Skip to content

Timeline analysis

Timeline formats




log2timeline - An artifact timeline creation and analysis framework. Log2timeline has been superseded by Plaso.

Plaso - (Plaso Langar Að Safna Öllu), or super timeline all the things, is a Python-based engine used by several tools for automatic creation of timelines. Plaso default behavior is to create super timelines but it also supports creating more targeted timelines.

Simile Timeline and Timeplot

sorter - The Sleuth Kit's mactime sorting program.

TimeFlow - Visual timelines for investigation - source freely available

Timesketch - tool for collaborative forensic timeline analysis

Zeitline - Forensic timeline editor