ENNAENNA

Timesketch

Apache-2.0

๐Ÿ”ฌ Digital Forensics ยท Python

Timesketch is Google's open-source collaborative forensic timeline analysis platform designed for security incident investigations. It ingests events from multiple forensic sources โ€” Plaso supertimelines, CSV files, JSONL logs, and direct uploads โ€” and presents them in a searchable, annotatable web interface where multiple analysts can work simultaneously. Investigators can create named views with saved queries, tag events with labels and comments, build investigation timelines, and share findings with teammates. Timesketch includes built-in analyzers that automatically detect suspicious patterns like lateral movement, credential access, and data staging. The Sigma integration allows analysts to run detection rules directly against timeline data. The sketch-based workflow means each investigation is self-contained with its own data, annotations, and analysis โ€” making it easy to hand off cases between analysts or revisit investigations months later.

3.3kstars
650forks
202issues
Updated 8d ago

Use Cases

  • Collaborative incident investigation timelines
  • Correlating events from multiple forensic sources
  • Annotating and sharing investigation findings

Tags

timelineforensicsdfircollaborationanalysissecurity

Community Reviews

More in Digital Forensics