win11-timeline-builder
I'm not calling your project slop! Geeze, it's a joke... Do you own this repo?
Log in with GitHub as Jumbalicious79. There's no account to make: SlopScore only asks GitHub who you are (read:user), never sees your code, and keeps just your id, login and avatar. Then you can:
- Keep it, on your terms. Commit your own
slopscore.md(spec) and press Refresh. Your paperwork replaces the Cap'm's, and you can submit it for Slop of the Day. - Take it down. One click on Remove. It stays gone; the trawl never brings it back.
Can't log in as the owner? Request a takedown. No login needed, and a trawled listing comes down right away.
- GitHub says
- Forensic timeline analysis tool that parses Win11 Triage Collector output into unified, color-coded timelines
- created
- 2026-04-10 · pushed 7 hours ago · 43 commits · 1 contributor
- languages
- paperwork
- licensereadme 42% health
- dependencies
- no dependency graph (no manifest, or disabled) · OSV.dev, checked 1 hour ago
Disclosures, inferred by the Cap'm
- slopbucket
- vibe-coded
- category
- other
- ai_generated
- mostly
- human_touch
- light
- status
- works-on-my-machine
- language (detected)
- batchfilepowershell
- license (detected)
- mit
The Cap'm's log
The Cap'm wrote this paperwork, not the owner. This repo never submitted itself to SlopScore. The Cap'm picked it by hand: Forensic timeline analysis tool that parses Win11 Triage Collector output into unified, color-coded timelines; its own README says "All PowerShell (Anthropic) scripts, batch launchers, and supporting code were written by Claude Code (claude". It carries the MIT license. The disclosures above are his best guess from what GitHub shows.
Is this yours? Commit a real slopscore.md and press Refresh to replace this, or remove the listing in one click. There's no account to make: you log in with GitHub.
README — the repo's own words, folded up so the grading fits on one screen
# Windows 11 Forensic Timeline Builder A pure PowerShell script that builds a unified, chronological CSV timeline from Windows forensic artifacts. Designed as a lightweight alternative to log2timeline/plaso, focused specifically on Windows 11 artifacts. Designed to be used with win11-triage-collector, which collects the forensic artifacts this script parses. The timeline builder is a pure parser -- it reads only from the triage collection and never queries the local system. Both tools are available as separate repos for independent use. Companion project: https://github.com/Jumbalicious79/win11-triage-collector ## Setup Both tools MUST be sibling directories (same parent folder) for the automatic browse mode to function. The timeline builder locates triage collections by looking for ..\win11-triage-collector\reports\ relative to its own location. Required directory structure: any-parent-folder\ win11-triage-collector\ <-- companion repo triage-collector.ps1 Run-TriageCollector.bat reports\ <-- collections save here win11-timeline-builder\ <-- this repo timeline-builder.ps1 Run-TimelineBuilder.bat reports\ <-- timelines save here tools\ <-- auto-downloaded on first run sqlite3\ <-- browser history parser TimelineExplorer\ <-- forensic CSV viewer To set up: git clone https://github.com/Jumbalicious79/win11-triage-collector git clone https://github.com/Jumbalicious79/win11-timeline-builder Or download both repos and extract them into the same parent folder. The parent folder can be anywhere -- your desktop, a USB drive, a network share, etc. If you pass -InputPath directly, the sibling requirement does not apply. But for the zero-config double-click workflow (browse mode), both directories must be siblings. ## Intended Workflow These two tools are designed to work together as a complete collect-and-analyze pipeline. Double-click to collect, double-click to analyze -- no configuration, no dependencies, no command-line knowledge needed. 1. COLLECT: Run triage-collector on the target system 2. ANALYZE: Run timeline-builder on the collection (this tool) 3. REVIEW: Timeline Explorer auto-opens with the timeline loaded ### Live System (Dirty Forensics) For incident response, triage, or non-legal investigations: 1. Copy both tools to a USB drive 2. Plug the USB into the target machine 3. Double-click Run-TriageCollector.bat (collects to reports\ on the USB) 4. Unplug the USB, take it to your analysis workstation 5. Double-click Run-TimelineBuilder.bat -- it auto-finds the triage zips 6. Pick a collection, timeline builds, Timeline Explorer opens automatically ### Forensic Image (Clean Forensics) For legal cases or chain-of-custody requirements: 1. Create a forensic image of the target system FIRST Use FTK Imager, dd, or your preferred imaging tool 2. Mount the image as read-only on your analysis workstation (e.g., E:) 3. Double-click Run-TriageCollector.bat -- select the mounted drive from the menu (the collector auto-detects mounted Windows volumes) 4. Double-click Run-TimelineBuilder.bat -- select the collection 5. The collection manifest (SHA256 hashes) provides integrity verification The triage collector auto-detects live vs mounted images and adjusts its collection methods accordingly. See the triage collector README for details on what gets collected in each mode. ### USB