timesketch
plaso
Our great sponsors
timesketch | plaso | |
---|---|---|
2 | 3 | |
2,485 | 1,617 | |
1.1% | 1.6% | |
8.7 | 8.9 | |
about 22 hours ago | 4 days ago | |
Python | Python | |
Apache License 2.0 | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
timesketch
-
Custom DFIR
Want to put those processed plaso files in an elasticsearch instance check out Timesketch - https://github.com/google/timesketch.
- Any Timeline self hosted types of software?
plaso
-
Custom DFIR
However, what you are trying to do has already been done. For collections look at velociraptor's offline collector https://github.com/Velocidex/velociraptor. For processing check out Log2Timeline (plaso) https://github.com/log2timeline/plaso.
-
Solving a child porn case (student environment)
My advice would be to go through a timeline to assert the activity before and after these files "appeared" . This can be done in log2timeline / plaso , this script can parse the raw image (or e01 or whatever you have) and build a timeline , parse it and sort it. Also look for lnk files and shellbags to see if the files were opened , used etc.
What are some alternatives?
IPED - IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by law enforcement or in a corporate investigation by private examiners.
mvt - MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.
OpenTimelineIO - Open Source API and interchange format for editorial timeline information.
WELA - WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)
TimelineJS - TimelineJS: A Storytelling Timeline built in JavaScript.
hindsight - Web browser forensics for Google Chrome/Chromium
beagle - Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
mac_apt - macOS (& ios) Artifact Parsing Tool
MalConfScan - Volatility plugin for extracts configuration data of known malware
turbinia - Automation and Scaling of Digital Forensics Tools
covid-19-germany-gae - COVID-19 statistics for Germany. For states and counties. With time series data. Daily updates. Official RKI numbers.
srum-dump - A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.