npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-timeline-with-timesketch, or copy the skill folder into ~/.claude/skills/building-incident-timeline-with-timesketch/.
Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/building-incident-timeline-with-timesketch/SKILL.md
SKILL.md (verbatim)
name: building-incident-timeline-with-timesketch
description: Build collaborative forensic incident timelines using Timesketch to ingest,
normalize, and analyze multi-source event data (including Plaso output) for attack
chain reconstruction and investigation documentation. Use when reconstructing the
sequence of events during an incident investigation or when multiple analysts need
to jointly tag, annotate, and search a shared DFIR timeline.
domain: cybersecurity
subdomain: incident-response
tags:
- timesketch
- timeline-analysis
- forensic-timeline
- plaso
- dfir
- incident-investigation
- collaborative-forensics
mitre_attack:
- T1059.001
- T1021.002
- T1547.001
- T1053.005
- T1070.006
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Executable Denylisting
- Execution Isolation
- File Metadata Consistency Validation
- Content Format Conversion
- File Content Analysis
nist_csf:
- RS.MA-01
- RS.MA-02
- RS.AN-03
- RC.RP-01
Building Incident Timeline with Timesketch
Overview
Timesketch is an open-source collaborative forensic timeline analysis tool developed by Google that enables security teams to visualize and analyze chronological data from multiple sources during incident investigations. It ingests logs and artifacts from endpoints, servers, and cloud services, normalizes them into a unified searchable timeline, and provides powerful analysis capabilities including built-in analyzers, tagging, sketch annotations, and story building. Timesketch integrates with Plaso (log2timeline) for artifact parsing and supports direct CSV/JSONL ingestion for rapid timeline construction during active incidents.
When to Use
When deploying or configuring building incident timeline with timesketch capabilities in your environment
When establishing security controls aligned to compliance requirements
When building or improving security architecture for this domain
When conducting security assessments that require this implementation
Prerequisites
Familiarity with incident response concepts and tools
Access to a test or lab environment for safe execution
Python 3.8+ with required dependencies installed
Appropriate authorization for any testing activities
Architecture and Components
Core Components
Timesketch Server: Web application with REST API for timeline management
OpenSearch/Elasticsearch: Backend storage and search engine for timeline events
PostgreSQL: Metadata storage for sketches, stories, and user data
Redis: Task queue management for background processing
Celery Workers: Asynchronous processing of timeline uploads and analyzers
Data Flow
Evidence Sources --> Plaso/log2timeline --> Plaso storage file (.plaso)
| |
v v
CSV/JSONL --> Timesketch Importer --> OpenSearch Index
|
v
Timesketch Web UI
(Search, Analyze, Story)
Deployment
Docker Deployment (Recommended)
# Clone Timesketch repository
git clone https://github.com/google/timesketch.git
cd timesketch
# Run deployment helper script
cd docker
sudo docker compose up -d
# Default access: https://localhost:443
# Admin credentials generated during first run
System Requirements
Minimum 8 GB RAM (16+ GB recommended for large investigations)
4 CPU cores minimum
SSD storage for OpenSearch indices
Docker and Docker Compose installed
Data Ingestion Methods
Method 1: Plaso Integration (Comprehensive)
# Process disk image with log2timeline
log2timeline.py --storage-file evidence.plaso /path/to/disk/image
# Process Windows event logs
log2timeline.py --parsers winevtx --storage-file windows_events.plaso /path/to/evtx/
# Process multiple evidence sources
log2timeline.py --parsers "winevtx,prefetch,amcache,shimcache,userassist" \
--storage-file full_analysis.plaso /path/to/mounted/image/
# Import Plaso file into Timesketch
timesketch_importer -s "Case-2025-001" -t "Endpoint-WKS01" evidence.plaso
# Upload Sigma rules for automated detection
timesketch_importer --sigma-rules /path/to/sigma/rules/
Analysis Workflow
Step 1: Create Investigation Sketch
1. Log into Timesketch web interface
2. Create new sketch (investigation case)
3. Add relevant timelines to the sketch
4. Set sketch description and tags
Step 2: Run Built-in Analyzers
Timesketch includes analyzers that automatically identify:
Browser Search Analyzer: Extracts search queries from browser history
Chain of Events Analyzer: Links related events (download -> execute)
Domain Analyzer: Extracts and categorizes domain names
Geo Location Analyzer: Maps events to geographic locations
Similarity Scorer: Finds similar events across timelines
Sigma Analyzer: Matches events against Sigma detection rules
Account Finder: Identifies user account activity patterns
Tagger: Applies labels based on predefined rules
Step 3: Search and Filter
# Search examples in Timesketch query language
# Find all events related to specific user
source_short:Security AND message:"john.admin"
