DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with built-in process inspection, lateral movement tracking, persistence detection, and VirusTotal enrichment.
☆227Mar 21, 2026Updated 3 weeks ago
Alternatives and similar repositories for irflow-timeline
Users that are interested in irflow-timeline are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Carve file metadata from NTFS index ($I30) attributes☆71Feb 3, 2024Updated 2 years ago
- A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight,…☆41Oct 24, 2025Updated 5 months ago
- Legacy Sigma Tools (sigmac etc.)☆16May 7, 2023Updated 2 years ago
- ☆11Dec 9, 2025Updated 4 months ago
- Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.☆15Oct 22, 2025Updated 5 months ago
- Deploy open-source AI quickly and easily - Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Sigma rules converted for direct use with Zircolite☆14Updated this week
- PyVelociraptor contains the python bindings for the Velociraptor API.☆21Updated this week
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆702Oct 22, 2025Updated 5 months ago
- ☆21Nov 19, 2025Updated 4 months ago
- Hunt for SQLite files used by various applications☆31Mar 1, 2026Updated last month
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆88Mar 11, 2026Updated last month
- VelociraptorMCP is a Model Context Protocol bridge for exposing LLMs to MCP clients.☆74Aug 20, 2025Updated 7 months ago
- An advanced parser for INDX records☆29Aug 7, 2019Updated 6 years ago
- A Docker lab integrating Splunk SIEM with Ollama LLM via MCP for AI security operations. Features Promptfoo OWASP evaluation, TA-ollama a…☆29Mar 8, 2026Updated last month
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A collection of scripts for use with CrowdStrike Falcon RTR☆19Oct 4, 2024Updated last year
- A project that aims to automate Volatility3 at scale with the use of cloud strength and the power of KQL inside ADX.☆16Aug 19, 2025Updated 7 months ago
- Yet Another Memory Analyzer for malware detection and Guarding Operations with YARA and SIGMA☆85Nov 19, 2025Updated 4 months ago
- ESXi Cyber Security Incident Response Script☆27Sep 4, 2024Updated last year
- Invictus Threat Intelligence: IOCs and TTPs from blogs, research and more☆30Mar 31, 2026Updated 2 weeks ago
- Takajō (鷹匠) is a Hayabusa results analyzer.☆156Apr 6, 2026Updated last week
- Better Exploit Code For CVE 2017 9805 apache struts☆21Dec 23, 2017Updated 8 years ago
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆32May 5, 2025Updated 11 months ago
- A Rust library for parsing and evaluating Sigma rules☆21Nov 26, 2025Updated 4 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Repo to hold mcp server for velociraptor☆35Jul 27, 2025Updated 8 months ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆65Dec 18, 2024Updated last year
- ETW forensic tool for Volatility3 plugin☆17Nov 15, 2024Updated last year
- Windows Event Log "Microsoft-Windows-Partition%4Diagnostic.evtx" parser and devices' VSNs extractor.☆20Nov 28, 2023Updated 2 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 9 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆26Dec 2, 2025Updated 4 months ago
- The backend server handling API requests and task management☆60Apr 3, 2026Updated last week
- Hunt the windows Registry automatically using VQL☆14Jan 6, 2026Updated 3 months ago
- Interface LLMs from within MISP to extract TTPs and threat intel from CTI reports☆18Nov 13, 2023Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Sigma detection rules for hunting with the threathunting-keywords project☆59Mar 2, 2025Updated last year
- The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifa…☆649Nov 7, 2025Updated 5 months ago
- Primarily aimed at replicating files that cannot be directly copied due to being in use.☆11Apr 22, 2024Updated last year
- ☆22Jan 31, 2023Updated 3 years ago
- $MFT directory tree reconstruction & FILE record info☆328Oct 7, 2024Updated last year
- Parses amcache.hve files, but with a twist!☆150Jan 12, 2025Updated last year
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Jan 9, 2023Updated 3 years ago