Important
This repository is Yamato Security's Linux fork of Renzon Cruz's original IRFlow Timeline. We created it because the original project did not provide a Linux port or Linux release packages. The application design and the great majority of its functionality come from Renzon's project; the Linux packaging, compatibility work, and validation are maintained here.
Native forensic timeline analysis for glibc-based Linux distributions on x64 and ARM64. Import, search, and investigate EVTX, CSV, TSV, XLSX, Plaso, $MFT, $J, triage collections, and local AI-assistant artifacts. IRFlow Timeline uses Electron, SQLite, and FTS5 to keep multi-million-row investigations responsive.
IRFlow Timeline keeps the familiar parts of Eric Zimmerman's Timeline Explorer—fast tabular review, sorting, filtering, searching, column management, bookmarks, and export—but goes substantially beyond a timeline grid:
- Direct evidence ingestion — Open raw EVTX, raw NTFS
$MFTand$UsnJrnl($J), Plaso databases, CSV, TSV, and XLSX without first converting everything to a common CSV. - Built-in investigation views — Process trees, lateral-movement graphs, RDP session reconstruction, persistence analysis, timestomping detection, ransomware-impact analysis, IOC review, and file-activity heatmaps.
- Detection and enrichment — Run bundled Hayabusa/Sigma rules against EVTX and enrich indicators through VirusTotal with local caching.
- Cross-source analysis — Work with multiple evidence tabs, correlate related telemetry, compare timelines, group events, and pivot between findings and source rows.
- Large-dataset performance — SQLite-backed imports, streaming parsers, virtualized grids, indexes, and FTS5 search support timelines containing millions of rows.
- Windows artifact workflows — KAPE/triage discovery, VHDX artifact extraction, RDP bitmap-cache recovery with bundled bmc-tools and Python, and offline EVTX message rendering.
- AI application forensics — Collect and normalize histories from Claude Code, Codex, ChatGPT, Gemini CLI, Cursor, Copilot, Windsurf, Continue, and other supported assistants, including secret/token exposure checks.
- Analyst reporting — Tags, bookmarks, saved sessions, filtered exports, evidence provenance, and HTML/PDF reporting from analyzer results.
- AI Artifacts — Collect local AI history from Claude Code, Codex, Grok Build, ChatGPT Desktop, Gemini CLI, Cursor, Copilot, Windsurf, and Continue into one timeline tab; ChatGPT Computer History for macOS interaction telemetry; AI Secret Hunt for exposed keys, tokens, and credentials
- Raw NTFS Artifact Import — Direct ingestion of
$MFTand$UsnJrnl($J) with full path reconstruction, SI/FN timestamps, and change reason mapping - Ransomware Analytics — Automated impact analysis from
$MFTdata: bulk rename detection, entropy-based extension analysis, ransom note identification, and temporal clustering - VirusTotal Enrichment — IOC matching with bulk VT lookups, malware family extraction, verdict badges, relationship pivoting, and local caching
- Process Inspector — Parent-child process tree analysis with 340+ MITRE ATT&CK detection rules
- Lateral Movement Tracker — Network logon and RDP session visualization as interactive force-directed graphs
- RDP Bitmap Cache Recovery — Recover
bcache*.bmcandcache????.binartifacts with bundled bmc-tools, preview images, and export evidence packages - Persistence Analyzer — 30+ persistence techniques with account chain detection, cross-technique correlation, and PowerShell 4104 script block reassembly
- IOC Matching — 17+ indicator categories with auto-defanging, inline highlighting, CSV/HTML export with VT enrichment data
For the upstream feature documentation, visit the original IRFlow Timeline documentation. Linux package and runtime instructions are in LINUX.md.
Prerequisites (for developers only):
- A glibc-based Linux desktop
- Node.js 22.14 or later
- An x64 or ARM64 system matching the build you want to run
git clone https://github.com/Yamato-Security/irflow-timeline-linux.git
cd irflow-timeline-linux
npm ci --ignore-scripts
npx patch-package
node node_modules/electron/install.js
# Development (hot-reload)
npm run dev
# Build + launch
npm run start
# Linux ARM64 AppImage + tar.gz
npm run dist:linux:arm64
# Or, for Intel/AMD Linux
npm run dist:linux:x64Linux packages are written under release/linux/. Both AppImage and tar.gz packages bundle Hayabusa, its offline rules, and bmc-tools. The optional RDP bitmap-cache workflow uses the host's python3. The release packages are unsigned and intentionally do not inherit the original repository's automatic-update feed.
This Linux port is based on IRFlow Timeline, created by Renzon Cruz. IRFlow Timeline was inspired by Eric Zimmerman's Timeline Explorer.
| Project | Usage | Link |
|---|---|---|
| Electron | Application framework | electron/electron |
| better-sqlite3 | High-performance SQLite engine with WAL mode, FTS5 | WiseLibs/better-sqlite3 |
| @ts-evtx/core | Native Windows EVTX event log parsing | NickSmet/ts-evtx |
| Plaso (log2timeline) | Forensic timeline generation (we import Plaso SQLite output) | log2timeline/plaso |
| ExcelJS | XLSX streaming reader | exceljs/exceljs |
| SheetJS (xlsx) | XLSX parsing | SheetJS/sheetjs |
| csv-parser | CSV/TSV streaming parser | mafintosh/csv-parser |
| React | UI rendering | facebook/react |
| Vite | Build tooling and hot-reload | vitejs/vite |
| VitePress | Documentation site | vuejs/vitepress |
| electron-builder | Linux and macOS application packaging | electron-userland/electron-builder |
| Hayabusa | Sigma-based Windows event-log detection | Yamato-Security/hayabusa |
| bmc-tools | RDP Bitmap Cache recovery | ANSSI-FR/bmc-tools |
- Eric Zimmerman -- Timeline Explorer for Windows, the original inspiration for this project
- log2timeline/Plaso -- Super timeline generation framework by Kristinn Gudjonsson and contributors
- SANS DFIR -- DFIR training and community resources
- The DFIR Report -- Real-world intrusion analysis reports that informed threat detection patterns
- CyberCX -- NTFS $UsnJrnl research that informed $J parsing implementation
Thanks to the following people for testing and providing feedback:
Apache-2.0
