Plaso 20190708 released

Plaso 20190708 released

The Plaso team are delighted to announce a new Plaso release, 20190708. Most of the changes in this release are internal: refactoring, cleaning up and fixing bugs.

One series of user-facing changes is some refactoring of the Windows Registry plugins. The ‘regvalue’ attribute has been removed from these plugins, and these plugins now produce events with different attributes. For now Plaso continues to support ‘regvalue’ in older Plaso storage files, note that some point this support will also be removed.

If you have any automation/templates relying on these values, you may need to update. Don’t hesitate to reach out to make sure we understand your use case(s).

Other new features

As usual, there’s a bunch of cleanups, performance tweaks and bug fixes, the full list of which are available in the release milestone.

Future plans

As part of the Python 2 retirement on January 1, 2020, this is the last release where we’ll provide a Python 2.7 PyInstaller build, these will be Python 3 only from now on. We’ll also no longer provide a 32-bit PyInstaller build for Windows.
We have also removed most of the older PyInstaller builds since we were made aware people were actively using this. We strongly encourage to use the most recent release of Plaso, since data formats and dependencies change, bugs get addressed and new features get added continuously.
In the next release, we’ll also not supply a Python 2.7 release for MacOS. We’ll provide more detail on MacOS installation at the time.

Where/how to get Plaso 20190708?

See Plaso's Users' Guide. As usual, builds are available for Docker, MacOS, Ubuntu, Fedora and Windows.

If you run into problems take a look at the Installation Problems page in the Plaso documentation, to see if other people have seen the issue before. If nothing there helps, ask for help on the discuss mailing list: log2timeline-discuss@googlegroups.com or open an issue on the tracker.

Comments

Popular posts from this blog

Parsing the $MFT NTFS metadata file

Incident Response in the Cloud

Container Forensics with Docker Explorer