Timeline Analysis
When investigating an incident, it is critical to have an idea of when applications or files were executed. Date and timestamps can sometimes be found in other aspects of the investigation, such as when examining memory images. Also, identifying specific DLL files or executable files in the memory image can be compared to the date and time they were accessed, to correlate other activity observed on the system.
Autopsy has functionality specifically for timeline analysis. Simply click on the Timeline button at the top of the window and Autopsy will begin the process of parsing out timeline data. Depending on the size of the image file being analyzed, it may take a few minutes.Once completed, the following window will open: ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access