Plaso 20180127 released

Plaso 20180127 released
The Plaso team is pleased to announce its first 2018 release, Plaso 20180127. A few highlights from this release:
  • We’ve updated the Chrome History SQLite plugin to be more strict about which version of the Chrome history file it’s parsing, and produce fewer spurious error messages.
  • Initial support for parsing System Resource Usage Monitor (SRUM) databases (SRUDB.dat) has been added, based on previous work.
  • There’s a new parser for processing MacOs FSEventsd files, from Leopard to High Sierra, inspired by Nicole Ibrahim’s OSDFCon 2017 presentation.
  • A basic sessionize analysis plugin has been added, which we’ll extend in the future to support functionality like Timesketch’s event similarity scoring. This work was catalysed by work like David Gresty’s (et. al) from DFRWS EU 2016.
  • As indicated previously, the ZIP storage implementation has been removed.


As usual, there’s a bunch of cleanups and bug fixes, the full list of which are available in the release milestone. One minor issue made it in to the release, event counts by parser will be incorrect in this release, and we’ll fix it up for the February version.


Where/how to get Plaso 20180127?


See Plaso's Users' Guide. As usual, builds are available for MacOS, Ubuntu, Fedora Core and Windows.

If you run into problems take a look at the Installation Problems page on the Plaso wiki, to see if other people have seen the issue before. If nothing there helps, ask for help on the discuss mailing list: log2timeline-discuss@googlegroups.com  or open an issue on the tracker.

Comments

Popular posts from this blog

Parsing the $MFT NTFS metadata file

Incident Response in the Cloud

Container Forensics with Docker Explorer