Open cardosec

Case FBF7BE · Blue team / DFIR · L4 Advanced

Building a Forensic Timeline

Practise as: Explain it · Interview · Deep dive

Interview questionHow do you build a timeline of an intrusion across multiple hosts?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Normalize all sources to UTC; collect with KAPE or Velociraptor, parse with plaso (log2timeline) or EZ Tools.
  2. Execution artifacts: Prefetch, Amcache, ShimCache, SRUM, UserAssist; each proves different things.
  3. NTFS: $MFT $STANDARD_INFORMATION times are easy to timestomp; compare with $FILE_NAME and $UsnJrnl.
  4. Anchor on a known-bad event, then pivot backward to initial access and forward to lateral movement.
  5. Output a super-timeline plus a curated key-events timeline for the report.

If the interviewer pushes back

  • ShimCache shows a binary but Prefetch does not. What can and can't you conclude about execution?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.