log2timeline/plaso
Super timeline all the things observed · 2026-08-28
Health v2 · maintenance only
87/100
- Activity 95
- Release rhythm 69
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 108
- age_days: 4377
- days_rel: 44
- days_push: 30
- n_releases_24m: 4
Adoption not part of the score
2140 stars · 423 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Plaso (log2timeline) is a Python-based engine for automatically creating super timelines from timestamped events found in logs and files on computer systems. It is a extensible framework with parser and analysis plug-ins used widely in digital forensic investigations (DFIR).
Use cases
- create a super timeline of events from a disk image
- parse windows event logs and browser history for forensic analysis
- correlate timestamps from many file formats into one timeline
- build a timeline of user activity during an incident response
- write custom parsers for forensic artifacts
- automate repetitive forensic log analysis tasks
When to choose
- you need to aggregate timestamped events from many sources into a single forensic timeline
- you are a DFIR investigator analyzing a compromised system
- you want an extensible framework for writing custom artifact parsers
When to avoid
- you only need simple log aggregation without timestamp correlation
- you need real-time log monitoring rather than post-hoc analysis
- you want a GUI-only forensic suite
Facets
framework · maturity active
parser etl search-engine cli security developer-tools files python windows cli digital-forensics dfir timeline-analysis log-parsing incident-response forensics linux macos
2 sources
- readme: https://github.com/log2timeline/plaso · fetched 2026-08-28 · a4b2448788f5
- registry_pypi: https://pypi.org/pypi/plaso/json · fetched 2026-08-29 · 41278f8c7a76
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| log2timeline/plaso | main | 87 |
For agents
markdown · JSON · MCP: product_card(name="log2timeline/plaso")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem