Skip to content

Releases: abrignoni/DLEAPP

DLEAPP v2026.4.3

Choose a tag to compare

@github-actions github-actions released this 02 Oct 00:35
50e4794

DLEAPP v2026.4.3

  • Windows registry: Amcache Applications, Amcache Shortcuts, Amcache Drivers and Amcache Devices join Amcache Application Files, and all five report the values a Windows 11 build 26200 hive stores. New artifacts for Image File Execution Options, the User Profile List and the Compatibility Assistant Store. Run and RunOnce Keys also reads Policies\Explorer\Run and the Load value.
  • Windows event logs: Event Logs Cleared (Security 1102 and System 104), Winlogon Logon and Logoff Notifications (7001 and 7002), and three Security policy change artifacts: Audit Policy Changes (4719), Logon Right Changes (4717 and 4718) and Domain Policy Changes (4739).
  • Safari on macOS: Safari History Tags, Safari Tabs, Safari Tab Snapshots and Safari iCloud Tab Devices are new. Each profile's History.db and TopSites.plist is read and the profile is named. Safari History gains Tags and Tag Identifiers columns, Safari iCloud Tabs gains Last Viewed and Device Type, and Recently Closed Tabs and Last Session show the tab's cached snapshot.
  • macOS reading: a file held under both Users/ and System/Volumes/Data/Users/ is read once, also when the extraction's tree sits inside a top folder. A Recently Closed Tabs entry holding a single tab is now reported.
  • Reading acquisitions with -t raw: qnxprobe is updated to 1.57. On NTFS, a cloud provider's online-only placeholder (OneDrive Files On-Demand) is no longer staged as zeros, a file the Windows Overlay Filter compressed with XPRESS is staged as its content, and an NTFS-compressed file with a compression unit that ends early is staged at its full length.

Full Changelog: v2026.4.2...v2026.4.3


Which file to download

Platform File
Windows 10 or 11, 64-bit Intel or AMD -windows-x64-setup.exe (installer), or -windows-x64-portable.zip to run without installing
Windows 11 on ARM -windows-arm64-setup.exe, or -windows-arm64-portable.zip
macOS, Apple silicon -macos-arm64.dmg
macOS, Intel -macos-x64.dmg
Linux, 64-bit Intel or AMD -linux-x64.AppImage
Linux on ARM -linux-arm64.AppImage

Every download holds one program, dleapp. Started without arguments, from the Start
menu, the Applications folder or a double-click, it opens the window. Given arguments in a
terminal, it is the command line. On macOS the command line is inside the app:

/Applications/DLEAPP.app/Contents/MacOS/dleapp --help

For tools that run DLEAPP themselves. The options, output and exit codes of dleapp
are those of earlier releases, but the downloads changed shape: there is no dleappGUI
any more, since dleapp without arguments opens the window. On Windows and macOS,
dleapp needs the folder it came in, so run it from there rather than copying the
executable elsewhere on its own; on Linux the AppImage is the whole program.

First launch

The macOS disk images are signed with a Developer ID and notarised by Apple, so they open
without a warning.

The Windows binaries are not signed yet, so SmartScreen says "Windows protected your PC"
the first time. Choose More info, then Run anyway.

On Linux, make the AppImage executable once (chmod +x DLEAPP-*.AppImage). It needs FUSE
to start; where FUSE is not available, run it with --appimage-extract-and-run.

If you would rather not clear a warning, run from source instead; the README has the steps.

Verify what you downloaded

SHA256SUMS.txt covers every file in this release. On macOS or Linux, from the folder you
downloaded into:

grep <the file you downloaded> SHA256SUMS.txt | shasum -a 256 -c -

Use sha256sum in place of shasum -a 256 on Linux. On Windows, in PowerShell:

(Get-FileHash -Algorithm SHA256 .\<the file you downloaded>).Hash

and compare it with the line in SHA256SUMS.txt, which is lower case.

Linux

The build is made on Ubuntu 22.04, so it needs glibc 2.35 or newer and will not start on
an older distribution.

DLEAPP v2026.4.2

Choose a tag to compare

@github-actions github-actions released this 01 Oct 15:24
9a58f2d

DLEAPP v2026.4.2

This release takes DLEAPP from 164 artifacts to 480, and adds Linux and IoT device images to the Windows and macOS coverage.

