Digital forensics Institution-led

orc2timeline

Local command-line utility that processes one or more DFIR ORC forensic archives and creates a per-host timeline for incident analysis.

By ANSSI · France

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
ANSSI
Recorded country
France
Product model
Open source
Deployment
Desktop/CLI
Software license
LGPL-3.0
Upstream status
Maintenance unconfirmed
Evidence class
Institution-led

What the sources establish

Origin note

Published in ANSSI’s official GitHub organization as a standalone forensic parser.

Reported capabilities

  • Accepts one or more ORC archives.
  • Groups archives by host and writes compressed CSV timelines.
  • Installs as a Python package with pip.

Scope and limits

Narrow parser dependent on DFIR ORC archives; current maintenance cadence was not verified. Distinct timeline output from DFIR-OGRE’s general structured extraction.

Inspect the research evidence 3 source observations
  1. identity / capabilities / deployment / license

    README documents pip installation, processing ORC archive directories, host grouping and compressed CSV timelines; repository labels the license LGPL-3.0.

    Read source
  2. origin / country

    ANSSI profile says repositories in its organization are projects developed by the French agency.

    Read source
  3. maintenance

    Upstream page does not establish a current release or maintenance schedule, so status remains unknown.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow