Windows Search index, and Prefetch files.
File system snapshot
The new file system snapshot artifact records the selected drive’s file system as a searchable metadata table without copying the files themselves. Essentially it's a copy of the file system metadata without the contents of the files: names, paths, sizes, creation and modification times, sitting between the full disk image and per-file collection. The result is a virtual file system you can browse on another computer. It includes file names, paths, creation and modification timestamps, and other file-system-specific metadata, with search by file name or mask and sorting by creation or modification time, allowing you to see what was on the disk and where it sat.
Other improvements
Password recovery now handles Microsoft Accounts more completely. If the password is not recovered from the NTLM hash, EQT extracts the MSA hash and offers an attack on it, using rules specific to MSA.
Full-text search now parses OpenDocument files (.odt, .ods, .odp) and looks inside nested archives up to ten levels deep. A new live-session acquisition option attempts to collect the available BitLocker keys for mounted volumes. Projects load asynchronously, the wizard for the "Logical drive" source was redesigned, and a set of search and export bugs was fixed, including case sensitivity in file artifact and global search.
A full list of changes in Elcomsoft Quick Triage 2.2 is available below.
Release Notes
Artifacts and Plugins
Timeline
Processing, Searching, and Indexing
.odt, .ods, and .odpPassword Recovery
Workflow and UI