Skip to content

Batch LEAPP v1.2.0: Disk Images, DLEAPP and the New Release Builds

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Oct 20:11
5441ecf

The LEAPPs have moved a lot since the last Batch LEAPP release: they read disk images directly now, there is a DLEAPP, and the release builds run from the command line. This release catches Batch LEAPP up with all of it.

What's new

  • Disk images. Batch LEAPP now finds .E01, .s01, .Ex01, .dd, .raw, .001, .aff, .afm, .aff4, .dmg, .sparseimage, .vhd, .vhdx, .vmdk, .qcow, .qcow2, .L01 and .ad1 files and runs them with -t raw. A multi-file image is run once, from its first file. This needs a LEAPP that takes -t raw, v2026.4.0 or later.
  • .tar.xz archives are picked up too.
  • DLEAPP is supported by name, with its own colour on the report index.
  • Use the LEAPP release apps directly. From iLEAPP v2026.4.3 and v2026.4.2 of the other four, a release is one program that opens its window when you double-click it and works as the command line when given arguments. Point Batch LEAPP at iLEAPP.app or ileapp.exe and go. No source checkout needed for a regular batch.
  • Your LEAPP history is left alone. The LEAPP command lines now record every run in the shared history, which only holds the last 10 paths and 20 runs. A batch of a dozen images would push out everything you had there. Every run now gets its own private settings folder, sequential runs included.

Fixes

  • Folders from earlier LEAPP runs are skipped under their current name (<tool>_Output_<date>), and under any custom name too. Before, pointing Batch LEAPP at a folder that held old reports could queue the files staged inside them as if they were extractions.
  • The GUI no longer offers Batch LEAPP itself as the LEAPP tool to run.
  • A locked image no longer stops a batch waiting on a password prompt. Pass the key through instead, for example -- --image_password_file /path/to/passwords.txt.
  • Coverage mode now records each extraction's input path and SHA-256 in batch_apps.sqlite. They were being written empty.
  • The docs said -- -p fast loads a profile. It is -- -m /path/to/case.ilprofile.

Good to know

  • .img and .bin files are only picked up when you set the type to raw, since plenty of files with those names are not disk images.
  • For a multi-file image, the SHA-256 in the manifest is the hash of its first file, not of the whole set.
  • .sparsebundle folders and striped .aff4 sets are not handled yet.

Details are in the README.

Downloads for macOS (Apple Silicon) and Windows are attached below. Free and open source, as always. Feedback and pull requests welcome.