ALEAPP v2026.4.2

ALEAPP, short for Android Logs, Events, and Protobuf Parser, is an open source digital forensics tool for analyzing Android full system extractions. It parses Android artifacts and converts the results into structured forensic reports, making it easier to investigate application activity, system events, usage data, and other information stored on an Android device.

The project is aimed primarily at digital forensic investigators and DFIR professionals. It provides both command line and graphical interfaces and supports several types of forensic input, including extracted file systems, archives, and raw disk images.

Features

ALEAPP provides a modular artifact parsing system designed specifically for Android forensic analysis.

Key features include:

  • Android full system extraction analysis

  • Android logs, events, and Protobuf parsing

  • Graphical user interface

  • Command line interface

  • File system extraction support

  • ZIP, TAR, and GZIP input

  • Raw disk image support

  • EnCase E01 acquisition support

  • HTML reports

  • TSV output

  • Timeline support

  • Case data files

  • Custom parsing profiles

  • Dynamically loaded artifact plugins

  • Selective artifact processing

  • Support for Android application artifacts

  • Direct processing of supported disk images without mounting

  • Cross-platform operation

  • Python-based architecture

The plugin architecture is one of ALEAPP's strongest features. Artifact modules are loaded dynamically and define the files they process, their category, requirements, notes, and processing function. This makes the project extensible as new Android artifacts are discovered.

Download ALEAPP v2026.4.2 - Software Mirrors

ALEAPP v2026.4.2 for Windows

ALEAPP-2026.4.2-windows-x64-setup.exe | 40.73 MB

ALEAPP-2026.4.2-windows-x64-portable.zip | 52.12 MB

ALEAPP-2026.4.2-windows-arm64-setup.exe | 36.93 MB

ALEAPP-2026.4.2-windows-arm64-portable.zip | 45.11 MB

ALEAPP v2026.4.2 for macOS

ALEAPP-2026.4.2-macos-x64.dmg | 48.4 MB

ALEAPP-2026.4.2-macos-arm64.dmg | 45.71 MB

ALEAPP v2026.4.2 for Linux

ALEAPP-2026.4.2-linux-x64.AppImage | 75.05 MB

ALEAPP-2026.4.2-linux-arm64.AppImage | 72.71 MB

ALEAPP v2026.4.2 Source Code

ALEAPP v2026.4.2 Source code (zip)

ALEAPP v2026.4.2 Source code (tar.gz)

ALEAPP v2026.4.2 Release Notes:

ALEAPP v2026.4.2

  • New downloads: ALEAPP is now built by one packaging driver on every platform. Windows gets an installer and a portable zip, macOS gets a signed and notarised disk image, and Linux gets an AppImage, for both Intel/AMD and ARM. There is one program, aleapp: started without arguments it opens the window, and given arguments it is the command line. There is no separate aleappGUI any more, and the download names changed. See "Which file to download" below.
  • More ways to read acquisitions with -t raw: E01 and Ex01, SMART, AFF and AFD images, Apple disk images (.dmg, .sparseimage, sparse bundles and segmented sets), encrypted Apple disk images, FTK Imager AD-encrypted images, and encrypted APFS volumes, each opened with the password you give. NTFS alternate data streams are now readable, and qnxprobe is updated to 1.55.
  • New and expanded Android apps: Nova AI Chatbot, Samsung Gallery Hidden Album, and Calculator Lock with a new Calculator History artifact and every Android user's note contacts. WhatsApp now reports channels and channel messages in their own artifacts, resolves LID jids for 1:1 chats, groups and call logs, and adds status text, wa_name and group pictures to Contacts and Group Details. Snapchat Android reports only the users the account added.
  • Media from streaming caches: ExoPlayer media is rejoined and shown on the Reddit, Twitter and Instagram cache rows, including HLS streams.
  • Faster and lighter runs: artifacts can stream their rows instead of holding them. Zip archives no longer walk every member to look for repeated names, a compressed tar is decompressed once, and the GUI accepts .tar.xz.
  • Reporting accuracy: the LAVA database and media items are recorded by their evidence path rather than the examiner's own folder, ORDER BY ties break on row id, Python text is stored for floats and booleans, test case zips keep each member's recorded times, archive members named like Windows devices are renamed when staged, and Gmail body text marks where each link sat.
  • Fixes: a command-line run is recorded in history after the LAVA file is written, a folder input no longer stages the examiner's files for links that point outside it, and a socket or block device is no longer walked as a directory.

