Blazing Fast
Phase-tuned SQLite engine with 1GB import cache, adaptive 100K-row batches, and background async indexing. Sub-100ms filtered queries on 10M+ rows. Handles 30GB+ files without breaking a sweat.
High-performance forensic timeline viewer for MacOS. Handles large files for timeline analysis. CSV/TSV/XLSX/EVTX/Plaso
IRFlow Timeline is a native macOS application purpose-built for digital forensics and incident response (DFIR) investigators. Inspired by Eric Zimmerman's Timeline Explorer for Windows, it brings high-performance timeline analysis to macOS with a modern interface and advanced analytics.
| Format | Extensions | Description |
|---|---|---|
| CSV/TSV | .csv, .tsv, .txt, .log | Auto-detects delimiters (comma, tab, pipe) |
| Excel | .xlsx, .xls, .xlsm | Streaming reader (XLSX) + legacy binary parser (XLS) with sheet selection |
| EVTX | .evtx | Windows Event Log binary format |
| Plaso | .plaso | Forensic timeline database |
IRFlow Timeline uses a SQLite-backed architecture with streaming import, lazy indexing, and virtual scrolling to deliver responsive performance even on the largest forensic timelines. Handle large CSV files (tested with 30GB+), search across millions of rows, and visualize your timeline — all without freezing.
Automatic detection and pre-configuration for 15+ KAPE tool output formats including MFTECmd, EvtxECmd, Hayabusa, Chainsaw, AmcacheParser, and more. Open your KAPE output and start analyzing immediately with optimized column layouts and color rules.