timeliner Logo

timeliner

0
Free
Visit Website

A rewrite of mactime, timeliner uses a real expression engine to parse and apply filtering logic, allowing complex queries like filtering events based on time, path, weekday, and date using a BPF syntax. Although still in alpha stage, its killer feature is the advanced expression engine.

FEATURES

ALTERNATIVES

A library to access and parse Windows NT Registry File (REGF) format.

A script for extracting common Windows artifacts from source images and VSCs with detailed dependencies and usage instructions.

Exiv2 is a C++ library and command-line utility for image metadata manipulation.

dc3dd is a patch to the GNU dd program, tailored for forensic acquisition with features like hashing and file verification.

A recognition framework for identifying products, services, operating systems, and hardware by matching fingerprints against network probes.

Open source digital forensics tools for analyzing disk images and recovering files.

A library to access FileVault Drive Encryption (FVDE) encrypted volumes on Mac OS X systems.

A command-line utility for extracting human-readable text from binary files.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved