Skip to content

Search and indicators

TRACE's Search tab with results from inside documents and archives
Search finds words inside files, not just in their names.

Search index and indicators is an analysis module: it walks each image once and stores the readable text of every file in a per-case full-text index (SQLite FTS5). Searching is then instant, and works offline on the case alone.

Text is extracted from:

  • Documents – PDF, Word, Excel, PowerPoint and OpenDocument, RTF, HTML, plain text in any common encoding.
  • Mail – Outlook PST / OST, EML and mbox, messages and attachments.
  • Archives – ZIP, 7z, RAR, TAR and compressed files, member by member, nested to a depth you set.
  • Registry hives – key names and values.
  • Everything else – printable runs of ASCII and UTF-16 text, since Windows stores much of its text as UTF-16.
  • File slack of every live file, as its own item (<file> [slack]).
  • Carved files, under [carved]/ with the name of the deleted file they came from.

A hit inside an archive or mailbox opens that member directly – read from the image, never unpacked to disk.

While indexing, TRACE extracts indicators and checks each one – a pattern alone produces too much noise:

Indicator Kept only if
E-mail addresses well-formed
URLs well-formed
Phone numbers in international form, 8-15 digits
Card numbers the Luhn check passes and the prefix belongs to a card scheme
IBANs the country’s length is right and the mod-97 check passes

Triage ▸ Indicators lists the values with how often they occur; select one to see every file holding it. The Findings ▸ Indicators node gives one entry per kind across the whole case. Which kinds are extracted is a case setting.