← All cheat sheets

PLASO / LOG2TIMELINE

Plain-text reference · 7 KB. Read it, search it (Ctrl-F) or print it.

Plaso (log2timeline) is a super timeline creation tool.
Essential for digital forensics timeline analysis.

INSTALLATION#

# pip
pip install plaso

# Ubuntu
apt install plaso

WORKFLOW#

1. Extract with log2timeline.py
2. Analyze with psort.py
3. Export to CSV/JSON/etc.

LOG2TIMELINE#


            

BASIC EXTRACTION#

log2timeline.py timeline.plaso image.dd
log2timeline.py timeline.plaso evidence/

COMMON OPTIONS#

-z TIMEZONE             Set timezone
--parsers LIST          Specific parsers
--partitions all        Process all partitions
-u                      Enable profiling
-q                      Quiet mode
--status_view none      Minimal output
--storage_file FILE     Output file

TIMEZONE#

log2timeline.py --timezone 'UTC' timeline.plaso image.dd
log2timeline.py --timezone 'US/Eastern' timeline.plaso image.dd

PARTITIONS#

log2timeline.py --partitions all timeline.plaso image.dd
log2timeline.py --partition 2 timeline.plaso image.dd

PARSERS#


            

LIST PARSERS#

log2timeline.py --parsers list

PARSER PRESETS#

--parsers win7           # Windows 7
--parsers win10          # Windows 10
--parsers linux          # Linux
--parsers macos          # macOS

COMMON PARSERS#

winreg                   Windows Registry
winevt                   Windows Event Log
winevtx                  Windows XML Event Log
pe                       PE executables
prefetch                 Windows Prefetch
mft                      NTFS MFT
usnjrnl                  NTFS USN Journal
filestat                 File system timestamps
chrome                   Chrome browser
firefox                  Firefox browser
msiecf                   IE history
syslog                   Linux syslog
utmp                     Linux logins
plist                    macOS plist

SPECIFIC PARSERS#

log2timeline.py --parsers 'winreg,winevtx,prefetch' timeline.plaso image.dd

EXCLUDE PARSERS#

log2timeline.py --parsers '!filestat' timeline.plaso image.dd

PSORT#


            

BASIC USAGE#

psort.py -o l2tcsv timeline.plaso > timeline.csv
psort.py -o json_line timeline.plaso > timeline.json

OUTPUT FORMATS#

-o l2tcsv           CSV format
-o dynamic          Dynamic CSV
-o json_line        JSON lines
-o elastic          Elasticsearch
-o timesketch       Timesketch
-o rawpy            Python raw

DATE FILTERING#

psort.py --date_filter '2024-01-01..2024-01-31' -o l2tcsv timeline.plaso
psort.py --date_filter '2024-01-15T00:00:00..2024-01-15T23:59:59' -o l2tcsv timeline.plaso

TIME SLICING#

psort.py -q -o l2tcsv timeline.plaso "date > '2024-01-01 00:00:00'"
psort.py -q -o l2tcsv timeline.plaso "date < '2024-01-31 23:59:59'"

FILTER BY SOURCE#

psort.py -o l2tcsv timeline.plaso "parser is 'winevtx'"
psort.py -o l2tcsv timeline.plaso "parser is 'prefetch'"
psort.py -o l2tcsv timeline.plaso "message contains 'powershell'"
psort.py -o l2tcsv timeline.plaso "filename contains '.exe'"

COMBINED FILTERS#

psort.py -o l2tcsv timeline.plaso "date > '2024-01-01' AND parser is 'winevtx'"

OUTPUT FIELDS#


            

L2TCSV FIELDS#

date                Timestamp
time                Time component
MACB                Modified/Accessed/Changed/Birth
source              Data source
sourcetype          Source type
type                Event type
user                Username
host                Hostname
short               Short description
desc                Full description
version             Parser version
filename            Source file
inode               Inode number
notes               Additional notes
format              Output format
extra               Extra data