Deployment Kit Both tools are designed to live side-by-side on a USB drive: USB_DRIVE\ win11-triage-collector\ triage-collector.ps1 Run-TriageCollector.bat tools\ dumpit\ <-- optional: DumpIt for memory capture reports\ <-- collections save here win11-timeline-builder\ timeline-builder.ps1 Run-TimelineBuilder.bat tools\ <-- auto-downloaded: sqlite3, Timeline Explorer volatility3\ <-- optional: vol.exe for memory analysis reports\ <-- timelines save here The timeline builder auto-discovers triage collections from the sibling directory. sqlite3.exe and Timeline Explorer are auto-downloaded on first run and cached in the tools\ directory for future use. For memory capture and analysis, extract Magnet DumpIt into the collector's tools\dumpit\ and Volatility 3 into the builder's tools\volatility3\. Both folders are in the repos with a README.txt explaining where to get the tool; the tools themselves are never committed. ## Quick Start ### Double-click (recommended) Run-TimelineBuilder.bat No arguments needed. The script automatically: 1. Finds triage collection .zip files from sibling triage-collector\reports\ 2. Lists them with size and date, newest first 3. You pick a number 4. Extracts to a temp folder (cleaned up after) 5. Builds the timeline (~2 minutes for ~36,000 events) 6. Generates a color-coded Excel file (rows colored by EventType) 7. Asks how you want to view: Excel (colored), Timeline Explorer, Both, None You can also pass a path directly, optionally followed by a comma-separated keyword list (both in quotes): Run-TimelineBuilder.bat "path\to\triage\collection" Run-TimelineBuilder.bat "path\to\collection" "mimikatz,psexec" The launcher asks for Administrator rights (UAC) and restarts itself elevated with the same arguments. Paths with spaces, apostrophes, & or ! are fine, and a relative path is turned into a full path first (the elevated window starts in C:\Windows\System32). ### PowerShell (Admin) powershell -ExecutionPolicy Bypass -NoProfile -File timeline-builder.ps1 -Browse powershell -ExecutionPolicy Bypass -NoProfile -File timeline-builder.ps1 -InputPath "D:\Cases\Case001\Collection" powershell -ExecutionPolicy Bypass -NoProfile -File timeline-builder.ps1 -InputPath "D:\Cases\Case001\Collection" -StartDate "2025-01-15" -EndDate "2025-01-20" powershell -ExecutionPolicy Bypass -NoProfile -File timeline-builder.ps1 -InputPath "D:\Cases\Case001\Collection" -Sources "EventLogs,Prefetch,Registry" powershell -ExecutionPolicy Bypass -NoProfile -File timeline-builder.ps1 -InputPath "D:\Cases\Case001\Collection" -Keywords "mimikatz,psexec,powershell -enc" powershell -ExecutionPolicy Bypass -NoProfile -File timeline-builder.ps1 -InputPath "D:\Cases\Case001\Collection" -MaxUsnEntries 200000 With -File, PowerShell passes a list such as "a","b" or a,b to the script as one string ("a,b"). The script splits -Sources and -Keywords on commas itself, so both forms work. From a PowerShell prompt (.\timeline-builder.ps1) normal arrays (-Keywords "a","b") work as well. ## Parameters -Browse Auto-find triage zips in sibling triage-collector\reports\ and present a numbered menu to select one. No InputPath needed. -InputPath Path to a triage collection directory or any directory containing supported artifacts. -OutputFile Output CSV path. Defaults to reports\timeline_<timestamp>\timeline.csv -StartDate Only include events after this date (UTC). -EndDate Only include events before this date (UTC). -Sources Parsers to run, as an array or a comma-separated string. Defaults to all 16 (Memory excluded). Valid: EventLogs, Prefetch, RecentFiles, Registry, FileSystem, Browser, ScheduledTasks, Services, Network, USB, Persistence, UsnJournal, Amcache, PowerShellHistory, SystemInfo, AntiVirus, Memory Note: Memory is opt-in. Requires Volatility 3 in tools\ and a memory dump in the collection. Adds 5-30 minutes. -Keywords Strings to flag in the timeline, as an array or a comma-separated string ("mimikatz,psexec"). Spaces around each keyword are trimmed and empty items ignored. Matching is case-insensitive against Description, Details, User and Source. Adds a Flagged column (TRUE/FALSE) for quick filtering. A keyword cannot itself contain a comma. -MaxUsnEntries Maximum number of USN journal rows to keep. The NEWEST rows are kept (older ones are dropped first). Default 0 = unlimited. The USN journal is usually the largest source; see "Known Limitations" for the Excel row limit. -Viewer Viewer to open at the end without the menu: Excel, TimelineExplorer, Both or None (for scripts and automation). -NoExcel CSV only: don't generate timeline.xlsx (ImportExcel is then not needed). -MftDays $MFT file-system events: only times within this many days before the collection are added. Default 7; 0 = all. A full $MFT can produce millions of rows, and one Windows update alone can add hundreds of thousands. Possible timestomping and Mark-of-the-Web (downloaded or extracted file) rows are always reported (see parser #8). ## Auto-Downloaded Dependencies The script auto-downloads tools on first run. All are cached in tools\ or installed as PowerShell modules -- no manual installation needed. ### ImportExcel PowerShell module (PSGallery) Used for generating color-coded .xlsx timeline with rows pre-colored by