Building Super Timelines with Plaso
SkillSecurityA skill for digital forensics and incident response that guides an agent through building forensic super-timelines with Plaso.
Use Building Super Timelines with Plaso in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Building Super Timelines with Plaso and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Building Super Timelines with Plaso skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Install Plaso, preferably via Docker (log2timeline/plaso) or on Ubuntu through the GIFT PPA.
What your AI can do with it
- Extract events from a disk image or mounted filesystem into a .plaso storage file
- Inspect a .plaso file's contents and processing metadata with pinfo.py
- Filter, deduplicate, and export timelines to CSV or JSONL using psort.py or psteal.py
- Fuse file-system MACB, registry, EVTX, browser history, prefetch, LNK, and other
- Import exported timelines into Timesketch for filtering, tagging, and running analyzers
- Spot anti-forensic behavior such as timestomping or log clearing
Getting started
- Install Plaso, preferably via Docker (log2timeline/plaso) or on Ubuntu through the GIFT PPA.
- Obtain a forensic image (E01 or raw) or a mounted filesystem that you are authorized to analyze.
- Have a Timesketch instance available, for example a docker-compose deployment, for triage.
- Add the skill to your agent and ask it to build a super-timeline from the evidence source.
- Review the exported CSV or JSONL timeline and the Timesketch analysis it produces.
What this skill tells your AI
The instructions your AI receives, as published by mukul975/anthropic-cybersecurity-skills in skills/building-super-timelines-with-plaso/SKILL.md and read by ahel’s review.
Authorized Use Only: Build timelines only from evidence you are authorized to analyze. Work from forensic images/copies and preserve chain of custody.
Overview
Plaso (Plaso Langar Að Safna Öllu) is the open-source engine behind log2timeline, the standard for building forensic super timelines — a single chronological, normalized view fusing hundreds of artifact types (file-system MACB times, registry, EVTX, browser history, prefetch, LNK, $UsnJrnl, syslog, and more) into one timeline. Plaso has three core CLI tools:
- log2timeline.py — extracts events from a source (disk image, mount point, directory, or device) into a
.plasostorage file using its large parser/plugin set. - pinfo.py — reports on the contents and processing metadata of a
.plasofile. - psort.py — post-processes, filters, deduplicates, time-zones, and exports the storage file to an output format (CSV, JSON-line, Elasticsearch, Timesketch, etc.).
- psteal.py — convenience wrapper that runs extraction + export in one step.
The resulting timeline is enormous, so analysts triage it in Timesketch — a collaborative, web-based timeline analysis platform that ingests .plaso files (or CSV/JSONL) and supports filtering, tagging, starring, saved searches, and automated analyzers.
When to Use
- Reconstructing the full sequence of events on a compromised host during incident response.
- Correlating activity across many artifact sources on a single normalized timeline.
- Investigating anti-forensic behavior such as timestomping or log clearing (which stands out against MACB and journal evidence).
- Feeding a curated timeline into Timesketch for team triage.
Prerequisites
- Install Plaso (Docker is the supported, reproducible method):
Alternatively on Ubuntu via the GIFT PPA:docker pull log2timeline/plaso # Run a tool, mounting your evidence/output directory docker run -v /cases:/data log2timeline/plaso log2timeline.py --versionsudo add-apt-repository ppa:gift/stable sudo apt-get update && sudo apt-get install -y plaso-tools - A Timesketch instance (docker-compose deployment from https://github.com/google/timesketch) for triage.
- A forensic image (E01/raw) or mounted file system.
Objectives
- Extract events from an image into a
.plasostorage file. - Inspect the storage file with pinfo.
- Filter and export a focused super timeline with psort.
- Import the timeline into Timesketch and triage it.
MITRE ATT&CK Mapping
| ID | Official Technique Name | Relevance to this skill |
|---|---|---|
| T1070 | Indicator Removal | Super timelines reveal indicator-removal behavior (log clearing, file deletion, timestomping) by exposing inconsistencies between MACB timestamps, the USN journal, and event logs. |
Plaso is a defensive forensics engine; the mapping reflects the anti-forensic adversary behavior super timelines are well suited to detect.