DYNAMIC OUTPUT#

psort.py -o dynamic --fields 'datetime,timestamp_desc,source,message' timeline.plaso

ANALYSIS WORKFLOW#


            

FULL EXTRACTION#

# 1. Extract all events
log2timeline.py --parsers all --partitions all timeline.plaso image.dd

# 2. Export to CSV
psort.py -o l2tcsv timeline.plaso > full_timeline.csv

TARGETED EXTRACTION#

# Windows focused
log2timeline.py --parsers 'winreg,winevtx,winevt,prefetch,mft,lnk' timeline.plaso image.dd

# Browser focused
log2timeline.py --parsers 'chrome,firefox,msiecf,safari' timeline.plaso image.dd

TIME-BOUNDED ANALYSIS#

psort.py --date_filter '2024-01-15T08:00:00..2024-01-15T18:00:00' -o l2tcsv timeline.plaso > incident_window.csv

GREP TIMELINE#

# Search for specific events
psort.py -o l2tcsv timeline.plaso | grep -i "powershell"
psort.py -o l2tcsv timeline.plaso | grep -i "mimikatz"

PINFO#


            

TIMELINE INFO#

pinfo.py timeline.plaso

# Shows:
# - Storage file info
# - Event counts
# - Parser statistics
# - Errors/warnings

TIMESKETCH INTEGRATION#


            

EXPORT TO TIMESKETCH#

psort.py -o timesketch --status_view none timeline.plaso --output_time_zone UTC

# Or direct upload
timesketch_importer -t "Case Name" --timeline_name "Evidence" timeline.plaso

IMAGE_EXPORT#


            

EXTRACT FILES#

image_export.py --write /output/dir image.dd

# Specific file types
image_export.py --filter '*.exe' --write /output/dir image.dd
image_export.py --filter '*.pdf' --write /output/dir image.dd

COMMON SCENARIOS#


            

WINDOWS INVESTIGATION#

# Extract
log2timeline.py --parsers 'winreg,winevtx,prefetch,mft,lnk,pe,usnjrnl' timeline.plaso image.dd

# Export with filter
psort.py -o l2tcsv timeline.plaso "parser is 'winevtx' AND message contains 'logon'" > logon_events.csv

MALWARE TIMELINE#

# Focus on execution artifacts
log2timeline.py --parsers 'prefetch,pe,mft,usnjrnl,amcache' timeline.plaso image.dd

# Search for suspicious
psort.py -o l2tcsv timeline.plaso | grep -iE '(temp|appdata).*\.exe'

BROWSER FORENSICS#

log2timeline.py --parsers 'chrome,firefox,msiecf,safari,opera' timeline.plaso image.dd
psort.py -o l2tcsv timeline.plaso > browser_timeline.csv

LINUX INVESTIGATION#

log2timeline.py --parsers 'syslog,utmp,bash_history,filestat' timeline.plaso image.dd

ERROR HANDLING#

# Skip errors
log2timeline.py --no_fail_on_error timeline.plaso image.dd

# Log errors
log2timeline.py --logfile extraction.log timeline.plaso image.dd

PERFORMANCE#

# Multi-processing
log2timeline.py --workers 4 timeline.plaso image.dd

# Status updates
log2timeline.py --status_view linear timeline.plaso image.dd

QUICK REFERENCE#

# Extract
log2timeline.py timeline.plaso image.dd

# With specific parsers
log2timeline.py --parsers 'winreg,winevtx' timeline.plaso image.dd

# Export to CSV
psort.py -o l2tcsv timeline.plaso > timeline.csv

# Filter by date
psort.py --date_filter '2024-01-01..2024-01-31' -o l2tcsv timeline.plaso

# Filter by content
psort.py -o l2tcsv timeline.plaso "message contains 'keyword'"

# Timeline info
pinfo.py timeline.plaso

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.