2.9.0
What's new in v2.9.0 :
- The mini-GUI now includes a timeline view check the screenshot here
- You can now use multiple rulesets by using
--rulesetor-rmultiple times - Correct a bug with CSV output
- Correct a bug with the
--limitparameter - Removed embedded version related code and formatting. Please use DFIR-ORC if you want an embedded version (docs here).
Known issues
- For users with an Apple Silicon computer : please use
--noexternalto prevent the use ofevtx_dumpexternal binaries