Introducing timelines
Timeline analysis is used extensively in forensic investigations that mainly involve collecting and analyzing large volumes of data within a particular timeframe. This is a great technique to determine what activity occurred on a system at a certain time and allows examiners to make inferences easily.
A timeline is essentially a list of events displayed in a particular order, usually chronologically. Timelines can be displayed as lists, tables, charts, or graphs.
By analyzing the timeline, a forensic analyst can easily find out when a particular event or incident happened. Timelining also helps figure out any other event that took place during the same time interval, and how these events are interconnected to one another.
Most forensic tools provide the examiner with the option of automatically generating a timeline of events that occurred during a specific timeframe. The timeline's data can then be exported as a CSV document and used to generate...