Skip to main content
File download is not currently available. Please reach out to sales@tantulabs.com for more information.
Back
File Cataloger Changelog

Changelog

Track the evolution of File Cataloger. See what's new, improved, and fixed in each release.

v3.18.1Latest
June 24, 2026

USB Packet Capture tab in Mobile Forensics, plus fixes for AI not activating after configuration.

  • New

    USB Capture tab (Tab 10) in Mobile Forensics records live USB traffic via ETW (built-in, admin required) and USBPcap (optional driver); both engines run simultaneously and produce a unified event timeline

  • New

    Each captured USB event shows direction, transfer type, endpoint, USBD status, bytes, and hex payload in a colour-coded table

  • Fixed

    Configuring an API key in Settings now immediately activates the AI provider — previously had no effect until the app was restarted or AI Chat was used first

  • Fixed

    AI features in Mobile Forensics, Evidence Tagging, and Folder Narratives now correctly pick up the saved API key at first use without a restart

v3.18.0
June 24, 2026

USB passive descriptor fingerprinting for locked/ADB-dead phones, major AI-Assisted Recovery improvements, and multi-drive database support.

  • New

    USB Fingerprint tab in Mobile Forensics reads descriptor data passively — works on locked phones, ADB-dead devices, and devices in deep sleep without any app on the device

  • New

    Descriptor fields read include manufacturer/product/serial strings, bcdUSB, bus speed, MaxPower declared mA, bmAttributes, and all interface class codes

  • New

    Forensic interpretation shows power-state hint (deep sleep vs active) and interface-mode hint (ADB present, MTP only, etc.) automatically

  • New

    USB fingerprint result is auto-logged to chain of custody and can be exported as JSON

  • New

    Recovery sessions now create a drive-stamped subfolder (e.g. C_Recovery_20260625_001200) so multiple runs are never mixed together

  • New

    Live ETA indicator in the recovery log estimates time remaining from file sizes before recovery starts, then refines from measured speed as files are processed

  • New

    Open Folder button next to the output path creates the folder if needed then opens it in Explorer

  • New

    AI rebuild option attempts to reconstruct Low and Medium chance files that cannot be recovered using structural repair and AI image reconstruction

  • New

    Patch-to-openable option injects minimum valid header/footer bytes (JPEG, PNG, GIF, BMP, MP4, PDF, ZIP, DOCX/XLSX/PPTX, SQLite) so partially rebuilt files can be opened

  • New

    Every AI-rebuilt file is accompanied by a caveat notice clearly stating it is reconstructed and must not be used as evidence

  • Fixed

    Catalogs scanned from multiple drives now correctly track and report availability for each drive independently instead of overwriting the first drive

v3.17.0
June 22, 2026

New Android Diagnostics companion APK for non-rooted devices. The Forensic Acquisition Wizard can sideload it, run collection, and pull the report back to the desktop.

  • New

    Diagnostics companion APK collects system, application, network, and log information without requiring root access

  • New

    Legacy APK variant supports Android 1.5+ for the oldest devices including the HTC Dream / G1

  • New

    Modern APK variant supports Android 5.0+ and is built with Android Studio

  • New

    Forensic Acquisition Wizard includes a Diagnostics APK section with install, run, wait, and pull workflow

  • Security

    Companion APK does not modify system partitions and writes output only to its own external storage folder

v3.16.0
June 21, 2026

New Forensic Acquisition wizard in Mobile Device Forensics pulls protected Android artifacts directly, or boots a recovery image temporarily via fastboot for non-rooted devices.

  • New

    Forensic Acquisition wizard in the Quick ADB Scan tab extracts SMS/MMS, contacts, call logs, browser history, Wi-Fi configs, accounts, packages, logcat, device properties, and /sdcard contents

  • New

    Non-rooted devices can use a user-selected recovery image with fastboot boot, which loads the image into RAM only and does not overwrite the recovery partition

  • Security

    Wizard requires explicit confirmation before rebooting the device and reports pulled, skipped, and errored artifact counts

v3.15.2
June 21, 2026

New Scan now includes a drive selector for mounted drives and physical disks. Mobile Device Forensics tabs are now scrollable so long tabs stay usable.

  • New

    New Scan dialog now includes a Drives source selector alongside folder, SIM card, and chip card options

  • New

    Drive list shows mounted logical drives with labels, filesystem, and size, plus physical disks with model and drive letters

  • Security

    Physical disk selection triggers a forensic raw-drive scan using carving to recover files before cataloging

  • Improved

    Mobile Device Forensics dialog tabs are now wrapped in scroll areas for better usability on smaller screens

v3.15.1
June 21, 2026

Mobile Device Forensics now includes AI analysis buttons and an offline vulnerability scanner that matches device hardware, OS, firmware, and version against a curated CVE knowledgebase.

