<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Timeline Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<atom:link href="https://compute-forensics.com/tag/timeline/feed/" rel="self" type="application/rss+xml" />
	<link>https://compute-forensics.com/tag/timeline/</link>
	<description></description>
	<lastBuildDate>Thu, 28 Jun 2018 15:41:05 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://compute-forensics.com/wp-content/uploads/2018/06/cropped-cropped-CF-1-32x32.png</url>
	<title>Timeline Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<link>https://compute-forensics.com/tag/timeline/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Incident Response: Creation of a Digital Timeline of User Actions</title>
		<link>https://compute-forensics.com/incident-response-creation-of-a-digital-timeline/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Thu, 28 Jun 2018 15:13:41 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[Supertimeline]]></category>
		<category><![CDATA[Timeline]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1817</guid>

					<description><![CDATA[Log2TimeLine Production: the Crème de la Crème of Incident Evidence What is the best method for analysing an intrusion or indeed for most computer forensic cases? It is the production of a super timeline. A timeline quickly highlights a chain of events that occur, a super timeline using a Linux based tool named log2timeline. This software]]></description>
										<content:encoded><![CDATA[<h3>Log2TimeLine Production: the Crème de la Crème of Incident Evidence</h3>
<p>What is the best method for analysing an intrusion or indeed for most computer forensic cases? It is the production of a super timeline. A timeline quickly highlights a chain of events that occur, a super timeline using a Linux based tool named log2timeline. This software produces the mother of all schedules. It merely creates an amalgamation of all the events contained within a system such as event logs, metadata, internet history and user actions and is an invaluable asset for analysis of a hacking event or incident.</p>
<p>If you are not proficient in computers or require an expert to produce and analyse this timeline, then please visit our <a href="http://compute-forensics.com/" rel="nofollow noopener">website</a>. Sans, a training computer forensics organisation, provided an excellent cheat sheet that can be viewed/downloaded from <a href="https://blogs.sans.org/computer-forensics/files/2011/12/digital-forensics-incident-response-log2timeline-timeline-cheatsheet.pdf" rel="nofollow noopener">here</a>. It is a little detailed, and I wanted to simplify it for those who never produced a &#8216;supertimeline&#8217; before.</p>
<p>DISCLAIMER: YOU MAY NEED AN EXPERT TO DO THIS IN YOUR ORGANISATION AS COLLECTING THE DATA INCORRECTLY AND NOT DOCUMENTING STEPS MAY RESULT IN EVIDENCE THAT DOESN&#8217;T STAND UP IN COURT!</p>
<h3>Log2timeline in Caine</h3>
<p><img fetchpriority="high" decoding="async" src="https://media.licdn.com/dms/image/C5612AQG6ihzrg6Mxww/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=0BfGEWtFggd09JA9GUSjpwx8bUDsfxdzEKK-Kt_G5b0" width="640" height="481" data-media-urn="urn:li:digitalmediaAsset:C5612AQG6ihzrg6Mxww" data-li-src="https://media.licdn.com/dms/image/C5612AQG6ihzrg6Mxww/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=0BfGEWtFggd09JA9GUSjpwx8bUDsfxdzEKK-Kt_G5b0" /></p>
<h3>Log2Timeline Basic Use</h3>
<p>The tool ‘log2timeline’ can be executed against a remotely connected network device, an E01 or DD image or a mounted image directory using Linux. The easiest way to create one is the &#8216;Hail Mary&#8217; approach, that is to say, dump all the data (web history, reg, link, evtx etc.), mount or present the image to Plaso or super timeline. Then output the &#8216;dump&#8217; file to a storage medium. You can then use another command line tool to output the timeline to a useful format (CSV) or filter using dates etc. Calc or Excel can then be used to filter dates or other fields, beware that these office tools can panic when handling massive data sets 200mb+. <a href="http://davnads.blogspot.co.uk/2012/12/4n6time-release-notice.html" rel="nofollow noopener">4n6time </a>is a tool you can use to analyse the events graphically; there are others.</p>
