r3nzsec / irflow-timeline
PublicDFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, and Plaso files with built-in process inspection, lateral movement tracking, and persistence detection.
IRFlow Timeline is a native macOS application designed for forensic investigators to efficiently load, view, filter, and analyze large timeline datasets from CSV, Excel, EVTX, and Plaso files.
How It Works
You hear about a fast Mac app that makes sorting through huge security event logs easy, like a timeline explorer for investigations.
Get the app ready on your Mac and open it up – it feels smooth and modern right away.
Drag in your CSV spreadsheets, Excel sheets, or log files, even massive ones, and watch it load without slowing down.
See all your events lined up by time in a clear table you can zoom, sort, and scroll through endlessly.
Filter for clues, bookmark interesting events, add tags, and run quick checks for suspicious patterns.
Create a shareable report or filtered list of key events to hand off to your team or investigation report.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.