| #182: X-Ways Forensics,
X-Ways Investigator, WinHex 21.9 released
Sep 16, 2026 |
This mailing is to announce the
availability of version 21.9, with official release date Sep 14,
2026. Plus, there are a lot of other news
below.
License owners please go to
https://www.x-ways.net/winhex/license.html
as always for the latest download instructions including the latest log-in
credentials (!), details about their licenses, and upgrade or renewal
offers. Please do not ask us for the download password. Your organization
has access to it already if eligible, as described.
Service releases are announced in the
Announcement section of the
forum,
and you can subscribe to instant e-mail notifications of postings in that
section if you have a forum profile. You can create such a profile
here
(if you have our log-in credentials). If you wish or need to stick with an
older version for a while, please switch to the latest service release of
that version to benefit from bug fixes. Many users seem to stick with
outdated releases of old versions or the current version unnecessarily. As a
special service to users of older versions of X-Ways Forensics and X-Ways
Investigator whose access to updates has ended, v21.5 SR-14, v21.6 SR-9,
v21.7 SR-7, v21.8 SR-6 are usually available on request at the moment, as
announced, depending on which versions were covered by their licenses. We do
not promise availability of downloads to such users for an indefinite time.
Upcoming Training Events
| Dates |
Location |
Target Region |
Course |
Delivered by |
Sep 21-25 |
Online |
Europe, Asia |
X-Ways Forensics 2 |
X-Ways |
Oct 5-8 |
London, UK |
UK (LE only!) |
X-Ways Forensics 1 |
X-Ways |
Oct 19-23 |
Online |
America, Europe |
X-Ways Forensics 1 |
X-Ways |
Oct 26-30 |
Online |
America, Europe |
X-Ways Forensics 2 |
X-Ways |
Oct 26-30 |
Burlington, ON |
Canada |
X-Ways Forensics 1 |
F111th |
Nov 2-6 |
Online |
Europe, Asia |
X-Ways Forensics 1 |
X-Ways |
Nov 2-5 |
Calgary, AB |
Canada |
X-Ways Forensics 1 |
F111th |
Nov 30-Dec 4 |
Online |
Europe, Asia |
X-Ways Forensics 2 |
X-Ways |
Dec 7-10 |
London, UK |
UK (LE only!) |
X-Ways Forensics 1 |
X-Ways |
Dec 8-11 |
Salt Lake City, UT |
USA |
X-Ways Forensics 1 |
H-11 |
Please sign up for our training notifications
here
if you would like to be kept posted on future training dates.
X-Tension Developer Training Course
Aspiring developers of
X-Tensions for X-Ways Forensics may want to consider a proper and
thorough training course, delivered online on demand, with individual
support, by
API
Forensics Inc. in Canada, resold by X-Ways
here.
Some programming background is required. Our
X-Tension Repository (the latest additions to which are also
listed below in this newsletter!) can give you ideas on what can be achieved
if you create X-Tensions for internal use in your organization (e.g. for
automation, data exchange/export/import/conversion, ...) or for public
release. You can also check out API Forensics Inc.'s
own
commercial X-Tensions. All details about this very unique and
highly specialized developer training can be found
here.
What's new in X‑Ways Forensics 21.9?
(where applicable, changes
also affect X‑Ways Investigator, WinHex, and X‑Ways Imager)
User Interface
-
When saving directory browser settings to a .settings
file, you now have more control over what is actually remembered and
what will be restored when loading that file. For example, you may prefer
to have .settings files with just your preferred column order and widths
that do not activate or deactivate any column-based filters and do not
make you lose your current filter settings. Or .settings files with just
your favorite conditional cell coloring that do not override column
widths. Or all settings except conditional cell coloring etc. To create
.settings files that are compatible with previous versions, you can
simply choose to store ALL settings in them.
-
Your favorite .settings files can now be loaded with
a single mouse click. That is possible if you name them with a
single-digit number or letter or any exotic single Unicode symbol,
followed optionally by a space and more descriptive text, e.g.
"1.settings" or "E Most essential columns only.settings" or "Ⓟ Default
filters for pictures.settings" etc. That first character will be
displayed in the caption line of the directory browser and will be
clickable. If multiple .settings files exist whose naming matches the
requirements, their respective first characters will be listed in
ascending order of Unicode values.
