awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Outils d'analyse forensique de logs système

Classement mis à jour le 30 juin 2026

For outil de timeline forensique, the strongest matches are yamato-security/hayabusa (Hayabusa is a Windows event log analyzer that generates), withsecurelabs/chainsaw (Chainsaw is a Windows forensic analysis tool that ingests) and log2timeline/plaso (Plaso ingests system logs from multiple sources, automatically parses). wazuh/wazuh and opensearch-project/opensearch round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Analysez et reconstruisez des séquences d'événements historiques en parsant et corrélant les données issues de divers logs système.

Outils d'analyse forensique de logs système

Trouvez les meilleurs dépôts grâce à l'IA.Nous recherchons les dépôts les plus pertinents grâce à l'IA.
  • yamato-security/hayabusaAvatar de Yamato-Security

    Yamato-Security/hayabusa

    3,027Voir sur GitHub↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Hayabusa is a Windows event log analyzer that generates chronological forensic timelines from EVTX files, directly aligning with the request for log ingestion and timeline reconstruction, though its focus is Windows-specific threat hunting rather than multi-source ingestion or visual timeline exports.

    RustForensic Event CorrelationWindows Event Log Analyzers
    Voir sur GitHub↗3,027
  • withsecurelabs/chainsawAvatar de WithSecureLabs

    WithSecureLabs/chainsaw

    3,446Voir sur GitHub↗

    Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa

    Chainsaw is a Windows forensic analysis tool that ingests Windows event logs and reconstructs execution timelines, with event correlation and Sigma-rule–based search and filtering, fitting your search for a timeline reconstruction tool—though it is limited to Windows event logs and does not include built-in timeline visualization or broad log format support.

    RustForensic Event Correlation
    Voir sur GitHub↗3,446
  • log2timeline/plasoAvatar de log2timeline

    log2timeline/plaso

    2,095Voir sur GitHub↗

    Super timeline all the things

    Plaso ingests system logs from multiple sources, automatically parses and correlates events into a chronological timeline for incident reconstruction, and supports search, filtering, and export to CSV and other formats—exactly the kind of tool this search targets.

    PythonDigital ForensicsForensics and Incident ResponseTimeline Analysis
    Voir sur GitHub↗2,095
  • wazuh/wazuhAvatar de wazuh

    wazuh/wazuh

    14,779Voir sur GitHub↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Wazuh is a security monitoring and SIEM platform that ingests logs from distributed agents, correlates events, and provides a timeline view for incident reconstruction, which aligns with the requested log analysis and timeline reconstruction capability even though its primary focus is security rather than general-purpose forensic timelines.

    CTelemetry Correlation Engines
    Voir sur GitHub↗14,779
  • opensearch-project/opensearchAvatar de opensearch-project

    opensearch-project/OpenSearch

    13,196Voir sur GitHub↗

    OpenSearch is a distributed search and analytics engine designed for indexing, searching, and analyzing massive volumes of structured and unstructured data in real time. It functions as a comprehensive platform that integrates enterprise-grade search capabilities, a vector database for high-dimensional similarity lookups, and a unified observability suite for monitoring logs, metrics, and traces across complex distributed environments. The platform distinguishes itself through its support for agentic workflow automation, allowing users to orchestrate multi-agent tasks and integrate foundation

    OpenSearch is a distributed search and analytics platform with an integrated observability suite that ingests logs from multiple sources and visualizes them as chronological timelines via dashboards, fitting the log analysis and timeline reconstruction use case, though it is a broader engine rather than a specialized timeline tool.

    JavaTelemetry CorrelationSecurity Event Correlation
    Voir sur GitHub↗13,196
  • openobserve/openobserveAvatar de openobserve

    openobserve/openobserve

    17,937Voir sur GitHub↗

    OpenObserve is a unified observability data platform designed to ingest, store, and analyze logs, metrics, and traces. It functions as a cloud-native monitoring tool that centralizes telemetry from diverse sources, including standard collectors and cloud service providers, into a single, scalable system. By utilizing a columnar storage engine backed by object storage, the platform enables efficient long-term data retention and high-performance analytical querying. The platform distinguishes itself through deep integration with artificial intelligence, allowing users to query data using natura

    OpenObserve is a unified observability platform that ingests logs from multiple sources and provides search and analytics, fitting the need for timeline-based incident reconstruction, though its broader scope and lack of explicit timeline visualization features make it a narrower fit than a dedicated timeline tool.

    TypeScriptTelemetry Correlation
    Voir sur GitHub↗17,937

Related searches

  • outil de triage forensique
  • un outil de gestion des post-mortems d'incidents
  • un SIEM auto-hébergé
  • un outil pour la criminalistique numérique et l'analyse mémoire
  • un moteur de recherche et d'analyse de logs
  • outil de carving et de récupération de fichiers
  • outil d'analyse forensique pour navigateur
  • un SIEM open source pour l'analyse de logs