AutoTimeliner lets you automagically extract forensic timeline from volatile memory dumps.
AutoTimeline automates this workflow:
- Identify correct volatility profile for the memory image.
- Runs the timeliner plugin against volatile memory dump using volatility.
- Runs the mftparser volatility plugin, in order to extract $MFT from memory and generate a bodyfile.
- Runs the shellbags volatility plugin in order to generate a bodyfile of the user activity.
- Merges the timeliner, mftparser and shellbags output files into a single bodyfile.
- Sorts and filters the bodyfile using mactime and exports data as CSV.
This is free and open source software.
Website: github.com/andreafortuna/autotimeliner
Support:
Developer: Andrea Fortuna
License: MIT License

AutoTimeliner is written in Python. Learn Python with our recommended free books and free tutorials.
Related Software
| Forensics Memory Tools | |
|---|---|
| MemProcFS | View physical memory as files in a virtual file system |
| pypykatz | Python implementation of Mimikatz |
| PCILeech | Security research and memory acquisition tool |
| Volatility | Advanced memory forensics framework |
| AVML | Acquire Volatile Memory for Linux |
| Volshell | CLI tool for working with memory |
| LeechCore | Physical memory acquisition library |
| EVTXtract | Recovers and reconstructs fragments of EVTX log files |
| mquire | Memory forensics and analysis tool |
| LEMON | Memory acquisition utility |
| yarp | Yet Another Registry Parser |
| emd | Command line memory acquisition tool for Linux systems |
| AutoTimeliner | Extract forensic timeline from volatile memory dump |
Read our verdict in the software roundup.
Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more. Discovered a useful open source Linux program that we haven’t covered yet? Let us know by completing this form. |