<h3>Example of Basic Log2TimeLine Usage the &#8216;Hail Mary&#8217;</h3>
<p><strong>1)</strong> Download live Linux distribution <a href="http://www.caine-live.net/" rel="nofollow noopener">Caine </a>v7.0 or later. Boot this in a virtual machine such as VirtualBox or VMware. Alternatively, you could burn the iso or use <a href="https://unetbootin.github.io/" rel="nofollow noopener">Unetbootin</a> to make a bootable USB version of the software.</p>
<h3>Caine, My Personal Favourite Linux Forensic Distro</h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C5612AQEWsXtmFdrjkA/article-inline_image-shrink_400_744/0?e=2129500800&amp;v=beta&amp;t=QyIJp2-_k4UiR8XW94BscBFprP4IdaXYs8JJegPLML0" width="594" height="394" data-media-urn="urn:li:digitalmediaAsset:C5612AQEWsXtmFdrjkA" data-li-src="https://media.licdn.com/dms/image/C5612AQEWsXtmFdrjkA/article-inline_image-shrink_400_744/0?e=2129500800&amp;v=beta&amp;t=QyIJp2-_k4UiR8XW94BscBFprP4IdaXYs8JJegPLML0" /></p>
<p><strong>2)</strong> Connect your disk containing images in Read/Write by right-clicking on the disk icon and selecting R/W mode.</p>
<h3>Read/Write GUI Mounting Icon</h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C5612AQHGjwBVRJ2ADQ/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=IPu0pUzQyIUiF8VslQxIyObCL3I9nfzBKMIXuMJ0wH8" width="391" height="49" data-media-urn="urn:li:digitalmediaAsset:C5612AQHGjwBVRJ2ADQ" data-li-src="https://media.licdn.com/dms/image/C5612AQHGjwBVRJ2ADQ/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=IPu0pUzQyIUiF8VslQxIyObCL3I9nfzBKMIXuMJ0wH8" /></p>
<p>You have to select the disk desired using the tick box then select &#8216;OK&#8217;. You can use this disk to write your plaso timeline file. If live evidence is being used such as a server mount the location in read mode. Mount the image using one of the GUI tools provided in the Linux distribution Caine or point log2timeline to the actual image file. If the image is dd or even E01 you can just point the tool to the location path: remember to include the file name and extension. Have somewhere in read-write mode mounted to push the outputted timeline which will be a &#8216;plaso&#8217; file.</p>
<p>Caine&#8217;s Mounting GUI</p>
<p><img loading="lazy" decoding="async" src="https://media.licdn.com/dms/image/C5612AQEWlSGQMmRa7A/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=3uwOScdEW1xP5XEFB4YWSNJoeMkUJclev5F2fmaMQRU" width="640" height="480" data-media-urn="urn:li:digitalmediaAsset:C5612AQEWlSGQMmRa7A" data-li-src="https://media.licdn.com/dms/image/C5612AQEWlSGQMmRa7A/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=3uwOScdEW1xP5XEFB4YWSNJoeMkUJclev5F2fmaMQRU" /></p>
<p><strong>3)</strong> Update your system, Open Terminal [Optional may cause issues!]:</p>
<p>sudo apt-get update</p>
<p>Then upgrade it:</p>
<p>sudo apt-get upgrade</p>
<p>Be sure Ubuntu Universe is installed and available:</p>
<p>sudo add-apt-repository universe</p>
<p>Update again:</p>
<p>sudo apt-get update</p>
<p>Add the GIFT PPA:</p>
<p>sudo add-apt-repository ppa:gift/stable</p>
<p>Update again:</p>
<p>sudo apt-get update</p>
<p>Now install Plaso:</p>
<p>sudo apt-get install python-plaso</p>
<p><strong>4)</strong> Mount the image using one of the 2 GUI mounting tools,FMOUNT is my favourite, in Caine v7.0. Another way is to is to point the program at the location of your image e.g.: &#8216;media/sdb1/foldertoputinimage/image.e01&#8217; (remember to have no spaces in this path!</p>
<h3>FMOUNT Select your Forensic Image (Split Images Supported)</h3>
