DLEAPP v2026.4.3
- Windows registry: Amcache Applications, Amcache Shortcuts, Amcache Drivers and Amcache Devices join Amcache Application Files, and all five report the values a Windows 11 build 26200 hive stores. New artifacts for Image File Execution Options, the User Profile List and the Compatibility Assistant Store. Run and RunOnce Keys also reads Policies\Explorer\Run and the Load value.
- Windows event logs: Event Logs Cleared (Security 1102 and System 104), Winlogon Logon and Logoff Notifications (7001 and 7002), and three Security policy change artifacts: Audit Policy Changes (4719), Logon Right Changes (4717 and 4718) and Domain Policy Changes (4739).
- Safari on macOS: Safari History Tags, Safari Tabs, Safari Tab Snapshots and Safari iCloud Tab Devices are new. Each profile's History.db and TopSites.plist is read and the profile is named. Safari History gains Tags and Tag Identifiers columns, Safari iCloud Tabs gains Last Viewed and Device Type, and Recently Closed Tabs and Last Session show the tab's cached snapshot.
- macOS reading: a file held under both Users/ and System/Volumes/Data/Users/ is read once, also when the extraction's tree sits inside a top folder. A Recently Closed Tabs entry holding a single tab is now reported.
- Reading acquisitions with
-t raw: qnxprobe is updated to 1.57. On NTFS, a cloud provider's online-only placeholder (OneDrive Files On-Demand) is no longer staged as zeros, a file the Windows Overlay Filter compressed with XPRESS is staged as its content, and an NTFS-compressed file with a compression unit that ends early is staged at its full length.
Full Changelog: v2026.4.2...v2026.4.3
Which file to download
| Platform | File |
|---|---|
| Windows 10 or 11, 64-bit Intel or AMD | -windows-x64-setup.exe (installer), or -windows-x64-portable.zip to run without installing |
| Windows 11 on ARM | -windows-arm64-setup.exe, or -windows-arm64-portable.zip |
| macOS, Apple silicon | -macos-arm64.dmg |
| macOS, Intel | -macos-x64.dmg |
| Linux, 64-bit Intel or AMD | -linux-x64.AppImage |
| Linux on ARM | -linux-arm64.AppImage |
Every download holds one program, dleapp. Started without arguments, from the Start
menu, the Applications folder or a double-click, it opens the window. Given arguments in a
terminal, it is the command line. On macOS the command line is inside the app:
/Applications/DLEAPP.app/Contents/MacOS/dleapp --helpFor tools that run DLEAPP themselves. The options, output and exit codes of dleapp
are those of earlier releases, but the downloads changed shape: there is no dleappGUI
any more, since dleapp without arguments opens the window. On Windows and macOS,
dleapp needs the folder it came in, so run it from there rather than copying the
executable elsewhere on its own; on Linux the AppImage is the whole program.
First launch
The macOS disk images are signed with a Developer ID and notarised by Apple, so they open
without a warning.
The Windows binaries are not signed yet, so SmartScreen says "Windows protected your PC"
the first time. Choose More info, then Run anyway.
On Linux, make the AppImage executable once (chmod +x DLEAPP-*.AppImage). It needs FUSE
to start; where FUSE is not available, run it with --appimage-extract-and-run.
If you would rather not clear a warning, run from source instead; the README has the steps.
Verify what you downloaded
SHA256SUMS.txt covers every file in this release. On macOS or Linux, from the folder you
downloaded into:
grep <the file you downloaded> SHA256SUMS.txt | shasum -a 256 -c -Use sha256sum in place of shasum -a 256 on Linux. On Windows, in PowerShell:
(Get-FileHash -Algorithm SHA256 .\<the file you downloaded>).Hashand compare it with the line in SHA256SUMS.txt, which is lower case.
Linux
The build is made on Ubuntu 22.04, so it needs glibc 2.35 or newer and will not start on
an older distribution.