-
When applying the same comment text to multiple
selected files, you now have a choice and can either replace the
existing comments or append to them or prepend text, delimited by a
space, one line break or two line breaks.
-
A fainter color for icons of previously existing
files in dark mode now means darker icons instead of lighter.
-
Some more icons in the graphical user interface.
-
Some automatic case adjustments of text in the user
interface are now also applied in the languages Ukrainian and Russian.
Event List
-
Ability to extract the following when UFDR report
archives are added to a case: WhatsApp message, Facebook Messenger
messages, TikTok chat messages, Skype messages, Instagram chat and
Telegram messages. All such messages are shown in the event list.
-
The event type filter dialog now only lists event
types that actually occur in the event list.
-
The event type filter dialog now lists event types
other than the internally defined ones if such events were added by an
X-Tension.
-
Fixed an error in .evtx event log processing and
output.
Filters
-
The Label filter is now more sophisticated and allows
to exclude specific labels on top of the previously known AND and OR
combinations of target labels. That means you can focus on files that
have (label A AND label B), but not label C. Or on files that have
(label A OR label B), but not label C. What's more, multiple targeted
excluded labels can also be ANDed or ORed: NOT (label C or label D) as
well as NOT (label C AND label D). The positive condition and the
negative condition are always ANDed with one another.
-
Whether labels are actually visible in the Label
column or deliberated hidden (for example when sharing the screen with a
3rd person) has no effect on the filter.
-
Optionally associate labels with light bulbs in four
different colors. Those light bulbs appear in the Name cell of labeled
files. Whether the icons are large or small depends on the height in
pixels of the rows in the directory browser, which in turn depends on
the DPI scaling in your Windows system (175% or more recommended for
high-resolution screens) and on your chosen font size adjustment in the
general options. The light bulbs can also simply help you locate certain
labels in long lists of label names, e.g. in the label filter dialog
window.
-
Option to apply the Metadata column's filter to the
more extensive metadata that are presented in Details mode, not the
subset stored in the Metadata column. This is slower because the
extensive metadata are not kept in the volume snapshot, but extracted
from each file each time on demand (when needed). Thus the
recommendation is to use this new filter setting only in conjunction
with other filters, e.g. the Type filter, if applied to very long file
listings. Anyway if such an operation takes too long, you can abort it
in the usual way.
Disk/Image/File System Support
-
Support for more compression variants in APFS.
Reading compressed files in APFS now requires a fresh volume snapshot
taken by v21.9 or later.
-
NTFS: Processing of large volume shadow copies slightly
accelerated.
-
Gives the user an extra hint if file system areas
were not included in a skeleton image, before closing that image, and
makes a note of the inclusion in the image log.
-
More visibility of volume labels from multiple file
system types: Previously only shown in the Technical Details Report and
in the Info Pane, they are now included in evidence object
titles/numbers when partitions are added to a case. That also means that
they can become part of the path of files in evidence file containers.
-
Support for some more VDI image variants.
-
Special blue disk icon for MD-RAID container
partitions (i.e. partitions that serve a similar function as a physical
disk) and for images of physical partitioned disks that have been
misinterpreted as images of a volume, to indicate that something is out
of the ordinary.
Picture Support
-
Accelerated loading of high-resolution pictures in
Preview mode with the internal graphics display library.
-
A new OCR option requires text or paper texture as a
result from the picture content detection in addition to the
device type requirement, i.e. combines these two conditions with a
logical AND instead of the previously used OR.
-
Updated detection of AI-generated pictures.
-
Improved front camera photo detection with a very low
false positive rate.
-
More reliable generating device detection.
-
Device definitions for smartphones were updated. As a
consequence, device class detection and processing state detection of
pictures were improved.
-
A new value for "Media design" can now occur: Swipe.
Swipe indicates that a picture was resized to match the screen width and
enable vertical swiping on the screen.
-
Updated recognition of aspect ratios of pictures.
-
An extraction of embedded pictures from MSPaint
canvas files is now predefined in new installations.
-
Annotation numbers in the Summary table of pictures
in Details mode are now prepended with a hash sign (#) so that you can
more reliably scan for files with specific annotation numbers as
described above for the new mode of operation of the Metadata filter.
