Digital forensics Institution-led
orc2timeline
Local command-line utility that processes one or more DFIR ORC forensic archives and creates a per-host timeline for incident analysis.
By ANSSI · France
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Digital forensics
- Developer or maintainer
- ANSSI
- Recorded country
- France
- Product model
- Open source
- Deployment
- Desktop/CLI
- Software license
- LGPL-3.0
- Upstream status
- Maintenance unconfirmed
- Evidence class
- Institution-led
What the sources establish
Origin notePublished in ANSSI’s official GitHub organization as a standalone forensic parser.
Reported capabilities
- Accepts one or more ORC archives.
- Groups archives by host and writes compressed CSV timelines.
- Installs as a Python package with pip.
Scope and limits
Narrow parser dependent on DFIR ORC archives; current maintenance cadence was not verified. Distinct timeline output from DFIR-OGRE’s general structured extraction.
Inspect the research evidence 3 source observations
identity / capabilities / deployment / license
README documents pip installation, processing ORC archive directories, host grouping and compressed CSV timelines; repository labels the license LGPL-3.0.
Read sourceorigin / country
ANSSI profile says repositories in its organization are projects developed by the French agency.
Read sourcemaintenance
Upstream page does not establish a current release or maintenance schedule, so status remains unknown.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.
A digital forensics triage and evidence workflow