Timeline Analysis
Use the initial alert as a starting location, then checking for network activity, process activity (including checking for injection), and then looking for names of files, look for activity of specific users that have been identified and then finally identify the IOCs from the data
Use Log2Timline / Plasofor timeline creation, then load into TimeSketch.
Logon Tracer is great for identifying user sessions!
MFTECmd is good for parsing MFT files and creating timelines from the file cache.
NTFS filesystem times:
Always stores times in UTC!
M / Modify - Data content change time A / Access - Data last access time C / change - Metadata change time B / Birth - File Creation time
M
A
B
C
exceptions to the above:
Applications:
office products
WinZip
Anti-Forensics:
Timestomp
Touch
Privacy Cleaners
Archives
ZIP, Rar, and TGZ retains original date / timstpamp
affects modified time only
Four step process:
Determine timeline scope - thorough analysis of the key questions
narrow pivot points - identify key files, users and machines
determine the best timeline for you - log2timline or MFT timelines?
filter & duplicate
Last updated