← All cheat sheets

TIMESKETCH

Plain-text reference · 3 KB. Read it, search it (Ctrl-F) or print it.

Open-source collaborative forensic timeline analysis tool by Google.
Import, search, annotate, and share investigation timelines.

INSTALLATION#

# Docker (recommended)
git clone https://github.com/google/timesketch
cd timesketch/docker/release
cp .env.example .env
# Edit .env (set passwords)
docker compose up -d

# Access: https://localhost
# Create initial user via CLI

IMPORTING DATA#

# Supported formats:
  - Plaso (L2T CSV, JSONL)
  - CSV/JSONL with timestamp column
  - EVTX (via Plaso processing)
  - Hayabusa CSV output
  - EZTools CSV output

# Import via CLI
timesketch_importer -s SKETCH_ID timeline.csv
timesketch_importer -s SKETCH_ID plaso_output.jsonl

# Import via Web UI
# Sketch > Upload Timeline > Select file

# Plaso processing (recommended for disk images)
log2timeline.py /path/to/output.plaso /path/to/disk_image
psort.py -o l2tcsv /path/to/output.plaso -w timeline.csv
# Then import timeline.csv into Timesketch

SEARCH QUERIES#

# Free text search
mimikatz
powershell
cmd.exe

# Field-specific
source_short:"EVT"
timestamp_desc:"File Created"
data_type:"windows:evtx:record"

# Wildcards
filename:*password*
message:*admin*

# Boolean
mimikatz AND powershell
cmd.exe OR powershell.exe
NOT source_short:"FILE"

# Time filtering (via UI timeline selector)

ANALYZERS#

# Built-in analyzers (run on imported timelines):
  - Domain analyzer (extract and categorize domains)
  - Browser search analyzer
  - Account finder
  - Chain of events (sigma-based)
  - YARA analyzer
  - Feature extraction
  - Tagger (auto-tag events)
  - Similarity scorer

# Run analyzer: Sketch > Analyze > Select analyzer

TAGS & ANNOTATIONS#

# Tag events for investigation tracking
# Star important events
# Add comments to events
# Create named views (saved searches)
# Share sketches with team members

STORIES#

# Narrative investigation reports within Timesketch
# Embed search results and timeline views
# Collaborative editing
# Export for reporting

SIGMA INTEGRATION#

# Apply Sigma rules to timeline data
# Automatic detection of known attack patterns
# Results tagged and highlighted in timeline

PYTHON API#

from timesketch_api_client import config
from timesketch_api_client import client

ts = client.TimesketchApi(
    host_url='https://localhost',
    username='admin',
    password='password'
)

# List sketches
sketches = ts.list_sketches()

# Get sketch
sketch = ts.get_sketch(1)

# Search
result = sketch.explore('mimikatz')
for event in result.events:
    print(event)

# Add timeline
sketch.upload('/path/to/timeline.csv')

TIPS#

  - Process disk images with Plaso first, then import
  - Hayabusa --profile timesketch exports directly
  - Tag events as you investigate for tracking
  - Use analyzers to auto-detect patterns
  - Stories feature creates investigation narratives
  - Collaborative — multiple analysts work on same sketch
  - Sigma rules auto-detect known attack patterns
  - Python API enables automation and bulk operations
  - Combine with EZTools CSV output for Windows forensics
  - Docker deployment is easiest for quick setup

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.