Skip to content
The TRACE logo, a cat looking through a magnifying glass

TRACE · Toolkit for Retrieval and Analysis of Cyber EvidenceOpen-source digital forensics software.

TRACE opens disk images read-only, organises them into cases, triages what stands out, recovers deleted files and searches inside the evidence – free and open source, on Windows, macOS and Linux.
file types carved
70
file systems read
9
kinds of encryption unlocked
5
platforms tested
4
free and open source
MIT

One window for the whole investigation: the evidence tree, every timestamp, and a viewer for whatever you select.

TRACE
TRACE: browse view. The evidence tree, a file listing with every timestamp, and a viewer for whatever is selected.
The evidence tree, a file listing with every timestamp, and a viewer for whatever is selected.

From the first hash check to the final report, in one application that never writes to the evidence.

Read-onlyImages are read, never mounted. A case refers to evidence by path and hash – nothing is copied or changed.
Audit trailVerification is a history, never overwritten. Every action that matters is an audit line in the case.
Offline by defaultNothing leaves the machine unless you say so. HTML from evidence is shown without scripts or network.
TestedTested against published forensic test images and their answer keys, on four platforms, for every change.
Disk images E01 / Ex01, AFF4, raw / dd (split too), ISO, DMG, VMDK, VHD / VHDX, QCOW2
Logical images AD1, L01, ZIP / TAR, a folder (KAPE, Velociraptor), iOS backups
Live disks an attached disk, read-only, without imaging it first
File systems NTFS, FAT, exFAT, ext2/3/4, HFS+, APFS, XFS, UFS, ISO 9660
Encrypted volumes BitLocker, FileVault 2, LUKS, encrypted APFS and iOS backups
Inside files archives (ZIP, 7z, RAR, TAR…), PST / OST, EML / mbox, registry hives, event logs, SQLite

Everything TRACE reads →

File carving is scored, not eyeballed: the real carvers run over public test images and are compared with the answer keys their authors published. A change that loses a file fails the build.

Test image Files located Byte-exact
DFTT #11 11-carve-fat.dd 15 / 15 –
DFTT #12 12-carve-ext2.dd 10 / 10 3 / 3
DFRWS 2006 challenge 27 / 27 12 / 12
DFRWS 2007 challenge 78 / 114 16 / 16
Real-file corpus (63 formats) 63 / 63 63 / 63

How TRACE is tested → · Every test image and what it tests →

Install from source for open code you can read and the newest fixes – or take the standalone app for the quickest start.

Recommended

Install from source

One script sets everything up – Python 3.10 or newer is all you need. No compiler, no Homebrew: every forensic engine installs as a pre-built package.

  • Open code – you run the code itself, not an unsigned executable.
  • The same code the tests check – installed and tested from scratch on every platform.
  • Newest fixes first, and the only way on Linux.
Full install guide
git clone https://github.com/Gadzhovski/TRACE-Forensic-Toolkit.gitcd TRACE-Forensic-Toolkitpowershell -ExecutionPolicy Bypass -File install_windows.ps1venv\Scripts\activatepython main.py

Standalone app Quickest

One download, nothing else to install – each package is self-tested against public disk images before release. It is not signed by a paid publisher certificate, so Windows SmartScreen and macOS Gatekeeper ask you to trust it once, and a packaged build can have problems the source install does not. If something misbehaves, install from source and tell us.

Latest release · free and open source (MIT) · all releases and checksums