PLASO / LOG2TIMELINE
Plaso (log2timeline) is a super timeline creation tool. Essential for digital forensics timeline analysis.
INSTALLATION#
# pip pip install plaso # Ubuntu apt install plaso
WORKFLOW#
1. Extract with log2timeline.py 2. Analyze with psort.py 3. Export to CSV/JSON/etc.
LOG2TIMELINE#
BASIC EXTRACTION#
log2timeline.py timeline.plaso image.dd log2timeline.py timeline.plaso evidence/
COMMON OPTIONS#
-z TIMEZONE Set timezone --parsers LIST Specific parsers --partitions all Process all partitions -u Enable profiling -q Quiet mode --status_view none Minimal output --storage_file FILE Output file
TIMEZONE#
log2timeline.py --timezone 'UTC' timeline.plaso image.dd log2timeline.py --timezone 'US/Eastern' timeline.plaso image.dd
PARTITIONS#
log2timeline.py --partitions all timeline.plaso image.dd log2timeline.py --partition 2 timeline.plaso image.dd
PARSERS#
LIST PARSERS#
log2timeline.py --parsers list
PARSER PRESETS#
--parsers win7 # Windows 7 --parsers win10 # Windows 10 --parsers linux # Linux --parsers macos # macOS
COMMON PARSERS#
winreg Windows Registry winevt Windows Event Log winevtx Windows XML Event Log pe PE executables prefetch Windows Prefetch mft NTFS MFT usnjrnl NTFS USN Journal filestat File system timestamps chrome Chrome browser firefox Firefox browser msiecf IE history syslog Linux syslog utmp Linux logins plist macOS plist
SPECIFIC PARSERS#
log2timeline.py --parsers 'winreg,winevtx,prefetch' timeline.plaso image.dd
EXCLUDE PARSERS#
log2timeline.py --parsers '!filestat' timeline.plaso image.dd
PSORT#
BASIC USAGE#
psort.py -o l2tcsv timeline.plaso > timeline.csv psort.py -o json_line timeline.plaso > timeline.json
OUTPUT FORMATS#
-o l2tcsv CSV format -o dynamic Dynamic CSV -o json_line JSON lines -o elastic Elasticsearch -o timesketch Timesketch -o rawpy Python raw
DATE FILTERING#
psort.py --date_filter '2024-01-01..2024-01-31' -o l2tcsv timeline.plaso psort.py --date_filter '2024-01-15T00:00:00..2024-01-15T23:59:59' -o l2tcsv timeline.plaso
TIME SLICING#
psort.py -q -o l2tcsv timeline.plaso "date > '2024-01-01 00:00:00'" psort.py -q -o l2tcsv timeline.plaso "date < '2024-01-31 23:59:59'"
FILTER BY SOURCE#
psort.py -o l2tcsv timeline.plaso "parser is 'winevtx'" psort.py -o l2tcsv timeline.plaso "parser is 'prefetch'"
TEXT SEARCH#
psort.py -o l2tcsv timeline.plaso "message contains 'powershell'" psort.py -o l2tcsv timeline.plaso "filename contains '.exe'"
COMBINED FILTERS#
psort.py -o l2tcsv timeline.plaso "date > '2024-01-01' AND parser is 'winevtx'"
OUTPUT FIELDS#
L2TCSV FIELDS#
date Timestamp time Time component MACB Modified/Accessed/Changed/Birth source Data source sourcetype Source type type Event type user Username host Hostname short Short description desc Full description version Parser version filename Source file inode Inode number notes Additional notes format Output format extra Extra data
DYNAMIC OUTPUT#
psort.py -o dynamic --fields 'datetime,timestamp_desc,source,message' timeline.plaso
ANALYSIS WORKFLOW#
FULL EXTRACTION#
# 1. Extract all events log2timeline.py --parsers all --partitions all timeline.plaso image.dd # 2. Export to CSV psort.py -o l2tcsv timeline.plaso > full_timeline.csv
TARGETED EXTRACTION#
# Windows focused log2timeline.py --parsers 'winreg,winevtx,winevt,prefetch,mft,lnk' timeline.plaso image.dd # Browser focused log2timeline.py --parsers 'chrome,firefox,msiecf,safari' timeline.plaso image.dd
TIME-BOUNDED ANALYSIS#
psort.py --date_filter '2024-01-15T08:00:00..2024-01-15T18:00:00' -o l2tcsv timeline.plaso > incident_window.csv
GREP TIMELINE#
# Search for specific events psort.py -o l2tcsv timeline.plaso | grep -i "powershell" psort.py -o l2tcsv timeline.plaso | grep -i "mimikatz"
PINFO#
TIMELINE INFO#
pinfo.py timeline.plaso # Shows: # - Storage file info # - Event counts # - Parser statistics # - Errors/warnings
TIMESKETCH INTEGRATION#
EXPORT TO TIMESKETCH#
psort.py -o timesketch --status_view none timeline.plaso --output_time_zone UTC # Or direct upload timesketch_importer -t "Case Name" --timeline_name "Evidence" timeline.plaso
IMAGE_EXPORT#
EXTRACT FILES#
