Case FBF7BE · Blue team / DFIR · L4 Advanced
Building a Forensic Timeline
Practise as: Explain it · Interview · Deep dive
Interview questionHow do you build a timeline of an intrusion across multiple hosts?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Normalize all sources to UTC; collect with KAPE or Velociraptor, parse with plaso (log2timeline) or EZ Tools.
- Execution artifacts: Prefetch, Amcache, ShimCache, SRUM, UserAssist; each proves different things.
- NTFS: $MFT $STANDARD_INFORMATION times are easy to timestomp; compare with $FILE_NAME and $UsnJrnl.
- Anchor on a known-bad event, then pivot backward to initial access and forward to lateral movement.
- Output a super-timeline plus a curated key-events timeline for the report.
If the interviewer pushes back
- ShimCache shows a binary but Prefetch does not. What can and can't you conclude about execution?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.