A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from processed triage evidence for Eric Zimmerman (EZ Tools) Kape, Axiom, Hayabusa, Chainsaw and Nirsoft into a unified timeline.
☆331Feb 26, 2026Updated 4 months ago
Alternatives and similar repositories for forensic-timeliner
Users that are interested in forensic-timeliner are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A tool for fetching DFIR and other GitHub tools.☆29Aug 2, 2025Updated 11 months ago
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆296Jun 6, 2026Updated last month
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,414Jul 1, 2026Updated 3 weeks ago
- Forensic Browser History Analyzer - Cross-platform browser history extractor (Chrome, Firefox, IE/Edge, Brave, Opera, Vivaldi)☆35Apr 11, 2026Updated 3 months ago
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆666Jul 6, 2026Updated 2 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Harness the power of Splunk for your investigations☆169Oct 11, 2025Updated 9 months ago
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆108Mar 12, 2026Updated 4 months ago
- A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.☆459Apr 29, 2026Updated 2 months ago
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆321May 14, 2026Updated 2 months ago
- A preconfigured Velociraptor triage collector☆77Jun 29, 2026Updated 3 weeks ago
- macOS forensic acquisition made simple☆288Jun 2, 2026Updated last month
- Scripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE☆201Apr 1, 2026Updated 3 months ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆16Jul 6, 2026Updated 2 weeks ago
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆182Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Windows Forensics Environment Builder☆189May 19, 2026Updated 2 months ago
- ☆69Jan 8, 2026Updated 6 months ago
- ☆29Oct 15, 2025Updated 9 months ago
- Quick ESXi Log Parser☆33Updated this week
- Search Index Database Reporter☆139Oct 28, 2025Updated 8 months ago
- Incident Response documents and tooling☆125Updated this week
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆49Updated this week
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆54Updated this week
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆157Apr 1, 2026Updated 3 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- USN Journal full path builder☆69Apr 16, 2026Updated 3 months ago
- CLI tools for forensic investigation of Windows artifacts☆355Jul 21, 2025Updated last year
- A curated list of KAPE-related resources☆190May 1, 2025Updated last year
- Parses USB connection artifacts from offline Registry hives☆109Feb 8, 2026Updated 5 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆728May 2, 2026Updated 2 months ago
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,267Updated this week
- Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!☆53Jan 9, 2026Updated 6 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆89Feb 9, 2025Updated last year
- A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.☆832Jun 29, 2026Updated 3 weeks ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts…☆1,130Feb 25, 2026Updated 4 months ago
- ☆84Feb 4, 2026Updated 5 months ago
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,609Updated this week
- A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as …☆471Feb 18, 2026Updated 5 months ago
- $MFT directory tree reconstruction & FILE record info☆330Oct 7, 2024Updated last year
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆235Jun 29, 2026Updated 3 weeks ago
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆859Jun 17, 2026Updated last month