Plaso 20180818 released
Plaso 20180818 released
The Plaso team is pleased to announce a new Plaso release, 20180818. We’ve continued our work on migrating Plaso to Python 3, and moving binary parsing to use dtFabric, but we’re aren’t quite ready to fully migrate just yet.A side effect of the dtFabric migration is that most of the binary-format parsers have been substantially rewritten, and are likely to be more strict parsing file-formats. If you spot any files not being parsed as they were in previous versions, please let us know by opening an issue.
Some of the more noteworthy user-facing features in this release are:
- A parser for the Windows 10 User Timeline database by new contributor everestmz
- Changes to the Chrome history parser to hopefully handle new versions of Chrome more effectively
- Plugins for Google Hangouts and Kodi from new contributor infosecjosh. These plugins were part of the winning solution to the DFRWS 2017 forensic challenge.
- Support for lz4 compressed systemd journal events.
As usual, there’s a bunch of cleanups, performance tweaks and bug fixes, the full list of which are available in the release milestone.
Where/how to get Plaso 20180818?
See Plaso's Users' Guide. As usual, builds are available for Docker, MacOS, Ubuntu, Fedora Core and Windows.If you run into problems take a look at the Installation Problems page on the Plaso wiki, to see if other people have seen the issue before. If nothing there helps, ask for help on the discuss mailing list: log2timeline-discuss@googlegroups.com or open an issue on the tracker.
Comments
Post a Comment