Plaso超时间线构建
原名:building-super-timelines-with-plaso
使用Plaso的log2timeline.py和pinfo.py生成法医超时间线,整合多源日志数据,构建全面事件时间轴以支持数字取证分析。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-24
- TRACE 评分
- 3.2 / 5
内容概览
Authorized Use Only: Build timelines only from evidence you are authorized to analyze. Work from forensic images/copies and preserve chain of custody. Plaso (Plaso Langar Að Safna Öllu) is the open-source engine behind log2timeline , the standard for building forensic super timelines — a single chronological, normalized view fusing hundreds of artifact types (file-system MACB times, registry, EVTX, browser history, prefetch, LNK, $UsnJrnl, syslog, and more) into one timeline. Plaso has three core CLI tools: - log2timeline.py — extracts events from a source (disk image, mount point, directory, or device) into a .plaso storage file using its large parser/plugin set. - pinfo.py — reports on the contents and processing metadata of a .plaso file. - psort.py — post-processes, filters, deduplicates, time-zones, and exports the storage file to an output format (CSV, JSON-line, Elasticsearch, Tim…