Trufflepig Logo


  • Is­sues
  • 4
  • Next Re­lease
  • Is­sues
  • 15
  • Within 3 Months
  • Is­sues
  • 9
  • Within 6 Months
  • Is­sues
  • 12
  • On our ToDo List


We are cur­rently work­ing on it

Re­lease date

2021-12-06 - de­layed due to ma­jor re­work and test­ing for new data­base in­te­gra­tion

Ar­ti­factsUs­abil­itySta­bil­ityFile & Op­er­a­tion Sys­tem Sup­port
  • Win­dows Clip­board
    Win­dows clip­board con­tent is ex­tracted and dis­played in the UI
  • Data­base
    Analy­sis ar­ti­facts are stored in the data­base for fil­ter­ing, sort­ing, search­ing and per­sis­tence
    • Win­dows 7 Sup­port
      Mi­nor Win­dows 7 fixes
    • Win­dows 11 Sup­port
      Mi­nor Win­dows 11 fixes


    Within 3 Months
    Ar­ti­factsUs­abil­itySta­bil­ityFile & Op­er­a­tion Sys­tem Sup­port
    • Reg­istry Key Ex­trac­tion
      Re­work of the reg­istry ex­trac­tion - be­cause of the mas­sive amount of data this will be in­te­grated with the data­base re­lease
    • Shim­cache
      Shim­cache is ex­tracted from reg­istry and dis­played in the UI - done but be­cause the mas­sive amount of reg­istry data this will be re­leased once the data­base is in­te­grated
    • Events View
      A new table view for the ex­tracted events (e.g. from shim­cache) is in­te­grated - done but in­te­grated with the new data­base
    • Win­dows Heap Struc­ture In­for­ma­tion
      All al­lo­ca­tion in­for­ma­tion from process heaps is ex­tracted
    • Shell­bag In­for­ma­tion
      Re­cently used/​viewed files and fold­ers are ex­tracted and dis­played
    • Tor IPs API
      Via our API you can find out whether any found IP ad­dress is or was part of the Tor net­work
    • Air­gap Sys­tem Li­cense
      An easy to use sys­tem to move li­censes to an air­gapped sys­tem
    • Knowl­edge­base Ar­ti­cles
      Ar­ti­cles about processes, IoCs, (Win­dows) in­ter­nals etc.
    • Process Mem­ory Ex­port
      The en­tire process mem­ory can be ex­ported as a crash dump
    • Re­port a Bug
      Cre­ate a sim­ple way of re­port­ing a bug from the Nexus UI
    • Dump Process
      Un­map mapped PEs from VAD re­gion to get orig­i­nal PE bi­nary
    • IoC Vis­i­bil­ity
      The found IoCs are shown in the IoC view for all kinds of ar­ti­facts (cur­rently only process-re­lated IoCs are dis­played)
    • Global Views for Process Ar­ti­facts
      Cre­ate global views for process spe­cific ar­ti­facts like VAD re­gions
      • Hi­ber­na­tion File Sup­port
        Hi­ber­na­tion files can be an­a­lyzed
      • Frag­mented Disk Im­ages
        Frag­mented disk im­ages can be added and an­a­lyzed


      Within 6 Months
      Ar­ti­factsUs­abil­itySta­bil­ityFile & Op­er­a­tion Sys­tem Sup­port
      • Virus­To­tal API
      • Win­dows Cre­den­tials Ex­trac­tion
        Ex­ctract­ing pass­words and hashes from lsass.exe
      • User and Ses­sion In­for­ma­tion
        In­for­ma­tion on cur­rently logged in users is ex­tracted
      • Truf­flepig IoC Heuris­tics
        Cus­tom Truf­flepig heuris­tics can be used to find IoCs
      • Fron­tend Im­age Up­load
        For server in­stal­la­tions im­ages can now be up­loaded in the fron­tend
      • Crypto Con­tainer De­cryp­tion
        Crypto con­tain­ers for which the re­spec­tive keys have been found can be de­crypted
      • Process Icon Vis­i­bil­ity
        All sup­ported browsers can dis­play the process icons
      • Mod­u­lar Min­ion
        File parser plu­g­ins can be im­ple­mented
      • Win­dows 8 + 8.1 Sup­port
        Win­dows 8 and 8.1 are fully sup­ported for the ar­ti­facts that are cur­rently dis­played


      Will be added to the time­line
      Ar­ti­factsUs­abil­itySta­bil­ityFile & Op­er­a­tion Sys­tem Sup­port
      • Re­port Gen­er­a­tion
        Re­ports of the find­ings can be gen­er­ated from tem­plates
      • So­cial Me­dia Ar­ti­facts
        Chat his­to­ries/​ses­sion to­kens/​so­cial me­dia/​emails can be ex­tracted
      • Time­line View
        New time­line view to dis­play the or­der of events in­tu­itively
      • Col­lab­o­ra­tive Work
        Users can cre­ate ac­counts and work col­lab­o­ra­tively on cases
      • Nexus SaaS
        Truf­flepig Nexus can be used as SaaS
      • Process Tree Pre­view
        A pre­view of the process tree is shown whithin the process de­tails
      • Mitre Att&ck In­te­gra­tion
        IoCs are dis­played in the Mitre Att&ck ma­trix
      • IoC Ed­i­tor
        Cus­tom rules for IoCs can be cre­ated in an in­tu­itive UI
        • STIX/​TAXI In­te­gra­tion
          STIX IoCs can be im­ported via TAXI
        • Linux Sup­port
          Linux is fully sup­ported for the ar­ti­facts that are cur­rently dis­played
        • OSX Sup­port
          OSX is fully sup­ported for the ar­ti­facts that are cur­rently dis­played
        • FreeBSD Sup­port
          FreeBSD is fully sup­ported for the ar­ti­facts that are cur­rently dis­played