A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from processed triage evidence for Eric Zimmerman (EZ Tools) Kape, Axiom, Hayabusa, Chainsaw and Nirsoft into a unified timeline.
☆334Feb 26, 2026Updated 6 months ago
Alternatives and similar repositories for forensic-timeliner
Users that are interested in forensic-timeliner are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A tool for fetching DFIR and other GitHub tools.☆29Aug 2, 2025Updated last year
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆348Aug 24, 2026Updated last week
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,441Aug 25, 2026Updated last week
- Forensic Browser History Analyzer - Cross-platform browser history extractor (Chrome, Firefox, IE/Edge, Brave, Opera, Vivaldi)☆38Aug 7, 2026Updated 3 weeks ago
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆678Jul 6, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Harness the power of Splunk for your investigations☆170Oct 11, 2025Updated 10 months ago
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆109Mar 12, 2026Updated 5 months ago
- A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.☆460Apr 29, 2026Updated 4 months ago
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆321May 14, 2026Updated 3 months ago
- A preconfigured Velociraptor triage collector☆77Aug 10, 2026Updated 3 weeks ago
- macOS forensic acquisition made simple☆297Jun 2, 2026Updated 3 months ago
- Scripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE☆201Updated this week
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆16Jul 6, 2026Updated last month
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆221Updated this week
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Windows Forensics Environment Builder☆190Aug 1, 2026Updated last month
- ☆29Oct 15, 2025Updated 10 months ago
- ☆70Jan 8, 2026Updated 7 months ago
- Quick ESXi Log Parser☆33Jul 21, 2026Updated last month
- Search Index Database Reporter☆142Oct 28, 2025Updated 10 months ago
- Incident Response documents and tooling☆133Jul 22, 2026Updated last month
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆49Updated this week
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆56Aug 24, 2026Updated last week
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆158Apr 1, 2026Updated 5 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- USN Journal full path builder☆71Apr 16, 2026Updated 4 months ago
- CLI tools for forensic investigation of Windows artifacts☆355Jul 21, 2025Updated last year
- A curated list of KAPE-related resources☆193May 1, 2025Updated last year
- Parses USB connection artifacts from offline Registry hives☆110Feb 8, 2026Updated 6 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆735Updated this week
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,330Updated this week
- Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!☆53Jan 9, 2026Updated 7 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆89Feb 9, 2025Updated last year
- A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.☆839Jun 29, 2026Updated 2 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts…☆1,150Feb 25, 2026Updated 6 months ago
- ☆84Feb 4, 2026Updated 6 months ago
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,654Aug 25, 2026Updated last week
- A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as …☆469Feb 18, 2026Updated 6 months ago
- $MFT directory tree reconstruction & FILE record info☆332Oct 7, 2024Updated last year
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆236Aug 20, 2026Updated 2 weeks ago
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆871Jun 17, 2026Updated 2 months ago