Workflow
1. Extract events into a storage file
log2timeline.py writes a .plaso file from a source. --storage-file names the output; the source can be an .E01, raw image, mount point, or directory.
log2timeline.py --storage-file timeline.plaso /cases/greendale/image.E01
Scope parsers for speed/relevance with --parsers (presets like win7, webhist, or explicit parser names):
log2timeline.py --parsers "win7,!filestat" --storage-file timeline.plaso /cases/image.E01
2. Inspect the storage file
pinfo.py reports source, parsers used, event counts, and any warnings.
pinfo.py timeline.plaso
3. Export a filtered super timeline (CSV)
psort.py selects an output module with -o, writes with -w, normalizes the timezone with --output-time-zone, and accepts an event filter expression to scope a date range.
psort.py --output-time-zone 'UTC' \
-o l2tcsv \
-w supertimeline.csv \
timeline.plaso \
"date > datetime('2026-01-01T00:00:00') AND date < datetime('2026-01-27T00:00:00')"
For Timesketch-friendly JSON lines, use the json_line output module:
psort.py --output-time-zone 'UTC' -o json_line -w supertimeline.jsonl timeline.plaso
4. One-step extraction + export with psteal
psteal.py runs extraction and CSV export together for quick triage.
psteal.py --source /cases/greendale/image.E01 -o l2tcsv -w supertimeline.csv
5. Import into Timesketch
Use the official timesketch_importer CLI to upload the .plaso (or CSV/JSONL) into a sketch. Timesketch chunks/reassembles and indexes the file.
timesketch_importer \
--host http://127.0.0.1:5000 \
--username admin \
--timeline_name "greendale-host01" \
--sketch_id 1 \
timeline.plaso
6. Triage in Timesketch
In the sketch UI:
- Filter to a suspicious window or
data_type(e.g.windows:evtx:record,fs:stat). - Star/tag events of interest and add comments for collaboration.
- Save searches and run analyzers (e.g. browser timeframe, similarity, sigma) over the timeline.
- Build a narrative from corroborating events across artifact sources.
7. Hunt for anti-forensics
Look for MACB timestamps that disagree with $UsnJrnl entries (timestomping), gaps or EventLog cleared (1102) records, and deleted-then-recreated files — all visible on the unified timeline.
Tools and Resources
| Resource | Purpose | Link |
|---|---|---|
| Plaso (log2timeline) | Timeline engine + tools | https://github.com/log2timeline/plaso |
| Plaso documentation | Tool usage and parsers | https://plaso.readthedocs.io/ |
| Timesketch | Timeline analysis platform | https://github.com/google/timesketch |
| Timesketch docs | Deployment, importer, analyzers | https://timesketch.org/ |
| Plaso Docker image | Reproducible runtime | https://hub.docker.com/r/log2timeline/plaso |
Key Commands
| Command | Purpose |
|---|---|
log2timeline.py --storage-file out.plaso <source> | Extract events |
log2timeline.py --parsers <preset> ... | Scope parsers |
pinfo.py out.plaso | Inspect storage file |
psort.py -o l2tcsv -w out.csv out.plaso "<filter>" | Filter + export CSV |
psort.py -o json_line -w out.jsonl out.plaso | Export JSONL |
psteal.py --source <img> -o l2tcsv -w out.csv | Extract + export in one step |
timesketch_importer --host ... <file> | Import into Timesketch |
Validation Criteria
-
.plasostorage file produced from the source image - pinfo confirms expected parsers ran and event counts are non-zero
- Super timeline exported with UTC normalization and a scoped filter
- Timeline imported into a Timesketch sketch and indexed
- Suspicious window triaged with tags/stars/saved searches
- Anti-forensic indicators (timestomping, log clearing) checked
- Findings documented with corroborating cross-source events
Signals
- GitHub stars
- 34k
- Forks
- 4k
- Last commit
- Aug 2026
ahel review
K1binfo
installs-packages
Automated review, not a security audit. Ruleset v1+k2.
Questions
- What is a super-timeline?
- A single chronological, normalized view that fuses hundreds of artifact types, file-system MACB times, registry, EVTX, browser history, prefetch, LNK, $UsnJrnl, syslog, and more, into one timeline built with Plaso.
- Which Plaso tools does the skill use?
- log2timeline.py for extraction, pinfo.py for inspecting the storage file, psort.py for post-processing and export, and psteal.py, a convenience wrapper that runs extraction and export in one step.
Advanced
- Item type
- skill
- Key
building-super-timelines-with-plaso-mukul975- Source
- github.com/mukul975/anthropic-cybersecurity-skills
github.com/mukul975/anthropic-cybersecurity-skills
Related picks
Skill · docker
The pick for Dockerdocker-sandbox
Skill · joelhooks
The pick for Dockergenerate-sandbox-policy
Skill · nvidia
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infraowasp-security
Skill · davila7
The pick for Web (OWASP)security-and-hardening
Skill · addyosmani
The pick for Web (OWASP)