
A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from processed triage evidence for Eric Zimmerman (EZ Tools) Kape, Axiom, Hayabusa, Chainsaw and Nirsoft into a unified timeline.
A high-speed forensic processing engine built for DFIR investigators. Quickly consolidate CSV output from top-tier triage tools into a unified mini timeline with built-in filtering, artifact detection, date filtering, keyword tagging, and deduplication.
Cross-Platform Browser History Parsing
ForensicWebHistoryParser — parses live browser history CSV from forensic-webhistory (Rust tool)Recovered Browser History Support
ForensicWebHistoryCarvedParser — parses recovered/deleted browser entriesCore Library Refactoring
ForensicTimeliner.Core class libraryRowsFilteredByDate was incorrectly calculated when no date filtering was applied, showing all rows as "filtered"RowCountAfterDedup)--NoPrompt flag for scripting and automation pipelinesTable of Contents
Combine csv output from
Automatic CSV discovery from triage directories (all configurable) with YAML
Timeline enrichment with with keyword tagging for use with Timeline Explorer. Automatically create a TLE session file based on keyword searching for CSV output.
RFC-4180-compliant export for compatibility with tools like Timeline Explorer
Date filtering and deduplication controls
Interactive Setup and Yaml Discovery Preview
TL;DR! Get some Kape/EZ Forensic Output
Download the exe and run:
ForensicTimeliner.exe --Interactive
ForensicTimeliner.exe --BaseDir C:\triage\hostname --ALL --OutputFile C:\timeline.csv
.\ForensicTimeliner.exe --ProcessEZ --BaseDir "C:\Users\admin0x\Desktop\sample_data\host_t800" --OutputFile "C:\Users\admin0x\Desktop\test" --ExportFormat csv --EnableTagger
Open TLE Session file from your output directory. If you move the file you need to updste the session file path.
Use default naming for your csv files and make sure they are inside the base directory you set. There is a fallback to auto discover csv files based on file headers, or adjust the filename in the YAML settings.
Use the --EnableTagger feature view command line to build a Timeline Explorer session file based on keyword tagging. Adjust keywords in config\keywords\keywords.yaml
Latest Release: v2.3
Download sample data for testing purposes here.
Interactive Menu
Timeline Explorer Support
