Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Incident Response
  3. Plaso

Plaso

Apache-2.0Python20260720

A Python-based engine for automatic creation of super timelines from computer system logs and files for digital forensic analysis.

Visit WebsiteGitHubGitHub
2.1k stars424 forks0 contributors

What is Plaso?

Plaso is a Python-based engine that automatically creates super timelines from timestamped events found on computer systems. It aggregates logs and file metadata into comprehensive timelines that help digital forensic investigators correlate information during forensic examinations. The tool supports both broad super timelines and more targeted timeline approaches depending on investigation needs.

Target Audience

Digital forensic investigators, incident response analysts, and security professionals who need to analyze computer system artifacts and correlate events across multiple log sources and files.

Value Proposition

Plaso provides an extensible framework that goes beyond simple timeline creation, allowing analysts to add custom parsers and analysis plug-ins while automating repetitive forensic tasks. Its evolution from a timeline tool to a comprehensive forensic framework makes it uniquely adaptable to changing investigation requirements.

Overview

Super timeline all the things

Use Cases

Best For

  • Creating comprehensive super timelines from multiple system artifacts during forensic investigations
  • Correlating events across different log files and system files in incident response scenarios
  • Automating repetitive parsing and analysis tasks in digital forensic workflows
  • Developing custom parsers for specialized or emerging forensic artifacts
  • Building targeted timelines for specific investigation focuses rather than collecting everything
  • Extending forensic analysis capabilities through plug-ins and scripting

Not Ideal For

  • Real-time security monitoring systems that require immediate alerting and live event processing
  • Simple log aggregation projects without the need for complex timeline correlation or forensic analysis
  • Non-forensic data analysis tasks, such as business intelligence or general data processing that don't rely on timestamped events

Pros & Cons

Pros

Comprehensive Super Timelines

Aggregates all timestamped events from a computer system into a single timeline for forensic analysis, as emphasized in the README for correlating large amounts of information.

Extensible Parser Framework

Supports adding new parsers and plug-ins, allowing adaptation to evolving forensic requirements, which is highlighted in the features for future-proofing.

Automation Scripting Support

Enables writing one-off scripts to automate repetitive forensic tasks, improving workflow efficiency as noted in the key features.

Targeted Timeline Creation

Allows creation of focused timelines based on specific forensic needs, rather than collecting everything, as referenced in the README for more efficient investigations.

Cons

Steep Learning Curve

Requires expertise in digital forensics and Python to effectively use custom parsers and analysis plug-ins, making it less accessible for generalists.

Complex Setup and Configuration

As an extensible framework, initial setup and customization can be time-consuming and non-trivial, relying heavily on external documentation and community support.

Documentation Reliance

Users must depend on external resources like Read the Docs and community channels, which may be incomplete or require active engagement for troubleshooting.

Frequently Asked Questions

Quick Stats

Stars2,148
Forks424
Contributors0
Open Issues255
Last commit11 days ago
CreatedSince 2014

Tags

#parsing#digital-forensics#timeline#automation-tools#python#log-analysis#forensics#incident-response#timeline-analysis#computer-forensics

Built With

P
Python

Links & Resources

Website

Included in

Incident Response8.9k
Auto-fetched 9 hours ago

Related Projects

TimesketchTimesketch

Collaborative forensic timeline analysis

Stars3,410
Forks663
Last commit4 days ago
Aurora Incident ResponseAurora Incident Response

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Stars1,077
Forks130
Last commit2 years ago
MorgueMorgue

post mortem tracker

Stars1,019
Forks126
Last commit7 years ago
HighlighterHighlighter

Free Tool available from Fire/Mandiant that will depict log/text file that can highlight areas on the graphic, that corresponded to a key word or phrase. Good for time lining an infection and what was done post compromise

Stars0
Forks0
Last commit
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub