01Structured queries for forensic artifacts, avoiding raw file grepping
02Cross-artifact correlation and timeline building for comprehensive views
03Automatic timestamp normalization (Mac Absolute Time to UTC)
04Artifact discovery to identify available data in triage collections
051 GitHub stars
06Pre-built security event detection patterns (e.g., user creation, SSH sessions)