  • New

    Mobile forensics AI analysis: generate section-specific AI summaries for device info and ADB scan results from within the Mobile Device Forensics dialog

  • New

    Vulnerabilities tab scans the extracted device against an offline knowledgebase of known mobile CVEs and exploits

  • New

    Vulnerability findings are saved to the forensic database, linked to the active case and session for reporting

  • Security

    Offline-only knowledgebase requires no external API calls, supporting air-gapped forensic environments

v3.15.0
June 20, 2026

New Catalog File Info dialog provides a complete overview of the current catalog database, including scan history, drive signatures, and export options. Court-ready forensic reports now include this provenance information automatically.

  • New

    Tools > Database > Catalog File Info: inspect catalog database path, size, modified date, DB schema version, app version, and comprehensive catalog statistics

  • New

    Scan history table with drive model, serial number, filesystem, files scanned, and duration — click any row to view the raw scan settings

  • New

    Export catalog info to JSON, CSV, or plain text for chain-of-custody and evidence documentation

  • New

    Court-ready forensic reports (HTML, Markdown, Plain Text) include a Catalog File Information section documenting the database, DB schema version, app version, and scan provenance

  • Improved

    Drive Overview Duplicates tab now supports column-header sorting with numeric sorting for copies, size, and wasted space

  • New

    Quick Triage Summary macro preset: generates a ranked briefing of suspicious, credential, crypto, and encrypted files with top 5 items per category

  • Improved

    File carving engine now uses page-level SQLite validation (page size + page type checks) to recover exact contiguous fragments of deleted or damaged SQLite databases

  • New

    Electrum wallet artifact extraction: when an Electrum wallet is detected, addresses, transaction IDs, xpub, xprv, derivation path, and encryption status are parsed and reported

  • New

    Cross-browser artifact correlation merges history from multiple browsers into a unified timeline and flags multi-browser activity and private-mode candidates

  • New

    iOS Safari KTX snapshot carving: recover cached webpage screenshots from raw disk images and extract dimensions, format, and snapshot metadata

  • New

    Mobile browser backup extraction locates Chrome, Firefox, Safari, and Chrome-iOS profiles inside extracted ADB and iTunes backups

  • New

    Case workflow checklist with 9-step forensic evidence extraction process (intake, identification, preparation, isolation, processing, verification, documentation, presentation, archival)

  • Improved

    Forensic Case Management dialog now links to the tamper-evident Chain of Custody tracker pre-filtered to the current case

  • Improved

    File carving engine now uses structure-aware parsers for AVI, WAV, and MP3 based on the Yoo et al. (2012) multimedia carving method

  • New

    NTFS/ReFS metadata recovery foundation: read-only MFT validation, forensic audit logging, and ReFS metadata block detection

  • New

    Bitcoin forensics transaction graph builder with JSON, DOT, and CSV export, plus Electrum wallet integration

  • Fixed

    Splash screen loading bar status text is now white and bold for high contrast

  • Fixed

    Mobile Forensics Quick ADB Scan device info panel has increased vertical spacing for easier reading

v3.14.3
June 20, 2026

New Folder & Drive Narrative feature: generate plain-language AI summaries of what any folder or entire drive contains, with a time-based activity arc and security highlights.

  • New

    Drive Narrative (Tools > Drive Narrative, Ctrl+Shift+N): AI-generated prose summary of your entire drive with time-based activity arc

  • New

    Folder Narrative: right-click any file to get an AI summary of that file's folder — file types, date range, suspicious or encrypted content

  • New

    Recursive subtree summarization with configurable depth (default 10 levels) — child summaries roll up into parent folder summaries automatically

  • New

    Export narrative reports as HTML or PDF directly from the dialog

  • New

    AI chat can now summarize folders and drives on request using the new summarize_folder and summarize_drive tools

  • Improved

    Summaries are cached in the database — re-opening an existing narrative costs zero tokens

v3.14.2
June 19, 2026

Direct ADB scanning for old Android devices — no virtual machine required. Connect any Android phone (including 2009–2011 era devices) and instantly scan its file system.

