Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
forensic-timeliner — A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from processed triage evidence for Eric Zimmerman (EZ Tools) Kape, Axiom, Hayabusa, Chainsaw and Nirsoft into a unified timeline. | Kitploit
Tools/GitHubGitHub/acquiredsecurity/forensic-timeliner
ForensicsIncident ResponseLog AnalysisRepository Deleted
GitHubacquiredsecurity/forensic-timeliner

forensic-timeliner

A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from processed triage evidence for Eric Zimmerman (EZ Tools) Kape, Axiom, Hayabusa, Chainsaw and Nirsoft into a unified timeline.

The upstream repository was not found during the latest Kitploit update check. This listing remains available for reference, but it has been removed from search results.
33338117 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

A high-speed forensic processing engine built for DFIR investigators. Quickly consolidate CSV output from top-tier triage tools into a unified mini timeline with built-in filtering, artifact detection, date filtering, keyword tagging, and deduplication.

Version Downloads Stars Contributors Maintained C# .NET 9


Release

Forensic Timeliner v2.3 – Release Notes

New Features

  • Cross-Platform Browser History Parsing

    • New ForensicWebHistoryParser — parses live browser history CSV from forensic-webhistory (Rust tool)
    • Supports Chrome, Firefox, Safari, Brave, Edge, Opera, Vivaldi, and Arc
    • Activity detection: Search queries, Downloads, and File Open events automatically enriched in description
    • Header validation to distinguish from other CSV formats
  • Recovered Browser History Support

    • New ForensicWebHistoryCarvedParser — parses recovered/deleted browser entries
    • Handles carved SQLite database rows with reduced column set
    • Identifies recovery source (e.g., "Carved from WAL", "Carved from Journal")
  • Core Library Refactoring

    • Extracted all parsers, models, utilities, and interfaces into ForensicTimeliner.Core class library
    • Enables reuse by the web platform without code duplication
    • All existing parsers (EZ Tools, Hayabusa, Chainsaw, Nirsoft, Axiom) moved to Core

Bug Fixes

  • Fixed date filtering display — RowsFilteredByDate was incorrectly calculated when no date filtering was applied, showing all rows as "filtered"
  • Fixed deduplication counter initialization (RowCountAfterDedup)

Other Changes

  • License updated to CC BY-NC 4.0
  • Added --NoPrompt flag for scripting and automation pipelines


Table of Contents

  • Main Features
  • Quick Start
  • Downloads
  • Screenshots
  • Command Line Arguments
  • Timeline Output
  • Yaml Config
  • Tool Documentation
  • Usage Guide
  • Artifact and Output Support Table
  • License

Main Features

  • Combine csv output from

    • EZ Tools / Kape
    • Axiom
    • Chainsaw
    • Hayabusa
    • Nirsoft
    • forensic-webhistory (cross-platform browser history)
    • output data into a unified timeline
  • Automatic CSV discovery from triage directories (all configurable) with YAML

    • Yaml files already use default namings for tools with default output
    • For tools like Hayabusa where you can set the file output name you should name the file some variaition of Hayabusa.csv and put it in a folder named Hayabusa
    • Simply provide the base directory of where the triage output lives and the tool will attempt to discover the csv files based on
    • File Name
    • Folder Name
    • File Headers
    • For Event Logs Channel\Provider Filters
    • For MFT File Extension and Path Filters
  • Timeline enrichment with with keyword tagging for use with Timeline Explorer. Automatically create a TLE session file based on keyword searching for CSV output.

  • RFC-4180-compliant export for compatibility with tools like Timeline Explorer

  • Date filtering and deduplication controls

  • Interactive Setup and Yaml Discovery Preview


Quick Start

TL;DR! Get some Kape/EZ Forensic Output

Download the exe and run:

ForensicTimeliner.exe --Interactive
ForensicTimeliner.exe --BaseDir C:\triage\hostname --ALL --OutputFile C:\timeline.csv
.\ForensicTimeliner.exe --ProcessEZ --BaseDir "C:\Users\admin0x\Desktop\sample_data\host_t800" --OutputFile "C:\Users\admin0x\Desktop\test" --ExportFormat csv --EnableTagger
  • Open TLE Session file from your output directory. If you move the file you need to updste the session file path.

  • Use default naming for your csv files and make sure they are inside the base directory you set. There is a fallback to auto discover csv files based on file headers, or adjust the filename in the YAML settings.

  • Use the --EnableTagger feature view command line to build a Timeline Explorer session file based on keyword tagging. Adjust keywords in config\keywords\keywords.yaml


Downloads

Latest Release: v2.3

Download sample data for testing purposes here.

Sample Data


Screenshots

Interactive Menu

image

Timeline Explorer Support image

  • Auto coloring applied in TLE with latest plugin files
  • Automatically Build a TLE Session File with tagged rows based on keywords
    • Edit the Keywords config file and add your keywords
    • Run ForensicTimeliner.exe from the command line using the --EnableTagger flag

Command Line Arguments