X-Ways
·.·. Computer forensics software made in Germany .·.·
   
 


WinHex & X-Ways Forensics Newsletter Archive

(You may sign up for the newsletter here.)

 

#182: X-Ways Forensics, X-Ways Investigator, WinHex 21.9 released

Sep 16, 2026

This mailing is to announce the availability of version 21.9, with official release date Sep 14, 2026. Plus, there are a lot of other news below.

License owners please go to https://www.x-ways.net/winhex/license.html as always for the latest download instructions including the latest log-in credentials (!), details about their licenses, and upgrade or renewal offers. Please do not ask us for the download password. Your organization has access to it already if eligible, as described.

Service releases are announced in the Announcement section of the forum, and you can subscribe to instant e-mail notifications of postings in that section if you have a forum profile. You can create such a profile here (if you have our log-in credentials). If you wish or need to stick with an older version for a while, please switch to the latest service release of that version to benefit from bug fixes. Many users seem to stick with outdated releases of old versions or the current version unnecessarily. As a special service to users of older versions of X-Ways Forensics and X-Ways Investigator whose access to updates has ended, v21.5 SR-14, v21.6 SR-9, v21.7 SR-7, v21.8 SR-6 are usually available on request at the moment, as announced, depending on which versions were covered by their licenses. We do not promise availability of downloads to such users for an indefinite time.


Upcoming Training Events

Dates Location Target Region Course Delivered by

Sep 21-25

Online Europe, Asia X-Ways Forensics 2 X-Ways

Oct 5-8

London, UK UK (LE only!) X-Ways Forensics 1 X-Ways

Oct 19-23

Online America, Europe X-Ways Forensics 1 X-Ways

Oct 26-30

Online America, Europe X-Ways Forensics 2 X-Ways

Oct 26-30

Burlington, ON Canada X-Ways Forensics 1 F111th

Nov 2-6

Online Europe, Asia X-Ways Forensics 1 X-Ways

Nov 2-5

Calgary, AB Canada X-Ways Forensics 1 F111th

Nov 30-Dec 4

Online Europe, Asia X-Ways Forensics 2 X-Ways

Dec 7-10

London, UK UK (LE only!) X-Ways Forensics 1 X-Ways

Dec 8-11

Salt Lake City, UT USA X-Ways Forensics 1 H-11

Please sign up for our training notifications here if you would like to be kept posted on future training dates.


X-Tension Developer Training Course

Aspiring developers of X-Tensions for X-Ways Forensics may want to consider a proper and thorough training course, delivered online on demand, with individual support, by API Forensics Inc. in Canada, resold by X-Ways here. Some programming background is required. Our X-Tension Repository (the latest additions to which are also listed below in this newsletter!) can give you ideas on what can be achieved if you create X-Tensions for internal use in your organization (e.g. for automation, data exchange/export/import/conversion, ...) or for public release. You can also check out API Forensics Inc.'s own commercial X-Tensions. All details about this very unique and highly specialized developer training can be found here.


What's new in X‑Ways Forensics 21.9?
(where applicable, changes also affect X‑Ways Investigator, WinHex, and X‑Ways Imager)

User Interface

  • When saving directory browser settings to a .settings file, you now have more control over what is actually remembered and what will be restored when loading that file. For example, you may prefer to have .settings files with just your preferred column order and widths that do not activate or deactivate any column-based filters and do not make you lose your current filter settings. Or .settings files with just your favorite conditional cell coloring that do not override column widths. Or all settings except conditional cell coloring etc. To create .settings files that are compatible with previous versions, you can simply choose to store ALL settings in them.

  • Your favorite .settings files can now be loaded with a single mouse click. That is possible if you name them with a single-digit number or letter or any exotic single Unicode symbol, followed optionally by a space and more descriptive text, e.g. "1.settings" or "E Most essential columns only.settings" or "Ⓟ Default filters for pictures.settings" etc. That first character will be displayed in the caption line of the directory browser and will be clickable. If multiple .settings files exist whose naming matches the requirements, their respective first characters will be listed in ascending order of Unicode values.

  • When applying the same comment text to multiple selected files, you now have a choice and can either replace the existing comments or append to them or prepend text, delimited by a space, one line break or two line breaks.

  • A fainter color for icons of previously existing files in dark mode now means darker icons instead of lighter.

  • Some more icons in the graphical user interface.

  • Some automatic case adjustments of text in the user interface are now also applied in the languages Ukrainian and Russian.

Event List

  • Ability to extract the following when UFDR report archives are added to a case: WhatsApp message, Facebook Messenger messages, TikTok chat messages, Skype messages, Instagram chat and Telegram messages. All such messages are shown in the event list.

  • The event type filter dialog now only lists event types that actually occur in the event list.

  • The event type filter dialog now lists event types other than the internally defined ones if such events were added by an X-Tension.

  • Fixed an error in .evtx event log processing and output.

Filters

  • The Label filter is now more sophisticated and allows to exclude specific labels on top of the previously known AND and OR combinations of target labels. That means you can focus on files that have (label A AND label B), but not label C. Or on files that have (label A OR label B), but not label C. What's more, multiple targeted excluded labels can also be ANDed or ORed: NOT (label C or label D) as well as NOT (label C AND label D). The positive condition and the negative condition are always ANDed with one another.

  • Whether labels are actually visible in the Label column or deliberated hidden (for example when sharing the screen with a 3rd person) has no effect on the filter.

  • Optionally associate labels with light bulbs in four different colors. Those light bulbs appear in the Name cell of labeled files. Whether the icons are large or small depends on the height in pixels of the rows in the directory browser, which in turn depends on the DPI scaling in your Windows system (175% or more recommended for high-resolution screens) and on your chosen font size adjustment in the general options. The light bulbs can also simply help you locate certain labels in long lists of label names, e.g. in the label filter dialog window.

  • Option to apply the Metadata column's filter to the more extensive metadata that are presented in Details mode, not the subset stored in the Metadata column. This is slower because the extensive metadata are not kept in the volume snapshot, but extracted from each file each time on demand (when needed). Thus the recommendation is to use this new filter setting only in conjunction with other filters, e.g. the Type filter, if applied to very long file listings. Anyway if such an operation takes too long, you can abort it in the usual way.

Disk/Image/File System Support

  • Support for more compression variants in APFS. Reading compressed files in APFS now requires a fresh volume snapshot taken by v21.9 or later.

  • NTFS: Processing of large volume shadow copies slightly accelerated.

  • Gives the user an extra hint if file system areas were not included in a skeleton image, before closing that image, and makes a note of the inclusion in the image log.

  • More visibility of volume labels from multiple file system types: Previously only shown in the Technical Details Report and in the Info Pane, they are now included in evidence object titles/numbers when partitions are added to a case. That also means that they can become part of the path of files in evidence file containers.

  • Support for some more VDI image variants.

  • Special blue disk icon for MD-RAID container partitions (i.e. partitions that serve a similar function as a physical disk) and for images of physical partitioned disks that have been misinterpreted as images of a volume, to indicate that something is out of the ordinary.

