TraceForge

Getting Started

  • Installation & Setup
    • 1. System Requirements
    • 2. One-Liner Quick Install (curl)
    • 3. Global Installation via pip
    • 4. Source Repository Installation
      • Step 1: Clone Repository
      • Step 2: Run the Setup Script
    • 5. Runtime Installation Profiles
    • 6. Native Go Fast-Path Compilation
    • 7. Diagnostics & Environment Repair
    • 8. Platform Specific Details
      • macOS
      • Linux
      • Termux / Android
  • Quick Start
    • Step 1: Check System Health
    • Step 2: Initialize a Case Workspace
    • Step 3: Ingest Evidence
    • Step 4: Run First-Party Analysis Tools
      • 1. Extract and Defang IOCs
      • 2. Dissect Network Traffic
      • 3. Build Asset Relationship Graph
    • Step 5: Export Case Deliverables
  • Using TraceForge
    • 1. Interactive TTY Console
      • Keyboard Shortcuts:
    • 2. Direct CLI Subcommands

Investigation & Tools

  • Command Reference
    • Global Options
    • 1. System & Diagnostics
      • traceforge doctor
      • traceforge termux
    • 2. Configuration & Profiles
      • traceforge profile [name]
      • traceforge config <list|get|set|paths>
    • 3. Case Management
      • traceforge case new <name> [--analyst <name>]
      • traceforge case list
      • traceforge case open <case_id>
      • traceforge case add-evidence <path> [--desc <text>] [--case-id <id>]
    • 4. First-Party Analytical Tools
      • traceforge tools asset-graph [file] [--html <out.html>]
      • traceforge tools diff <file1> <file2> [--domain <name>]
      • traceforge tools ioc-extract [file] [--defang] [--json]
      • traceforge tools evidence-index [dir] [--json]
      • traceforge tools log-triage [file]
      • traceforge tools pcap-summary <file>
      • traceforge tools file-baseline <dir> [--out <out.json>]
      • traceforge tools endpoint-inspect
    • 5. Investigation Modules
      • traceforge module <id> [target] [case_id]
    • 6. Case Export Subsystem
      • traceforge export [case_id] [--redact] [--out <dir>]
    • 7. Tool Catalog
      • traceforge catalog [query]
  • Investigation Modules
    • Overview
    • Module 01: Image & Media Forensics
    • Module 02: Network Recon & PCAP Triage
    • Module 03: Identity & Social Recon
    • Module 04: Email & Breach Intelligence
    • Module 05: Domain & DNS Intelligence
    • Module 06: Document & Metadata Harvesting
    • Module 07: Defensive OPSEC Audit
  • Tool Catalog & First-Party Engine
    • 1. First-Party Analytical Utilities
    • 2. The 152-Tool Catalog
      • Catalog Breakdown by Category
    • 3. Tool Installation Ecosystems
    • 4. Platform-Aware Tool Management & CLI Commands
    • 5. Web Console Platform Lifecycle Explorer
    • 6. Termux & Android Tool Support
  • TraceForge Interactive Web Console
    • 1. Quick Start
    • 2. Desktop-Grade Architecture & Capabilities
      • Navigation Hierarchy:
        • WORKSPACE
        • INVESTIGATION
        • ANALYSIS
        • OUTPUT
        • SYSTEM
    • 3. Security & Safety Standards
  • Configuration & Runtime Profiles
    • 1. Runtime Profiles
    • 2. Managing Profiles
      • View Active Profile
      • Switch Active Profile
    • 3. Feature Fast-Path Overrides
    • 4. Configuration Storage & CLI Settings
    • 5. Environment Variables

