: Introduced the ability to automatically create a Virtual Machine (VM) directly from forensic disk images, allowing investigators to boot the suspect's OS in a safe, sandboxed environment. 🔍 Advanced Data Recovery & Carving
Implemented minimum size requirements for carved files (e.g., 126 bytes for JPGs) to reduce false positives. 🕵️ New Artifact Analysis
: This module evolved from a simple prefetch viewer to include a wider range of program activity traces.
: Added support for carving Master File Table (MFT) records on non-NTFS quick-formatted volumes, which allows for recovering files that would otherwise be lost after a format. Improved Media Handling : Added a quality level indicator for thumbnail previews.
: The password module was updated to automatically scan "Windows.old" folders for legacy credentials. 🛠️ Workflow & Security
: A new housekeeping button verifies the digital signatures of the OSForensics executable itself to ensure the program has not been tampered with. Using the OSForensics Workflow
Below is a feature highlight of the version 10 series improvements: 🚀 Speed and Imaging Enhancements