timeliner Logo

timeliner

0
Free
Visit Website

A rewrite of mactime, timeliner uses a real expression engine to parse and apply filtering logic, allowing complex queries like filtering events based on time, path, weekday, and date using a BPF syntax. Although still in alpha stage, its killer feature is the advanced expression engine.

FEATURES

ALTERNATIVES

A tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container, aiding in digital forensic triage.

RegRippy is a modern Python 3 alternative to RegRipper for extracting data from Windows registry hives.

A library to access and parse Windows XML Event Log (EVTX) format, useful for digital forensics and incident response.

DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.

A suite of console tools for working with timestamps in Windows with 100-nanosecond precision.

Second-order subdomain takeover scanner

AMExtractor is an Android Memory Extractor tool.

A tool for creating compact Linux memory dumps compatible with popular debugging tools.

PINNED