EventType. Auto-installed from PowerShell Gallery on first run. Source: https://github.com/dfinke/ImportExcel License: Apache 2.0 Installed: Per-user scope (CurrentUser) -- no system-wide changes Used by: Excel timeline generation (color-coded .xlsx output) ### sqlite3.exe (sqlite.org) Used for parsing browser history databases (Chrome, Edge, Firefox). Downloaded from: https://www.sqlite.org/download.html Cached in: tools\sqlite3\sqlite3.exe Lookup order: sqlite3.exe on the PATH, then tools\, then a download of the x64 build (sqlite.org has no ARM64 tools build; x64 runs under emulation on ARM64 Windows). ### Timeline Explorer (Eric Zimmerman) Used for viewing and analyzing the timeline CSV output. Downloaded only if the user selects Timeline Explorer from the viewer menu. Downloaded from: https://ericzimmerman.github.io/ Cached in: tools\TimelineExplorer\ Credit: Timeline Explorer is developed by Eric Zimmerman and is part of his comprehensive suite of free forensic tools. His work has been foundational to the DFIR community, providing investigators with powerful, free, and actively maintained tools for Windows forensic analysis. Eric Zimmerman's tools: https://ericzimmerman.github.io/ All downloads happen once. On subsequent runs, cached copies are reused. All temp files (download zips, extraction dirs) are cleaned up automatically. ## Output The script creates a timestamped report folder next to the script: win11-timeline-builder\ reports\ timeline_2026-04-08_09-43-57\ timeline_builder_log.txt -- Full processing log timeline.csv -- The unified timeline (~12 MB, ~36K events) timeline.xlsx -- Color-coded Excel version (~2 MB) tools\ sqlite3\ -- Auto-downloaded, cached TimelineExplorer\ -- Auto-downloaded on first use, cached ## Output Format (CSV and Excel) Both timeline.csv and timeline.xlsx contain the same columns: Timestamp UTC-normalized datetime (yyyy-MM-dd HH:mm:ss.fff) Source Which artifact produced the entry (e.g., Security.evtx, Prefetch) EventType Category: Execution, FileAccess, Logon, NetworkConnection, PersistenceChange, AccountChange, ProcessCreation, ServiceChange, ScheduledTaskChange, USBDevice, Installation, SecurityAlert, Snapshot (see below) Description Human-readable summary of what happened User Account the artifact belongs to, if known (see below) Details Additional context (command line, file path, IP, etc.) Artifact Parser that produced the entry RawPath Path of the collected artifact file Flagged (Only when -Keywords used) TRUE if any keyword matched Rows are sorted by Timestamp; rows with the same time stay in the order the parsers produced them. ### Where the times come from Every Timestamp is taken from the artifact data itself, never from when the files were copied, extracted or parsed: - Prefetch: run times stored inside the .pf file - LNK files: the original file times recorded in the collection manifest (collected file times are not used) - Registry entries (TypedPaths, RunMRU, RecentDocs, run keys, services, ...): the registry key's last-write time. Values that store a time of their own use it (TaskCache, Office TrustRecords and File/Place MRU) - BAM: bam_entries.csv, or the collected SYSTEM hive - Browser history, downloads, logins, cookies, form entries and permissions: times the browsers store in UTC - USN journal and setupapi logs: these are local-time text. They are converted to UTC with the time zones the collector recorded in collection_info.json (the collector host's zone for fsutil USN output, the examined system's zone for setupapi). Collections from older collector versions have no collection_info.json; the time zone is then read from collection_log.txt. ### Snapshot rows Some artifacts describe the state of the system when it was collected, not an event: the service and driver list, DNS and ARP cache, current TCP connections, shares, Wi-Fi profiles, loaded DLLs, and scheduled tasks, services or run keys that have no usable time of their own. These rows have EventType "Snapshot" and the collection time as their Timestamp. A few context rows are Snapshot rows at a time of their own: a security product reported ON to Security Center (event time), the Outlook attachment folder and the triage collector's own Defender exclusion (registry key last-write time). Snapshot rows are colored light gray in Excel. Filter them out (EventType <> Snapshot) to see only real events. ### User column The user is taken from the collection's own folder layout: Registry\<user>\, UserActivity\<user>\, Browser\<user>\ or a Users\<user>\ folder inside the collection. It is never taken from the analysis machine's path (for example the %TEMP% folder a browse-mode zip is extracted to). Rows that do not belong to a specific profile have an empty User. ### Duplicates A row is removed as a duplicate only if Timestamp, Source, EventType, Description, User and Details are all identical (case-sensitive); the first copy is kept. The count is shown in the summary. ### CSV vs Excel differences The CSV file contains the complete data from all parsers. Use it when you need full-fidelity data for SIEM import, scripted analysis, or when any cell value exceeds 32,767 characters. Both files keep all text as found, including accented and non-Latin characters (e.g. Japanese file names), symbols such as the euro sign and emoji. Only characters that an .xlsx file cannot store are removed from both: control characters other than tab/CR/LF, U+FFFE/U+FFFF and broken (unpaired) UTF-16 surrogates. The CSV is UTF-8. The Excel file (.xlsx) is color-coded by EventType for visual analysis. Differences from the CSV: 1. Strings over 32,767 characters are truncated with a [TRUNCATED] marker. This is Excel's hard cell limit. The full data is always in the CSV. Affected fields are typically long UserAssist entries or command lines. 