CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back 🔍 Digital Forensics Aug 13, 2022

Modular artifact scripts coming to iLEAPP

DFIR Science Archived Apr 23, 2026 ✓ Full text saved

kviddy has been pushing some great core updates to ALEAPP. Specifically, artifact scripts are now self-contained. This means that script authors no longer need to update an artifacts list. Instead they can write their parser script, drop it into the scripts folder, and DONE! Awesome.

Full text archived locally
✦ AI Summary · Claude Sonnet


    kviddy has been pushing some great core updates to ALEAPP. Specifically, artifact scripts are now self-contained. This means that script authors no longer need to update an artifacts list. Instead they can write their parser script, drop it into the scripts folder, and DONE! Awesome. This change also makes it easier to create “run filters” based on the datasets you are processing. For example, say you are only interested in calendar and sms artifacts for most of your cases. Now you can create a parsing filter to just run selected modules. One click and done! This is extremely useful since the supported artifacts in all LEAPPs is getting very large. These updates are already rolled out to ALEAPP v3.0+. Go check it out! These great features, however, were not pushed to iLEAPP and others yet, so I’ve started working on that. iLEAPP modular artifact scripts based on kviddy’s work was submitted this week. Currently working on the selectable script filters and updating everything in RLEAPP. After that, I want to start working on LEAPP core optimization. I suspect the new way of calling scripts may see better performance with concurrency or multiprocessing. Needs more testing. SHARE ON Twitter Facebook LinkedIn
    💬 Team Notes
    Article Info
    Source
    DFIR Science
    Category
    🔍 Digital Forensics
    Published
    Aug 13, 2022
    Archived
    Apr 23, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