Binary Data Interpretation/Presentation
-
Ability to toggle between the usual high-low nibble
order within one byte in the hex display and the low-high order, by
clicking a new cell in the status bar, which shows either "BEN" for
big-endian nibbles or "LEN" for little-endian nibbles. Alternatively you
can make use of a new checkbox in the top right corner of the general
options. Though uncommon and awkward for human reading habits, showing
the lower nibble first and the higher nibble second is a logical choice
where multiple bytes belong to an integer value stored in little-endian
byte order because that way all hex digits are arranged in ascending
order of power. The difference that this setting makes is apparent in
particular when looking at the 12-bit entries in a FAT12 file allocation
table, whose nibbles usually appear intertwined, but in low-high order
are straight-forward and consecutive.
-
The data interpretation in the status bar now has its
own big endian switch and does not use the big endian setting of the
Data Interpreter. It shows "BE" if big endian interpretation is active.
Other settings are still inherited from the Data Interpreter.
-
The bits in binary representation in the Data
Interpreter, in templates as well as in the status bar can now
optionally be shown in ascending order, i.e. from the lowest-valued /
least significant bit (LSB) to the highest-valued / most significant bit
(MSB). This is not to be confused with and works in addition to the byte
order, which defines which of multiple bytes is the highest valued one
(depends on the Big Endian switch). If the LSB-to-MSB order is active, a
triangle with its smaller end of the left and its bigger end on the
right is displayed before the word "Binary:" to remind you.
-
Checksums are by convention usually displayed in
big-endian byte order. That means for example that a 2-byte file with
the byte values 0x33 0x00 has a 16-bit checksum that is shown as 0033.
That is understandable because checksums are true integer numbers with a
meaning (the result of an addition of assumed integer numbers), and
numbers are read and written by humans with the most significant digit
first from left to right (even in Arabic and Hebrew). CRCs like CRC16,
CRC32 and Adler32 are also often (but not always) byte-wise reversed for
display purposes. However, this is already harder to justify because
those hash values are more random in nature and do not have an actual
meaning as numbers. Longer hashes are never byte-reversed. A new
notation setting allows you to see checksums and CRCs in litte endian /
original byte order, for compatibility with specific other tools if
necessary or when comparing checksums and CRCs to how they are actually
stored on disk / in files, e.g. in zip archives.
-
Challenging the brain supposedly
boosts neuroplasticity and maintains cognitive fitness during aging.
Therefore, if you occasionally switch up the endianness settings in
X-Ways Forensics installations of your colleagues when they are not
looking, they will likely thank you later.
-
The binary representation in the Data Interpreter as
well as in the status bar can now show 24 bits. For better readability,
a space is now inserted after every 8 bits for 16-, 24- and 32-bit
representations.
-
The Data Interpreter settings can now be saved to and
loaded from .dlg files completely.
Case Management
-
New time zone definitions for British Columbia and
Alberta (not in strictly ascending order in the list). Previous users of
the Saskatchewan time zone need to change to the combined Central
America, Saskatchewan time zone, please. Daylight saving time can now be
defined in the GUI for an entire year safely (without potentially
missing a few days in early January or late December) by entering 0 as
the start month and 13 as the end of month. Up to 100 different time
zone variants can now theoretically be defined (previously 76).
-
More graceful dealing with incomplete cases, where
you only have the .xfc file and no corresponding subdirectories.
-
Choose from four different light bulb colors to mark
evidence objects as notable. The light bulbs can also simply help you
find certain evidence objects in long lists of evidence objects, e.g.
when exploring recursively from the case root or when importing relevant
evidence objects from another case. And you can click a new button to
quickly select all the evidence objects that have a light bulb (of any
color).
Miscellaneous
-
Ability to compare directory listings, i.e. find out
which files or subdirectories are present in the current listing in the
active data window that are missing in another. Right-click anywhere in
the directory browser and invoke Select | Items missing elsewhere. This
will match by name and optionally also require identical sizes,
identical modification timestamps, and/or the same general existence
status (existing vs. previously existing [of any kind]). Once the
non-matching / additional items are selected, you can easily copy a list
of them (Ctrl+C), export a list of them, copy them, hash them etc. This
works with non-recursive and recursive listings alike.
