Automating Log / Timeline Analysis

I haven’t gotten around to it yet but I think this is a must for automation:

Thoughts, alternatives?

@dave @mike.mitchell @SwedishMike @mark.vankempen @michael.butler


I’ve never seen that tool before but it looks like it would be a perfect fit from most DFIR workflows. It looks like tool has a pretty well defined API as well.

1 Like

log2timeline is a good tool for this. It was a part of the SIFT wks toolset (SANS DFIR).

1 Like