MeiTian Digital Forensics
Parses Windows USN / Linux auditd / macOS FSEvents to produce court-admissible timeline reports.

What MeiTian Digital Forensics does
MeiTian Digital Forensics is a cross-platform file-system log forensics tool that parses Windows USN journals, Linux auditd and macOS FSEvents, produces court-admissible timeline reports, and automatically detects timestamp tampering, ransomware activity spikes and bulk deletions.
Built for real-world scenarios
Multi-platform log parsing
Unified parsing of Windows USN journal, Linux auditd and macOS FSEvents file-system logs.
Timeline reconstruction
Reconstructs file-operation timelines into court-admissible forensic reports.
Anomaly detection
Detects timestamp tampering, ransomware activity spikes and bulk deletion patterns.
Multi-format reports
Exports CSV, JSON and forensic-grade PDF for archiving and evidence.
See it in action



Key advantages
About MeiTian Digital Forensics
Which logs can MeiTian Digital Forensics analyze?
It parses Windows USN journals, Linux auditd and macOS FSEvents file-system logs across all three platforms to reconstruct file-operation timelines.
Can the reports be used as legal evidence?
It produces court-admissible timeline reports and exports forensic-grade PDF for archiving and evidence.
What anomalies can it detect?
Timestamp tampering, ransomware activity spikes and bulk file deletions, to aid security-incident tracing.
Learn more about MeiTian Digital Forensics
Explore more capabilities, or browse the full MeiTian product matrix.