Plaso 20221229 released

Plaso 20221229 released

The Plaso team is delighted to announce a new Plaso release, 20221229. This release has a mixture of new features and under the hood improvements.

Notable changes

  • The sources.conf configuration file has been moved to formatter configuration (#4287).

  • Updated the maximum worker limit to 99 (#4312).

  • Event generation has been split from event data extraction and can be configured using timeliner.yaml.

  • Unified single-line and multi-line text parsers.

  • Changes to the located parser with thanks to @sydp (#4395).

  • Added support for Safari Downloads.plist with thanks to @chb2mn (#4486).

  • Fix for an issue that did not surface before the 20221227 release with thanks to @william-billaud (#4526).

The full list of cleanups, performance tweaks and bug fixes can be found in the release milestone

Upcoming changes in future releases

  • Additional improvements to Windows EventLog resource extraction and message formatting (#4259).

  • Various legacy/backwards compatibility components, like the text prepend option, will be removed (#4255).

Where/how to get Plaso 20221229?

See Plaso's Users' Guide. The development team recommends using Docker to install Plaso without hassle. 

If Docker does not fit your needs there are installation instructions available for MacOS, Ubuntu and Fedora

If you run into problems take a look at the Installation Problems page in the Plaso documentation, to see if other people have seen the issue before. If nothing there helps, ask for help on the Open Source DFIR slack or open an issue on the tracker.


Popular posts from this blog

Parsing the $MFT NTFS metadata file

Incident Response in the Cloud

Container Forensics with Docker Explorer