2. Excel may show a "Repaired Records" or "Do you want to recover" prompt when opening the file. Click Yes -- this is a known ImportExcel/EPPlus library issue with XML formatting. The data and color-coding are intact. This does not indicate data loss or corruption. 3. An Excel worksheet holds at most 1,048,575 data rows. If the timeline is larger (usually because of a very large USN journal), the .xlsx is not generated and a warning is logged; use the CSV, or narrow the run with -StartDate, -EndDate, -Sources or -MaxUsnEntries. ## What Each Parser Extracts (17 Parsers) ### 1. Event Logs Parses .evtx files using Get-WinEvent. Targets high-value forensic events (the Source is the log file name, e.g. Security.evtx): - Security: Logon success/fail (4624/4625), explicit credentials (4648), special privileges (4672), process creation (4688), account created or deleted (4720/4726, with the account SID), session reconnected or disconnected (4778/4779, EventType Logon, with the client name and address) - Security account changes (EventType AccountChange): member added to a security-enabled global, local or universal group (4728/4732/4756; Details Group, GroupSID, Member, MemberSID -- a local member, which the event gives only by SID, is named from the other Security events), password reset attempt (4724), account locked out (4740, with the CallerComputer) - Security log and persistence changes: audit log cleared (1102, with ClearedBy) and system audit policy changed (4719, category and subcategory by name), both SecurityAlert; service installed (4697, PersistenceChange); scheduled task registered, updated, deleted, enabled or disabled (4698/4702/4699/4700/4701, ScheduledTaskChange, with Command, Arguments and RunAs from the task XML) - System: Service crashes (7034), state changes (7036), start type changes (7040, with the service name), new service installs (7045), shutdowns (1074/6008), event log cleared (104, SecurityAlert, with the log name and who cleared it), event log service started/stopped (6005/6006: the markers of a boot and of a clean shutdown) - Application: software installed or removed (MsiInstaller 1033/1034, EventType Installation, with Product, Version, Manufacturer, Status and the installing account as User; 11707/11724 only when there is no matching 1033/1034), application crashes and hangs (Application Error 1000, Application Hang 1002, EventType Execution, with the faulting Module and ExceptionCode), ESE database created, attached, detached or moved (ESENT 325/326/327/216, FileAccess -- shows copies of ntds.dit). Only these events and the security-product events below are read from this log; Windows Error Reporting 1001 is not (it repeats 1000/1002) - Application, security products: the state each product reports to Security Center (SecurityCenter 15: the first state per product and every change; 16: a failed state update). A product reported OFF, SNOOZED, EXPIRED or in an unknown state is a SecurityAlert; one reported ON is a Snapshot row at the event time (context). Events that third-party antivirus writes to this log (Symantec / Norton, McAfee / Trellix, Sophos, ESET, Trend Micro, Bitdefender, Kaspersky, Malwarebytes, Webroot, CrowdStrike) are SecurityAlert rows with the message text, trimmed: Critical, Error and Warning events, and Information events only when their text reports a detection - PowerShell Operational: Script block logging (4104), module logging (4103) - Sysmon (if present): Process creation (1), network (3), image loads (7), file creation (11), registry changes (13) - Task Scheduler: Task registered (106), updated (140), deleted (141) - TerminalServices (RDP) logs: remote logons, session connect, disconnect and reconnect, with user and source address - Windows Defender Operational: malware detections and actions, security-control changes such as real-time protection disabled or an exclusion added, malware detection history deleted (1013; the service's own daily retention purge is labelled as such), and attack surface reduction rules that blocked or audited an action (1121/1122, with the rule name; audits are folded into one row per rule, path, process and day, with Count and LastSeen) (EventType SecurityAlert) - BITS Client: background transfer jobs and the URLs they download from - Defender detections (defender_detections.csv) with the threat name and severity from defender_threats.csv - Defender support logs (MPLog-*.log): detections and remediations, exclusion lists and exclusion/protection-setting changes (EventType SecurityAlert; MPLog times are UTC) ### 2. Prefetch Extracts execution evidence from the .pf files: - Executable name, run count and the last run times stored inside the .pf file (up to 8 on