Picture Support

  • Accelerated loading of high-resolution pictures in Preview mode with the internal graphics display library.

  • A new OCR option requires text or paper texture as a result from the picture content detection in addition to the device type requirement, i.e. combines these two conditions with a logical AND instead of the previously used OR.

  • Updated detection of AI-generated pictures.

  • Improved front camera photo detection with a very low false positive rate.

  • More reliable generating device detection.

  • Device definitions for smartphones were updated. As a consequence, device class detection and processing state detection of pictures were improved.

  • A new value for "Media design" can now occur: Swipe. Swipe indicates that a picture was resized to match the screen width and enable vertical swiping on the screen.

  • Updated recognition of aspect ratios of pictures.

  • An extraction of embedded pictures from MSPaint canvas files is now predefined in new installations.

  • Annotation numbers in the Summary table of pictures in Details mode are now prepended with a hash sign (#) so that you can more reliably scan for files with specific annotation numbers as described above for the new mode of operation of the Metadata filter.

Binary Data Interpretation/Presentation

  • Ability to toggle between the usual high-low nibble order within one byte in the hex display and the low-high order, by clicking a new cell in the status bar, which shows either "BEN" for big-endian nibbles or "LEN" for little-endian nibbles. Alternatively you can make use of a new checkbox in the top right corner of the general options. Though uncommon and awkward for human reading habits, showing the lower nibble first and the higher nibble second is a logical choice where multiple bytes belong to an integer value stored in little-endian byte order because that way all hex digits are arranged in ascending order of power. The difference that this setting makes is apparent in particular when looking at the 12-bit entries in a FAT12 file allocation table, whose nibbles usually appear intertwined, but in low-high order are straight-forward and consecutive.

  • The data interpretation in the status bar now has its own big endian switch and does not use the big endian setting of the Data Interpreter. It shows "BE" if big endian interpretation is active. Other settings are still inherited from the Data Interpreter.

  • The bits in binary representation in the Data Interpreter, in templates as well as in the status bar can now optionally be shown in ascending order, i.e. from the lowest-valued / least significant bit (LSB) to the highest-valued / most significant bit (MSB). This is not to be confused with and works in addition to the byte order, which defines which of multiple bytes is the highest valued one (depends on the Big Endian switch). If the LSB-to-MSB order is active, a triangle with its smaller end of the left and its bigger end on the right is displayed before the word "Binary:" to remind you.

  • Checksums are by convention usually displayed in big-endian byte order. That means for example that a 2-byte file with the byte values 0x33 0x00 has a 16-bit checksum that is shown as 0033. That is understandable because checksums are true integer numbers with a meaning (the result of an addition of assumed integer numbers), and numbers are read and written by humans with the most significant digit first from left to right (even in Arabic and Hebrew). CRCs like CRC16, CRC32 and Adler32 are also often (but not always) byte-wise reversed for display purposes. However, this is already harder to justify because those hash values are more random in nature and do not have an actual meaning as numbers. Longer hashes are never byte-reversed. A new notation setting allows you to see checksums and CRCs in litte endian / original byte order, for compatibility with specific other tools if necessary or when comparing checksums and CRCs to how they are actually stored on disk / in files, e.g. in zip archives.

  • Challenging the brain supposedly boosts neuroplasticity and maintains cognitive fitness during aging. Therefore, if you occasionally switch up the endianness settings in X-Ways Forensics installations of your colleagues when they are not looking, they will likely thank you later.

  • The binary representation in the Data Interpreter as well as in the status bar can now show 24 bits. For better readability, a space is now inserted after every 8 bits for 16-, 24- and 32-bit representations.

  • The Data Interpreter settings can now be saved to and loaded from .dlg files completely.

Case Management

  • New time zone definitions for British Columbia and Alberta (not in strictly ascending order in the list). Previous users of the Saskatchewan time zone need to change to the combined Central America, Saskatchewan time zone, please. Daylight saving time can now be defined in the GUI for an entire year safely (without potentially missing a few days in early January or late December) by entering 0 as the start month and 13 as the end of month. Up to 100 different time zone variants can now theoretically be defined (previously 76).

  • More graceful dealing with incomplete cases, where you only have the .xfc file and no corresponding subdirectories.

  • Choose from four different light bulb colors to mark evidence objects as notable. The light bulbs can also simply help you find certain evidence objects in long lists of evidence objects, e.g. when exploring recursively from the case root or when importing relevant evidence objects from another case. And you can click a new button to quickly select all the evidence objects that have a light bulb (of any color).

Miscellaneous

  • Ability to compare directory listings, i.e. find out which files or subdirectories are present in the current listing in the active data window that are missing in another. Right-click anywhere in the directory browser and invoke Select | Items missing elsewhere. This will match by name and optionally also require identical sizes, identical modification timestamps, and/or the same general existence status (existing vs. previously existing [of any kind]). Once the non-matching / additional items are selected, you can easily copy a list of them (Ctrl+C), export a list of them, copy them, hash them etc. This works with non-recursive and recursive listings alike.

  • Ability to change the selection in the directory browser during an ongoing Export List operation without affecting that operation's scope.

  • X-Tension API: The functions XWF_AddComment() and XWF_AddExtractedMetadata() now support additional flags to append or prepend more text to existing comments/metadata.

  • The chapter in the documentation about command line parameters now has information about exit codes. In particular if you run X-Ways Forensics in an automated, unmonitored way and check the exit code, this can give you an idea whether the execution was generally successful (0 or 710) or failed for some reason that you need to look into. Various failure indicating exit codes are possible, and they can be interpreted roughly in accordance with the error codes that Microsoft defines on the page https://learn.microsoft.com/en-us/windows/win32/debug/system-error-codes--0-499- and the following pages. In particular you could prepare for the following exit codes:
    0 = normal program termination, no special exit code was set
    353 = maximum simultaneous user count exceeded according to network dongle
    710 = normal unlocked execution was possible
    1067 = execution was aborted in an unexpected manner
    10003 = dongle not found
    11111 = server with network dongle not found.

  • The NSRL RDS hash sets have been updated to release 2026.09.1. They are available in a format for import into XWF in both MD5 and SHA-1 versions. Licensed users with access to updates can download the files from the link available by querying your licence status..

  • The program help and the user manual were updated.

  • Many minor improvements.


Changes of Service Releases of 21.8

  • SR-1: Fixed description of events generated by the revised .evtx processing.

  • SR-1: Fixed a file clean-up error in v21.8 that occurred when closing not case-associated volumes/disks.

  • SR-2: Fixed omission of volume snapshot data when importing evidence objects from other cases in v21.8.

  • SR-2: Fixed proposed .css filename for case report generation in fresh installations.

  • SR-2: Fixed encoding of a few words in non-Western-European languages in the Metadata column.

  • SR-2: Avoided a potential exception error that could occur during picture content analysis.

  • SR-2: When creating a skeleton image, confirms if the entire file system data as parsed by X-Ways Forensics were included in the image.

  • SR-3: Fixed an exception error that could occur when computing ed2k hash values in certain constellations.

