Plaso Logo

Plaso

0
Free
Visit Website

Plaso Langar Að Safna Öllu, or super timeline all the things, is a Python-based engine used by several tools for automatic creation of timelines. These timelines support digital forensic investigators/analysts, to correlate the large amount of information found in logs and other files found on an average computer. The initial purpose of Plaso was to collect all timestamped events of interest on a computer system and have them aggregated in a single place for computer forensic analysis (aka Super Timeline). However Plaso has become a framework that supports: adding new parsers or parsing plug-ins; adding new analysis plug-ins; writing one-off scripts to automate repetitive tasks in computer forensic analysis or equivalent. And is moving to support: adding new general purpose parses/plugins that may not have timestamps associated to them; adding more analysis context; tagging events; allowing more targeted approach to the collection/parsing.

FEATURES

ALTERNATIVES

Python script to parse macOS MRU plist files into human-friendly format

A powerful reverse engineering framework

A library to access and parse Windows NT Registry File (REGF) format.

Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.

PowerForensics is a PowerShell digital forensics framework for hard drive forensic analysis.

An anti-forensic kill-switch tool for USB ports to shut down the computer immediately in case of unauthorized access.

Powerful tool for searching and hunting through Windows forensic artefacts with support for Sigma detection rules and custom Chainsaw detection rules.

A forensics tool for tracking USB device artifacts on Linux machines.

PINNED