# Find PowerShell execution events
data_type:"windows:evtx:record" AND event_identifier:4104
# Find lateral movement indicators
source_short:Security AND event_identifier:4624 AND xml_string:"LogonType\">3"
# Find events within specific time range
datetime:[2025-01-15T00:00:00 TO 2025-01-15T23:59:59]
# Find file creation events
data_type:"fs:stat" AND timestamp_desc:"Creation Time"
# Search with tags
tag:"suspicious" OR tag:"lateral_movement"
Step 4: Build Investigation Story
1. Create new story within the sketch
2. Add search views that support each finding
3. Annotate key events with investigator notes
4. Link events to MITRE ATT&CK techniques
5. Document the attack narrative chronologically
6. Export story for inclusion in incident report
Advanced Features
Collaborative Investigation
Multiple analysts work on the same sketch simultaneously
Comments and annotations persist on events
Saved searches shared across the team
Investigation stories document findings in context
API Automation
from timesketch_api_client import config
from timesketch_api_client import client as ts_client
# Connect to Timesketch
ts = ts_client.TimesketchApi(
host_uri="https://timesketch.local",
username="analyst",
password="password"
)
# Get sketch
sketch = ts.get_sketch(1)
# Search events
search = sketch.explore(
query_string='event_identifier:4624 AND LogonType:3',
return_fields='datetime,message,hostname,source_short'
)
# Add tags to events
for event in search.get('objects', []):
sketch.tag_event(event['_id'], ['lateral_movement'])
Integration with Dissect
# Use Dissect for faster artifact parsing (alternative to Plaso)
target-query -f timesketch://timesketch.local/case-001 \
targets/hostname/ -q "windows.evtx" --limit 0
START: Evidence Collection Complete
|
v
[Mount Evidence / Extract Artifacts]
|-- Mount disk image (read-only)
|-- Extract event logs from triage package
|-- Collect cloud service logs
|-- Gather network device logs
|
v
[Process with Plaso/log2timeline]
|-- Select appropriate parsers
|-- Configure filter files for scope
|-- Run log2timeline on each source
|-- Verify output .plaso files
|
v
[Import into Timesketch]
|-- Create sketch for investigation
|-- Upload each timeline with descriptive name
|-- Wait for indexing to complete
|-- Verify event counts per timeline
|
v
[Run Automated Analyzers]
|-- Domain analyzer
|-- Sigma rule analyzer
|-- Chain of events analyzer
|-- Feature extraction analyzer
|
v
[Manual Analysis and Tagging]
|-- Search for key indicators
|-- Tag events by attack phase
|-- Add investigator annotations
|-- Build investigation story
|
v
END: Timeline Ready for Analysis
Workflow 2: Rapid Triage Timeline
START: Incident Detected - Quick Timeline Needed
|
v
[Collect Quick-Win Artifacts]
|-- Windows Event Logs (Security, System, PowerShell)
|-- Prefetch files
|-- Browser history
|-- Recent file access (NTUSER.DAT)
|
v
[Fast Processing]
|-- Targeted Plaso parsers only
| (winevtx, prefetch, chrome_history)
|-- Or convert logs to CSV format
|-- Import directly into Timesketch
|
v
[Initial Analysis]
|-- Search for known IOCs
|-- Run Sigma analyzer for quick wins
|-- Identify suspicious time periods
|-- Tag initial findings
|
v
[Expand if Needed]
|-- Add additional evidence sources
|-- Run full parser set
|-- Broaden search scope
|
v
END: Initial Triage Complete
Workflow 3: Multi-Source Correlation
START: Multiple Evidence Sources Available
|
v
[Normalize Timestamps]
|-- Ensure all sources use UTC
|-- Account for clock skew between systems
|-- Document any time synchronization issues
|
v
[Import All Sources as Separate Timelines]
|-- Timeline 1: Endpoint logs (Plaso)
|-- Timeline 2: Network logs (CSV)
|-- Timeline 3: Cloud logs (JSONL)
|-- Timeline 4: Email logs (CSV)
|-- Timeline 5: Firewall logs (CSV)
|
v
[Cross-Source Correlation]
|-- Search across all timelines simultaneously
|-- Identify same events seen from different perspectives
|-- Build complete picture of attacker activity
|-- Tag correlated events with shared labels
|
v
[Build Attack Narrative]
|-- Create story in Timesketch
|-- Link saved views for each attack phase
|-- Add context and analysis notes
|-- Export for final report
|
v
END: Correlated Timeline Analysis Complete
Workflow 4: Collaborative Team Investigation
START: Investigation Assigned to Team
|
v
[Sketch Setup by Lead Investigator]
|-- Create sketch with case details
|-- Import initial timeline data
|-- Define investigation objectives
|-- Assign analysis areas to team members
|
v
[Parallel Analysis by Team]
|-- Analyst 1: Network traffic analysis
|-- Analyst 2: Endpoint artifact analysis
|-- Analyst 3: Cloud/identity analysis
|-- Each analyst tags and annotates findings
|
v
[Consolidation]
|-- Review all tagged events
|-- Resolve conflicting findings
|-- Build unified attack narrative
|-- Create investigation story
|
v
[Quality Review]
|-- Lead reviews complete timeline
|-- Verify attack chain is complete
|-- Ensure all IOCs documented
|-- Export findings for report
|
v
END: Team Investigation Complete