Windows 8 and later) - The times of the copied .pf file are not used (they are only the time the collector copied it) ### 3. Recent Files (LNK) Parses Windows shortcut files from the collection's RecentFiles folders: - Target file path, arguments, working directory - Times: the shortcut's original created/modified times from the collection manifest - User from the collection folder (UserActivity\<user>\RecentFiles) - Only the collection is read. If it has no .lnk files there are no LNK rows; the analysis machine's own Recent folder is never used. - Jump Lists: AutomaticDestinations (DestList entries: path, last access time, access count, pinned) and CustomDestinations (target paths), per application -- the app name comes from the AppID (well-known IDs) or the program the list starts ### 4. Registry Parses the offline hives of the triage collection (NTUSER.DAT, UsrClass.dat, SOFTWARE and SYSTEM via reg load) for user activity, persistence and security settings. Sources are named Registry-<item> (e.g. Registry-RunMRU, Registry-TaskCache); Details give the Key and say where the time came from. From each user's NTUSER.DAT: - TypedPaths: Explorer address bar history - TypedURLs: Internet Explorer typed URLs - RunMRU: Run dialog command history - UserAssist: ROT13-decoded program execution counts and last run times - RecentDocs: Recently opened documents - Per-user Run / RunOnce values - WordWheelQuery: Explorer search box terms - Open/Save dialogs (Registry-OpenSaveMRU, Registry-LastVisitedMRU): files picked in Open/Save dialogs and the folder each program's dialog last used; paths are decoded like ShellBags - Office trusted documents (Registry-TrustRecords): "Office macros enabled on document" (EventType Execution) when the user enabled macros, otherwise "Office editing enabled on document" (FileAccess), at the time the document was trusted - Office File MRU / Place MRU (Registry-OfficeMRU): recent documents and folders per Office app, at the time each was last opened - Outlook attachment temp folder (OutlookSecureTempFolder): one Snapshot row with the folder - Remote Desktop client (Registry-RDPClient, EventType NetworkConnection): outbound RDP targets from the MRU list and the saved servers with their user name hint From UsrClass.dat: - ShellBags: folders the user browsed in Explorer (BagMRU), timed with each key's last-write time From the SOFTWARE hive (EventType PersistenceChange unless noted): - Image File Execution Options Debugger values (Registry-IFEO). A Debugger on an accessibility program (sethc.exe, utilman.exe, osk.exe, narrator.exe, magnify.exe, displayswitch.exe, atbroker.exe) is marked "(accessibility program)": the Debugger then runs at the logon screen as SYSTEM - SilentProcessExit monitor processes and dumps on exit, described by what ReportingMode makes Windows do; Details say whether it is Active (that also needs IFEO GlobalFlag 0x200) - Winlogon Shell, Userinit and Taskman when not the Windows default - AppInit_DLLs when not empty (native and Wow6432Node), with LoadAppInit_DLLs - Scheduled tasks from the TaskCache (Registry-TaskCache): hidden tasks and task folders -- a Tree entry without an SD value, which schtasks and Task Scheduler do not list (ScheduledTaskChange); and, from DynamicInfo, "Scheduled task registered" (ScheduledTaskChange) and "Scheduled task last run" (Execution, with LastErrorCode) with the task's Actions, for tasks that scheduled_tasks.csv or the task XML files do not already put on the timeline - Defender exclusions (Registry-DefenderExclusions; Paths, Extensions, Processes, IpAddresses; local and Group Policy): one SecurityAlert row each; local ones are "ignored by policy" when Group Policy sets DisableLocalAdminMerge. The exclusion the triage collector adds for its own output folder while it runs is recognised from collection_log.txt and shown as a Snapshot row "(triage collector's own temporary exclusion)", or as a SecurityAlert when the log says the collector could not remove it From the SYSTEM hive: - LSA Authentication, Notification (password filter) and Security Packages entries that are not Windows defaults (Registry-LSA, PersistenceChange) - WDigest UseLogonCredential=1: clear-text passwords kept in memory (Registry-WDigest, SecurityAlert) - BAM/DAM: Background/Desktop Activity Moderator last execution times, from bam_entries.csv (current collector) or the collected SYSTEM hive - AppCompatCache (ShimCache): programs recorded by the compatibility cache, from the collected SYSTEM hive / appcompat_cache.reg MRU-style entries (TypedPaths, RunMRU, RecentDocs, Open/Save dialogs, WordWheelQuery, Remote Desktop MRU) are timed with the registry key's last-write time, which is when the most recent entry was added -- older entries in the same key happened before that time. TrustRecords, Office MRU and TaskCache DynamicInfo store their own times, which are used. The settings (IFEO, Winlogon, AppInit_DLLs, Defender exclusions, LSA, WDigest, hidden tasks) use their key's last-write time: when the key last changed, so the value itself may be older. ### 5. Browser History Parses Chromium (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi) and Firefox SQLite databases using auto-downloaded sqlite3.exe -- no DLLs needed. Each database is read