A rewrite of mactime, timeliner uses a real expression engine to parse and apply filtering logic, allowing complex queries like filtering events based on time, path, weekday, and date using a BPF syntax. Although still in alpha stage, its killer feature is the advanced expression engine.
This tool is not verified yet and doesn't have listed features.
Did you submit the verified tool? Sign in to add features.
Are you the author? Claim the tool by clicking the icon above. After claiming, you can add features.
A tool for parsing and extracting information from the Master File Table of NTFS file systems.
A console program for file recovery through data carving.
A comprehensive Linux log analysis tool that streamlines the investigation of security incidents by extracting and organizing critical details from supported log files.
Open Source computer forensics platform with modular design for easy automation and scripting.
Second-order subdomain takeover scanner
Python forensic tool for extracting and analyzing information from Firefox, Iceweasel, and Seamonkey browsers.