  • SR-3: Fixed inability of v21.6 and later to carve HEIC files with the ~27 algorithm as defined in the File Type Signatures Search.txt file.

  • SR-3: Fixed inability of v21.5 and later to explore certain corrupt/incomplete zip archives.

  • SR-4: Fixed an exception error that could occur when processing corrupt .evtx files.

  • SR-4: Fixed inability to carve certain video files at the correct size since v21.6.

  • SR-4: Fixed an exception error that occurred when creating bookmarks from within the recursively explored Case Root window.

  • SR-4: X-Tension API: Fixed failure of XWF_OpenItem() when called from XT_ProcessItem() for files in nested archives using multiple threads.

  • SR-5: A special comment tooltip and message is output for images of physical, partitioned disks that have been misinterpreted as images of a volume. This text now reminds users that they should get such images properly interpreted, if necessary by holding the Shift key when adding the image to the case to get that option.

  • SR-5: Ability to open external 0x90 attributes in NTFS as directory data.

  • SR-5: X-Tension API: Exceptions that occur when processing calls of the XWF_GetCellText function are now caught by that function itself and should not impact the X-Tension in a potentially uncontrolled manner any more. Important notes about the XWF_GetCellText function have been added to the documentation.

  • SR-5: Fixed an exception error that could occur when running the picture content analysis.

  • SR-5: Prevented the unintended insertion of UTF-8 byte order marks and line breaks in non-textual surrogate patterns for unreadable sectors by v21.7 and later.

  • SR-5: The +9 investigator.ini setting now has an effect in v21.8. Also, it is no longer possible to reach the security options dialog when trying to turn off the strict drive letter protection.

  • SR-6: At the moment when directories are added to the directory tree of an evidence object (only once while a case is loaded), now the status of the description filter decides whether excluded directories are added to the tree or not. Previously, excluded directories were never added to the tree when that tree was initially constructed. If added/visible, excluded directories are presented with a gray directory icon instead of the usual yellow one.

  • SR-6: The scope of an ongoing Export List operation is no longer affected by selection changes with the left mouse button.

  • SR-6: The various double-click Explore vs. View options did not work in v21.8. That was fixed.

  • SR-6: Fixed missing last box in the status bar under certain screen conditions.

  • SR-6: User settings for notable picture content categorizations previously were not retained if no AND combination was used at all. That was fixed.

  • SR-6: Updated to the latest release of SQLite.

  • SR-6: Fixed assessment of Picture size+ in Details mode for videos.


 

Notable 3rd-party additions in the general resource download directory
 
ImageIO DMG
by Kevin Stokes

Source code

Support for Apple DMG (UDIF) disk images. Interprets such containers as flat sector arrays. Supports all six UDIF chunk types (raw, zero-fill, ADC, zlib, bzip2, LZFSE, LZMA), XML-plist and resource-fork block maps, encrypted images (encrcdsa v2, AES-128/256) with a password prompt, segmented images, .sparseimage and .sparsebundle containers.

Brief instructions: Place the DLL in the \x64 subdirectory of your installation before you start the application and add .dmg images to a case as you would add raw images.

Requires X-Ways Forensics, X-Ways Investigator or WinHex Lab Edition 19.5 or later x64. Tested with X-Ways Forensics 21.x on Windows 11.

Clees4All (C4All)
by Chris Lees

User guide
Source code

Exports picture and video evidence from an X-Ways Forensics case into formats suitable for import into third-party review tools, most notably Griffeye Analyze. It runs as part of the Refine Volume Snapshot (RVS) process and, for every picture/video item it finds, can write:

  • a Project VICS JSON export (VICS_Pictures_Results.json / VICS_Movies_Results.json), optionally packaged as a compressed zip archive alongside the source files, and/or

  • a C4All XML export (... C4P Index.xml / ... C4M Index.xml), the project's own legacy format.

It can also drive Griffeye Analyze's command-line case creation so a fully populated case is waiting once export finishes.

  • Exports pictures and/or videos independently, with per-type min/max file size filters

  • Filters by X-Ways type status (confirmed, mismatch detected, etc.) and file format consistency

  • Excludes embedded Thumbnail.jpg files, with an option to still include ones flagged as a thumbnail mismatch

  • Excludes media carved from within already-exported live video files, avoiding duplicate export

  • Deduplicates files by MD5 + physical offset, preferring live over deleted over carved copies

  • Optional VICS JSON output, C4All XML output, or both, with VICS output optionally written straight into a zip archive

  • Optional automatic Griffeye Analyze case creation, including a named Griffeye import-settings profile

  • Remembers your last-used settings between runs (stored in a local SQLite database)

  • Scriptable via X-Ways XTParam: command-line arguments for unattended/batch processing

  • Multi-threaded; tested with RVS running up to 8 threads

Requires X-Ways Forensics 19.2 or later (newer versions for some features), Windows 7 or later, 64-bit.

Recent additions to the X-Tension Repository
 
Bulk Extractor
by Kevin Stokes

Runs Simson Garfinkel's bulk_extractor against evidence from within X-Ways Forensics and feeds the results back into the case. Three input modes — the active evidence object's source image, an external file/folder, or the items selected in the directory browser — with a settings dialog for the scanner list, thread count, recursion depth and free-form bulk_extractor arguments. Output can be added to the case as a directory evidence object, and in selected-items mode source files are labelled per scanner that hit them (BE: email, BE: exif, …), giving an audit trail of what was scanned and where the hits came from.

Requires a bulk_extractor binary, which is not bundled — bulk_extractor64.exe v2.2.0 or later, placed next to the DLL or pointed at from the dialog. Optionally, runs a Linux bulk_extractor through WSL instead. No other dependencies.

XML Viewer
by Kevin Stokes

Viewer X-Tension to see and search XML files with a live XPath 1.0 query box and a collapsible tree in the Preview pane, plus a colour-coded source view. A built-in value interpreter decodes selected timestamps (Unix, FILETIME, WebKit, HFS+, Cocoa, OLE, DOS), Base64, and hex. Handles UTF-8/UTF-16 and declared code pages, namespaces, scheduled-task XML, EVTX exports, Office parts, plists, and manifests.

Requires the separate viewer component to be active and the Microsoft Edge WebView2 Runtime (preinstalled on Windows 11 / Windows 10 with Edge). Loaded via Options → File Viewing → "Load viewer X-Tensions".

JSON Viewer
by Kevin Stokes

Viewer X-Tension for JSON and JSONL files: renders the file in the Preview pane with a live JMESPath (jmespath.org) query box — filter/reshape as you type, with a collapsible tree view, a pretty-printed text view, line-delimited JSON (JSONL) support, and per-file query history.

Requires the separate viewer component to be active and the Microsoft Edge WebView2 Runtime (preinstalled on Windows 11 / Windows 10 with Edge). Loaded via Options → File Viewing → "Load viewer X-Tensions".

TruffleHog
by Kevin Stokes

Wraps TruffleHog to scan items in a volume snapshot (or a right-click selection) for secrets and credentials. Runs TruffleHog’s built-in detectors plus optional custom YAML patterns, deduplicates by stored hash so identical copies across profiles/VSCs/restore points scan once, and assigns results to per-detector labels plus a consolidated XLSX per evidence object. Verification is off by default (no outbound network calls); read-only against evidence via XWF_Read.