<p><img loading="lazy" decoding="async" src="https://media.licdn.com/dms/image/C5612AQEwiS3TaaC2vg/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=-eyxk2x7lfHTxWxLuI0_gXbiWT53SZYULqwd5IqcjNQ" width="640" height="446" data-media-urn="urn:li:digitalmediaAsset:C5612AQEwiS3TaaC2vg" data-li-src="https://media.licdn.com/dms/image/C5612AQEwiS3TaaC2vg/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=-eyxk2x7lfHTxWxLuI0_gXbiWT53SZYULqwd5IqcjNQ" /></p>
<p><strong>5)</strong> Create the Timeline: Paths can be copy and pasted from the web bar of Caine&#8217;s Explorer type interface.</p>
<h3>Copy and Paste Paths from the Explorer, as Typing Long a Path can Result in Errors</h3>
<p><img loading="lazy" decoding="async" src="https://media.licdn.com/dms/image/C4E12AQHK_f-Zln7QuA/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=pRn6u1y3mVhQkarke5FIo6L3u2v_GSU1OPCljEBz1tc" width="640" height="94" data-media-urn="urn:li:digitalmediaAsset:C4E12AQHK_f-Zln7QuA" data-li-src="https://media.licdn.com/dms/image/C4E12AQHK_f-Zln7QuA/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=pRn6u1y3mVhQkarke5FIo6L3u2v_GSU1OPCljEBz1tc" /></p>
<p>&nbsp;</p>
<p>Open log2timeline from the menu and enter something like this: [comments in brackets, do not use in Terminal!]:</p>
<p>sudo [admin command] log2timeline.py [The software used] -z Europe/London [z- is the time zone flag, be sure to use capitals and find your desired timezone dependent on the case <a href="http://www.timezoneconverter.com/cgi-bin/zoneinfo.tzc?s=default&amp;tz=CST6CDT" rel="nofollow noopener">here</a>, pick the location desired and insert after flag] &#8211;status_view window [Adds status window optional can cause errors) /path/to/nameyourfile.plaso [output location] media/sdb1/foldertoputinimage/image.e01 [Windows or Image Directory the path can be copied from the &#8216;computer&#8217; window similar to explorer]
<p>Hit &#8216;return&#8217; and wait. The process may take a long time.</p>
<p><strong>6)</strong> Output the timeline into another format, open Terminal and input something like this:</p>
<p>sudo psort.py -o [Output Format CSV] l2tcsv w- [Storage Path] /mnt/hgfs/CaseSensitiveWindowsPath/YOURCSVTIMELINE.csv [Location of your Plaso Dump] /mnt/hgfs/CaseSensitiveWindowsPath/nameyourfile.plaso</p>
<p><strong>7)</strong> Viola! You have produced your very own supertimeline.</p>
<p><strong>8)</strong> For an analysis in excel or calc, the contents of the spreadsheet may be pasted into a template found <a href="https://digital-forensics.sans.org/blog/2012/01/25/digital-forensic-sifting-colorized-super-timeline-template-for-log2timeline-output-files" rel="nofollow noopener">here</a>.</p>
<ul>
<li><a href="https://blogs.sans.org/computer-forensics/files/2012/01/TIMELINE_COLOR_TEMPLATE.zip" rel="nofollow noopener">Download it</a> &#8211; Open Timeline Color Template</li>
<li>Switch to Color Timeline worksheet/tab</li>
<li>Click on Cell A-1</li>
<li>Select &#8216;DATA&#8217; Ribbon</li>
<li>Import Data &#8220;FROM TEXT&#8221;</li>
<li>Select log2timeline.CSV file</li>
<li>TEXT IMPORT WIZARD Will Start</li>
<li>Step 1 -&gt; Select Delimited -&gt;Select NEXT</li>
<li>Step 2 -&gt; Unselect Tab under Delimiters -&gt; Select Comma under Delimiters -&gt; Select NEXT &gt;</li>
<li>Step 3 -&gt;Select Finish</li>
<li>Where do you want to put the data? Simply Select OK.</li>
<li>Once imported View -&gt; Freeze Panes -&gt; Freeze Top Row</li>
<li>Optional Hide Columns Timezone, User, Host, Short or Desc (keep one of these), Version</li>
<li>Select HOME Ribbon</li>
<li>Select all Cells &#8220;CTRL-A.&#8221;</li>
<li>In-Home Ribbon -&gt; Sort and Filter &#8211; Filter</li>
</ul>
<h3>Resources:</h3>
<p><a href="http://www.caine-live.net/" rel="nofollow noopener">http://www.caine-live.net/</a></p>
<p>https://github.com/log2timeline/plaso/wiki</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