from a temporary copy with its -wal and -journal files, so a copy taken while the browser was writing is read in its last committed state. Sources are "<Browser> <store>", for example "Edge History", "Chrome Downloads" or "Firefox Cookies": - URL, page title, visit timestamp (stored by the browser in UTC and kept as UTC), visit count - Bookmarks (Chromium Bookmarks file, Firefox moz_bookmarks): date added - Chromium address bar shortcuts (Shortcuts database): last used, hits - Chromium Top Sites (Snapshot rows; no times are stored) - Downloads ("<Browser> Downloads", EventType FileAccess; the Chromium History downloads table, the Firefox places.sqlite annotations): a row when the download started; one when it completed, was cancelled, interrupted or blocked, if that was at least a minute later; and, for Chromium, one when the file was last opened from the browser. Details: Path, URL (Chromium: the file's URL, the last of the redirect chain; Firefox: the URL the download started from), Referrer, State (COMPLETE, CANCELLED, INTERRUPTED, IN_PROGRESS, BLOCKED; Firefox's own name in FirefoxState), DangerType (Chromium danger type or the Firefox reputation verdict, e.g. Malware), Bytes, StartUtc, EndUtc; Chromium adds OriginalURL (the first URL of the chain), TabURL, MimeType, InterruptReason and SHA256 - Saved logins ("<Browser> Logins", "Firefox Logins"; Chromium Login Data, Firefox logins.json): when a login was saved, last used (only if at least a minute after it was saved), its password changed, and when the user chose "never save" for a site. Details: URL, Action, Realm, Username (Chromium only -- Firefox stores user names encrypted), TimesUsed - Cookies ("<Browser> Cookies", "Firefox Cookies"; Chromium Network\Cookies or Cookies, Firefox cookies.sqlite), aggregated per host: a row when the host's oldest cookie was set and one when its cookies were last accessed. Details: Host, Cookies (count), Names (first 200 characters), Persistent / Secure / HttpOnly counts - Form entries ("<Browser> Autofill", "Firefox Form History"; Chromium Web Data, Firefox formhistory.sqlite): the form field name, when an entry was first saved and last used, and TimesUsed. The newest 20,000 entries per database are kept - Search engines ("<Browser> Search Engines", Chromium Web Data): when each engine was added, modified and last used, with its Keyword and URL template. Kind: Prepopulated, Policy, StarterPack, AutoGenerated (from a site's search form) or Custom (added or edited by the user -- or by software that wrote to Web Data, a known search-hijack technique) - Firefox site permissions ("Firefox Permissions", permissions.sqlite): notifications, camera, microphone, location, pop-ups, add-on installs and more, with the value set (ALLOW, DENY, PROMPT) and when - User from the collection folder (Browser\<user>\) Downloads are FileAccess rows (a download writes a file to disk); all other browser rows are NetworkConnection (Top Sites: Snapshot). The credential, cookie and form stores are read as metadata only: saved passwords, cookie values, autofill and form values, payment cards, addresses and Firefox's encrypted user names and passwords are never read (the queries never select them, and in logins.json they are blanked before parsing). key4.db is never opened. ### 6. Scheduled Tasks Parses scheduled_tasks.csv from the triage collection (live collections): - Task name, path, state, author, run-as user, actions (the command) and triggers - Registration and last run times; tasks with no usable time are Snapshot rows Mounted-image collections have no scheduled_tasks.csv; the task XML files the collector copies from Windows\System32\Tasks are parsed instead (registration date, author, command). ### 7. Services Parses services.csv from triage collection: - Service name, binary path, start mode, state, service account - Timed with the service registry key's last-write time when the collector recorded it (KeyLastWriteUtc); otherwise a Snapshot row ### 8. File System ($MFT) Parses the raw $MFT the collector copies (FileSystem\$MFT): - File and folder created/modified times ($STANDARD_INFORMATION), with full paths rebuilt from the parent references, MFT record number, size and the $FILE_NAME created time in Details - Deleted files and folders (record no longer in use) are included and labelled "Deleted file"; their paths may be partial (<orphan>\...) - Possible timestomping is flagged with [SI<FN] in the Description for an executable or script (.exe .dll .sys .ps1 .bat .vbs .js .scr .lnk ...) whose $STANDARD_INFORMATION created time is on a whole second and more than 1 s earlier than its $FILE_NAME created time -- the pattern backdating tools leave. Windows servicing and installers lay files down the same way, so WinSxS, servicing, SoftwareDistribution, Installer, assembly, dotnet and WindowsApps are not flagged (on a test system that cut 10,230 hits to 180). Treat a flag as a lead, not proof. - Downloads (Mark of the Web): a file saved from the internet by a browser or mail client carries a Zone.Identifier stream ([ZoneTransfer] ZoneId=3, HostUrl=..., ReferrerUrl=...). Its text is small and almost always stored inside the MFT record, so it is read from the collected $MFT, also for deleted files. Each such