Requires Windows 10/11/Server 2016+, trufflehog.exe v3.x+ for Windows (from TruffleHog’s GitHub releases) — not bundled; placed in a tools\trufflehog\ subfolder or pointed to via the dialog.

Snappy Fox
by Anna Kirpichnikova

Automatically detects and decompresses Mozilla Firefox disk cache (morgue) files within a case. During volume snapshot refinement it identifies Firefox cache entries by their path (*morgue*final); from the directory browser context menu it processes the items selected by the examiner. Each cache entry is decompressed using the open-source snappy-fox core and the resulting plaintext is added back into the volume snapshot as a child item (_decompressed), preserving the original hierarchy. Items get the "Snappy decompressed" label assigned. Output is CRC-verified by default; reconstruction of damaged or corrupted streams is offered as an opt-in prompt at startup, and any reconstructed output is flagged with a comment indicating that it is not CRC-verified and may be incomplete.

No external dependencies. After the X-Tension creates the child items, the examiner should run X-Ways' file type verification on them so the decompressed content is recognized by signature (e.g. as a PNG or JPEG image) and rendered in the Viewer and gallery.

AI Assistance for Building X-Tensions

The X-Tension Builder Skill by Kevin Stokes is a Claude Code skill plus a curated knowledge base and starter templates for authoring X-Ways Forensics X-Tensions (C++ and Python). It helps developers scaffold new X-Tensions, wrap external CLI tools, and follow consistent conventions, with API notes that route every call back to publicly available documentation. Developers can install it with: `claude plugin marketplace add kev365/xways-xtension-builder-skill`. Building the C++ templates needs Visual Studio 2019/2022 (x64); the Python template needs X-Ways' XT_Python.dll (Python 3.10/3.12). The X-Ways SDK is acquired separately (not redistributed). No other dependencies.


Become a certified user of X‑Ways Forensics
Become an X-PERT
(X‑Ways Professional in Evidence Recovery Techniques)

Prove your proficiency in computer forensics in general and X‑Ways Forensics in particular with our certification program. After passing the challenging exam, you will be part of an exclusive circle and enjoy various benefits such as special recognition, training discounts, updated training material. For further details, please check here.


Thank you for your attention! We hope to see you soon somewhere at https://www.x-ways.net or on our Facebook page. You may also follow us on Twitter/X. Please forward this newsletter to anyone who you think will be interested. If you wish to subscribe with another e-mail address, please do so here.

Kind regards

Stefan Fleischmann

X‑Ways Software Technology AG
Carl-Diem-Str. 32
32257 Bünde
Germany

 

#181: X-Ways Forensics, X-Ways Investigator, WinHex 21.8 released

May 25, 2026

This mailing is to announce the availability of version 21.8, with official release date May 25, 2026.

License owners please go to https://www.x-ways.net/winhex/license.html as always for the latest download instructions including the latest log-in credentials (!), details about their licenses, and upgrade or renewal offers. Please do not ask us for the download password. Your organization has access to it already if eligible, as described.

Service releases are announced in the Announcement section of the forum, and you can subscribe to instant e-mail notifications of postings in that section if you have a forum profile. You can create such a profile here (if you have our log-in credentials). If you wish or need to stick with an older version for a while, please switch to the latest service release of that version.


Upcoming Training Events

Dates Location Target Region Course Delivered by

June 1-5

Online Europe, Asia X-Ways Forensics 1 X-Ways

June 8-12

Online America, Europe X-Ways Forensics 2 X-Ways

June 22-26

Online America, Europe X-Ways Forensics 1 X-Ways

July 6-10

Online Europe, Asia X-Ways Forensics 2 X-Ways

July 13-17

Online Europe, Asia X-Ways Forensics 1 X-Ways

July 20-24

Online America, Europe X-Ways Forensics 1 X-Ways

July 20-23

Davie, FL USA X-Ways Forensics 1 H-11

Aug. 10-14

Online America, Europe X-Ways Forensics 2 X-Ways

Aug. 11-14

Salt Lake City, UT USA X-Ways Forensics 1 H-11

Sep. 14-18

Online Europe, Asia File Systems Revealed X-Ways

Please sign up for our training notifications here if you would like to be kept posted on future training dates.


What's new in X‑Ways Forensics 21.8?
(where applicable, changes also affect X‑Ways Investigator, WinHex, and X‑Ways Imager)

File Format Support

  • Carving algorithm significantly improved for certain MPEG video variants.

  • File carving support for AVIF files.

  • No longer includes extra Exif Makernote data in the thumbnail child object of JPEG files whose embedded data is uncovered, to achieve more universally usable hash values for such child objects.

  • Alternative extraction method for attachments encoded in .eml files.

  • Completely revised parsing of .evtx Windows event log files and more complete output of event data to the event list. More stable with corrupt .evtx files.

  • Recognizes DocuRay-processed document files as encrypted/DRM-protected.

  • Identifies hardlinks and symlinks in TAR archives as such. Hardlinks are presented with the original file contents and the hardlink count within the archive.

  • That certain binary files are included in the case report in a readable format if possible is now optional. This affects for example .job files, .lnk, prefetch files, $I*, $LogFile, $UsnJrnl:$J, wtmp, utmp, btmp, TCP and UDP packets, and many more. If binary copies are preferred that cannot be viewed in the browser along with the report, the new box for this can be unchecked.

  • Tentatively identifies RTF files that contain embedded pictures, using a label ("No pictures extracted").

Picture Support

  • Ability of the internal graphics display library and the picture content analyis to load pictures from AVIF files.

  • HEIC display support completely revised.

  • PNG and JPEG support updated in the internal graphics display library.

  • Improved detection of AI-generated pictures through various micropatterns. You can check the software class row in the summary table in Details mode for an assessment. If it does not say "AI-generated", the device class/type "No device" could also raise suspicion, as should Annotation No. 201 if it is output.

  • Updated picture generating device detection.

  • Improved picture size+ information in the Summary table in Details mode (called sensor size or paper size in previous versions), with textual descriptions of the resolution, output of the aspect ratio if worth pointing out, and potentially a known previous resolution if a picture was resized. An arrow up indicates an unexpectedly high propensity score. An arrow down indicates an unexpectedly low propensity score, which is correlated with reduced-resolution copies for dissemination and a lower generic relevance. "Picture size" is now marked there with a tiny + symbol to set it apart from the directory browser column of the same name.

  • A new entry called “Media design” in the Summary table for several picture file types, already introduced in v21.7, is meant to aid the assessment of a picture's aspect ratio. There are about 128 aspect ratios that represent a statistically significant variant. All other aspect ratios are labeled "Random". Particularly common aspect ratios, like e.g. 4:3, which are used by camera sensors, are labeled "Native". The group of "Framed" media designs are further distinguished as "Framed", "Square", "Scaled", "Social media" or "Featured". The latter refers to the "Open Graph" standard introduced by Google, which identifies pictures that are meant to represent a website as a whole. Media design information can be used to assess the overall consistency: A picture with a processing state labeled "Original" should always have a media design labeled "Native". A modified picture would expect a "Framed" variety, while "Featured" or "Social media" correlates with the processing state of "Disseminated". If no other tangible context exists, the media design could still be used for a general assessment.