New Contributors

  • @AndroidIosForensik made their first contribution in #1453
Full Changelog: v2026.4.1...v2026.4.2

Which file to download

  • Windows 10 or 11, 64-bit Intel or AMD: -windows-x64-setup.exe (installer), or -windows-x64-portable.zip to run without installing
  • Windows 11 on ARM: -windows-arm64-setup.exe, or -windows-arm64-portable.zip
  • macOS, Apple silicon: -macos-arm64.dmg
  • macOS, Intel: -macos-x64.dmg
  • Linux, 64-bit Intel or AMD: -linux-x64.AppImage
  • Linux on ARM: -linux-arm64.AppImage
Every download holds one program, aleapp. Started without arguments, from the Start menu, the Applications folder or a double-click, it opens the window. Given arguments in a terminal, it is the command line. On macOS the command line is inside the app:
bash
/Applications/ALEAPP.app/Contents/MacOS/aleapp --help
For tools that run ALEAPP themselves. The options, output and exit codes of aleapp are those of earlier releases, but the downloads changed shape: there is no aleappGUI any more, since aleapp without arguments opens the window. On Windows and macOS, aleapp needs the folder it came in, so run it from there rather than copying the executable elsewhere on its own; on Linux the AppImage is the whole program.

First launch

The macOS disk images are signed with a Developer ID and notarised by Apple, so they open without a warning. The Windows binaries are not signed yet, so SmartScreen says "Windows protected your PC" the first time. Choose More info, then Run anyway. On Linux, make the AppImage executable once (chmod +x ALEAPP-*.AppImage). It needs FUSE to start; where FUSE is not available, run it with --appimage-extract-and-run. If you would rather not clear a warning, run from source instead; the README has the steps.

Verify what you downloaded

SHA256SUMS.txt covers every file in this release. On macOS or Linux, from the folder you downloaded into:
bash
grep  SHA256SUMS.txt | shasum -a 256 -c -
Use sha256sum in place of shasum -a 256 on Linux. On Windows, in PowerShell:
powershell
(Get-FileHash -Algorithm SHA256 .\).Hash
and compare it with the line in SHA256SUMS.txt, which is lower case.

Linux

The build is made on Ubuntu 22.04, so it needs glibc 2.35 or newer and will not start on an older distribution.

ALEAPP is a useful tool for investigators who need to extract meaningful information from Android forensic images without manually examining thousands of individual files.

Its main strength is automation. Android applications and the operating system generate large amounts of databases, XML files, logs, Protobuf data, and other artifacts. ALEAPP identifies supported artifacts and processes them into structured reports, reducing the amount of repetitive manual analysis required.

The modular design also makes ALEAPP practical for an evolving Android ecosystem. New artifact parsers can be added as plugins, and existing modules can be updated independently. This is particularly important for Android forensics because application storage formats and operating system artifacts change frequently.

Raw image support is another useful capability. ALEAPP can process supported .img, .dd, .bin, and split image files as well as EnCase E01 acquisitions directly. The tool does not require the image to be mounted, and it reads only the files requested by the artifact modules.

The GUI makes the software easier to approach for investigators who prefer not to work entirely from a terminal. At the same time, the CLI makes it possible to integrate ALEAPP into repeatable forensic workflows and scripts.

The main limitation is that ALEAPP is an artifact parser rather than a complete digital forensics platform. It does not replace dedicated acquisition, evidence management, case management, or advanced forensic analysis software.

It also requires investigators to understand Android artifacts and forensic methodology. A parsed artifact is not automatically proof of an event, and results need to be interpreted within the context of the device, extraction method, application, and available evidence.

For Android artifact triage, however, ALEAPP offers a strong combination of automation, extensibility, and broad forensic coverage.

