A lean, local-first DFIR log workbench. Parses log sources into a normalized, taggable timeline stored in DuckDB, with a Splunk-inspired search syntax and a SQLite session layer for analyst tags. Rust + egui, no server, no cloud.
Runs standalone, or can be started and handed evidence paths by crush, then continues completely independently (no IPC).
Currently implemented: AUL (.logarchive), EVTX, journald, Android Intrusion
Log (Advanced Protection Mode), and TOML-configurable text log parsing,
import-time and re-tag tagging, session persistence, portable
case export/import for handing a case to another analyst, downloadable updates
to the built-in tagging rule packs (File → Rule packs..., independent of
app releases — see kalink0/peach-rules),
and CLI source handoff. See docs/supported-sources.md
for the authoritative, up-to-date list of what actually works today.
Prebuilt binaries for Linux, Windows, and macOS (universal — Apple Silicon and Intel in one binary) are attached to
every GitHub release — no Rust
toolchain or build step needed. A nightly build
tracks main and is rebuilt automatically whenever new commits land.
macOS (Homebrew)
brew tap kalink0/forensics
brew trust kalink0/forensics
brew install peach-forensicsWindows (Scoop)
scoop bucket add forensics https://github.com/kalink0/scoop-forensics
scoop install forensics/peach-forensicsWindows (winget) — pending initial review, not yet published.
No native package for Linux yet — grab the binary from Releases.
Needs the Microsoft Visual C++ Redistributable 2015-2022 (x64) installed (bundled DuckDB/SQLite link against it) — install it manually if peach fails to start with a missing DLL error.
Building from source is only needed to modify peach yourself — see Download above for ready-to-run binaries.
Requires a Rust toolchain (stable) and a C/C++ compiler + CMake (DuckDB is compiled from source on first build).
cargo build # first build compiles bundled DuckDB — several minutes
cargo run # build + launch the GUILocal checks (mirrors CI):
just check # cargo fmt --check + clippy -D warnings + test
just fmt # auto-formatpeach --add-source <path> [--add-source <path> ...] [--cleanup-dir <path> ...] [--ephemeral-session]--add-source pre-fills a source to load in the GUI (sourcetype is still confirmed
manually — peach never auto-detects a format). --cleanup-dir marks a directory
(e.g. a temp extraction dir crush created) to be deleted when peach closes; it's
only ever deleted if it resolves to somewhere under the OS temp directory.
--ephemeral-session disables session persistence for the run: the session's
.duckdb/.sqlite are written to a one-off temp directory instead of the
persistent sessions directory and removed on exit regardless of whether they hold
data — for evidence handed off from a temp extraction or a decrypted source, where
no durable unencrypted session copy should be left behind.
- docs/user-guide.md — how to use peach: loading sources, tagging rules, search syntax, sessions
- docs/supported-sources.md — supported/planned source types
- docs/rules-reference.md — every built-in tagging rule (AUL/EVTX/journald/intrusion_log), generated from the actual shipped rule files; also available fully offline in-app via Help → Rules reference...
- CHANGELOG.md — what changed in each release
Peach builds on the open-source and DFIR community. AUL (.logarchive) parsing
uses macos-unifiedlogs by
Mandiant (Apache-2.0); EVTX parsing uses
evtx by
@omerbenamram (MIT/Apache-2.0). The GUI is
built on egui/eframe; the bulk timeline on
DuckDB via duckdb-rs; the session layer on SQLite via
rusqlite. See the in-app Help → About → Acknowledgements tab for the
full dependency list with licenses.
The built-in tagging rule packs (rules/examples/*.toml) are built on
published research and primary sources, not re-derived from scratch. Curated
updates to them are published independently of Peach itself at
kalink0/peach-rules — see
File → Rule packs... in the app, or that repo's own README for the bundle/
version format if you just want the rules for something other than Peach:
- AUL — most predicates sourced from "Apple Unified Log Predicates in iLEAPP: The Reference" by Alexis Brignoni, with a handful of newer ones (dialed-number recovery, device orientation, Apple Watch Crown/button, CarPlay handshake) from Tim Korver's Thesis Friday series.
- EVTX — cross-checked against Microsoft's official Security Auditing event reference for each event ID, with a handful from JPCERT/CC's "Detecting Lateral Movement through Tracking Event Logs" report and PowerShell's own logging docs.
- journald — message text sourced directly from OpenSSH, sudo, shadow-utils, and systemd's own logging code.
- Android Intrusion Log — tag IDs and descriptions sourced from
Android's own AOSP
SecurityLogTags.logtags/SecurityLog.java(Apache-2.0); the JSON format itself and each event'stag_keycross-confirmed against two independent implementations that parse real device exports: the Mobile Verification Toolkit (Amnesty International's Security Lab) and ALEAPP.
See each rule file's own header comment for its specific citation, and docs/rules-reference.md for the full, generated rule-by-rule breakdown.
Special thanks to @dugeonlady for suggesting the Rainbow theme in crush — Peach's Rainbow theme (View → Theme → Rainbow) carries over the same cycle and colors. Forensics tools don't have to be grey.
Parts of this software were developed with assistance from Claude AI / Claude Code by Anthropic.
Use GitHub Issues. Please include the Peach version (shown in Help → About), your OS, and steps to reproduce.
