Plaso 20240826 released
Plaso 20240826 released
The Plaso team is delighted to announce a new Plaso release, 20240826. This release has a mixture of new features and under the hood improvements.
Notable changes
Migrated Docker image to Ubuntu 24.04 with Python 3.12. If you are using Timesketch or Turbinia, work is in progress to migrate to Ubuntu 24.04 and this version of Plaso.
Changed year-less log helper into date-less log helper to support date-less log formats (#4697), added a SQLite parser plugin for Android's app_usage database (#4881) and Android turbo.db SQLite parser plugin (#4880) with thanks to @rick-slin
Added basic support for Windows 10 push notification SQLite databases (#4458) and Container Runtime Interface log parser (#4742) with thanks to @sydp
Read support for SQLite-based storage format 20221023 was removed (#4849).
The full list of cleanups, performance tweaks and bug fixes can be found in the release milestone.
Upcoming changes in future releases
Extend support for Windows 10 push notification databases (#4458)
Continued work on pre-processing and knowledge base (#4543).
Move image export to the dfImageTools project (#1).
Where/how to get Plaso 20240826?
See Plaso's Users' Guide. The development team recommends using Docker to install Plaso without hassle.
If Docker does not fit your needs there are installation instructions available for Mac OS, Ubuntu and Fedora.
If you run into problems take a look at the Installation Problems page in the Plaso documentation, to see if other people have seen the issue before. If nothing there helps, ask for help on the Open Source DFIR slack or open an issue on the tracker.
Comments
Post a Comment