building-super-timelines-with-plaso
mukul975/Anthropic-Cybersecurity-Skills
Plaso (log2timeline) is an open-source engine used to generate forensic super-timelines. This skill guides the process of normalizing hundreds of diverse artifact types—including MACB times, registry keys, EVTX logs, and browser history—into a single, cohesive chronological view. The workflow covers extraction, filtering, and importing the timeline into Timesketch for collaborative analysis, which is crucial for incident response, correlating complex activity chains, and detecting anti-forensic techniques like timestomping.