Threat & Timeline Analysis
Normalise timestamps, examine suspicious files and messages safely, and connect independent evidence into a supported sequence of activity.
Build context safely
Select each stage to see how analysts turn varied evidence into a defensible account.
Record the authorised evidence, relevant identities and systems, time range, and isolation requirements.
Ask: What must be answered, and what material needs special handling?Find your analysis path
Choose the route that matches your primary evidence and investigation question.
Normalise timestamps from several sources and reconstruct a supported sequence.
Build your foundation
Learn how to handle each evidence type before using the analysis tools.
Normalise time and test a sequence across sources.
Analyse safely and separate observation from attribution.
Preserve and interpret mail stores, headers, and attachments.
Choose a tool by task
Use one focused tool first, then corroborate important results with another method.
Parse NTFS Master File Table records into structured output for filtering and timeline correlation.
Check investigation readiness
Prepare the evidence, time context, and isolation boundary before analysis.