  • New downloads: DLEAPP is now built by one packaging driver on every platform. Windows gets an installer and a portable zip, macOS gets a signed and notarised disk image, and Linux gets an AppImage, for both Intel/AMD and ARM. There is one program, dleapp: started without arguments it opens the window, and given arguments it is the command line. There is no separate dleappGUI any more, and the download names changed. See "Which file to download" below. The builds bundle the Unified Log parser and python-evtx.
  • Linux: login records (wtmp, lastlog, btmp), user accounts, and the auth.log, secure and messages lines for the SSH server, sudo, su, pkexec, PAM sessions, logind sessions and power events, and account changes, with the same artifacts read from the systemd journal. Also the audit log, syslog messages, cron log and crontab entries, systemd unit files, apt and dpkg history and package status, USB device connections, SSH authorized keys, known hosts and client and server configs, command histories (bash, Python, less, SQLite shell, wget HSTS hosts), Trash, recently used files, thumbnail cache, XDG autostart entries, application launchers and default applications, hosts file, system information, and the GNOME desktop: application usage, screen time, search index files, dconf settings, GVfs metadata, starred files and Evolution Data Server contacts, calendars and tasks.
  • Windows: registry artifacts for system information, installed programs and per-user activity, Store apps, more event log artifacts (Microsoft Defender, power events with sleep reason and wake source, firewall, time changes, process creation, compatibility, device setup, user profile and OpenSSH), NTFS Zone.Identifier, USN journal and MFT, PowerShell PSReadLine history, Windows Error Reporting, CryptnetUrlCache, the scheduled task cache, RecentApps, Sysinternals EULA acceptance, firewall rules, Remote Desktop connections and the client bitmap cache, Setup answer files, StartupInfo, CLR usage logs, the Windows Update ReportingEvents log, CapabilityAccessManager.db, BITS jobs and files, and the hosts file.
  • Windows reading: registry transaction logs are replayed before a dirty hive is read, a dirty event log's uncounted chunks are read, an event log keeps being read past a record python-evtx cannot render, ESE tables skip records marked deleted and read values stored apart from their record, a truncated ESE database no longer stalls the run, the Prefetch run count is read where each version 30 variant keeps it, the WOW6432Node Run and RunOnce keys are read, and the blank event time in five event log artifacts is fixed.
  • macOS: accounts, devices, Wi-Fi, installs, persistence and recent items, Apple app databases, FSEvents, Unified Logs, Biome streams and sets, PowerLog, Apple System Log, zsh startup files, history and Terminal sessions, Saved Application State, Spotlight store files, CoreSpotlight items and shortcuts, Finder .DS_Store entries and Trash Put Back, QuickLook thumbnails, kext load history, kext policy, Gatekeeper and ExecPolicy, notarization tickets, System Information, install log, fsck logs, crash reports, current logins, local user accounts, DHCP leases, Location Services clients, Application Firewall settings, app URL cache, binary cookies, WebKit network cache, File Provider items, Reminders, iOS device backups, and the hosts file. Home-folder files are read from acquisitions of a single user folder.
  • Browsers and apps: Chromium browser artifacts for Windows, macOS and Linux profiles (including snap and Flatpak installs), Firefox artifacts, Threema Desktop with password-based key recovery, Google Drive for desktop, OneDrive client logs, Garmin Express, Potato Desktop, Discord's Windows blockfile cache, and Telegram Desktop's Linux data folders. Wire reports each account separately when a profile holds two.
  • IoT devices: Eufy floodlight camera recordings and log events, Skybell doorbell logs and settings, LG webOS TV stores and browser profile, Ring Chime Pro configuration and logs, Belkin WeMo NVRAM, device description and manufacture data, and the U-Boot environment.
  • More ways to read acquisitions with -t raw: Ex01, SMART, AFF, AFD, AFF4 and AFM images, VHD, VHDX, VMDK and QCOW virtual disks, Apple disk images (.dmg, .sparseimage, sparse bundles and segmented sets), and logical evidence (EnCase L01, FTK Imager AD1) read as the files it holds. Encrypted Apple disk images, FTK Imager AD-encrypted images, encrypted APFS volumes and BitLocker volumes open with the password or key you give, and an image sealed to a certificate opens with its private key. The raw image seeker lists NTFS alternate data streams, and qnxprobe is updated to 1.55.
  • Archive input: zip archives no longer walk every member to look for repeated names, a compressed tar is decompressed once before it is read, and the window accepts .tar.xz.
  • Reporting accuracy: the LAVA database and media items are recorded by their evidence path rather than the examiner's own folder, Python text is stored for floats and booleans, test case zips keep each member's recorded times, and archive members named like Windows devices are renamed when staged.
  • Fixes: a folder input no longer stages the examiner's files for links that point outside it, a socket or block device is no longer walked as a directory, and checked module boxes are visible in the window on Windows.
  • Profiles are saved as .dlprofile, and .rlprofile files still load. The unused PyMuPDF dependency is dropped.
  • A new DLEAPP logo, by Kevin Pagano.

