Plaso 20260119 released

 Plaso 20260119 released

The Plaso team is delighted to announce a new Plaso release, 20260119. This release has a mixture of new features and under the hood improvements.

Notable changes

  • Changes for compatibility with OpenSearch 2.5 and later (#4997) with thanks to @jaegeral

  • Added support for Firefox 118+ download end time (/#5019) and improvement to AppCompatCache parser (#5025) with thanks to @Spferical

  • Changes to use pyproject.toml (#5015)

  • Changes to Windows EventLogs parameter expansion (#5023)


The full list of cleanups, performance tweaks and bug fixes can be found in the release milestone.

Upcoming changes in future releases

  • Extend support for Windows 10 push notification databases (#4458)

  • Continued work on pre-processing and knowledge base (#4543).

  • Move image export to the dfImageTools project (#1).


Where/how to get Plaso 20260119?

See Plaso's Users' Guide. The development team recommends using Docker to install Plaso without hassle. 


If Docker does not fit your needs there are installation instructions available for Mac OS, Ubuntu and Fedora


If you run into problems take a look at the Installation Problems page in the Plaso documentation, to see if other people have seen the issue before. If nothing there helps, ask for help on the Open Source DFIR slack or open an issue on the tracker.

Comments

Popular posts from this blog

Parsing the $MFT NTFS metadata file

Incident Response in the Cloud

Container Forensics with Docker Explorer