  • Improved interpretation of picture aspect ratios in v21.8.

Evidence Object Support

  • For a while already, UFDR reports can be added as evidence objects just like normal Zip archives, and the file report.xml in .ufdr archives is presented as a virtual file because it contains metadata for the examination and is not an original file. It can optionally be parsed to present all the other files in the archive with their original timestamps and in their original paths whenever possible. In v21.8, the timestamps that the other files have according to the Zip archive records can now optionally be discarded altogether if you find them too unreliable/misleading.

  • If report.xml interpretation is fully selected instead of just half, X-Ways Forensics can now also extract messages and present them as events. Messages of the following types are usually supported so far:
    Instant Messages: Android CallLog database
    Instant Messages: Android
    Chats: Kik Messenger
    Instant Messages: Phone
    Chats: Native Messages
    Chats: Kik Messenger
    Chats: Snapchat

  • More detailed feedback on report.xml parsing in case of problems.

  • Ability to store decoded document text and OCR-derived text along with the corresponding files in evidence file containers. This allows recipients of such containers to run fast logical searches in the included files without spending time on text decoding and OCR, if they are using v21.7 SR-3 or later.

  • Ability to continue filling encrypted container archives. (The user needs to enter the same password again.)

File System Support

  • Ability to detect an exFAT file system in a partition and immediately work with it even if the boot sector was overwritten, as long as the backup boot sector is available.

  • A template for exFAT boot sectors is now included.

  • The directory tree depth at which an error in the file system will be presumed and at which recursion will be aborted when taking a volume snapshot of FAT* or Ext* file systems can now be defined in the Volume Snapshot Options, and helps to avoid stack overflow errors, which would otherwise occur in some very rare cases. If this situation occurs, a message will be output: "Probably circular link detected. Recursion depth ...".

  • Improved ability to cope with a certain type of NTFS file system manipulation.

  • Broader recognition of BitLocker recovery key files, which are identified as "blkey" in the Type column.

  • Recovery keys that were encountered in any evidence object in the case already are automatically used to decrypt other BitLocker partitions that you open, if they fit.

  • A new security option controls whether BitLockers passwords and keys that you enter manually or that are found automatically (BEK and recovery key files) or that match when trying out passwords from a list are centrally stored in the case (on disk). That is convenient and the default setting, but perhaps not desirable for internal investigations if the case directory itself is not protected/encrypted.

User Interface

  • More granular setting for what action should be triggered when double-clicking files with child objects (explore or view).

  • The first 4-state check box in X-Ways Forensics (or maybe in the universe) has been introduced. Grid lines in the directory browser are now available in 3 different shades (and can optionally be completely hidden).

  • Ctrl+A now works in windows of the viewer component to select all, in text documents and spreadsheets (but not in PDF documents, presentations, ...).

  • The Description filter can now filter for directories.

  • Extended UTF-8 support in some functions/parts of the user interface.

  • The Ukrainian and Russian translations of the user interface were updated.

Notation and Output

  • A new notation setting allows to see the complete internal path of an evidence object in the evidence object column instead of the user-definable, up to 79 characters long title or number of the evidence object.

  • Another new notation setting allows to not show filename extensions in the columns "Name" and "Parent name", which could be useful for users of X-Ways Investigator in particular who do not care much about what type a file is or pretends to be.

  • You can tell X-Ways Forensics what you like to see in the Int. Parent column: The internal ID of the parent as in previous versions, its name, or its description, or a combination of these three. The filename can optionally be truncated before the extension in this column as well.

  • Another new notation setting allows to display file sizes in units of sectors. If not found on storage devices or images with sector-level access, but e.g. in evidence objects that are zip archives or directories, a standard sector size of 512 bytes is assumed. The display sector count is either rounded up (because a file occupying 1 full sector plus 2 bytes actually utilizes 2 sectors where files are stored as sector-aligned) or it is displayed with one decimal digit. The display style with one decimal digit can give you an idea how precisely or roughly carved files were sized because if a file size is an exact multiple of the sector size, it will be displayed with no decimal, whereas .0 indicates a few extra bytes that just do not amount to one tenth of a sector. This can also give you an idea which file types are naturally rounded in size, e.g. Windows registry hives and OLE compound files. On the other hand, if a JPEG or HEIC or any other usually unrounded file is shown with no decimal digit, that is a candidate for a file that was truncated, e.g. by carving or file system corruption. (Though if file sizes are equally distributed, one in 512 files would happen to be a multiple of the sector size naturally.)

  • The notation settings dialog window was tidied up and renamed Notation/Output. The main notation/output settings of the graphical user interface itself can now be reached from the main menu. The "Notation..." button in the General Options dialog window will probably be removed at some point.

  • The option to output either the main filename, an alternative name or both in exported lists and in copylog files, if an alternative filename is known at all, has become a setting in the Notation/Output dialog window.

  • The two options for the "1st sector" column, previously part of the directory browser options, have become notation settings and thus can now be different for the GUI and exported lists.

  • The setting to display a triangle in Name cells to indicate the presence of labels has been moved from the notation settings to the directory browser options dialog.

X-Tension API

  • The functions XWF_GetReportTableAssocs() and XWF_AddToReportTable() got new names: XWF_Label() and XWF_GetLabels(). These functions can still be called by their old names for compatibility purposes, but the old names are now deprecated since the arrival of v21.7 SR-4.

  • The XWF_Label() function can now be used to remove a label from a file.

  • The XWF_OpenItem() function now supports a flag to embed attachments in an .eml file, usually for export purposes.

Miscellaneous

  • When importing hash values, either from an external text file with ASCII hex values or from files selected in the directory browser, you now have the option to merely find out which hash values are already contained in your database and which hash values are new, without actually adding the hash values to the database. This can be used for example to find out how an import would affect your database / if there is any new material included at all etc., or if you get your hands on a list of hash values of files of interest and do not have access to the files themselves (e.g. files that once were in someone's possession) and need to find out whether they are known in your hash database.

  • The Recover/Copy function's log function, if fully checked, now also logs directories that are being recreated in the output path, with their original names, internal IDs, timestamps, attributes or whatever you select.

  • X-Ways Forensics now monitors additional threads during volume snapshot refinement and attempts to terminate and resume hanging threads if they are found to be unresponsive for e.g. 15 minutes. This is a new settings under Options | Security and assumes that the user interface itself is still responsive. Even if a particular file takes longer to process (e.g. large Outlook PST e-mail archive with many e-mails and attachments), the corresponding thread makes it known that it is still alive, so that alone will not trigger any recovery measures.

  • Ability to simulate hanging on a file, using one of the unlabeled, but tooltipped check boxes in Options | Security, only in Preview and Beta releases. (v21.8 Beta is still downloadable for a while.)