Full Changelog: v2026.4.1...v2026.4.2


Which file to download

Platform File
Windows 10 or 11, 64-bit Intel or AMD -windows-x64-setup.exe (installer), or -windows-x64-portable.zip to run without installing
Windows 11 on ARM -windows-arm64-setup.exe, or -windows-arm64-portable.zip
macOS, Apple silicon -macos-arm64.dmg
macOS, Intel -macos-x64.dmg
Linux, 64-bit Intel or AMD -linux-x64.AppImage
Linux on ARM -linux-arm64.AppImage

Every download holds one program, dleapp. Started without arguments, from the Start
menu, the Applications folder or a double-click, it opens the window. Given arguments in a
terminal, it is the command line. On macOS the command line is inside the app:

/Applications/DLEAPP.app/Contents/MacOS/dleapp --help

For tools that run DLEAPP themselves. The options, output and exit codes of dleapp
are those of earlier releases, but the downloads changed shape: there is no dleappGUI
any more, since dleapp without arguments opens the window. On Windows and macOS,
dleapp needs the folder it came in, so run it from there rather than copying the
executable elsewhere on its own; on Linux the AppImage is the whole program.

First launch

The macOS disk images are signed with a Developer ID and notarised by Apple, so they open
without a warning.

The Windows binaries are not signed yet, so SmartScreen says "Windows protected your PC"
the first time. Choose More info, then Run anyway.

On Linux, make the AppImage executable once (chmod +x DLEAPP-*.AppImage). It needs FUSE
to start; where FUSE is not available, run it with --appimage-extract-and-run.

If you would rather not clear a warning, run from source instead; the README has the steps.

Verify what you downloaded

SHA256SUMS.txt covers every file in this release. On macOS or Linux, from the folder you
downloaded into:

grep <the file you downloaded> SHA256SUMS.txt | shasum -a 256 -c -

Use sha256sum in place of shasum -a 256 on Linux. On Windows, in PowerShell:

(Get-FileHash -Algorithm SHA256 .\<the file you downloaded>).Hash

and compare it with the line in SHA256SUMS.txt, which is lower case.

Linux

The build is made on Ubuntu 22.04, so it needs glibc 2.35 or newer and will not start on
an older distribution.

v2026.4.1

Choose a tag to compare

@Johann-PLW Johann-PLW released this 20 Sep 10:51
697333a

DLEAPP v2026.4.1

Massive Windows artifact expansion: over 25 new parsers covering execution evidence (Prefetch, Amcache, AppCompatCache/Shimcache, BAM/DAM, UserAssist, Scheduled Tasks, Run/RunOnce autostart keys), user activity (ShellBags, Jump Lists with DestList MRU parsing, RecentDocs, LNK shortcuts, Explorer per-user MRU), system artifacts (SRUM, SAM local accounts, Services registry, Mounted Devices, Network Profiles, USB Storage Devices, Capability Access Manager, PCA), and Windows Event Log coverage (Security logons, service installations, Terminal Services sessions, power events, account management).

  • New Windows search and cache artifacts: WebCache, Windows Search index (both legacy Windows.edb and Windows 11 Windows.db), thumbnail cache, and Recycle Bin ($I) records, validated against a new "Lone Wolf" sample corpus.
  • New macOS parsers rounding out desktop coverage: KnowledgeC, Network Usage, TCC, InteractionC, Notes, and LaunchServices Quarantine.
  • Forensic input and performance improvements: NTFS and APFS images now read in one pass with qnxprobe 1.30, the LAVA database now commits once per artifact instead of once per staged file, and a new ArtifactResult streaming path added for handling large artifacts more efficiently.