  • New

    Quick ADB Scan tab in Mobile Forensics: scan connected Android devices directly without setting up a forensic VM — works with Android 1.5 and newer

  • New

    Automatic detection of 2009–2011 era Android devices (HTC Dream/G1, myTouch 3G, Motorola Droid, Samsung Galaxy S, LG Optimus, and more)

  • New

    Device info panel shows manufacturer, model, OS version, SDK level, battery, storage, encryption status, and root status for connected Android devices

  • New

    File browser tab lets you list and filter files on the device, then pull individual files directly to your computer

  • Improved

    Old Android devices (pre-4.2) are automatically identified — no RSA authorization prompt is needed for these devices

v3.14.1
June 19, 2026

Significantly improved detection of Bitcoin wallets — especially early-era wallets from 2009–2011 — with new signature patterns and confidence scoring.

  • Improved

    Bitcoin wallet detection now recognizes more record types found in early Bitcoin Core wallets, improving accuracy for pre-2012 wallets

  • New

    Very early unencrypted wallets (pre-v0.4, 2009–2011) are now flagged with a distinct high-risk warning

  • New

    Bootstrap.dat and wallet backup files are now recognized as Bitcoin Core data artifacts

  • New

    Bitcoin Signed Message and P2SH markers added as high-confidence indicators of active Bitcoin key usage

v3.14.0
June 19, 2026

Major update to cryptocurrency scanning — better coverage of pre-2016 wallets and full support for modern Bitcoin features including Lightning Network, Ordinals, PSBT, and Silent Payments.

  • New

    Detects btcrecover password-recovery tool files — high forensic value indicator of wallet recovery attempts

  • New

    Detects bitaddress.org offline paper wallet HTML files — common artifact on old drives

  • New

    PSBT (Partially Signed Bitcoin Transaction) binary detection at file header level

  • New

    Lightning Network invoice detection (BOLT11 mainnet and testnet) and Lightning node file recognition (LND, Core Lightning)

  • New

    Ordinals index database and BRC-20/Runes keyword detection for modern Bitcoin NFT activity

  • New

    Silent Payment address detection (BIP352), extended key detection (xpub/xprv/zpub/zprv), and output descriptor pattern matching

  • Improved

    Taproot bech32m address regex corrected to match the proper charset

v3.13.6
June 19, 2026

Drive remapping — if a previously cataloged drive is connected at a different drive letter, the app automatically detects it and transparently redirects all file access for that session.

  • New

    Automatic drive remap detection: if a cataloged drive is now mounted at a different letter, a one-time prompt lets you redirect all file access for the session

  • Improved

    Status bar shows the active drive translation (e.g. F: → E:) so you always know when a remap is in effect

  • Improved

    All file operations — double-click, Open File Location, right-click open — transparently use the remapped path

v3.13.5
March 10, 2026

Secure Transfer admin enhancements — full transfer detail panel, password changes, expiration extension, access log viewer, and AI-assisted reply drafting for support tickets.

  • New

    Transfer detail panel: view full transfer details including recipient, files, access log, and admin audit trail

  • New

    Admin can change transfer passwords and extend expiration dates, with all actions logged

  • New

    Support ticket system: conversation threads, canned responses, AI grammar and tone review for replies, and customer email notifications on status changes

  • New

    Customer ticket tracking page: customers can view their ticket status and full conversation history in real time

v3.13.4
March 10, 2026

Timeline chart auto-scaling, custom SQL filter persistence fix, and Secure File Transfer multi-file and folder support.

  • New

    Timeline chart automatically picks the best time granularity (hour/day/month/year/decade) based on your data range

  • Fixed

    Custom SQL filters now persist correctly between app restarts — previously saved filters were lost on exit

  • Improved

    Secure Transfer now supports sending multiple files or entire folders in a single transfer

  • New

    Admin can attach a separate help/reference document to a transfer for the recipient to download independently

v3.13.3
February 27, 2026

The AI support chat on the website dashboard is now significantly smarter — it knows about all app features, security practices, pricing, and troubleshooting

  • Improved

    AI support chat now has comprehensive knowledge of all File Cataloger features, security architecture, pricing plans, AI tokens, forensic tools, and troubleshooting steps

  • Improved

    AI chat remembers conversation context — follow-up questions work naturally across multiple messages

  • Improved

    AI chat upgraded to the latest Gemini 2.0 Flash model for faster, more accurate responses

  • Fixed

    Stripe checkout for token purchases now works correctly from the desktop app

v3.13.2
February 26, 2026

AI chat shows animated thinking phrases, timeline drill-down by double-clicking, and automatic AI model validation

  • Improved

    AI chat shows rotating investigative phrases while thinking instead of a static spinner

  • Improved

    Double-click timeline chart points to drill down into finer time granularity

  • Fixed

    Rapid timeline chart clicks no longer freeze the app — filter updates are now debounced

  • Fixed

    Deprecated AI model names are automatically replaced with the best available model on startup

For older releases, please contact support.