Plaso 20250918 released
Plaso 20250918 released
This post has been pending for a while, but the Plaso team is delighted to announce a new Plaso release, 20250918. This release has a mixture of new features and under the hood improvements.
Notable changes
Added motherboard information Windows Registry plugin (#4953) with thanks to @elad-levi-cyberark
Changes to image export to map extracted files to artifact definitions (#4949) with thanks to @sa3eed3ed
Changes to Google Cloud audit logs parser (#4923) with thanks to @roshanmaskey
Changed amcache.hve parser to extract file identifier and application key modification time (#4942) with thanks to @coperni
Changes to IIS parser (#4904, #4910, #4911) with thanks to @pyllyukko
Changes to run plaso as user in Docker (#4975)
The full list of cleanups, performance tweaks and bug fixes can be found in the release milestone.
Upcoming changes in future releases
Extend support for Windows 10 push notification databases (#4458)
Continued work on pre-processing and knowledge base (#4543).
Move image export to the dfImageTools project (#1).
Where/how to get Plaso 20250918?
See Plaso's Users' Guide. The development team recommends using Docker to install Plaso without hassle.
If Docker does not fit your needs there are installation instructions available for Mac OS, Ubuntu and Fedora.
If you run into problems take a look at the Installation Problems page in the Plaso documentation, to see if other people have seen the issue before. If nothing there helps, ask for help on the Open Source DFIR slack or open an issue on the tracker.
Comments
Post a Comment