Full Changelog: v2026.4.0...v2026.4.1

v2026.4.0

Choose a tag to compare

@Johann-PLW Johann-PLW released this 13 Sep 19:30
76acbc7

DLEAPP v2026.4.0

  • Forensic input expansion: raw disk images and E01 acquisitions now readable directly via a new -t raw flag, with qnxprobe re-vendored to add F2FS filesystem support and fix a NAT copy-selection bug.
  • GUI responsiveness fix: artifact crunching now runs on a worker thread so the interface no longer freezes during processing, with a follow-up fix resetting stdout and guarding the close button, plus a Windows build fix closing an unterminated quote in the CLI version info that had broken dleapp.exe compilation.
  • Major macOS desktop coverage added: iMessage, Safari, and Keychain support for macOS, plus Slack Desktop, significantly broadening DLEAPP's native macOS artifact reach.
  • Data-quality and reporting fixes: date/datetime values now bound as text in SQLite writers, every Wire cache entry and cookie store read now properly cited, and evidence-relative paths shown consistently in the processed files log.

New Contributors

Full Changelog: v2026.3.1...v2026.4.0

v2026.3.1

Choose a tag to compare

@Johann-PLW Johann-PLW released this 27 Aug 19:42
5d69b98

DLEAPP v2026.3.1

  • New parser: ChatGPT (macOS) activity recording artifacts.
  • Timestamp accuracy fixes: corrected Unix timestamp conversion for pre-1970/pre-2001 values, plist date helpers made compatible with Python 3.10, and a fix stopping setupapiSections from duplicating every row on Windows.
  • Source-path and reporting integrity: real device paths returned as source_path instead of prose, new checks flagging local filesystem paths and prose mistakenly returned as source paths, only the image file name recorded in case files, and case-variant evidence files preserved when the report volume folds case.
  • Conversation artifact columns now ordered by their declared roles, and the unused get_sqlite_multiple_db_records helper removed.

Full Changelog: v2026.3.0...v2026.3.1

v2026.3.0

Choose a tag to compare

@Johann-PLW Johann-PLW released this 14 Aug 09:52
79ee087

DLEAPP v2026.3.0

  • New parsers: Roblox artifacts for both macOS and Windows, Telegram Desktop (tdata) artifacts with registered corpus sample data, and expanded Windows system artifact support including modern Photos and Clock apps.
  • Cross-version schema resilience: new null_absent_columns() helper tolerates missing columns across schema versions, with SQLite now naming the specific missing column when it happens.
  • Security and stability hardening: HTML report injection fixes (escaped evidence media names, removed remote destinations, new CI guard), a MemoryError fix during HTML report generation, hardened zip extraction against Windows-incompatible member names, and a fix for concurrent runs corrupting history.json.
  • Documentation integrity: unsourced claims removed from artifact descriptions and held to a sourced-evidence standard, with a new CI check guarding against unsupported claim language going forward.
  • Platform and CI improvements: automatic --run input type detection from corpus extension, restored module checkbox indicators on Windows and fixed macOS checkbox color inconsistencies, expanded CI (runtime contract across all supported Python versions, Windows import smoke tests, manual PyInstaller test-build workflow), and additional run information included in LAVA output.

New Contributors

Full Changelog: v2026.2.0...v2026.3.0

v2026.2.0

Choose a tag to compare

@Johann-PLW Johann-PLW released this 27 Jul 12:53
1f3a9e2

DLEAPP v2026.2.0

  • First public release of DLEAPP, a new member of the LEAPP family dedicated to desktop artifact parsing.
  • Parsers: Wire (Desktop), Discord Desktop (with reusable Chromium container readers), Signal Desktop (including decrypted-database parsing and macOS Keychain key recovery via login password/KDF confirmation), and WhatsApp Desktop for macOS.
  • Platform-accurate categorization: artifacts relabeled by verified platform rather than a generic "Desktop" tag (Signal - macOS, WhatsApp - Apple, Discord/Wire by platform), improving accuracy as Windows support remains partial (Signal's encryptedKey unwrap explicitly flagged as not yet implemented).

New Contributors

Full Changelog: https://github.com/abrignoni/DLEAPP/commits/v2026.2.0