Plaso 20230717 released

 Plaso 20230717 released

The Plaso team is delighted to announce a new Plaso release, 20230717. This release has a mixture of new features and under the hood improvements.

Notable changes

  • Support for Windows AppCompat PCA (Program Compatibility Assistant) log (#4560) and Apple Unified Logging (#4557) files with thanks to @Fryyyyy

  • Support for Microsoft OneDrive log (#4148) files with thanks to @sydp

  • Support for PowerShell transcript log (#4168) files with thanks to @FabFaeb

  • Support for Siemens WinCC log (#4585) files with with thanks to @rgayon

  • Support for Firefox Cookie SQLite schema version 10 (#4665), MSIE webcache cookies (#4682), Chrome cache version 3 (#4694) and changes to Chrome history parser to extract visit count (#4644) with thanks to @chb2mn

  • Changes to CUPS IPP parser to support no-value type (#4671)

  • Support for iOS data usage SQLite parser plugin (#4672) and plist plugin parser for com.apple.identityservices.idstatuscache.plist (#4673) with thanks to @rick-slin

  • Changes to the Spotlight store.db parser to support dbStr map files (#4698)

  • Changes in JSON output for Windows Registry values (#4581)

  • Python 3.11 deprecated support for building MSI. l2tbinaries now provides wheels instead.


The full list of cleanups, performance tweaks and bug fixes can be found in the release milestone.

Upcoming changes in future releases

  • Removal of various legacy/backwards compatibility components (#4543).

  • Continued work on pre-processing and knowledge base (#4543).

  • Move image export to the dfImageTools project (#1).

  • Additional improvements to Windows EventLog resource extraction and message formatting (#4259).


Where/how to get Plaso 20230717?

See Plaso's Users' Guide. The development team recommends using Docker to install Plaso without hassle. 


If Docker does not fit your needs there are installation instructions available for MacOS, Ubuntu and Fedora


If you run into problems take a look at the Installation Problems page in the Plaso documentation, to see if other people have seen the issue before. If nothing there helps, ask for help on the Open Source DFIR slack or open an issue on the tracker.


Comments

Popular posts from this blog

Parsing the $MFT NTFS metadata file

Incident Response in the Cloud

Container Forensics with Docker Explorer