  • Registering at least one e-mail address specifically for the insurance of each dongle is now much more optional (and will also be treated as more optional in future releases of older versions). If no e-mail address is defined for that purpose, the final transaction code to complete the cancelation of the insurance will be e-mailed to all e-mail addresses connected with the entire license group that the dongle belongs to. If you think that is too annoying for too many colleagues, you can still register more targeted e-mail addresses specifically just for this purpose like before.

  • The viewer component was last updated with patches on our server for download on Feb 26, 2026.

  • An MPlayer release from 2025 is now downloadable.

  • The NSRL RDS hash sets, in a format for import into X-Ways Forensics, have been updated to release 2026.03.1, and are available for download in both MD5 and SHA-1 versions, now from the alternative download server.

  • The program help and the user manual were updated.

  • Many minor improvements.


Changes of Service Releases of 21.7:

  • SR-1: Fixed an exception error that could occur when applying OCR to certain PDF documents.

  • SR-2: Fixed an exception error that could occur when applying OCR to certain PDF documents.

  • SR-2: Fixed a memory allocation error that could occur when reaching around 358 million items in a volume snapshot.

  • SR-2: Fixed inability to recognize a FAT file system as such if it consists of less than 100 sectors in total.

  • SR-2: The option to skip and omit data in free clusters when creating an image was ignored when active in the .cfg file and when imaging was triggered from the command line. That was changed.

  • SR-2: Fixed inability of v21.6 SR-4 and later to extract e-mails from small MBOX e-mail archives.

  • SR-2: Improved simultaneous compatibility with v8.5.4 and v8.5.7 of the viewer component.

  • SR-2: Improved compatibility of "File Type Signatures Search.txt" with editing in MS Excel.

  • SR-3: Ability to import extracted text from evidence file containers, which can be included in evidence file containers in v21.8 and later.

  • SR-3: Fixed an exception error that could occur when parsing the report.xml file in some UFDR archives.

  • SR-3: Support for overlong UNC (network) paths for progress notifications as files.

  • SR-3: v21.7 did not present the dongle management dialog window in some situations when needed at startup. That was fixed.

  • SR-4: The Exif table in Details mode was not present for HEIC files since v21.6. That was fixed. The fix is has also been applied to v21.6 SR-8.

  • SR-4: Content created timestamps from HEIC files were not translated correctly to local time. That was fixed.

  • SR-4: Improved size detection of QuickTime video files with an mvhd atom. This change is also available in v21.6 SR-8.

  • SR-4: Fixed an instability associated with the parsing of certain PList files.

  • SR-4: Fixed a division by zero error in v21.7 when processing certain video files.


Recent Additions to the X-Tension Repository

UAL Timeliner
by Kevin Stokes

Parses Windows User Access Logging (UAL) databases (Current.mdb /{GUID}.mdb under the SUM folder of Windows Server installations) and ingests one event per UAL record into the X-Ways Forensics event list, anchored to its source .mdb. Optional per-format reports can be written to disk at the same time (CSV, XLSX, SQLite, Parquet, K2T / Timesketch JSONL). Each ingested .mdb is tagged with a "ual-timeliner" Report Table label. Auto-detects re-runs and enables event-level deduplication so re-ingest can attempt to avoide duplicate rows. Runs from Tools | Run X-Tensions (whole-snapshot scan) or from the  directory-browser right-click menu (selected .mdb files only). Requires ual-timeliner.exe (the upstream parser binary) next to the DLL or on PATH, download from here.

Updater for X-Ways Forensics
by Kevin Stokes

Downloads and installs/updates X-Ways Forensics (dongle or BYOD) inside an existing installation; optionally pulls Viewer, Tesseract, Excire, AFF4 X-Tension, and Conditional Coloring. Run from Tools | Run X-Tensions.

Dahua DHFS 4.1 file system parser
by Dane Wullen

Reads video contents of Dahua DHFS4.1 file system and represents available and carved video data in X-Ways Forensics. Right-click the virtual file that represents the entire space of the file system unknown to X-Ways Forensics and run the X-Tension. After that, open the disk via disk I/O with the same X-Tension to access the fragmented video data.

HIKVISION file system parser
by Dane Wullen

Reads video contents of HIKVISION file system and represents available video data in X-Ways Forensics. Right-click the virtual file that represents the entire space of the file system unknown to X-Ways Forensics and run the X-Tension.

XT_RefineSearchTerm
by Jamie Sharpe

Source Code

Assists in reducing the number of false positive keyword hits in a Simultaneous Search where bytes are read before and after the keyword, and a percentage is calculated on printable characters [printable meaning > 0x20]. If the percentage is over a user's threshold, then the keyword is marked positive, otherwise it is removed as a hit. The reason this was developed is due to the large amounts of false positives when a keyword term is rather small, less than 5 characters for example.


Become a certified user of X‑Ways Forensics
Become an X-PERT
(X‑Ways Professional in Evidence Recovery Techniques)

Prove your proficiency in computer forensics in general and X‑Ways Forensics in particular with our certification program. After passing the challenging exam, you will be part of an exclusive circle and enjoy various benefits such as special recognition, training discounts, updated training material. For further details, please check here.


Thank you for your attention! We hope to see you soon somewhere at https://www.x-ways.net or on our Facebook page. You may also follow us on Twitter/X. Please forward this newsletter to anyone who you think will be interested. If you wish to subscribe with another e-mail address, please do so here.

Kind regards

Stefan Fleischmann

X‑Ways Software Technology AG
Carl-Diem-Str. 32
32257 Bünde
Germany

 

 

 

#180: X-Ways Forensics, X-Ways Investigator, WinHex 21.7 released

Feb 19, 2026

This mailing is to announce the availability of version 21.7, with official release date Feb 17, 2026.

License owners please go to https://www.x-ways.net/winhex/license.html as always for the latest download instructions including the latest log-in credentials (!), details about their licenses, and upgrade or renewal offers. Please do not ask us for the download password. Your organization has access to it already if eligible, as described.

Service releases are announced in the Announcement section of the forum, and you can subscribe to instant e-mail notifications of postings in that section if you have a forum profile. You can create such a profile here (if you have our log-in credentials). If you wish or need to stick with an older version for a while, please switch to the latest service release of that version.


Upcoming Training Events

Dates Location Target Region Course Delivered by

Mar 2-6

Online America, Europe X-Ways Forensics 2 X-Ways

Mar 3-6

Salt Lake City, UT USA X-Ways Forensics 1 H-11

Mar 23-27

Online America, Europe X-Ways Forensics 1 X-Ways

Apr 20-24

Online Europe, Asia X-Ways Forensics 2 X-Ways

Apr 20-23

Davie, FL USA X-Ways Forensics 1 H-11

Apr 27-May 1

Online Europe, Asia X-Ways Forensics 1 X-Ways

May 4-7

Guelph, ON Canada X-Ways Forensics 1 F111th

May 11-15

Online America, Europe X-Ways Forensics 1 X-Ways

May 12-15

Scottsdale, AZ USA X-Ways Forensics 1 H-11

Jun 1-5

Online Europe, Asia X-Ways Forensics 1 X-Ways

Jun 8-12

Online America, Europe X-Ways Forensics 2 X-Ways

Sep 14-18

Online Europe, Asia File Systems Revealed X-Ways

Please sign up for our training notifications here if you would like to be kept posted on future training dates.


