{"adoption": {"forks": 151, "observed_at": "2026-08-28T04:04:28.324798+00:00", "stars": 1351}, "canonical_url": "https://ross.abutalabs.com/products/beagle", "card": {"archived": false, "artifact_type": "application", "description": "Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.", "domain": ["security", "developer-tools", "analytics"], "enriched": true, "function": ["security", "parser", "data-visualization"], "health_score": 20, "homepage": null, "language": "Python", "license": "MIT", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["yampelo/beagle"], "name": "yampelo/beagle", "platform": ["python", "cross-platform"], "pushed_at": "2022-12-13T21:24:54+00:00", "repo": "yampelo/beagle", "stars": 1351, "tags": ["dfir", "incident-response", "digital-forensics", "threat-hunting", "graph-database", "networkx", "neo4j", "evtx", "sysmon", "graph", "docker", "web-server"], "topics": ["security", "digital-forensics", "incident-response", "graph", "dfir", "forensic-analysis", "threat-hunting"], "urls": [], "use_cases": ["transform evtx and sysmon logs into investigation graphs", "analyze fireeye hx triage data as a graph", "load windows memory images for forensic analysis", "send forensic graphs to neo4j or dgraph for threat hunting", "explore incident response artifacts interactively in a web ui", "combine multiple forensic data sources into one graph"], "what_it_is": "Beagle is an incident response and digital forensics tool that transforms security logs and data sources such as EVTX files, SysMon logs, FireEye HX triages, PCAPs, and memory images into graphs. It can be used as a Python library or through a web interface, and outputs graphs to Neo4j, DGraph, or local NetworkX objects.", "when_to_avoid": ["you need a full SIEM or log aggregation platform", "your data sources are unsupported by Beagle's datasource list", "you need actively developed tooling with frequent releases"], "when_to_choose": ["you need to turn DFIR artifacts like EVTX, SysMon, or memory dumps into navigable graphs", "you want a Python library plus web UI for forensic graph generation", "you want to push investigation graphs into Neo4j or DGraph"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/beagle", "repo": "yampelo/beagle", "role": "main", "score": 23}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:42:14.657478+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "682898b5f9eb7b7da3b81a55fcc7e8fea9cd0bad7fc4af397f4fb02d813c2692", "fetched_at": "2026-08-28T04:04:28.324798+00:00", "kind": "readme", "missing": false, "url": "https://github.com/yampelo/beagle"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:42:14.657478+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "682898b5f9eb7b7da3b81a55fcc7e8fea9cd0bad7fc4af397f4fb02d813c2692", "fetched_at": "2026-08-28T04:04:28.324798+00:00", "kind": "readme", "missing": false, "url": "https://github.com/yampelo/beagle"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:42:14.657478+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "682898b5f9eb7b7da3b81a55fcc7e8fea9cd0bad7fc4af397f4fb02d813c2692", "fetched_at": "2026-08-28T04:04:28.324798+00:00", "kind": "readme", "missing": false, "url": "https://github.com/yampelo/beagle"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:42:14.657478+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "682898b5f9eb7b7da3b81a55fcc7e8fea9cd0bad7fc4af397f4fb02d813c2692", "fetched_at": "2026-08-28T04:04:28.324798+00:00", "kind": "readme", "missing": false, "url": "https://github.com/yampelo/beagle"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:42:14.657478+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "682898b5f9eb7b7da3b81a55fcc7e8fea9cd0bad7fc4af397f4fb02d813c2692", "fetched_at": "2026-08-28T04:04:28.324798+00:00", "kind": "readme", "missing": false, "url": "https://github.com/yampelo/beagle"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:42:14.657478+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "682898b5f9eb7b7da3b81a55fcc7e8fea9cd0bad7fc4af397f4fb02d813c2692", "fetched_at": "2026-08-28T04:04:28.324798+00:00", "kind": "readme", "missing": false, "url": "https://github.com/yampelo/beagle"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:28.324798+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:42:14.657478+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "682898b5f9eb7b7da3b81a55fcc7e8fea9cd0bad7fc4af397f4fb02d813c2692", "fetched_at": "2026-08-28T04:04:28.324798+00:00", "kind": "readme", "missing": false, "url": "https://github.com/yampelo/beagle"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:42:14.657478+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "682898b5f9eb7b7da3b81a55fcc7e8fea9cd0bad7fc4af397f4fb02d813c2692", "fetched_at": "2026-08-28T04:04:28.324798+00:00", "kind": "readme", "missing": false, "url": "https://github.com/yampelo/beagle"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:42:14.657478+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "682898b5f9eb7b7da3b81a55fcc7e8fea9cd0bad7fc4af397f4fb02d813c2692", "fetched_at": "2026-08-28T04:04:28.324798+00:00", "kind": "readme", "missing": false, "url": "https://github.com/yampelo/beagle"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:42:14.657478+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "682898b5f9eb7b7da3b81a55fcc7e8fea9cd0bad7fc4af397f4fb02d813c2692", "fetched_at": "2026-08-28T04:04:28.324798+00:00", "kind": "readme", "missing": false, "url": "https://github.com/yampelo/beagle"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3146, "days_push": 1359, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 23, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}