A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from processed triage evidence for Eric Zimmerman (EZ Tools) Kape, Axiom, Hayabusa, Chainsaw and Nirsoft into a unified timeline.
☆335Feb 26, 2026Updated 6 months ago
Alternatives and similar repositories for forensic-timeliner
Users that are interested in forensic-timeliner are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A tool for fetching DFIR and other GitHub tools.☆30Updated this week
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆370Sep 8, 2026Updated 2 weeks ago
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,460Sep 9, 2026Updated 2 weeks ago
- Forensic Browser History Analyzer - Cross-platform browser history extractor (Chrome, Firefox, IE/Edge, Brave, Opera, Vivaldi)☆39Aug 7, 2026Updated last month
- Harness the power of Splunk for your investigations☆170Oct 11, 2025Updated 11 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆679Jul 6, 2026Updated 2 months ago
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆109Mar 12, 2026Updated 6 months ago
- A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.☆463Apr 29, 2026Updated 4 months ago
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆323May 14, 2026Updated 4 months ago
- A preconfigured Velociraptor triage collector☆78Aug 10, 2026Updated last month
- macOS forensic acquisition made simple☆301Jun 2, 2026Updated 3 months ago
- Scripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE☆201Sep 1, 2026Updated 3 weeks ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆17Jul 6, 2026Updated 2 months ago
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆223Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆29Oct 15, 2025Updated 11 months ago
- Windows Forensics Environment Builder☆190Aug 1, 2026Updated last month
- ☆70Jan 8, 2026Updated 8 months ago
- Quick ESXi Log Parser☆33Jul 21, 2026Updated 2 months ago
- Search Index Database Reporter☆145Oct 28, 2025Updated 10 months ago
- Incident Response documents and tooling☆133Jul 22, 2026Updated 2 months ago
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆52Sep 13, 2026Updated last week
- USN Journal full path builder☆71Apr 16, 2026Updated 5 months ago
- CLI tools for forensic investigation of Windows artifacts☆355Jul 21, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A curated list of KAPE-related resources☆192May 1, 2025Updated last year
- Parses USB connection artifacts from offline Registry hives☆110Feb 8, 2026Updated 7 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆737Aug 31, 2026Updated 3 weeks ago
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,361Sep 12, 2026Updated last week
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆159Apr 1, 2026Updated 5 months ago
- Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!☆53Jan 9, 2026Updated 8 months ago
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆57Sep 6, 2026Updated 2 weeks ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆90Feb 9, 2025Updated last year
- A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.☆850Jun 29, 2026Updated 2 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts…☆1,160Sep 11, 2026Updated last week
- ☆84Feb 4, 2026Updated 7 months ago
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,669Aug 25, 2026Updated 3 weeks ago
- A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as …☆472Feb 18, 2026Updated 7 months ago
- $MFT directory tree reconstruction & FILE record info☆331Oct 7, 2024Updated last year
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆245Sep 15, 2026Updated last week
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆877Updated this week