What's new in X‑Ways Forensics 21.7?
(where applicable, changes also affect X‑Ways Investigator, WinHex, and X‑Ways Imager)

File Type Support

  • The play duration of certain video files that cannot be determined and added to the Metadata column during the metadata extraction step can now be extracted when capturing sporadic still images.

  • If you select multiple video files whose play durations are known in the Metadata column, the total play duration of all these videos combined is computed and shown below the directory browser. This enables you and others (e.g. lawyers) to better understand the amount of video data, for example to assess how complete the coverage of surveillance videos is or to judge the amount of illegal videos found, in a more meaningful way than measuring it in megabytes, gigabytes or terabytes, especially for a computer layman.

  • Updated support for PNG, TIFF and WEBP files in the internal graphics display library.

  • More pictures can now be identified as belonging to the “No device” class, which are known to not have been generated by optical input devices like cameras or scanners, but purely by software.

  • The propensity score in the summary table was superseded with the introduction of the confidence about the device class.

  • Self-extracting archives in the form of Windows PE .exe files (if they are identified as type “sfx”) are now treated as general-purpose archives and are thus explored along with ordinary archives like Zip, RAR, and 7z, revealing their various sections, and certificates if signed. The PE section that contains data that can be interpreted as an embedded Zip or RAR archive is then usually identified and processed as such.

  • Revised processing of .evtx event log files. Fixed some parsing errors. More complete coverage of data types and output of the Name attribute.

  • "Uncover embedded data..." now outputs all timestamps found within BPLists as a separate type of event.

File System Support

  • Support for WofCompressed files in NTFS with resident storage.

  • Support for namespace extended attributes in Ext4 file systems.

  • More robust processing of certain corrupt directory cluster chains in FAT file systems.

  • For more convenience, when starting off filling a skeleton image by taking a new snapshot of an already open volume/partition, a few sectors from the start of that volume/partition are now included as well to enable the recipient to identify the most common file systems. Note that you absolutely do not have to take a volume snapshot and thus transfer all essential file system data structures into the skeleton image. That could easily include a hundred thousand names of files and directories names, which may or may not be necessary or appropriate for your purpose. If you just need the contents and some metadata of certain files in an NTFS file system for example, you can specifically include the FILE records and contents of those files, without the entire $MFT, and thanks to the inclusion of sector 0 (the boot sector) X-Ways Forensics will know what the file system and the cluster size were, and can find the FILE records with a particular thorough file system data structure search in the skeleton image (quickly, thanks to the sparse nature of the image) and will therefore know the storage locations and names and timestamps etc. of those files in the volume.

  • A small number of sectors are no longer included in skeleton images indirectly if they are only read for internal purposes (e.g. to identify and highlight slack space area).

  • When creating a skeleton image, the contents of small files that are stored within the $MFT system file can now be automatically excluded from the acquisition when X-Ways Forensics reads $MFT to take a volume snapshot. This may seem like a natural choice since ordinary (larger) files are by default not included in the target image either unless you specifically include them. However, this involves redacting data within certain sectors and as such alters the hash value of the affected sector range in the target image compared to the source volume. As a compromise, if hashing is active, a second hash value for the redacted data is included in the .log file, and that second hash value is the one that is re-computed when you have X-Ways Forensics verify the integrity of a skeleton image created with this new option. Resident main file contents and resident alternative data streams that share the same FILE record as storage space are excluded or included together.

  • Adding selected files to a skeleton image will now usually copy those files without slack space, i.e. trigger sector I/O only for the logical file size.

  • After taking a volume snapshot of the subject volume that is being acquired as a skeleton image, which includes the essential file system data structures required to locate all file contents, the user is now offered to revert to idle mode so that any subsequent random read operations do not trigger acquisitions any more and the user can freely click around and navigate in the directory browser and will only specifically add file contents to the skeleton image using the dedicated command in the directory browser context menu.

BitLocker Support

  • Informs the user if a fitting startup key for a BitLocker volume is found in a .BEK file in the case directory and names that file and where it was found.

  • On BitLocker volumes that it can decrypt, X-Ways Forensics now tries to automatically detect unencrypted areas. Such areas can be present if only in-use drive space was encrypted and rewritten when the BitLocker volume was created, for example for performance reasons or because the security implications of this were not understood. If this situation is detected, X-Ways Forensics will recommend running your analyses also on the undecrypted volume, bypassing BitLocker decryption. For example a physical keyword search in the undecrypted sectors in addition to a logical search in the files found in the decrypted volume could be advisable.

  • There is a new command in the context menu of an evidence object that is a BitLocker volume that X-Ways Forensics knows how to decrypt. That command allows to open such a volume without decrypting the data in any of its sectors, to see what data are actually, literally stored in them. In that state you could run physical searches or carve data automatically or manually. Not available in X-Ways Investigator.

  • The file header signature search can now additionally and automatically perform a second run on the data directly as stored in a partition that is protected with BitLocker, bypassing the decryption algorithm. Either only if the presence of unencrypted areas was detected by X-Ways Forensics in the BitLocker volume (potentially just seconds before during the first, regular run of the file header signature search!) or, if fully checked, on any BitLocker volume that is processed in its decrypted form.

  • X-Ways Forensics will specifically remember which files were carved (automatically or manually) while BitLocker decryption was bypassed so that those files in future can be read correctly even when BitLocker decryption is otherwise active. The Description column will identify such files. When working with the decrypted BitLocker volume, switching between Volume/Partition and File mode for such files will show the obvious difference between the data that are either passed through the decryption algorithm in the former modes (falsely, because it was never encrypted in the first place) or not in File mode.

Performance and Stability

  • Greatly accelerated loading of very large Passwords.txt files.

  • The password collection in Passwords.txt can now be tried to open BitLocker volumes using multiple threads for much better performance.

  • Internal graphics display library thoroughly revised.

  • Does not waste time with certain unnecessary file system I/O or opening compressed files when including selected files in a hash set and the hash values can simply be taken from the volume snapshot.

User Interface

  • The option to assign labels to a parent file now has a tooltip that defines exactly what to expect: The next (closest) parent object that is not a directory will be targeted. This option skips parent directories and keeps looking until a file is found. If no file is found upwards in the hierarchy, no label will be set.

  • A new related option was introduced, which targets the so-called ultimate file. That is the parent object highest in the hierarchy that is a file, i.e. the most aggregate file that indirectly contains the data. Parent directories (in file or e-mail archives) can be skipped over optionally. If not, then the last parent file encountered before a directory will be considered the ultimate file. If no file is found upwards in the hierarchy, the label will be set to the selected item itself, if it is a file.

  • Another new option allows to simply assign label to all the parent object files of a selected file, in a sequence that may or may not be interrupted by directories. You could then decide later for example based on file type which of those you actually need (e.g. e-mails).

