TIMESKETCH
Open-source collaborative forensic timeline analysis tool by Google. Import, search, annotate, and share investigation timelines.
INSTALLATION#
# Docker (recommended) git clone https://github.com/google/timesketch cd timesketch/docker/release cp .env.example .env # Edit .env (set passwords) docker compose up -d # Access: https://localhost # Create initial user via CLI
IMPORTING DATA#
# Supported formats: - Plaso (L2T CSV, JSONL) - CSV/JSONL with timestamp column - EVTX (via Plaso processing) - Hayabusa CSV output - EZTools CSV output # Import via CLI timesketch_importer -s SKETCH_ID timeline.csv timesketch_importer -s SKETCH_ID plaso_output.jsonl # Import via Web UI # Sketch > Upload Timeline > Select file # Plaso processing (recommended for disk images) log2timeline.py /path/to/output.plaso /path/to/disk_image psort.py -o l2tcsv /path/to/output.plaso -w timeline.csv # Then import timeline.csv into Timesketch
SEARCH QUERIES#
# Free text search mimikatz powershell cmd.exe # Field-specific source_short:"EVT" timestamp_desc:"File Created" data_type:"windows:evtx:record" # Wildcards filename:*password* message:*admin* # Boolean mimikatz AND powershell cmd.exe OR powershell.exe NOT source_short:"FILE" # Time filtering (via UI timeline selector)
ANALYZERS#
# Built-in analyzers (run on imported timelines): - Domain analyzer (extract and categorize domains) - Browser search analyzer - Account finder - Chain of events (sigma-based) - YARA analyzer - Feature extraction - Tagger (auto-tag events) - Similarity scorer # Run analyzer: Sketch > Analyze > Select analyzer
TAGS & ANNOTATIONS#
# Tag events for investigation tracking # Star important events # Add comments to events # Create named views (saved searches) # Share sketches with team members
STORIES#
# Narrative investigation reports within Timesketch # Embed search results and timeline views # Collaborative editing # Export for reporting
SIGMA INTEGRATION#
# Apply Sigma rules to timeline data # Automatic detection of known attack patterns # Results tagged and highlighted in timeline
PYTHON API#
from timesketch_api_client import config
from timesketch_api_client import client
ts = client.TimesketchApi(
host_url='https://localhost',
username='admin',
password='password'
)
# List sketches
sketches = ts.list_sketches()
# Get sketch
sketch = ts.get_sketch(1)
# Search
result = sketch.explore('mimikatz')
for event in result.events:
print(event)
# Add timeline
sketch.upload('/path/to/timeline.csv')
TIPS#
- Process disk images with Plaso first, then import - Hayabusa --profile timesketch exports directly - Tag events as you investigate for tracking - Use analyzers to auto-detect patterns - Stories feature creates investigation narratives - Collaborative — multiple analysts work on same sketch - Sigma rules auto-detect known attack patterns - Python API enables automation and bulk operations - Combine with EZTools CSV output for Windows forensics - Docker deployment is easiest for quick setup
TIMESKETCH CHEATSHEET
======================
Source: https://cheatsheet.johlem.net
Open-source collaborative forensic timeline analysis tool by Google.
Import, search, annotate, and share investigation timelines.
INSTALLATION
-------------
# Docker (recommended)
git clone https://github.com/google/timesketch
cd timesketch/docker/release
cp .env.example .env
# Edit .env (set passwords)
docker compose up -d
# Access: https://localhost
# Create initial user via CLI
IMPORTING DATA
----------------
# Supported formats:
- Plaso (L2T CSV, JSONL)
- CSV/JSONL with timestamp column
- EVTX (via Plaso processing)
- Hayabusa CSV output
- EZTools CSV output
# Import via CLI
timesketch_importer -s SKETCH_ID timeline.csv
timesketch_importer -s SKETCH_ID plaso_output.jsonl
# Import via Web UI
# Sketch > Upload Timeline > Select file
# Plaso processing (recommended for disk images)
log2timeline.py /path/to/output.plaso /path/to/disk_image
psort.py -o l2tcsv /path/to/output.plaso -w timeline.csv
# Then import timeline.csv into Timesketch
SEARCH QUERIES
----------------
# Free text search
mimikatz
powershell
cmd.exe
# Field-specific
source_short:"EVT"
timestamp_desc:"File Created"
data_type:"windows:evtx:record"
# Wildcards
filename:*password*
message:*admin*
# Boolean
mimikatz AND powershell
cmd.exe OR powershell.exe
NOT source_short:"FILE"
# Time filtering (via UI timeline selector)
ANALYZERS
----------
# Built-in analyzers (run on imported timelines):
- Domain analyzer (extract and categorize domains)
- Browser search analyzer
- Account finder
- Chain of events (sigma-based)
- YARA analyzer
- Feature extraction
- Tagger (auto-tag events)
- Similarity scorer
# Run analyzer: Sketch > Analyze > Select analyzer
TAGS & ANNOTATIONS
--------------------
# Tag events for investigation tracking
# Star important events
# Add comments to events
# Create named views (saved searches)
# Share sketches with team members
STORIES
--------
# Narrative investigation reports within Timesketch
# Embed search results and timeline views
# Collaborative editing
# Export for reporting
SIGMA INTEGRATION
-------------------
# Apply Sigma rules to timeline data
# Automatic detection of known attack patterns
# Results tagged and highlighted in timeline
PYTHON API
-----------
from timesketch_api_client import config
from timesketch_api_client import client
ts = client.TimesketchApi(
host_url='https://localhost',
username='admin',
password='password'
)
# List sketches
sketches = ts.list_sketches()
# Get sketch
sketch = ts.get_sketch(1)
# Search
result = sketch.explore('mimikatz')
for event in result.events:
print(event)
# Add timeline
sketch.upload('/path/to/timeline.csv')
TIPS
-----
- Process disk images with Plaso first, then import
- Hayabusa --profile timesketch exports directly
- Tag events as you investigate for tracking
- Use analyzers to auto-detect patterns
- Stories feature creates investigation narratives
- Collaborative — multiple analysts work on same sketch
- Sigma rules auto-detect known attack patterns
- Python API enables automation and bulk operations
- Combine with EZTools CSV output for Windows forensics
- Docker deployment is easiest for quick setup
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.