Plaso 20180930 released
Plaso 20180930 released
The Plaso team is delighted to announce a new Plaso release, 20180930. We have a mix of behind the scenes improvements and user facing features.
Behind the scenes, we’ve updated Plaso to work with Python 3, as well as migrated fully to dtFabric for binary format parsing (and updated our format documentation). As a result of this migration, we’ve bid farewell to construct, which simplifies dependencies a bit.
We’re planning to discontinue Python 2 support in the near future, likely in the first release of 2019. If this if you think the removal of Python 2 support will cause you problems, please reach out to the development team. We aren’t providing Python 3 Plaso binary builds at the moment, but we plan to in the near future.
Some of the more noteworthy user-facing features in this release are:
- New plugins for parsing Tango and Twitter databases on Android
- New parser for the macOS NotificationCenter database by new contributor pstirparo
- New parsers for Apache access logs and Santa
- Improved parsing for the Chrome Cookies database on newer versions of Chrome, thanks to new contributor obsidianforensics
As usual, there’s a bunch of cleanups, performance tweaks and bug fixes, the full list of which are available in the release milestone.
Where/how to get Plaso 20180930?
See Plaso's Users' Guide. As usual, builds are available for Docker, MacOS, Ubuntu, Fedora Core and Windows.
If you run into problems take a look at the Installation Problems page on the Plaso wiki, to see if other people have seen the issue before. If nothing there helps, ask for help on the discuss mailing list: log2timeline-discuss@googlegroups.com or open an issue on the tracker.
If you run into problems take a look at the Installation Problems page on the Plaso wiki, to see if other people have seen the issue before. If nothing there helps, ask for help on the discuss mailing list: log2timeline-discuss@googlegroups.com or open an issue on the tracker.
Comments
Post a Comment