Chapter 5. Timeline
In this chapter, we will look at timeline analysis. We will learn a few different approaches to perform a timeline analysis with The Sleuth Kit and Plaso Framework. We will also cover some theoretical issues that are specific to some filesystems and how they work with file time-related attributions. Also, we will demonstrate how we can use Plaso in practice.
In a nutshell, we will cover the following topics:
- Timeline
- The Sleuth Kit (TSK)
- Plaso architecture
- Plaso in practice