v5.4 [May 9, 2012]
Native image mounting (.E01/'dd' images)
Live RAM Captures - 32/64bit OS support (Triage Edition)
Drive Imaging (Triage Edition)
Automated Encryption Check (Triage Edition)
Updated UI and improved speed (up to 20% faster)
Multiple drives/volumes can be selected
All recovered data saved to SQLite database
Brand new Report Viewer with Search, Filter, Bookmarking capabilities - view recovered data as it is found
New customizable, simpler "preset" searches
New "Search Alert" feature
Removing duplicates now optional
All sector offsets now map to a physical offset (vs logical)
IEF Triage is shipped on a 16GB thumb drive to accomodate RAM captures
v4.2 [Jun 16, 2011]
New features in IEF v4 include:
- New, simplified Graphical User Interface
- 11 new searches for grand total of 30 artifacts IEF can search for (see below)
- The file system is now also searched instead of just a sector level search
- Can search Unallocated Clusters only, optionally including file slack space
- On NTFS drives, the MFT (Master File Table) is searched for resident deleted files
- All recovered data outputs to a report case folder now and viewed with the IEF Report Viewer, full report can be created or data exported to multiple formats
- Yahoo!® Messenger existing log files are now parsed without requiring usernames
- Yahoo!® Messenger chat log validation has been improved, with support for date ranges and message text filterin
- The compressed data in Hiberfil.sys files is decompressed on-the-fly during searches making it easy to recover artifacts within these files
- 5 total search functions (Quick, Full, Unallocated Only, Full – Sector level, and Files/Folders)
- Major re-write of most old searches and program code to improve speed and stability
- Facebook® live chat search completely rewritten to find even more chat, including damaged fragments
- Facebook® unicode text is now converted
- Updated MSN®/Windows Live Messenger® search re-written to find more chat, faster
- New Portable Edition that can run on live systems
- Portable and Standard versions can both access locked files such as the Pagefile.sys file on a live system
- Volume Shadow Copies can be mounted and searched (Quick Search or Full – Sector Level Search) in the Portable Edition
Registry Trash Keys Finder (TrashReg) is an advanced Registry cleaning tool.