A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from processed triage evidence for Eric Zimmerman (EZ Tools) Kape, Axiom, Hayabusa, Chainsaw and Nirsoft into a unified timeline.
☆333Feb 26, 2026Updated 5 months ago
Alternatives and similar repositories for forensic-timeliner
Users that are interested in forensic-timeliner are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A tool for fetching DFIR and other GitHub tools.☆29Aug 2, 2025Updated last year
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆306Jul 27, 2026Updated 2 weeks ago
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,432Jul 1, 2026Updated last month
- Forensic Browser History Analyzer - Cross-platform browser history extractor (Chrome, Firefox, IE/Edge, Brave, Opera, Vivaldi)☆37Updated this week
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆668Jul 6, 2026Updated last month
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Harness the power of Splunk for your investigations☆170Oct 11, 2025Updated 10 months ago
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆108Mar 12, 2026Updated 5 months ago
- A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.☆460Apr 29, 2026Updated 3 months ago
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆321May 14, 2026Updated 3 months ago
- A preconfigured Velociraptor triage collector☆77Updated this week
- macOS forensic acquisition made simple☆294Jun 2, 2026Updated 2 months ago
- Scripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE☆201Apr 1, 2026Updated 4 months ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆16Jul 6, 2026Updated last month
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆211Aug 3, 2026Updated last week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Windows Forensics Environment Builder☆191Aug 1, 2026Updated last week
- ☆69Jan 8, 2026Updated 7 months ago
- ☆29Oct 15, 2025Updated 9 months ago
- Quick ESXi Log Parser☆33Jul 21, 2026Updated 3 weeks ago
- Search Index Database Reporter☆142Oct 28, 2025Updated 9 months ago
- Incident Response documents and tooling☆128Jul 22, 2026Updated 3 weeks ago
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆49Jul 20, 2026Updated 3 weeks ago
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆56Updated this week
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆158Apr 1, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- USN Journal full path builder☆71Apr 16, 2026Updated 3 months ago
- CLI tools for forensic investigation of Windows artifacts☆355Jul 21, 2025Updated last year
- A curated list of KAPE-related resources☆191May 1, 2025Updated last year
- Parses USB connection artifacts from offline Registry hives☆110Feb 8, 2026Updated 6 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆728May 2, 2026Updated 3 months ago
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,304Aug 3, 2026Updated last week
- Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!☆53Jan 9, 2026Updated 7 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆89Feb 9, 2025Updated last year
- A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.☆837Jun 29, 2026Updated last month
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts…☆1,142Feb 25, 2026Updated 5 months ago
- ☆84Feb 4, 2026Updated 6 months ago
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,627Aug 4, 2026Updated last week
- A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as …☆469Feb 18, 2026Updated 5 months ago
- $MFT directory tree reconstruction & FILE record info☆331Oct 7, 2024Updated last year
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆235Aug 1, 2026Updated last week
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆867Jun 17, 2026Updated last month