Skip to content

Where TRACE keeps data

TRACE never writes beside the application or to the evidence. It uses three kinds of place.

Wherever you create the case:

  • DirectoryMy Case/
    • case.db evidence, verification history, audit trail, bookmarks, notes, findings, activity
    • search.db the full-text search index (a cache: rebuilt rather than migrated)
    • Directorycarved/ copies of carved files, only if the case setting asks for them
      • …
    • Directoryexports/ exported files and reports
      • …
    • Directorythumbnails/
      • …
Folder
Windows %APPDATA%\TRACE
macOS ~/Library/Application Support/TRACE
Linux $XDG_CONFIG_HOME/TRACE, else ~/.config/TRACE

It holds config.ini – theme, recent cases, window layout, your user settings (examiner, organisation, default case folder, size units) and API keys – and saved report templates.

Folder
Windows %LOCALAPPDATA%\TRACE
macOS ~/Library/Application Support/TRACE
Linux $XDG_DATA_HOME/TRACE, else ~/.local/share/TRACE
  • DirectoryTRACE/
    • trace.log the application log
    • Directoryhashsets/ imported hash sets (NSRL is linked where it is, not copied)
      • …
    • Directoryyara/ YARA rule sets, copied with their SHA-256s
      • …
    • Directorysigma/ Sigma rules
      • …
    • Directorykeywords/ keyword lists
      • …
    • Directorycarved_files/ quick-triage carve copies, if that setting is on
      • …