-
Ability to change the selection in the directory
browser during an ongoing Export List operation without affecting that
operation's scope.
-
X-Tension
API: The functions XWF_AddComment() and XWF_AddExtractedMetadata()
now support additional flags to append or prepend more text to existing
comments/metadata.
-
The chapter in the documentation about command line
parameters now has information about exit codes. In particular if you
run X-Ways Forensics in an automated, unmonitored way and check the exit
code, this can give you an idea whether the execution was generally
successful (0 or 710) or failed for some reason that you need to look
into. Various failure indicating exit codes are possible, and they can
be interpreted roughly in accordance with the error codes that Microsoft
defines on the page
https://learn.microsoft.com/en-us/windows/win32/debug/system-error-codes--0-499-
and the following pages. In particular you could prepare for the
following exit codes:
0 = normal program termination, no special exit code was set
353 = maximum simultaneous user count exceeded according to network
dongle
710 = normal unlocked execution was possible
1067 = execution was aborted in an unexpected manner
10003 = dongle not found
11111 = server with network dongle not found.
-
The NSRL RDS hash sets have been updated to release
2026.09.1. They are available in a format for import into XWF in both
MD5 and SHA-1 versions. Licensed users with access to updates can
download the files from the link available by querying your licence
status..
-
The program help and the user manual were updated.
-
Many minor improvements.
Changes of Service Releases of 21.8
-
SR-1: Fixed description of events generated by the
revised .evtx processing.
-
SR-1: Fixed a file clean-up error in v21.8 that
occurred when closing not case-associated volumes/disks.
-
SR-2: Fixed omission of volume snapshot data when
importing evidence objects from other cases in v21.8.
-
SR-2: Fixed proposed .css filename for case report
generation in fresh installations.
-
SR-2: Fixed encoding of a few words in non-Western-European languages in the Metadata column.
-
SR-2: Avoided a potential exception error that could
occur during picture content analysis.
-
SR-2: When creating a skeleton image, confirms if the
entire file system data as parsed by X-Ways Forensics were included in
the image.
-
SR-3: Fixed an exception error that could occur when
computing ed2k hash values in certain constellations.
-
SR-3: Fixed inability of v21.6 and later to carve
HEIC files with the ~27 algorithm as defined in the File Type Signatures
Search.txt file.
-
SR-3: Fixed inability of v21.5 and later to explore
certain corrupt/incomplete zip archives.
-
SR-4: Fixed an exception error that could occur when
processing corrupt .evtx files.
-
SR-4: Fixed inability to carve certain video files at
the correct size since v21.6.
-
SR-4: Fixed an exception error that occurred when
creating bookmarks from within the recursively explored Case Root
window.
-
SR-4: X-Tension API: Fixed failure of XWF_OpenItem()
when called from XT_ProcessItem() for files in nested archives using
multiple threads.
-
SR-5: A special comment tooltip and message is output
for images of physical, partitioned disks that have been misinterpreted
as images of a volume. This text now reminds users that they should get
such images properly interpreted, if necessary by holding the Shift key
when adding the image to the case to get that option.
-
SR-5: Ability to open external 0x90 attributes in
NTFS as directory data.
-
SR-5: X-Tension API: Exceptions that occur when
processing calls of the XWF_GetCellText function are now caught by that
function itself and should not impact the X-Tension in a potentially
uncontrolled manner any more. Important notes about the XWF_GetCellText
function have been added to the documentation.
-
SR-5: Fixed an exception error that could occur when
running the picture content analysis.
-
SR-5: Prevented the unintended insertion of UTF-8
byte order marks and line breaks in non-textual surrogate patterns for
unreadable sectors by v21.7 and later.
-
SR-5: The +9 investigator.ini setting now has an
effect in v21.8. Also, it is no longer possible to reach the security
options dialog when trying to turn off the strict drive letter
protection.
-
SR-6: At the moment when directories are added to the
directory tree of an evidence object (only once while a case is loaded),
now the status of the description filter decides whether excluded
directories are added to the tree or not. Previously, excluded
directories were never added to the tree when that tree was initially
constructed. If added/visible, excluded directories are presented with a
gray directory icon instead of the usual yellow one.
