timeliner Logo

timeliner

0
Free
Visit Website

A rewrite of mactime, timeliner uses a real expression engine to parse and apply filtering logic, allowing complex queries like filtering events based on time, path, weekday, and date using a BPF syntax. Although still in alpha stage, its killer feature is the advanced expression engine.

FEATURES

ALTERNATIVES

Visually inspect regex matches in binary data/text with YARA and regular expressions, displaying matched bytes and surrounding context.

AMExtractor is an Android Memory Extractor tool.

A software that collects forensic artifacts on systems for forensic investigations.

A tool for fixing acquired .evt Windows Event Log files in digital forensics.

Educational CTF-styled challenges for Memory Forensics.

mXtract is a Linux-based tool for memory analysis and dumping with regex pattern search capabilities.

MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.

Recreates the File/Directory tree structure from an extracted $MFT file with detailed record mapping and analysis capabilities.