Skip to content

log2timeline/plaso

This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.

Folders and files

NameName
Last commit message
Last commit date

Latest commit

80ff8c0 · Sep 30, 2017
Mar 18, 2016
Sep 30, 2017
Jul 20, 2016
Sep 26, 2017
Sep 30, 2017
Aug 24, 2017
Sep 22, 2017
Sep 22, 2017
Sep 26, 2017
Jul 5, 2017
Sep 2, 2017
Aug 28, 2017
May 12, 2017
Sep 18, 2016
Feb 3, 2016
Dec 31, 2015
May 20, 2017
May 20, 2017
May 17, 2017
May 17, 2017
Aug 7, 2017
Aug 8, 2017
Jul 12, 2017
Aug 8, 2017
May 29, 2017
Aug 8, 2017
Aug 5, 2017
Jul 3, 2017

Repository files navigation

plaso (Plaso Langar Að Safna Öllu)

super timeline all the things

In short, plaso is a Python-based backend engine for the tool log2timeline.

A longer version

log2timeline is a tool designed to extract timestamps from various files found on a typical computer system(s) and aggregate them.

The initial purpose of plaso was to collect all timestamped events of interest on a computer system and have them aggregated in a single place for computer forensic analysis (aka Super Timeline).

However plaso has become a framework that supports:

  • adding new parsers or parsing plug-ins;
  • adding new analysis plug-ins;
  • writing one-off scripts to automate repetitive tasks in computer forensic analysis or equivalent.

And is moving to support:

  • adding new general purpose parses/plugins that may not have timestamps associated to them;
  • adding more analysis context;
  • tagging events;
  • allowing more targeted approach to the collection/parsing.

Project status

Travis-CI AppVeyor Coveralls
Build Status Build status Coverage Status

Also see