-
SR-6: The scope of an ongoing Export List operation
is no longer affected by selection changes with the left mouse button.
-
SR-6: The various double-click Explore vs. View
options did not work in v21.8. That was fixed.
-
SR-6: Fixed missing last box in the status bar under
certain screen conditions.
-
SR-6: User settings for notable picture content
categorizations previously were not retained if no AND combination was
used at all. That was fixed.
-
SR-6: Updated to the latest release of SQLite.
-
SR-6: Fixed assessment of Picture size+ in Details
mode for videos.
Notable 3rd-party additions in the general resource download directory
|
ImageIO DMG
by Kevin Stokes
Source code |
Support for Apple DMG (UDIF) disk images. Interprets such containers as flat
sector arrays. Supports all six UDIF chunk types (raw, zero-fill, ADC, zlib,
bzip2, LZFSE, LZMA), XML-plist and resource-fork block maps, encrypted
images (encrcdsa v2, AES-128/256) with a password prompt, segmented images,
.sparseimage and .sparsebundle containers.
Brief instructions: Place the DLL in the \x64 subdirectory of your
installation before you start the application and add .dmg images to a case
as you would add raw images.Requires X-Ways Forensics, X-Ways
Investigator or WinHex Lab Edition 19.5 or later x64. Tested with X-Ways
Forensics 21.x on Windows 11. |
Clees4All (C4All)
by Chris Lees
User guide
Source code |
Exports picture and video evidence from an
X-Ways Forensics case into formats suitable for import into third-party
review tools, most notably Griffeye Analyze. It runs as part of the Refine
Volume Snapshot (RVS) process and, for every picture/video item it finds,
can write:
-
a Project VICS JSON export
(VICS_Pictures_Results.json / VICS_Movies_Results.json), optionally
packaged as a compressed zip archive alongside the source files, and/or
-
a C4All XML export (... C4P Index.xml
/ ... C4M Index.xml), the project's own legacy format.
It can also drive Griffeye Analyze's
command-line case creation so a fully populated case is waiting once export
finishes.
-
Exports pictures and/or videos
independently, with per-type min/max file size filters
-
Filters by X-Ways type status
(confirmed, mismatch detected, etc.) and file format consistency
-
Excludes embedded Thumbnail.jpg files,
with an option to still include ones flagged as a thumbnail mismatch
-
Excludes media carved from within
already-exported live video files, avoiding duplicate export
-
Deduplicates files by MD5 + physical
offset, preferring live over deleted over carved copies
-
Optional VICS JSON output, C4All XML
output, or both, with VICS output optionally written straight into a zip
archive
-
Optional automatic Griffeye Analyze
case creation, including a named Griffeye import-settings profile
-
Remembers your last-used settings
between runs (stored in a local SQLite database)
-
Scriptable via X-Ways XTParam:
command-line arguments for unattended/batch processing
-
Multi-threaded; tested with RVS
running up to 8 threads
Requires X-Ways Forensics 19.2 or later (newer versions
for some features), Windows 7 or later, 64-bit. |
Recent additions to the
X-Tension Repository
|
Bulk Extractor
by Kevin Stokes |
Runs Simson Garfinkel's bulk_extractor
against evidence from within X-Ways Forensics and feeds the results back
into the case. Three input modes — the active evidence object's source
image, an external file/folder, or the items selected in the directory
browser — with a settings dialog for the scanner list, thread count,
recursion depth and free-form bulk_extractor arguments. Output can be added
to the case as a directory evidence object, and in selected-items mode
source files are labelled per scanner that hit them (BE: email, BE: exif,
…), giving an audit trail of what was scanned and where the hits came from.
Requires a bulk_extractor binary, which is not bundled —
bulk_extractor64.exe v2.2.0 or later, placed next to the DLL or pointed at
from the dialog. Optionally, runs a Linux bulk_extractor through WSL
instead. No other dependencies. |
XML Viewer
by Kevin Stokes |
Viewer X-Tension to see and search XML
files with a live XPath 1.0 query box and a collapsible tree in the Preview
pane, plus a colour-coded source view. A built-in value interpreter decodes
selected timestamps (Unix, FILETIME, WebKit, HFS+, Cocoa, OLE, DOS), Base64,
and hex. Handles UTF-8/UTF-16 and declared code pages, namespaces,
scheduled-task XML, EVTX exports, Office parts, plists, and manifests.
