The LEAPPs have moved a lot since the last Batch LEAPP release: they read disk images directly now, there is a DLEAPP, and the release builds run from the command line. This release catches Batch LEAPP up with all of it.
What's new
- Disk images. Batch LEAPP now finds
.E01,.s01,.Ex01,.dd,.raw,.001,.aff,.afm,.aff4,.dmg,.sparseimage,.vhd,.vhdx,.vmdk,.qcow,.qcow2,.L01and.ad1files and runs them with-t raw. A multi-file image is run once, from its first file. This needs a LEAPP that takes-t raw, v2026.4.0 or later. .tar.xzarchives are picked up too.- DLEAPP is supported by name, with its own colour on the report index.
- Use the LEAPP release apps directly. From iLEAPP v2026.4.3 and v2026.4.2 of the other four, a release is one program that opens its window when you double-click it and works as the command line when given arguments. Point Batch LEAPP at
iLEAPP.apporileapp.exeand go. No source checkout needed for a regular batch. - Your LEAPP history is left alone. The LEAPP command lines now record every run in the shared history, which only holds the last 10 paths and 20 runs. A batch of a dozen images would push out everything you had there. Every run now gets its own private settings folder, sequential runs included.
Fixes
- Folders from earlier LEAPP runs are skipped under their current name (
<tool>_Output_<date>), and under any custom name too. Before, pointing Batch LEAPP at a folder that held old reports could queue the files staged inside them as if they were extractions. - The GUI no longer offers Batch LEAPP itself as the LEAPP tool to run.
- A locked image no longer stops a batch waiting on a password prompt. Pass the key through instead, for example
-- --image_password_file /path/to/passwords.txt. - Coverage mode now records each extraction's input path and SHA-256 in
batch_apps.sqlite. They were being written empty. - The docs said
-- -p fastloads a profile. It is-- -m /path/to/case.ilprofile.
Good to know
.imgand.binfiles are only picked up when you set the type toraw, since plenty of files with those names are not disk images.- For a multi-file image, the SHA-256 in the manifest is the hash of its first file, not of the whole set.
.sparsebundlefolders and striped.aff4sets are not handled yet.
Details are in the README.
Downloads for macOS (Apple Silicon) and Windows are attached below. Free and open source, as always. Feedback and pull requests welcome.