Case Management & Reporting

  • Case Management & Evidence Handling
    • 1. Case Lifecycle & Directory Structure
    • 2. Managing Cases via CLI
      • Create a Case
      • List Registered Cases
      • Switch Active Case
    • 3. Evidence Ingestion & Cryptographic Integrity
    • 4. Findings, Indicators & Timeline
    • 5. Case Archiving & Packaging
  • Reporting & Export Subsystem
    • 1. Supported Export Formats
    • 2. Generating Case Exports
    • 3. CSV Formula Injection Defense
    • 4. PII & Threat Indicator Redaction
    • 5. Optional Document Renderers
  • TraceForge — Termux & Android Platform Architecture Guide
    • 1. Overview & Android Execution Model
    • 2. Prerequisites & Quickstart
      • Step 1: Install Termux
      • Step 2: Update Packages & Grant Storage
      • Step 3: Clone & Install TraceForge
    • 3. Storage Architecture & Accessing Files
    • 4. Capability Matrix: Supported vs Root-Required
    • 5. Optional Termux:API Integration
    • 6. Runtime Profiles on Android
    • 7. Troubleshooting & FAQs
      • Q: Why does live packet capture or wireless monitor mode fail?
      • Q: Permission denied when accessing /sdcard?
      • Q: Can TraceForge compile Go helpers on ARM64?

System Architecture

  • System Architecture
    • 1. High-Level Architecture
    • 2. Component Roles
      • 1. Python Application Layer (traceforge/)
      • 2. Go Native Engine (go/ ➔ traceforge-native)
      • 3. Bash Installation & Execution Scripts (lib/, modules/, install_all.sh)
      • 4. Central Tool Catalog (catalog/tools.tsv)
    • 3. Evidence & Data Isolation
  • Troubleshooting & Common Issues
    • 1. Environment & Path Issues
      • Issue: command not found: traceforge
      • Issue: Homebrew commands not found on Apple Silicon macOS
    • 2. Termux / Android Issues
      • Issue: Permission denied when accessing /sdcard or ~/storage
      • Issue: tshark or aircrack-ng live capture fails on Termux
    • 3. Toolchain & Compiler Issues
      • Issue: Go Toolchain: Not available in traceforge doctor
    • 4. Reporting & Rendering Dependencies
      • Issue: [WARN] openpyxl not installed. Skipping XLSX generation.
    • 5. macOS Terminal Permissions (TCC)
      • Issue: Operation not permitted when reading evidence in Downloads or Desktop

Policies & Legal Boundaries

  • Responsible Use & Scope Limitations
    • 1. Authorized Operator Mandate
      • Legitimate Use Cases:
    • 2. Prohibited Activities
    • 3. Statutory Notice
  • Privacy Policy & Local Data Handling
    • 1. Zero Cloud Telemetry
    • 2. Evidence Storage & Redaction
  • Security Policy & Vulnerability Reporting
    • 1. Reporting a Security Vulnerability
      • Preferred Reporting Method
      • What to Include in Your Report
    • 2. Defensive Security Architecture
      • Zero Command Injection
      • Zero Secret Exposure
      • CSV Formula Injection Mitigation
      • Path Traversal Defense
  • Third-Party Tools & Licensing
    • 1. Third-Party Licenses

Development & Community

  • Contributing to TraceForge
    • 1. Two-Branch Contribution Workflow
    • 2. Contribution Standards
  • Development & Building
    • 1. Setting Up Development Environment
    • 2. Building the Go Native Fast-Path Helpers
    • 3. Running Diagnostics & Validation
    • 4. Building Read the Docs Documentation Locally
  • Branching Model & Release Lifecycle
    • 1. Branch Roles & Rules
      • master (Stable)
      • beta (Development & Integration)
    • 2. Working Branches (Short-Lived)
    • 3. Pull Request (PR) Workflow
      • Pull Request Rules:
    • 4. Release Promotion: beta ➔ master
    • 5. Hotfix & Security Emergency Protocol
  • Bug Reporting & Issue Guidelines
    • 1. Where to Report Issues
    • 2. Bug Target Branch Policy
    • 3. Bug Report Requirements
    • 4. Zero Sensitive Data Policy
    • 5. Bug-Fix Lifecycle
  • PyPI Publishing & Trusted Publishing Guide
    • 1. Distribution & Package Overview
    • 2. Local Package Build & Validation
    • 3. GitHub Actions Trusted Publishing Setup (OIDC)
      • One-Time PyPI Configuration (Maintainer Checklist):
    • 4. Releasing to PyPI
    • 5. Testing on TestPyPI
  • Changelog & Releases
    • Release History Overview
TraceForge
  • Search


© Copyright 2026, Aman Kumar Pandey.

Built with Sphinx using a theme provided by Read the Docs.