Requires the separate viewer component to be active and the Microsoft Edge
WebView2 Runtime (preinstalled on Windows 11 / Windows 10 with Edge). Loaded
via Options → File Viewing → "Load viewer X-Tensions". |
JSON Viewer
by Kevin Stokes |
Viewer X-Tension for JSON and JSONL files:
renders the file in the Preview pane with a live JMESPath (jmespath.org)
query box — filter/reshape as you type, with a collapsible tree view, a
pretty-printed text view, line-delimited JSON (JSONL) support, and per-file
query history.
Requires the separate viewer component to be active and the Microsoft Edge
WebView2 Runtime (preinstalled on Windows 11 / Windows 10 with Edge). Loaded
via Options → File Viewing → "Load viewer X-Tensions". |
TruffleHog
by Kevin Stokes |
Wraps TruffleHog to scan items in a volume
snapshot (or a right-click selection) for secrets and credentials. Runs
TruffleHog’s built-in detectors plus optional custom YAML patterns, deduplicates
by stored hash so identical copies across profiles/VSCs/restore points scan
once, and assigns results to per-detector labels plus a consolidated XLSX
per evidence object. Verification is off by default (no outbound network
calls); read-only against evidence via XWF_Read.
Requires Windows 10/11/Server 2016+, trufflehog.exe v3.x+ for Windows (from
TruffleHog’s GitHub releases) — not bundled; placed in a tools\trufflehog\
subfolder or pointed to via the dialog. |
Snappy
Fox
by Anna Kirpichnikova |
Automatically detects and decompresses
Mozilla Firefox disk cache (morgue) files within a case. During volume
snapshot refinement it identifies Firefox cache entries by their path
(*morgue*final); from the directory browser context menu it processes the
items selected by the examiner. Each cache entry is decompressed using the
open-source snappy-fox core and the resulting plaintext is added back into
the volume snapshot as a child item (_decompressed), preserving the original
hierarchy. Items get the "Snappy decompressed" label assigned. Output is CRC-verified
by default; reconstruction of damaged or corrupted streams is offered as an
opt-in prompt at startup, and any reconstructed output is flagged with a
comment indicating that it is not CRC-verified and may be incomplete.
No external dependencies. After the
X-Tension creates the child items, the examiner should run X-Ways' file type
verification on them so the decompressed content is recognized by signature
(e.g. as a PNG or JPEG image) and rendered in the Viewer and gallery. |
AI Assistance for Building X-Tensions
The
X-Tension Builder Skill by Kevin Stokes is a Claude Code skill plus a
curated knowledge base and starter templates for authoring X-Ways Forensics
X-Tensions (C++ and Python). It helps developers scaffold new X-Tensions,
wrap external CLI tools, and follow consistent conventions, with API notes
that route every call back to publicly available documentation. Developers
can install it with: `claude plugin marketplace add
kev365/xways-xtension-builder-skill`. Building the C++ templates needs
Visual Studio 2019/2022 (x64); the Python template needs X-Ways'
XT_Python.dll (Python 3.10/3.12). The X-Ways SDK is acquired separately (not
redistributed). No other dependencies.
Become a certified user of X‑Ways Forensics
Become an
X-PERT (X‑Ways Professional in Evidence Recovery Techniques)
Prove your proficiency
in computer forensics in general and X‑Ways Forensics in particular with our
certification program. After passing the challenging exam, you will be part
of an exclusive circle and enjoy various benefits such as special
recognition, training discounts, updated training material. For further
details, please check
here.
Thank you for your attention! We hope to see you soon
somewhere at https://www.x-ways.net or
on our
Facebook page. You may also follow us on
Twitter/X. Please forward this newsletter to anyone who you think
will be interested. If you wish to subscribe with another e-mail address,
please do so
here.
Kind regards
Stefan Fleischmann
X‑Ways Software Technology AG
Carl-Diem-Str. 32 32257 Bünde Germany |