Skip to content

DLEAPP v2026.4.2

Choose a tag to compare

@github-actions github-actions released this 01 Oct 15:24
· 262 commits to main since this release
9a58f2d

DLEAPP v2026.4.2

This release takes DLEAPP from 164 artifacts to 480, and adds Linux and IoT device images to the Windows and macOS coverage.

  • New downloads: DLEAPP is now built by one packaging driver on every platform. Windows gets an installer and a portable zip, macOS gets a signed and notarised disk image, and Linux gets an AppImage, for both Intel/AMD and ARM. There is one program, dleapp: started without arguments it opens the window, and given arguments it is the command line. There is no separate dleappGUI any more, and the download names changed. See "Which file to download" below. The builds bundle the Unified Log parser and python-evtx.
  • Linux: login records (wtmp, lastlog, btmp), user accounts, and the auth.log, secure and messages lines for the SSH server, sudo, su, pkexec, PAM sessions, logind sessions and power events, and account changes, with the same artifacts read from the systemd journal. Also the audit log, syslog messages, cron log and crontab entries, systemd unit files, apt and dpkg history and package status, USB device connections, SSH authorized keys, known hosts and client and server configs, command histories (bash, Python, less, SQLite shell, wget HSTS hosts), Trash, recently used files, thumbnail cache, XDG autostart entries, application launchers and default applications, hosts file, system information, and the GNOME desktop: application usage, screen time, search index files, dconf settings, GVfs metadata, starred files and Evolution Data Server contacts, calendars and tasks.
  • Windows: registry artifacts for system information, installed programs and per-user activity, Store apps, more event log artifacts (Microsoft Defender, power events with sleep reason and wake source, firewall, time changes, process creation, compatibility, device setup, user profile and OpenSSH), NTFS Zone.Identifier, USN journal and MFT, PowerShell PSReadLine history, Windows Error Reporting, CryptnetUrlCache, the scheduled task cache, RecentApps, Sysinternals EULA acceptance, firewall rules, Remote Desktop connections and the client bitmap cache, Setup answer files, StartupInfo, CLR usage logs, the Windows Update ReportingEvents log, CapabilityAccessManager.db, BITS jobs and files, and the hosts file.
  • Windows reading: registry transaction logs are replayed before a dirty hive is read, a dirty event log's uncounted chunks are read, an event log keeps being read past a record python-evtx cannot render, ESE tables skip records marked deleted and read values stored apart from their record, a truncated ESE database no longer stalls the run, the Prefetch run count is read where each version 30 variant keeps it, the WOW6432Node Run and RunOnce keys are read, and the blank event time in five event log artifacts is fixed.
  • macOS: accounts, devices, Wi-Fi, installs, persistence and recent items, Apple app databases, FSEvents, Unified Logs, Biome streams and sets, PowerLog, Apple System Log, zsh startup files, history and Terminal sessions, Saved Application State, Spotlight store files, CoreSpotlight items and shortcuts, Finder .DS_Store entries and Trash Put Back, QuickLook thumbnails, kext load history, kext policy, Gatekeeper and ExecPolicy, notarization tickets, System Information, install log, fsck logs, crash reports, current logins, local user accounts, DHCP leases, Location Services clients, Application Firewall settings, app URL cache, binary cookies, WebKit network cache, File Provider items, Reminders, iOS device backups, and the hosts file. Home-folder files are read from acquisitions of a single user folder.
  • Browsers and apps: Chromium browser artifacts for Windows, macOS and Linux profiles (including snap and Flatpak installs), Firefox artifacts, Threema Desktop with password-based key recovery, Google Drive for desktop, OneDrive client logs, Garmin Express, Potato Desktop, Discord's Windows blockfile cache, and Telegram Desktop's Linux data folders. Wire reports each account separately when a profile holds two.
  • IoT devices: Eufy floodlight camera recordings and log events, Skybell doorbell logs and settings, LG webOS TV stores and browser profile, Ring Chime Pro configuration and logs, Belkin WeMo NVRAM, device description and manufacture data, and the U-Boot environment.
  • More ways to read acquisitions with -t raw: Ex01, SMART, AFF, AFD, AFF4 and AFM images, VHD, VHDX, VMDK and QCOW virtual disks, Apple disk images (.dmg, .sparseimage, sparse bundles and segmented sets), and logical evidence (EnCase L01, FTK Imager AD1) read as the files it holds. Encrypted Apple disk images, FTK Imager AD-encrypted images, encrypted APFS volumes and BitLocker volumes open with the password or key you give, and an image sealed to a certificate opens with its private key. The raw image seeker lists NTFS alternate data streams, and qnxprobe is updated to 1.55.
  • Archive input: zip archives no longer walk every member to look for repeated names, a compressed tar is decompressed once before it is read, and the window accepts .tar.xz.
  • Reporting accuracy: the LAVA database and media items are recorded by their evidence path rather than the examiner's own folder, Python text is stored for floats and booleans, test case zips keep each member's recorded times, and archive members named like Windows devices are renamed when staged.
  • Fixes: a folder input no longer stages the examiner's files for links that point outside it, a socket or block device is no longer walked as a directory, and checked module boxes are visible in the window on Windows.
  • Profiles are saved as .dlprofile, and .rlprofile files still load. The unused PyMuPDF dependency is dropped.
  • A new DLEAPP logo, by Kevin Pagano.

Full Changelog: v2026.4.1...v2026.4.2


Which file to download

Platform File
Windows 10 or 11, 64-bit Intel or AMD -windows-x64-setup.exe (installer), or -windows-x64-portable.zip to run without installing
Windows 11 on ARM -windows-arm64-setup.exe, or -windows-arm64-portable.zip
macOS, Apple silicon -macos-arm64.dmg
macOS, Intel -macos-x64.dmg
Linux, 64-bit Intel or AMD -linux-x64.AppImage
Linux on ARM -linux-arm64.AppImage

Every download holds one program, dleapp. Started without arguments, from the Start
menu, the Applications folder or a double-click, it opens the window. Given arguments in a
terminal, it is the command line. On macOS the command line is inside the app:

/Applications/DLEAPP.app/Contents/MacOS/dleapp --help

For tools that run DLEAPP themselves. The options, output and exit codes of dleapp
are those of earlier releases, but the downloads changed shape: there is no dleappGUI
any more, since dleapp without arguments opens the window. On Windows and macOS,
dleapp needs the folder it came in, so run it from there rather than copying the
executable elsewhere on its own; on Linux the AppImage is the whole program.

First launch

The macOS disk images are signed with a Developer ID and notarised by Apple, so they open
without a warning.

The Windows binaries are not signed yet, so SmartScreen says "Windows protected your PC"
the first time. Choose More info, then Run anyway.

On Linux, make the AppImage executable once (chmod +x DLEAPP-*.AppImage). It needs FUSE
to start; where FUSE is not available, run it with --appimage-extract-and-run.

If you would rather not clear a warning, run from source instead; the README has the steps.

Verify what you downloaded

SHA256SUMS.txt covers every file in this release. On macOS or Linux, from the folder you
downloaded into:

grep <the file you downloaded> SHA256SUMS.txt | shasum -a 256 -c -

Use sha256sum in place of shasum -a 256 on Linux. On Windows, in PowerShell:

(Get-FileHash -Algorithm SHA256 .\<the file you downloaded>).Hash

and compare it with the line in SHA256SUMS.txt, which is lower case.

Linux

The build is made on Ubuntu 22.04, so it needs glibc 2.35 or newer and will not start on
an older distribution.