Plaso 20180818 released

Plaso 20180818 released

The Plaso team is pleased to announce a new Plaso release, 20180818. We’ve continued our work on migrating Plaso to Python 3, and moving binary parsing to use dtFabric, but we’re aren’t quite ready to fully migrate just yet.

A side effect of the dtFabric migration is that most of the binary-format parsers have been substantially rewritten, and are likely to be more strict parsing file-formats. If you spot any files not being parsed as they were in previous versions, please let us know by opening an issue.

Some of the more noteworthy user-facing features in this release are:



As usual, there’s a bunch of cleanups, performance tweaks and bug fixes, the full list of which are available in the release milestone.

Where/how to get Plaso 20180818?

See Plaso's Users' Guide. As usual, builds are available for Docker, MacOS, Ubuntu, Fedora Core and Windows.

If you run into problems take a look at the Installation Problems page on the Plaso wiki, to see if other people have seen the issue before. If nothing there helps, ask for help on the discuss mailing list: log2timeline-discuss@googlegroups.com or open an issue on the tracker.

Comments

Popular posts from this blog

Parsing the $MFT NTFS metadata file

Incident Response in the Cloud

Container Forensics with Docker Explorer