DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt, process inspection, lateral movement tracking, persistence detection, and VirusTotal enrichment.
☆294Jun 6, 2026Updated 3 weeks ago
Alternatives and similar repositories for irflow-timeline
Users that are interested in irflow-timeline are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Carve file metadata from NTFS index ($I30) attributes☆73May 25, 2026Updated last month
- A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight,…☆45Oct 24, 2025Updated 8 months ago
- Legacy Sigma Tools (sigmac etc.)☆17May 7, 2023Updated 3 years ago
- ☆14Jun 1, 2026Updated last month
- Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.☆16Oct 22, 2025Updated 8 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Sigma rules converted for direct use with Zircolite☆15Updated this week
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆724May 2, 2026Updated 2 months ago
- ☆21Nov 19, 2025Updated 7 months ago
- Hunt for SQLite files used by various applications☆31Jun 17, 2026Updated 2 weeks ago
- PyVelociraptor contains the python bindings for the Velociraptor API.☆23May 5, 2026Updated last month
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆92Mar 11, 2026Updated 3 months ago
- VelociraptorMCP is a Model Context Protocol bridge for exposing LLMs to MCP clients.☆91Updated this week
- ☆18Feb 2, 2026Updated 5 months ago
- An advanced parser for INDX records☆30Aug 7, 2019Updated 6 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- A Docker lab integrating Splunk SIEM with Ollama LLM via MCP for AI security operations. Features Promptfoo OWASP evaluation, TA-ollama a…☆30Mar 8, 2026Updated 3 months ago
- A collection of scripts for use with CrowdStrike Falcon RTR☆19Oct 4, 2024Updated last year
- A project that aims to automate Volatility3 at scale with the use of cloud strength and the power of KQL inside ADX.☆16Aug 19, 2025Updated 10 months ago
- Invictus Threat Intelligence: IOCs and TTPs from blogs, research and more☆30Mar 31, 2026Updated 3 months ago
- Takajō (鷹匠) is a Hayabusa results analyzer.☆160May 11, 2026Updated last month
- Better Exploit Code For CVE 2017 9805 apache struts☆21Dec 23, 2017Updated 8 years ago
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆33Jun 5, 2026Updated 3 weeks ago
- A parser for the MFT (Master File Table) format☆161Jan 3, 2026Updated 6 months ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆65Dec 18, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ETW forensic tool for Volatility3 plugin☆17Nov 15, 2024Updated last year
- Repo to hold mcp server for velociraptor☆39Apr 15, 2026Updated 2 months ago
- Windows Event Log "Microsoft-Windows-Partition%4Diagnostic.evtx" parser and devices' VSNs extractor.☆20Nov 28, 2023Updated 2 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 9 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆26Jun 25, 2026Updated last week
- Hunt the windows Registry automatically using VQL☆18May 4, 2026Updated 2 months ago
- Interface LLMs from within MISP to extract TTPs and threat intel from CTI reports☆18Nov 13, 2023Updated 2 years ago
- Sigma detection rules for hunting with the threathunting-keywords project☆60Mar 2, 2025Updated last year
- Primarily aimed at replicating files that cannot be directly copied due to being in use.☆10Apr 22, 2024Updated 2 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifa…☆656May 11, 2026Updated last month
- ☆22Jan 31, 2023Updated 3 years ago
- The backend server handling API requests and task management☆67Jun 17, 2026Updated 2 weeks ago
- Parses amcache.hve files, but with a twist!☆154Jun 17, 2026Updated 2 weeks ago
- Deep Packet Inspection • Traffic Forensics • Network Threat Detection☆54Feb 20, 2026Updated 4 months ago
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Jan 9, 2023Updated 3 years ago
- Python client for DFIR-IRIS☆27Aug 19, 2024Updated last year