Performance and Compatibility

ALEAPP supports several input formats, including extracted file systems, ZIP, TAR, GZIP, raw disk images, and E01 acquisitions.

Performance depends heavily on the size of the extraction, number of artifacts being processed, storage speed, and the selected artifact modules. Large Android extractions can contain substantial amounts of application and system data, so processing time can vary considerably.

The ability to select artifact categories and use custom profiles can help reduce unnecessary processing when an investigation is focused on particular evidence.

ALEAPP runs on Windows, macOS, and Linux when installed from source, with PyInstaller configurations provided for creating standalone executables on all three platforms.

System Requirements

ALEAPP currently requires:

  • Python 3.10 or newer

  • Dependencies listed in requirements.txt

  • Tkinter for the GUI on Linux

The project provides PyInstaller specifications for creating standalone versions for Windows, macOS, and Linux, allowing ALEAPP to run without a separate Python installation after compilation.

On Linux, Tkinter can be installed separately through the operating system's package manager.

Pros and Cons

Pros

  • Free and open source

  • Designed specifically for Android forensics

  • Large collection of artifact parsers

  • GUI and CLI interfaces

  • Supports Android full system extractions

  • Supports raw disk images

  • Supports E01 forensic acquisitions

  • Supports ZIP, TAR, and GZIP inputs

  • Generates HTML and TSV reports

  • Timeline support

  • Custom parsing profiles

  • Extensible plugin architecture

  • Cross-platform

  • Can process raw images without mounting them

Cons

  • Intended for forensic professionals rather than general users

  • Requires knowledge of Android forensic artifacts

  • Not a complete digital forensics suite

  • Large extractions can take significant processing time

  • Results require proper forensic interpretation

  • Python dependencies are required when running directly from source

How to Install

The simplest approach for investigators is to use a compiled version of ALEAPP if one is available for the target operating system.

For a source installation, install Python 3.10 or newer and clone the ALEAPP repository. Install the required Python dependencies with:

pip3 install -r requirements.txt

Linux users who want to use the graphical interface also need Tkinter. On Debian and Ubuntu-based systems, it can be installed with:

sudo apt-get install python3-tk

ALEAPP can then be started through the command line with the appropriate input type and output directory, or the graphical interface can be launched with aleappGUI.py.

For users who need a standalone executable, the project includes PyInstaller specifications for Windows, macOS, and Linux.

Frequently Asked Questions

What is ALEAPP?

ALEAPP is an open source forensic parser for analyzing Android logs, events, Protobuf data, application artifacts, and other information contained in Android full system extractions.

What does ALEAPP stand for?

ALEAPP stands for Android Logs, Events, and Protobuf Parser.

What operating systems does ALEAPP support?

ALEAPP can be used on Windows, macOS, and Linux. The repository includes PyInstaller configurations for building standalone versions for all three platforms.

Does ALEAPP have a graphical interface?

Yes. ALEAPP provides both a GUI and command line interface.

Can ALEAPP analyze Android disk images?

Yes. ALEAPP supports raw disk images including IMG, DD, BIN, and split image files, as well as EnCase E01 acquisitions.

Does ALEAPP need to mount a disk image?

No. Its raw image functionality can search supported file systems directly without mounting the image or requiring administrator rights.

Can ALEAPP analyze ZIP and TAR files?

Yes. ZIP, TAR, and GZIP inputs are supported.

Can ALEAPP create timelines?

Yes. Artifact modules can submit records to ALEAPP's timeline output in addition to HTML and TSV reports.

Can ALEAPP be extended?

Yes. ALEAPP uses dynamically loaded artifact plugins. Developers can add new Python modules to the artifact system to support additional Android data sources.

Is ALEAPP a complete forensic suite?

No. ALEAPP specializes in Android artifact parsing and triage. It is better viewed as one component of a broader digital forensics workflow.

ALEAPP v2026.4.2
Free
Software Informations:
Developer:

Operating System:
Windows / macOS / Linux
Date Added:
2026-09-29T22:03:33.261Z
Categories:

Post a Comment/Report Broken Link: