Home / software

Log2timeline

Posted on 12 September 2011

From: Kristinn Gudjonsson

log2timeline, a framework for automatic creation of a super timeline.

The main purpose is to provide a single tool to parse various log files and artifacts found on suspect systems (and supporting systems, such as network equipment) and produce a timeline that can be analyzed by forensic investigators/analysts.

The tool is written in Perl for Linux but has been tested using Mac OS X (10.5.7+ and 10.6.+). Parts of it should work natively in Windows as well (with ActiveState Perl installed) while other parts need to be slightly to considerably modified to work properly.

 

TOP