Files
Anthropic-Cybersecurity-Skills/skills/building-incident-timeline-with-timesketch/assets/template.md
T

1.6 KiB

Forensic Timeline Investigation Report Template

Case Information

Field Details
Case ID
Sketch Name
Lead Investigator
Date Started
Timesketch Instance
Number of Timelines
Total Events Indexed

Evidence Sources

Timeline Name Source Type Host/System Events Time Range
Windows EVTX
Plaso Full
Cloud Logs
Network Logs

Investigation Objectives

  1. Determine initial access vector
  2. Identify compromised accounts
  3. Map lateral movement paths
  4. Identify persistence mechanisms
  5. Determine data access and exfiltration
  6. Establish complete attack timeline

Attack Timeline Summary

Time (UTC) Event Source Host ATT&CK Technique Tags

Key Findings

Finding 1: [Title]

  • Timesketch Search: [query string]
  • Events: [count]
  • Time Range: [start] to [end]
  • Description: [analysis]
  • Impact: [assessment]

Analyzers Run

Analyzer Results Findings
Sigma Rules
Domain Analyzer
Chain of Events
Feature Extraction

Saved Views

View Name Query Purpose

IOC Summary

IP Addresses

Domains

File Hashes

User Accounts

Recommendations

Appendix

  • Timesketch sketch export
  • Full query list
  • Plaso parser configuration