Skip to content

Get TRACE

Two ways, both free: install from source – what we recommend – or download the standalone app for the quickest start.

Recommended

Install from source

One script sets everything up – Python 3.10 or newer is all you need. No compiler, no Homebrew: every forensic engine installs as a pre-built package.

  • Open code – you run the code itself, not an unsigned executable.
  • The same code the tests check – installed and tested from scratch on every platform.
  • Newest fixes first, and the only way on Linux.
Full install guide
git clone https://github.com/Gadzhovski/TRACE-Forensic-Toolkit.gitcd TRACE-Forensic-Toolkitpowershell -ExecutionPolicy Bypass -File install_windows.ps1venv\Scripts\activatepython main.py

Standalone app Quickest

One download, nothing else to install – each package is self-tested against public disk images before release. It is not signed by a paid publisher certificate, so Windows SmartScreen and macOS Gatekeeper ask you to trust it once, and a packaged build can have problems the source install does not. If something misbehaves, install from source and tell us.

Latest release · free and open source (MIT) · all releases and checksums

From source Standalone app
Windows Python 3.10 or newer Windows 10 or 11, 64-bit
macOS Python 3.10 or newer (from python.org) macOS 13 or later – the DMG for your Mac: Apple Silicon or Intel
Linux Python 3.10 or newer; on Debian/Ubuntu the script installs the rest –
  1. Unzip the whole folder somewhere you can write, for example Documents. Do not run TRACE.exe from inside the zip.

  2. Double-click TRACE\TRACE.exe.

  3. Windows SmartScreen may say it “protected your PC”: TRACE is not signed by a publisher. Choose More info, then Run anyway. Windows asks once.

Each release file has a .sha256 beside it on the releases page. Compare it with the file you have before using TRACE on a case:

Terminal window
Get-FileHash .\TRACE-2.0.0-windows-x64.zip -Algorithm SHA256

TRACE can check itself. The self-test exercises every engine and native library the app depends on, then runs the full case workflow – create, add evidence, verify, analyse, index, search, reopen – on any disk image you give it, inside a temporary sandbox that is deleted afterwards. It writes one JSON report and exits with status 0 only if every check passed.

Terminal window
.\TRACE\TRACE.exe --self-test report.json C:\images\known-good.E01

This is the same check every release passes before it is published, and a validation step you can record for your own lab.

Download the new release and replace the old folder or app. Cases are kept wherever you created them and settings in your user profile, so nothing is lost; a case opened in a newer TRACE is upgraded in place.