From isolated clues to an investigation narrative

Threat & Timeline Analysis

Normalise timestamps, examine suspicious files and messages safely, and connect independent evidence into a supported sequence of activity.

3analysis routes15practical tools1supported narrative
01

Build context safely

Select each stage to see how analysts turn varied evidence into a defensible account.

Stage 1Define the question and safety boundary

Record the authorised evidence, relevant identities and systems, time range, and isolation requirements.

Ask: What must be answered, and what material needs special handling?
02

Find your analysis path

Choose the route that matches your primary evidence and investigation question.

Best matchStart with timeline and correlation

Normalise timestamps from several sources and reconstruct a supported sequence.

03

Build your foundation

Learn how to handle each evidence type before using the analysis tools.

04

Choose a tool by task

Use one focused tool first, then corroborate important results with another method.

Best starting point for MFT-derived timelinesMFTECmd

Parse NTFS Master File Table records into structured output for filtering and timeline correlation.

Also consider Plaso for multi-source super-timelines or The Sleuth Kit for broader file-system examination.
Explore MFTECmd
05

Check investigation readiness

Prepare the evidence, time context, and isolation boundary before analysis.

!
Preparation required5 checks remaining.