DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with built-in process inspection, lateral movement tracking, persistence detection, and VirusTotal enrichment.
☆217Mar 21, 2026Updated this week
Alternatives and similar repositories for irflow-timeline
Users that are interested in irflow-timeline are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Carve file metadata from NTFS index ($I30) attributes☆71Feb 3, 2024Updated 2 years ago
- A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight,…☆40Oct 24, 2025Updated 5 months ago
- Legacy Sigma Tools (sigmac etc.)☆16May 7, 2023Updated 2 years ago
- ☆11Dec 9, 2025Updated 3 months ago
- Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.☆16Oct 22, 2025Updated 5 months ago
- Sigma rules converted for direct use with Zircolite☆14Mar 16, 2026Updated last week
- PyVelociraptor contains the python bindings for the Velociraptor API.☆21Feb 11, 2026Updated last month
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆701Oct 22, 2025Updated 5 months ago
- ☆21Nov 19, 2025Updated 4 months ago
- Hunt for SQLite files used by various applications☆30Mar 1, 2026Updated 3 weeks ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆88Mar 11, 2026Updated last week
- VelociraptorMCP is a Model Context Protocol bridge for exposing LLMs to MCP clients.☆73Aug 20, 2025Updated 7 months ago
- An advanced parser for INDX records☆29Aug 7, 2019Updated 6 years ago
- A collection of scripts for use with CrowdStrike Falcon RTR☆19Oct 4, 2024Updated last year
- A project that aims to automate Volatility3 at scale with the use of cloud strength and the power of KQL inside ADX.☆16Aug 19, 2025Updated 7 months ago
- Yet Another Memory Analyzer for malware detection and Guarding Operations with YARA and SIGMA☆82Nov 19, 2025Updated 4 months ago
- ESXi Cyber Security Incident Response Script☆25Sep 4, 2024Updated last year
- Invictus Threat Intelligence: IOCs and TTPs from blogs, research and more☆30Mar 10, 2026Updated 2 weeks ago
- Takajō (鷹匠) is a Hayabusa results analyzer.☆154Feb 23, 2026Updated last month
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆30May 5, 2025Updated 10 months ago
- A Rust library for parsing and evaluating Sigma rules☆19Nov 26, 2025Updated 3 months ago
- Repo to hold mcp server for velociraptor☆32Jul 27, 2025Updated 7 months ago
- Hunt the windows Registry automatically using VQL☆14Jan 6, 2026Updated 2 months ago
- ETW forensic tool for Volatility3 plugin☆17Nov 15, 2024Updated last year
- Windows Event Log "Microsoft-Windows-Partition%4Diagnostic.evtx" parser and devices' VSNs extractor.☆20Nov 28, 2023Updated 2 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 9 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆26Dec 2, 2025Updated 3 months ago
- The backend server handling API requests and task management☆59Mar 17, 2026Updated last week
- Sigma detection rules for hunting with the threathunting-keywords project☆58Mar 2, 2025Updated last year
- Interface LLMs from within MISP to extract TTPs and threat intel from CTI reports☆18Nov 13, 2023Updated 2 years ago
- The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifa…☆648Nov 7, 2025Updated 4 months ago
- Primarily aimed at replicating files that cannot be directly copied due to being in use.☆11Apr 22, 2024Updated last year
- ☆22Jan 31, 2023Updated 3 years ago
- $MFT directory tree reconstruction & FILE record info☆326Oct 7, 2024Updated last year
- Parses amcache.hve files, but with a twist!☆151Jan 12, 2025Updated last year
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Jan 9, 2023Updated 3 years ago
- Deep Packet Inspection • Traffic Forensics • Network Threat Detection☆50Feb 20, 2026Updated last month
- Python client for DFIR-IRIS☆25Aug 19, 2024Updated last year
- Extract compressed memory pages from page-aligned data☆47Sep 25, 2018Updated 7 years ago