Plaso Logo

Plaso

0
Free
Visit Website

Plaso Langar Að Safna Öllu, or super timeline all the things, is a Python-based engine used by several tools for automatic creation of timelines. These timelines support digital forensic investigators/analysts, to correlate the large amount of information found in logs and other files found on an average computer. The initial purpose of Plaso was to collect all timestamped events of interest on a computer system and have them aggregated in a single place for computer forensic analysis (aka Super Timeline). However Plaso has become a framework that supports: adding new parsers or parsing plug-ins; adding new analysis plug-ins; writing one-off scripts to automate repetitive tasks in computer forensic analysis or equivalent. And is moving to support: adding new general purpose parses/plugins that may not have timestamps associated to them; adding more analysis context; tagging events; allowing more targeted approach to the collection/parsing.

FEATURES

ALTERNATIVES

A digital forensics tool that provides read-only access to file-system objects from various storage media types and file formats.

Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.

A tool for analyzing pentest screenshots using a convolutional neural network

A suite of console tools for working with timestamps in Windows with 100-nanosecond precision.

Truehunter is a tool designed to detect encrypted containers with a focus on Truecrypt and Veracrypt, utilizing a fast and memory efficient approach.

A tool for triaging crash files with various output formats and debugging engine options.

A framework for orchestrating forensic collection, processing, and data export.

Universal hexadecimal editor for computer forensics, data recovery, and IT security.