awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

系统日志取证工具

排名更新于 2026年6月30日

For 取证时间线分析工具, the strongest matches are yamato-security/hayabusa (Hayabusa is a Windows event log analyzer that generates), withsecurelabs/chainsaw (Chainsaw is a Windows forensic analysis tool that ingests) and log2timeline/plaso (Plaso ingests system logs from multiple sources, automatically parses). wazuh/wazuh and opensearch-project/opensearch round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

通过解析和关联各类系统日志,分析并重构历史事件序列。

系统日志取证工具

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • yamato-security/hayabusaYamato-Security 的头像

    Yamato-Security/hayabusa

    3,027在 GitHub 上查看↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Hayabusa is a Windows event log analyzer that generates chronological forensic timelines from EVTX files, directly aligning with the request for log ingestion and timeline reconstruction, though its focus is Windows-specific threat hunting rather than multi-source ingestion or visual timeline exports.

    RustForensic Event CorrelationWindows Event Log Analyzers
    在 GitHub 上查看↗3,027
  • withsecurelabs/chainsawWithSecureLabs 的头像

    WithSecureLabs/chainsaw

    3,446在 GitHub 上查看↗

    Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa

    Chainsaw is a Windows forensic analysis tool that ingests Windows event logs and reconstructs execution timelines, with event correlation and Sigma-rule–based search and filtering, fitting your search for a timeline reconstruction tool—though it is limited to Windows event logs and does not include built-in timeline visualization or broad log format support.

    RustForensic Event Correlation
    在 GitHub 上查看↗3,446
  • log2timeline/plasolog2timeline 的头像

    log2timeline/plaso

    2,095在 GitHub 上查看↗

    Super timeline all the things

    Plaso ingests system logs from multiple sources, automatically parses and correlates events into a chronological timeline for incident reconstruction, and supports search, filtering, and export to CSV and other formats—exactly the kind of tool this search targets.

    PythonDigital ForensicsForensics and Incident ResponseTimeline Analysis
    在 GitHub 上查看↗2,095
  • wazuh/wazuhwazuh 的头像

    wazuh/wazuh

    14,779在 GitHub 上查看↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Wazuh is a security monitoring and SIEM platform that ingests logs from distributed agents, correlates events, and provides a timeline view for incident reconstruction, which aligns with the requested log analysis and timeline reconstruction capability even though its primary focus is security rather than general-purpose forensic timelines.

    CTelemetry Correlation Engines
    在 GitHub 上查看↗14,779
  • opensearch-project/opensearchopensearch-project 的头像

    opensearch-project/OpenSearch

    13,196在 GitHub 上查看↗

    OpenSearch is a distributed search and analytics engine designed for indexing, searching, and analyzing massive volumes of structured and unstructured data in real time. It functions as a comprehensive platform that integrates enterprise-grade search capabilities, a vector database for high-dimensional similarity lookups, and a unified observability suite for monitoring logs, metrics, and traces across complex distributed environments. The platform distinguishes itself through its support for agentic workflow automation, allowing users to orchestrate multi-agent tasks and integrate foundation

    OpenSearch is a distributed search and analytics platform with an integrated observability suite that ingests logs from multiple sources and visualizes them as chronological timelines via dashboards, fitting the log analysis and timeline reconstruction use case, though it is a broader engine rather than a specialized timeline tool.

    JavaTelemetry CorrelationSecurity Event Correlation
    在 GitHub 上查看↗13,196
  • openobserve/openobserveopenobserve 的头像

    openobserve/openobserve

    17,937在 GitHub 上查看↗

    OpenObserve is a unified observability data platform designed to ingest, store, and analyze logs, metrics, and traces. It functions as a cloud-native monitoring tool that centralizes telemetry from diverse sources, including standard collectors and cloud service providers, into a single, scalable system. By utilizing a columnar storage engine backed by object storage, the platform enables efficient long-term data retention and high-performance analytical querying. The platform distinguishes itself through deep integration with artificial intelligence, allowing users to query data using natura

    OpenObserve is a unified observability platform that ingests logs from multiple sources and provides search and analytics, fitting the need for timeline-based incident reconstruction, though its broader scope and lack of explicit timeline visualization features make it a narrower fit than a dedicated timeline tool.

    TypeScriptTelemetry Correlation
    在 GitHub 上查看↗17,937

Related searches

  • 取证分类工具
  • 用于管理事件复盘的工具
  • 自托管安全信息与事件管理 (SIEM) 系统
  • 用于数字取证和内存分析的工具
  • 日志搜索与分析引擎
  • 文件雕刻与恢复工具
  • 浏览器取证工具
  • 用于日志分析的开源 SIEM