![]() Mobile device forensics & digital investigationMonthly report nโฐ39 - 2025-05https://pts-project.org/blog/monthly-report-n39-2025-05/Project overviewPiRogue Tool Suite (PTS) provides a platform combining analysis tools, knowledge management, incident response management and artifact management, which allows civil society organizations with limited resources to equip themselves at a low cost. The project consists of an open-source tool suite that provides a comprehensive mobile device forensics and digital investigation platform.
๐ข Announcements
๐ Impacts and resultsWith the release of Colander ๐ Activity reportYou can find more details about the different activities in the project roadmap. ๐ฆ US2 - Better knowledge managementA significant improvement involves refining knowledge organization and representation within Colander. This includes establishing a hierarchical structure for cases, where parent cases inherit from child cases, enhancing the management of extensive investigations. Furthermore, Colander will support the creation of multiple graphs within a single case, allowing for diverse projections of a subset of the case knowledge graph. The inclusion of thumbnails on graph nodes will simplify the investigation by involving pictures. Overview of the different activities
Create a hierarchy of casesThis monthColander now supports the creation of a hierarchy of cases, allowing zero or one ancestor per case. The user interface has been redesigned to highlight the case hierarchy, if any. This feature has been released in Colander
Next monthNothing, as this task is now complete. Create multiple graphsThis monthThis feature has been released in Colander Next monthNothing as this task is now complete Batch import of knowledgeThis monthColander now allows the user to load a CSV file and import each row as an entity. This feature has been released in Colander v1.2.3. Next monthNothing, as this task is now complete. ๐ฆ US3 - InteroperabilityThe project seeks to enhance interoperability by enabling the import and export of knowledge in industry-standard format. This includes batch importing of knowledge, data interchange in MISP format, and the support for user-defined templates to generate custom knowledge feeds. PTS users must have the freedom to move their data and findings from and to other tools such as OpenCTI or MISP. Overview of the different activities
Use HAR to store the decrypted network trafficThis monthThe decryption of the traffic captured during a PiRogue experiment now creates an HAR file containing the decrypted traffic. This HAR can be open directly with Colander. This feature has been released in Colander Next monthNothing as this task is now complete ๐ฆ US5 - Offline artifact analysisTo bolster security measures and guarantee a sufficient level of confidentiality, Colander will allow the offline analysis of artifacts using antivirus software and user-defined Yara rules. In the context of forensic analysis, this is crucial to be able to locally analyze extracted files (without relying on 3rd-party services) to ensure case confidentiality. Overview of the different activities
Offline artifact analysis with Apache TikaThis monthWe have improved the offline analysis of artifacts. Now, Colander automatically analyzes uploaded artifacts with Apache Tika by invoking Mandolin. This analysis supports more than 200 file formats. It extracts text content with OCR when necessary, and extracts file metadata including location information. This feature has been released in Colander Next monthNothing, as this task is now complete. ๐ฆ US100 - DocumentationDocumenting the project is key in its usability. We are continuously documenting the different tools and features we develop and build new learning materials to facilitate skills development. This monthWeโve updated the documentationโs installation steps for PiRogue to reflect recent changes, particularly after resolving the default SSH credentials issue. Next monthWe will continue to improve the project documentation to accurately reflect ongoing changes and updates. ๐ฆ US101 - MaintenanceWe manufacture PiRogues to supply organizations, while taking care of its maintenance. We will include OS upgrades, improvement of the documentation and fixing bugs. Regarding Colander and Threatr, we maintain the public Colander server, upgrade dependencies, improve the documentation and fix bugs. This monthA user preference system has been implemented. This allows the user to pin sub-graphs. Many other minor UI and UX fixes and enhancements have been done, which includes: the addition of visual hints to represent the hierarchy of case, the improvement of the graph editor to fix the difference of rendering between WebKit and Gecko. MVTWe have upgraded MVT, and is now available in version FridaWe initially published the versions If you are experiencing issues with Frida, make sure to downgrade to the version pcapng-utilsWe have released the version MandolinWe have released the version Next monthWe will continue the maintenance of the tools, Debian packages we maintain and Colander ecosystem. ๐ฆ US102 - Community and outreachGiven the success of events, webinars and demos with members of the civil society, NGOs and security researchers, we continue with our outreach plan. We organize trainings and demonstration sessions as well as creating spaces for the community to share feedback and request new features via our mailing list, GitHub issues or Discord server. We analyze one Android app that has received the community’s interest (ex COP28 app) per month. The application to be analyzed is chosen by the community. The analysis report is first privately shared with the community and one month later it is publicly released. We organize monthly calls open to all members of the community to share project updates and get the communityโs feedback. This monthThe analysis report of the Botim v3.38.1 Android application has been published. The PTS community meeting took place on May 30. It was a great opportunity to present the latest release of Colander. The next one will happen online on Jun. 27 at 2pm CET. To expand our reach, we began announcing community meetings on other platforms like IFF Mattermost. Next monthWe will continue with our recurring activities. ๐ฆ US103 - GovernanceThis monthThe recent US aid cuts mean that our primary avenues for support are diminishing rapidly, placing the continued development, maintenance, and user support for PTS in jeopardy. We are working tirelessly behind the scenes, exploring every possible avenue to secure alternative and sustainable funding as quickly as possible. We are actively engaging with potential new partners and grant opportunities. However, the landscape is competitive, and the timeline for securing such support is often lengthy and uncertain. While we are doing our utmost to navigate this period and find new financial backing, the future remains precarious. If PTS is a valuable asset in your work, if it helps you conduct crucial investigations, research, or defend digital rights, we now earnestly ask for your support. We are continuing the implementation of the working plan with The Engine Room. Weโve followed up with potential partners to explore different hosting options for our users. Next monthWe will submit a proposal to the Spyware Accountability Initiative. We will continue with our recurring activities. List of changespiroguetoolsuite.github.io
colander
debian-12
pirogue-admin
deb-frido
pcapng-utils
mandolin-python-client
mandolin |