For outil de timeline forensique, the strongest matches are yamato-security/hayabusa (Hayabusa is a Windows event log analyzer that generates), withsecurelabs/chainsaw (Chainsaw is a Windows forensic analysis tool that ingests) and log2timeline/plaso (Plaso ingests system logs from multiple sources, automatically parses). wazuh/wazuh and opensearch-project/opensearch round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Analysez et reconstruisez des séquences d'événements historiques en parsant et corrélant les données issues de divers logs système.
Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment
Hayabusa is a Windows event log analyzer that generates chronological forensic timelines from EVTX files, directly aligning with the request for log ingestion and timeline reconstruction, though its focus is Windows-specific threat hunting rather than multi-source ingestion or visual timeline exports.
Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa
Chainsaw is a Windows forensic analysis tool that ingests Windows event logs and reconstructs execution timelines, with event correlation and Sigma-rule–based search and filtering, fitting your search for a timeline reconstruction tool—though it is limited to Windows event logs and does not include built-in timeline visualization or broad log format support.
Super timeline all the things
Plaso ingests system logs from multiple sources, automatically parses and correlates events into a chronological timeline for incident reconstruction, and supports search, filtering, and export to CSV and other formats—exactly the kind of tool this search targets.
Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito
Wazuh is a security monitoring and SIEM platform that ingests logs from distributed agents, correlates events, and provides a timeline view for incident reconstruction, which aligns with the requested log analysis and timeline reconstruction capability even though its primary focus is security rather than general-purpose forensic timelines.
OpenSearch is a distributed search and analytics engine designed for indexing, searching, and analyzing massive volumes of structured and unstructured data in real time. It functions as a comprehensive platform that integrates enterprise-grade search capabilities, a vector database for high-dimensional similarity lookups, and a unified observability suite for monitoring logs, metrics, and traces across complex distributed environments. The platform distinguishes itself through its support for agentic workflow automation, allowing users to orchestrate multi-agent tasks and integrate foundation
OpenSearch is a distributed search and analytics platform with an integrated observability suite that ingests logs from multiple sources and visualizes them as chronological timelines via dashboards, fitting the log analysis and timeline reconstruction use case, though it is a broader engine rather than a specialized timeline tool.
OpenObserve is a unified observability data platform designed to ingest, store, and analyze logs, metrics, and traces. It functions as a cloud-native monitoring tool that centralizes telemetry from diverse sources, including standard collectors and cloud service providers, into a single, scalable system. By utilizing a columnar storage engine backed by object storage, the platform enables efficient long-term data retention and high-performance analytical querying. The platform distinguishes itself through deep integration with artificial intelligence, allowing users to query data using natura
OpenObserve is a unified observability platform that ingests logs from multiple sources and provides search and analytics, fitting the need for timeline-based incident reconstruction, though its broader scope and lack of explicit timeline visualization features make it a narrower fit than a dedicated timeline tool.