> cat /dev/github | grep security-tools
discovered 03 Aug 2026

tracehound

Python ★ 13 via github-topic
→ View on GitHub
Tracehound is a Linux DFIR tool designed to parse host artifacts and compile them into a unified, UTC-normalized timeline, facilitating the analysis of attacker behavior during forensic investigations. It processes log files, mounted images, and evidence folders, employing detection rules with MITRE ATT&CK mappings to convert raw events into actionable findings. Notable features include exporting results in various formats such as JSON, HTML, or CSV, and capabilities for maintaining a timeline in SQLite for extensive datasets.