Digital Forensics and Incident Response | DFIR
  • Blog
  • Infosec
  • Windows Forensics
  • Mac Forensics
  • Memory Forensics
  • Incident Response
  • Cloud Security

TimeSketch - Forensic Timeline Analysis

7/28/2019

0 Comments

 
Developing timeline of forensic artifacts is a great practice. There are several tools like log2timeline, Plaso, commercial tools etc will develop a timeline for you. Today, we are going to discuss about another tool called Timesketch. 

Here is the GitHub repo: https://github.com/google/timesketch

The easiest way to get up and running is by using Docker Image. Fortunately, there is already an image of TimeSketch in docker: ​https://hub.docker.com/r/ilyaglow/timesketch

Another way it to compose docker image on the host itself: 
​

    
Timesketch will be up and running on http://127.0.0.1:5000
Picture
It'll give you a nice option to upload a CSV file or a Plaso Dump file. 
Picture
Picture
0 Comments



Leave a Reply.

    Archives

    April 2020
    September 2019
    August 2019
    July 2019
    June 2019
    April 2019
    February 2019
    March 2018

    Categories

    All
    Aws
    Cloud
    Dfir
    Incident Response
    Linux
    Recon

    RSS Feed