image_export.py --write /output/dir image.dd # Specific file types image_export.py --filter '*.exe' --write /output/dir image.dd image_export.py --filter '*.pdf' --write /output/dir image.dd
COMMON SCENARIOS#
WINDOWS INVESTIGATION#
# Extract log2timeline.py --parsers 'winreg,winevtx,prefetch,mft,lnk,pe,usnjrnl' timeline.plaso image.dd # Export with filter psort.py -o l2tcsv timeline.plaso "parser is 'winevtx' AND message contains 'logon'" > logon_events.csv
MALWARE TIMELINE#
# Focus on execution artifacts log2timeline.py --parsers 'prefetch,pe,mft,usnjrnl,amcache' timeline.plaso image.dd # Search for suspicious psort.py -o l2tcsv timeline.plaso | grep -iE '(temp|appdata).*\.exe'
BROWSER FORENSICS#
log2timeline.py --parsers 'chrome,firefox,msiecf,safari,opera' timeline.plaso image.dd psort.py -o l2tcsv timeline.plaso > browser_timeline.csv
LINUX INVESTIGATION#
log2timeline.py --parsers 'syslog,utmp,bash_history,filestat' timeline.plaso image.dd
ERROR HANDLING#
# Skip errors log2timeline.py --no_fail_on_error timeline.plaso image.dd # Log errors log2timeline.py --logfile extraction.log timeline.plaso image.dd
PERFORMANCE#
# Multi-processing log2timeline.py --workers 4 timeline.plaso image.dd # Status updates log2timeline.py --status_view linear timeline.plaso image.dd
QUICK REFERENCE#
# Extract log2timeline.py timeline.plaso image.dd # With specific parsers log2timeline.py --parsers 'winreg,winevtx' timeline.plaso image.dd # Export to CSV psort.py -o l2tcsv timeline.plaso > timeline.csv # Filter by date psort.py --date_filter '2024-01-01..2024-01-31' -o l2tcsv timeline.plaso # Filter by content psort.py -o l2tcsv timeline.plaso "message contains 'keyword'" # Timeline info pinfo.py timeline.plaso
PLASO / LOG2TIMELINE CHEATSHEET ================================ Source: https://cheatsheet.johlem.net Plaso (log2timeline) is a super timeline creation tool. Essential for digital forensics timeline analysis. INSTALLATION ------------ # pip pip install plaso # Ubuntu apt install plaso WORKFLOW ======== 1. Extract with log2timeline.py 2. Analyze with psort.py 3. Export to CSV/JSON/etc. LOG2TIMELINE ============ BASIC EXTRACTION ---------------- log2timeline.py timeline.plaso image.dd log2timeline.py timeline.plaso evidence/ COMMON OPTIONS -------------- -z TIMEZONE Set timezone --parsers LIST Specific parsers --partitions all Process all partitions -u Enable profiling -q Quiet mode --status_view none Minimal output --storage_file FILE Output file TIMEZONE -------- log2timeline.py --timezone 'UTC' timeline.plaso image.dd log2timeline.py --timezone 'US/Eastern' timeline.plaso image.dd PARTITIONS ---------- log2timeline.py --partitions all timeline.plaso image.dd log2timeline.py --partition 2 timeline.plaso image.dd PARSERS ======= LIST PARSERS ------------ log2timeline.py --parsers list PARSER PRESETS -------------- --parsers win7 # Windows 7 --parsers win10 # Windows 10 --parsers linux # Linux --parsers macos # macOS COMMON PARSERS -------------- winreg Windows Registry winevt Windows Event Log winevtx Windows XML Event Log pe PE executables prefetch Windows Prefetch mft NTFS MFT usnjrnl NTFS USN Journal filestat File system timestamps chrome Chrome browser firefox Firefox browser msiecf IE history syslog Linux syslog utmp Linux logins plist macOS plist SPECIFIC PARSERS ---------------- log2timeline.py --parsers 'winreg,winevtx,prefetch' timeline.plaso image.dd EXCLUDE PARSERS --------------- log2timeline.py --parsers '!filestat' timeline.plaso image.dd PSORT ===== BASIC USAGE ----------- psort.py -o l2tcsv timeline.plaso > timeline.csv psort.py -o json_line timeline.plaso > timeline.json OUTPUT FORMATS -------------- -o l2tcsv CSV format -o dynamic Dynamic CSV -o json_line JSON lines -o elastic Elasticsearch -o timesketch Timesketch -o rawpy Python raw DATE FILTERING -------------- psort.py --date_filter '2024-01-01..2024-01-31' -o l2tcsv timeline.plaso psort.py --date_filter '2024-01-15T00:00:00..2024-01-15T23:59:59' -o l2tcsv timeline.plaso TIME SLICING ------------ psort.py -q -o l2tcsv timeline.plaso "date > '2024-01-01 00:00:00'" psort.py -q -o l2tcsv timeline.plaso "date < '2024-01-31 23:59:59'" FILTER BY SOURCE ---------------- psort.py -o l2tcsv timeline.plaso "parser is 'winevtx'" psort.py -o l2tcsv timeline.plaso "parser is 'prefetch'" TEXT SEARCH ----------- psort.py -o l2tcsv timeline.plaso "message contains 'powershell'" psort.py -o l2tcsv timeline.plaso "filename contains '.exe'" COMBINED FILTERS ---------------- psort.py -o l2tcsv timeline.plaso "date > '2024-01-01' AND parser is 'winevtx'" OUTPUT FIELDS ============= L2TCSV FIELDS ------------- date Timestamp time Time component MACB Modified/Accessed/Changed/Birth source Data source sourcetype Source type type Event type user Username host Hostname short Short description desc Full description version Parser version filename Source file inode Inode number notes Additional notes format Output format extra Extra data DYNAMIC OUTPUT -------------- psort.py -o dynamic --fields 'datetime,timestamp_desc,source,message' timeline.plaso ANALYSIS WORKFLOW ================= FULL EXTRACTION --------------- # 1. Extract all events log2timeline.py --parsers all --partitions all timeline.plaso image.dd # 2. Export to CSV psort.py -o l2tcsv timeline.plaso > full_timeline.csv TARGETED EXTRACTION ------------------- # Windows focused log2timeline.py --parsers 'winreg,winevtx,winevt,prefetch,mft,lnk' timeline.plaso image.dd # Browser focused log2timeline.py --parsers 'chrome,firefox,msiecf,safari' timeline.plaso image.dd TIME-BOUNDED ANALYSIS --------------------- psort.py --date_filter '2024-01-15T08:00:00..2024-01-15T18:00:00' -o l2tcsv timeline.plaso > incident_window.csv GREP TIMELINE ------------- # Search for specific events psort.py -o l2tcsv timeline.plaso | grep -i "powershell" psort.py -o l2tcsv timeline.plaso | grep -i "mimikatz" PINFO ===== TIMELINE INFO ------------- pinfo.py timeline.plaso # Shows: # - Storage file info # - Event counts # - Parser statistics # - Errors/warnings TIMESKETCH INTEGRATION ====================== EXPORT TO TIMESKETCH -------------------- psort.py -o timesketch --status_view none timeline.plaso --output_time_zone UTC # Or direct upload timesketch_importer -t "Case Name" --timeline_name "Evidence" timeline.plaso IMAGE_EXPORT ============ EXTRACT FILES ------------- image_export.py --write /output/dir image.dd # Specific file types image_export.py --filter '*.exe' --write /output/dir image.dd image_export.py --filter '*.pdf' --write /output/dir image.dd COMMON SCENARIOS ================ WINDOWS INVESTIGATION --------------------- # Extract log2timeline.py --parsers 'winreg,winevtx,prefetch,mft,lnk,pe,usnjrnl' timeline.plaso image.dd # Export with filter psort.py -o l2tcsv timeline.plaso "parser is 'winevtx' AND message contains 'logon'" > logon_events.csv MALWARE TIMELINE ---------------- # Focus on execution artifacts log2timeline.py --parsers 'prefetch,pe,mft,usnjrnl,amcache' timeline.plaso image.dd # Search for suspicious psort.py -o l2tcsv timeline.plaso | grep -iE '(temp|appdata).*\.exe' BROWSER FORENSICS ----------------- log2timeline.py --parsers 'chrome,firefox,msiecf,safari,opera' timeline.plaso image.dd psort.py -o l2tcsv timeline.plaso > browser_timeline.csv LINUX INVESTIGATION ------------------- log2timeline.py --parsers 'syslog,utmp,bash_history,filestat' timeline.plaso image.dd ERROR HANDLING ============== # Skip errors log2timeline.py --no_fail_on_error timeline.plaso image.dd # Log errors log2timeline.py --logfile extraction.log timeline.plaso image.dd PERFORMANCE =========== # Multi-processing log2timeline.py --workers 4 timeline.plaso image.dd # Status updates log2timeline.py --status_view linear timeline.plaso image.dd QUICK REFERENCE --------------- # Extract log2timeline.py timeline.plaso image.dd # With specific parsers log2timeline.py --parsers 'winreg,winevtx' timeline.plaso image.dd # Export to CSV psort.py -o l2tcsv timeline.plaso > timeline.csv # Filter by date psort.py --date_filter '2024-01-01..2024-01-31' -o l2tcsv timeline.plaso # Filter by content psort.py -o l2tcsv timeline.plaso "message contains 'keyword'" # Timeline info pinfo.py timeline.plaso
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.