Plaso超时间线构建

原名:building-super-timelines-with-plaso

使用Plaso的log2timeline.py和pinfo.py生成法医超时间线,整合多源日志数据,构建全面事件时间轴以支持数字取证分析。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-08-24
TRACE 评分
3.2 / 5

内容概览

Authorized Use Only: Build timelines only from evidence you are authorized to analyze. Work from forensic images/copies and preserve chain of custody. Plaso (Plaso Langar Að Safna Öllu) is the open-source engine behind log2timeline , the standard for building forensic super timelines — a single chronological, normalized view fusing hundreds of artifact types (file-system MACB times, registry, EVTX, browser history, prefetch, LNK, $UsnJrnl, syslog, and more) into one timeline. Plaso has three core CLI tools: - log2timeline.py — extracts events from a source (disk image, mount point, directory, or device) into a .plaso storage file using its large parser/plugin set. - pinfo.py — reports on the contents and processing metadata of a .plaso file. - psort.py — post-processes, filters, deduplicates, time-zones, and exports the storage file to an output format (CSV, JSON-line, Elasticsearch, Tim…

查看 SKILL 详情