timesketch
mac_apt
Our great sponsors
timesketch | mac_apt | |
---|---|---|
2 | 2 | |
2,485 | 714 | |
1.2% | - | |
8.7 | 7.6 | |
3 days ago | 19 days ago | |
Python | Python | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
timesketch
-
Custom DFIR
Want to put those processed plaso files in an elasticsearch instance check out Timesketch - https://github.com/google/timesketch.
- Any Timeline self hosted types of software?
mac_apt
- My productivity app is a never-ending .txt file
-
Mac OS
If you are capable of running cli applications macApt is pretty sophisticated and feature rich analysis tool for MacOS. If it doesn’t have the exact feature you need you could extend it to identify activities of this ‘foreign’ software. Full disclosure I contributed to this project by developing the Docker container, and published the work, unpaid.
What are some alternatives?
plaso - Super timeline all the things
usbrip - Tracking history of USB events on GNU/Linux
WELA - WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)
RecuperaBit - A tool for forensic file system reconstruction.
TimelineJS - TimelineJS: A Storytelling Timeline built in JavaScript.
docker-explorer - A tool to help forensicate offline docker acquisitions
hindsight - Web browser forensics for Google Chrome/Chromium
beagle - Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
MalConfScan - Volatility plugin for extracts configuration data of known malware
turbinia - Automation and Scaling of Digital Forensics Tools
velociraptor - Digging Deeper....
varc - Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use when investigating a security incident.