  • A new option allows to assign a label to the direct parent object of a selected file, no matter whether it's a file or directory.

  • Slightly revised look of the dialog window in which labels are managed.

  • If a file is destined to appear in the case report because it was assigned to a label that is includable in the report as a report table, that file is now marked with a special icon in its name cell, where also a yellow post-it icon appears if the file was commented on. The icon for the report is displayed in a fainter color if the label is not currently selected for output in the report options.

  • Omitting excluded child objects when printing is now optional.

  • Some icons in the user interface were revised, for the simultaneous search, copying extracted text, skeleton imaging and running external programs.

Search Hit Lists and Event Lists

  • The search hit filter now allows to more precisely define where in the context of a search hit an additional keyword is required, either to the left or to the right of the search hit or both. Also, an additional keyword can be required in the search hit itself. That can be useful if the data in the search hit is variable for example because it is based not on a fixed keywords, but on a regular expression (e.g. to match e-mail addresses in general), or because the user has shifted the offset of the search hit to the left or to the right to cover related data that needs to be exported etc.

  • For both search hits and events there are now two distinct menu commands to add items to the report and remove them. (For search hits there was previously only a single menu command that toggled that state.)

  • Selected events from all selected evidence objects can now be included in the case report, near the end, in the order that was last defined in an event list, e.g. sorted by timestamps for a chronological timeline view. (Not in X-Ways Investigator.)

  • The description of individual events can now be changed or set retroactively by the user, using the context menu. (Event descriptions are currently limited to 255 bytes in UTF-8.).

Miscellaneous

  • Progress notifications can now optionally by output into subdirectories that are named after the machine on which the X-Ways Forensics session is running that produces these notifications.

  • Surrogate ASCII patterns for unreadable sectors on storage devices with errors, redacted sectors in cleansed images etc. are now prepended with an UTF-8 signature so that the latest version of the viewer component will display such patterns when viewing or previewing files that consist of only such text (interspersed with binary zeroes), assuming that they are text files.

  • X-Tension API: The XT_PREPARE_TARGETFILESWITHUNKNOWNDATA flag now forces XT_ProcessItem() and XT_ProcessItemEx() calls for files with unsupported encryption or compression.

  • Files in certain corrupt/incomplete archives can now be opened with 0 bytes instead of not at all. That also means that the X-Tension API function XT_ProcessItemEx() can now receive calls for such files with (useless) handles.

  • The viewer component was last updated with patches on our server for download on Nov 2, 2025.

  • The NSRL RDS hash sets, in a format for import into X-Ways Forensics, have been updated to release 2025.12.1, and are available for download from the resource directory in both MD5 and SHA-1 versions.

  • The program help and the user manual were updated.

  • Many minor improvements.


Changes of service releases of 21.6:

  • SR-1: Ability to display a rare JPEG variant.

  • SR-1: Fixed inability of the original v21.6 release to open the same case with the same user account in cooperative mode more than once (the second time as one's alter ego).

  • SR-1: Using only AND combinations of detections of the picture content analysis for the categorization as notable did not work because those combinations were lost. That was fixed.

  • SR-2: Avoided an unnecessary error message about the creation of a temporary file at start-up in certain situations.

  • SR-2: The data density/compression statistics window is now more likely in the visible range of a monitor with a low screen resolution.

  • SR-2: Fixed an exception error that occurred when computing ed2k along with any other hash value at the same time. (also in v21.5 SR-10)

  • SR-2: Fixed decrementation of the remaining execution count of insured dongles after automatic restarts. (also in v21.5 SR-10)

  • SR-2: Fixed device type dependent application of OCR in certain situations. (also in v21.5 SR-10)

  • SR-3: Simple checksums that are computed on a multi-byte accumulator, but byte-wise, are now presented in reverse hex ASCII byte order again like in v21.4 and earlier.

  • SR-3: Fixed an exception error that could occur in v21.6 when creating a new evidence file container.

  • SR-3: Works with more Tesseract versions.

  • SR-3: Navigating back to a parent file by double-clicking the .. entry can no longer cause unintended viewing of the file.

  • SR-3: Support for Windows 11 24H2 Prefetch files.

  • SR-3: Fixed an error in the Undo command in v21.6.

  • SR-3: The character adjustment feature did not work for indexing in v21.6. That was fixed.

  • SR-4: Fixed decompression of certain WofCompressed files in NTFS with non-resident storage.

  • SR-4: Support for longer paths and filenames in the progress notification function.

  • SR-4: Fixed an error in the non-alternative method of TAR archive extraction in v21.4 and later, which occurred with certain TAR archives that contain nested archives.

  • SR-4: Fixed an error that caused certain e-mails to be extracted from within MBOX archives with a size of 4 GB.

  • SR-4: Prevented potential separation of the [XT] prefix and an actual message in the Messages window sent from an X-Tension that could occur with multiple threads.

  • SR-5: Fixed a potential instability in mass picture processing.

  • SR-6: SHA-512 was not usable as a hash for disk imaging. That was fixed.

  • SR-6: Slightly more accurate representation of the existence status of deleted files and directories in exFAT whose respective first cluster is unknown.

  • SR-6: Fixed preview of some rare $I recycle bin files with v8.5.7 of the viewer component.

  • SR-6: Fixed BitLocker-to-go FAT16 file system detection.

  • SR-6: X-Tension API: The flags XT_PREPARE_DONTOMIT and XT_PREPARE_TARGETFILESWITHUNKNOWNDATA combined now override the user interface setting to omit files whose first cluster of original data is known not to be available.


Become a certified user of X‑Ways Forensics
Become an X-PERT
(X‑Ways Professional in Evidence Recovery Techniques)

Prove your proficiency in computer forensics in general and X‑Ways Forensics in particular with our certification program. After passing the challenging exam, you will be part of an exclusive circle and enjoy various benefits such as special recognition, training discounts, updated training material. For further details, please check here.


Thank you for your attention! We hope to see you soon somewhere at https://www.x-ways.net or on our Facebook page. You may also follow us on Twitter/X. Please forward this newsletter to anyone who you think will be interested. If you wish to subscribe with another e-mail address, please do so here.

Kind regards

Stefan Fleischmann

X‑Ways Software Technology AG
Carl-Diem-Str. 32
32257 Bünde
Germany

 

 

 

> Archive of the year 2025 <

> Archive of the year 2024 <

> Archive of the year 2023 <

> Archive of the year 2022 <

> Archive of the year 2021 <

> Archive of the year 2020 <

> Archive of the year 2019 <

> Archive of the year 2018 <

> Archive of the year 2017 <

> Archive of the year 2016 <

> Archive of the year 2015 <

> Archive of the year 2014 <

> Archive of the year 2013 <

> Archive of the year 2012 <

> Archive of the year 2011 <

> Archive of the year 2010 <

> Archive of the year 2009 <

> Archive of the year 2008 <

> Archive of the year 2007 <

> Archive of the year 2006 <

> Archive of the year 2005 <

> Archive of the year 2004 <

> Archive of the year 2003 <

> Archive of the year 2002 <

> Archive of the year 2001 <

> Archive of the year 2000 <