Plaso Logo

Plaso

0
Free
Visit Website

Plaso Langar Að Safna Öllu, or super timeline all the things, is a Python-based engine used by several tools for automatic creation of timelines. These timelines support digital forensic investigators/analysts, to correlate the large amount of information found in logs and other files found on an average computer. The initial purpose of Plaso was to collect all timestamped events of interest on a computer system and have them aggregated in a single place for computer forensic analysis (aka Super Timeline). However Plaso has become a framework that supports: adding new parsers or parsing plug-ins; adding new analysis plug-ins; writing one-off scripts to automate repetitive tasks in computer forensic analysis or equivalent. And is moving to support: adding new general purpose parses/plugins that may not have timestamps associated to them; adding more analysis context; tagging events; allowing more targeted approach to the collection/parsing.

FEATURES

ALTERNATIVES

A portable volatile memory acquisition tool for Linux.

Autopsy is a GUI-based digital forensics platform for analyzing hard drives and smart phones, with a plug-in architecture for custom modules.

A library and tools for accessing and analyzing Linux Logical Volume Manager (LVM) volume system format.

Visually inspect regex matches in binary data/text with YARA and regular expressions, displaying matched bytes and surrounding context.

Highlighter is a FireEye Market app that integrates with FireEye products to provide enhanced cybersecurity capabilities.

Analyzing WiFiConfigStore.xml file for digital forensics on Android devices.

A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.

mXtract is a Linux-based tool for memory analysis and dumping with regex pattern search capabilities.