DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with built-in process inspection, lateral movement tracking, persistence detection, and VirusTotal enrichment.
☆243Apr 30, 2026Updated 3 weeks ago
Alternatives and similar repositories for irflow-timeline
Users that are interested in irflow-timeline are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Carve file metadata from NTFS index ($I30) attributes☆73Feb 3, 2024Updated 2 years ago
- A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight,…☆43Oct 24, 2025Updated 7 months ago
- Legacy Sigma Tools (sigmac etc.)☆16May 7, 2023Updated 3 years ago
- ☆13Updated this week
- Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.☆16Oct 22, 2025Updated 7 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Sigma rules converted for direct use with Zircolite☆15Updated this week
- PyVelociraptor contains the python bindings for the Velociraptor API.☆21May 5, 2026Updated 2 weeks ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆715May 2, 2026Updated 3 weeks ago
- ☆21Nov 19, 2025Updated 6 months ago
- Hunt for SQLite files used by various applications☆31Mar 1, 2026Updated 2 months ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆89Mar 11, 2026Updated 2 months ago
- VelociraptorMCP is a Model Context Protocol bridge for exposing LLMs to MCP clients.☆85May 18, 2026Updated last week
- An advanced parser for INDX records☆30Aug 7, 2019Updated 6 years ago
- A Docker lab integrating Splunk SIEM with Ollama LLM via MCP for AI security operations. Features Promptfoo OWASP evaluation, TA-ollama a…☆30Mar 8, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A collection of scripts for use with CrowdStrike Falcon RTR☆19Oct 4, 2024Updated last year
- A project that aims to automate Volatility3 at scale with the use of cloud strength and the power of KQL inside ADX.☆16Aug 19, 2025Updated 9 months ago
- Yet Another Memory Analyzer for malware detection and Guarding Operations with YARA and SIGMA☆85Nov 19, 2025Updated 6 months ago
- ESXi Cyber Security Incident Response Script☆28Sep 4, 2024Updated last year
- Invictus Threat Intelligence: IOCs and TTPs from blogs, research and more☆30Mar 31, 2026Updated last month
- Takajō (鷹匠) is a Hayabusa results analyzer.☆159May 11, 2026Updated last week
- Better Exploit Code For CVE 2017 9805 apache struts☆21Dec 23, 2017Updated 8 years ago
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆33May 11, 2026Updated last week
- A Rust library for parsing and evaluating Sigma rules☆22Nov 26, 2025Updated 5 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A parser for the MFT (Master File Table) format☆159Jan 3, 2026Updated 4 months ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆65Dec 18, 2024Updated last year
- ETW forensic tool for Volatility3 plugin☆17Nov 15, 2024Updated last year
- Repo to hold mcp server for velociraptor☆38Apr 15, 2026Updated last month
- Windows Event Log "Microsoft-Windows-Partition%4Diagnostic.evtx" parser and devices' VSNs extractor.☆20Nov 28, 2023Updated 2 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 9 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆26Dec 2, 2025Updated 5 months ago
- The backend server handling API requests and task management☆64May 14, 2026Updated last week
- Hunt the windows Registry automatically using VQL☆16May 4, 2026Updated 2 weeks ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Interface LLMs from within MISP to extract TTPs and threat intel from CTI reports☆18Nov 13, 2023Updated 2 years ago
- Sigma detection rules for hunting with the threathunting-keywords project☆60Mar 2, 2025Updated last year
- Primarily aimed at replicating files that cannot be directly copied due to being in use.☆11Apr 22, 2024Updated 2 years ago
- The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifa…☆653May 11, 2026Updated last week
- ☆22Jan 31, 2023Updated 3 years ago
- $MFT directory tree reconstruction & FILE record info☆330Oct 7, 2024Updated last year
- Parses amcache.hve files, but with a twist!☆154Apr 28, 2026Updated 3 weeks ago