Where TRACE keeps data
TRACE never writes beside the application or to the evidence. It uses three kinds of place.
The case folder
Section titled “The case folder”Wherever you create the case:
DirectoryMy Case/
- case.db evidence, verification history, audit trail, bookmarks, notes, findings, activity
- search.db the full-text search index (a cache: rebuilt rather than migrated)
Directorycarved/ copies of carved files, only if the case setting asks for them
- …
Directoryexports/ exported files and reports
- …
Directorythumbnails/
- …
Your settings
Section titled “Your settings”| Folder | |
|---|---|
| Windows | %APPDATA%\TRACE |
| macOS | ~/Library/Application Support/TRACE |
| Linux | $XDG_CONFIG_HOME/TRACE, else ~/.config/TRACE |
It holds config.ini – theme, recent cases, window layout, your user settings (examiner, organisation, default case folder, size units) and API keys – and saved report templates.
Your libraries and the log
Section titled “Your libraries and the log”| Folder | |
|---|---|
| Windows | %LOCALAPPDATA%\TRACE |
| macOS | ~/Library/Application Support/TRACE |
| Linux | $XDG_DATA_HOME/TRACE, else ~/.local/share/TRACE |
DirectoryTRACE/
- trace.log the application log
Directoryhashsets/ imported hash sets (NSRL is linked where it is, not copied)
- …
Directoryyara/ YARA rule sets, copied with their SHA-256s
- …
Directorysigma/ Sigma rules
- …
Directorykeywords/ keyword lists
- …
Directorycarved_files/ quick-triage carve copies, if that setting is on
- …