Skip to main content

Plaso (Plaso Langar Að Safna Öllu) - super timeline all the things

Plaso (Plaso Langar Að Safna Öllu), or super timeline all the things, is a Python-based engine used by several tools for automatic creation of timelines. Plaso default behavior is to create super timelines but it also supports creating more targeted timelines.

These timelines support digital forensic investigators/analysts, to correlate the large amount of information found in logs and other files found on an average computer.

A longer version

The initial purpose of Plaso was to collect all timestamped events of interest on a computer system and have them aggregated in a single place for computer forensic analysis (aka Super Timeline).

However Plaso has become a framework that supports:

  • adding new parsers or parsing plug-ins;
  • adding new analysis plug-ins;
  • writing one-off scripts to automate repetitive tasks in computer forensic analysis or equivalent.

And is moving to support:

  • adding new general purpose parses/plugins that may not have timestamps associated to them;
  • adding more analysis context;
  • tagging events;
  • allowing more targeted approach to the collection/parsing.

Also see

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

plaso-20260720.tar.gz (2.9 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

plaso-20260720-py3-none-any.whl (3.0 MB view details)

Uploaded Python 3

File details

Details for the file plaso-20260720.tar.gz.

File metadata

  • Download URL: plaso-20260720.tar.gz
  • Upload date:
  • Size: 2.9 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for plaso-20260720.tar.gz
Algorithm Hash digest
SHA256 c868892d9f203a3d002a907ef1942344ab06706412f32aefef856940a371927e
MD5 ccbc84c8bfddab3f0556feb3bfb69b41
BLAKE2b-256 c37c738f884fdf42a23744f868e2d3184cb273978ac5bcb4bb77e40f1e66b74c

See more details on using hashes here.

Provenance

The following attestation bundles were made for plaso-20260720.tar.gz:

Publisher: build_wheel.yml on log2timeline/plaso

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file plaso-20260720-py3-none-any.whl.

File metadata

  • Download URL: plaso-20260720-py3-none-any.whl
  • Upload date:
  • Size: 3.0 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for plaso-20260720-py3-none-any.whl
Algorithm Hash digest
SHA256 d9ade1e336a7900bd0e173a21c26b4c69eba6f6fbeef8ef23d6d332e40405782
MD5 abb1e17f3ef176d523892dcf12325987
BLAKE2b-256 3e151dc165e541f64f069b36b3292aa0e31a1e586a8079cb3530241d771fe6b1

See more details on using hashes here.

Provenance

The following attestation bundles were made for plaso-20260720-py3-none-any.whl:

Publisher: build_wheel.yml on log2timeline/plaso

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page