Plaso 20171231 released
Plaso 20171231 released
Squeaking out just before the end of the year, the Plaso team is delighted to release Plaso 20171231. This will be the last release for 2017 😉. A few highlights from this release:
- We introduced the SQLite Plaso storage file support a back in Heimdall. In 20171231 it’s now the default, and the older ZIP format is deprecated.
- The biggest changes you’ll notice are that storage files are a bit larger, and extraction speed faster.
- If you need to use the old ZIP storage, run log2timeline.py with the ‘--storage-format=zip’ option.
- We’re planning to remove the ZIP storage completely in the next release in January, which will unblock a few other changes, allowing us to shrink the SQLite storage file size.
- A new SQLite parser plugin to handle Safari’s newer history format thanks to new contributor @chimau.
- Updates to dfvfs to support libstk 4.5.0 and multi-member gzip files, needed for upcoming fsevents support.
- Nicer looking partition and VSS overviews in log2timeline.
As usual, there’s a bunch of cleanups and bug fixes, the full list of which are available in the release milestone.
See Plaso's Users' Guide. As usual, builds are available for MacOS, Ubuntu, Fedora Core and Windows.
f you run into problems take a look at the Installation Problems page on the Plaso wiki, to see if other people have seen the issue before. If nothing there helps, ask for help on the discuss mailing list: log2timeline-discuss@googlegroups.com or open an issue on the tracker.
One other note - Richard Davis from the Youtube channel 13Cubed recorded a short introduction to Plaso. While it was produced with Heimdall in mind, it's still largely applicable to this most recent release. If you're looking for a quickstart guide, it's worth a watch.
Comments
Post a Comment