file gets a row "Downloaded file (Mark of the Web, Internet zone): <path>" (Source MFT, EventType FileAccess; "; record deleted" is added in the brackets when the record is no longer in use). Details: ZoneId, HostUrl, ReferrerUrl, any other key of the stream, the MFT record, size and all times. Zones: 0 Local machine, 1 Local intranet, 2 Trusted sites, 3 Internet, 4 Restricted sites; "zone unknown" when there is no ZoneId - "Extracted file (Mark of the Web, <zone>): <path>": the stream has no HostUrl and a local or network path as ReferrerUrl. Explorer writes this for each file it extracts from an archive with Mark of the Web; ReferrerUrl is the archive, whose own row has the HostUrl - These rows are at the $STANDARD_INFORMATION created time, or at the $FILE_NAME created time (RowTime=FN.Created in Details) when the SI time is missing, before 1980 or more than 1 s earlier (backdated, or set from the archive entry on extraction). They are added whatever -MftDays (-StartDate/-EndDate still apply). The file's "File created" row, when in the window, gets ZoneId and HostUrl (or ReferrerUrl) appended to its Details - Only times within -MftDays (default 7) days before the collection are added; flagged records are kept when their $FILE_NAME time is in range Older collections without a $MFT: file listing CSVs are parsed if present (capped at 50,000 entries); otherwise an info line, not a warning. ### 9. USN Journal Parses $UsnJrnl_$J.txt exported by the triage collector: - File create, modify, delete, rename, security change events - Filters out noisy "Close" and "Basic info change | Close" entries - Keeps every row by default; with -MaxUsnEntries N only the NEWEST N rows are kept, so the most recent activity before collection is always included - The export has local-time text; it is converted to UTC with the collector's recorded time zone (see "Where the times come from") - Typically the highest-volume source with fine-grained file activity ### 10. Network Parses network artifacts from triage collection (Snapshot rows -- state at collection time): - TCP connections (tcp_connections.csv) with process info - DNS cache entries (dns_cache.txt) - ARP cache (arp_cache.txt) - Network shares (network_shares.txt) - WiFi profiles (wifi_profiles.txt) ### 11. USB Parses USB device history: - USB storage devices from usb_storage_devices.csv: first install, install, last arrival (connected) and last removal times per device - All SetupAPI device install logs (setupapi.dev.log and the rotated setupapi.dev.<date>.log files): first-install times, converted from the examined system's local time to UTC - USB devices and storage devices (usb_devices.txt, usb_storage_devices.txt) - Mounted devices (mounted_devices.txt) ### 12. Persistence Parses persistence mechanisms from triage collection: - Run keys (run_keys.csv) - HKLM and every user's Run/RunOnce values, timed with the key's last-write time - Startup folders (startup_folders.csv) - all-users and per-user Startup folder items with their created/modified times - Startup entries (startup_entries.csv) - startup folder items - Drivers (drivers.csv) - kernel and filesystem drivers (key last-write time, otherwise Snapshot) - WMI subscriptions (wmi_subscriptions.csv) - event consumers - Suspicious loaded DLLs (loaded_dlls_suspicious.txt) - Snapshot Older collections only have run_keys.txt / startup_folders.txt; their entries have no times and appear as Snapshot rows. ### 13. Amcache Parses Amcache.hve registry hive for program installation/execution history: - InventoryApplicationFile: executables with paths, publishers, SHA1 hashes (EventType Execution) - InventoryApplication: installed applications with versions (EventType Installation) - Times are each entry's registry key last-write time (when Windows recorded or last updated the entry). The PE compile time (LinkDate) is shown in Details only -- it is often meaningless (e.g. year 2105). - The collector copies the hive's transaction logs (.LOG1/.LOG2) so the hive can be loaded. If the hive is still dirty/corrupt, Amcache parsing is skipped for that collection with a warning ### 14. PowerShell History Parses command history: - ConsoleHost_history.txt: PSReadLine command history per user. The file stores no per-command times; all commands get the time of the history file's last write (when the last command was added) ### 15. Memory Dump (opt-in, requires Volatility 3) Analyzes memory dumps captured by the triage collector using Volatility 3: the crash dump from DumpIt (<collection>_memory_dump.dmp) or a raw image (_memory_dump.raw), found next to the collection zip. Opt-in only -- not included in default Sources. Add "Memory" to -Sources to enable. Requires vol.exe in tools\volatility3\ (see tools\volatility3\README.txt). Windows ARM64 dumps are detected from the dump header and skipped: Volatility 3 analyzes Intel x86/x64 Windows memory only (use WinDbg). - windows.pslist: Running processes with creation timestamps, PIDs, parent PIDs - windows.netscan: Network connections with protocol, addresses, ports, state - windows.cmdline: Full command line arguments for each process - windows.svcscan: Windows services with binary paths, state, start type Memory artifacts use the same EventTypes as disk artifacts (ProcessCreation, NetworkConnection, Execution, ServiceChange) and are color-coded automatically. The Source column distinguishes them (Memory-Processes, Memory-Network, etc.). ### 16. System Info Parses systeminfo.txt and the firewall rule list: - "Windows installed" (Original Install Date, EventType Installation) and "System booted" (System Boot Time) at their real times - One Snapshot row with OS name, version, build, system type and domain - Enabled inbound Allow firewall rules (Snapshot rows) ### 17. Antivirus Logs (third-party) Parses the third-party AV logs the collector copies to AntiVirus\<vendor>\ into SecurityAlert rows (detections, blocks, quarantines, failures; routine scan/update lines are skipped): - Symantec / Broadcom Endpoint Protection: daily AV logs (AV\*.Log) - Sophos Anti-Virus: SAV.txt - McAfee VirusScan Enterprise: AccessProtectionLog.txt (blocked and would-be-blocked actions) - ESET: virlog.dat (binary; best effort -- the format is undocumented) These logs record the examined machine's local time, converted to UTC. Built and tested against public sample logs from the plaso project (Symantec, Sophos, McAfee) and a public ESET sample. Other products (CrowdStrike, SentinelOne, Carbon Black, Kaspersky, Malwarebytes, ...) are collected but not parsed: no public sample logs, and several keep their detections in the vendor's cloud console rather than in local logs. ## Viewing the Timeline After the timeline builds, the script presents a viewer menu: [1] Excel -- rows pre-colored by EventType, ready to analyze (Logon=Green, Execution=Orange, Persistence=Red, Network=Blue, etc.) [2] Timeline Explorer -- powerful forensic CSV viewer (no colors, requires manual conditional formatting setup per session) [3] Both -- open Excel (colored) and Timeline Explorer side by side [4] None -- just save the files, don't open anything Both output files are always generated regardless of viewer choice: - timeline.csv -- plain CSV for any tool (Timeline Explorer, SIEM, etc.) - timeline.xlsx -- color-coded Excel with rows pre-formatted by EventType ### Option 1: Excel (recommended for most users) The .xlsx file has every row pre-colored by EventType using the ImportExcel PowerShell module. No manual formatting needed -- open it and start analyzing. Note: Excel may show a repair prompt when opening -- click Yes. This is a known ImportExcel library issue, not data corruption. See "CSV vs Excel differences" above for details. Color scheme (applied automatically): Logon Green -- authentication events Execution Orange -- program execution evidence ProcessCreation Orange -- new processes (Sysmon/4688) PersistenceChange Red -- autostart, services, tasks modified AccountChange Red -- user accounts created/modified NetworkConnection Blue -- network activity, browser, DNS FileAccess Gray -- file system activity ServiceChange Yellow -- service state changes ScheduledTaskChange Yellow -- task scheduler changes USBDevice Purple -- USB device connections Installation Light Blue -- application installs SecurityAlert Bright red -- AV detections, security tampering (Defender disabled, exclusion added); text in bold Snapshot Light gray -- state at collection time, not an event (see "Snapshot rows") The Excel file includes AutoFilter on all columns and a frozen header row. Use column filters to narrow by EventType, Source, User, or date range. If you used -Keywords, filter the Flagged column to TRUE for quick hits. ### Option 2: Timeline Explorer (Eric Zimmerman) A powerful forensic CSV viewer designed for timeline analysis. Downloaded automatically on first selection and cached for future use. Tips for analysis: - Use column filters to narrow by EventType, Source, User, or date range - If you used -Keywords, filter the Flagged column to TRUE for quick hits - Right-click column headers to sort, group, or hide columns - Ctrl+F to search across all columns - File -> Save Session to preserve your filters, colors, and layout Manual color-coding (one-time per session): 1. Right-click any cell in the EventType column 2. Conditional Formatting -> Highlight Cell Rules -> Text That Contains 3. Enter an event type (e.g., "Logon"), pick a color 4. CHECK "Apply formatting to an entire row" 5. Repeat for each event type. File -> Save Session to keep your setup. Note: Timeline Explorer does not support loading color profiles. Colors must be set up manually per session, then saved. This is why the Excel option exists -- it applies the same color scheme automatically. ### Option 3: Both Opens Excel (colored) and Timeline Explorer side by side. Useful when you want the visual color-coding in Excel and the forensic filtering power of Timeline Explorer at the same time. ### Other options for reading the output: PowerShell: $timeline = Import-Csv ".\reports\timeline_<timestamp>\timeline.csv" $timeline | Where-Object { $_.EventType -eq "Logon" } $timeline | Where-Object { $_.EventType -eq "SecurityAlert" } $timeline | Where-Object { $_.EventType -ne "Snapshot" } $timeline | Where-Object { $_.User -match "admin" } $timeline | Where-Object { $_.Flagged -eq "TRUE" } ## Investigation Workflow 1. COLLECT artifacts with triage-collector on the target system Companion: https://github.com/Jumbalicious79/win11-triage-collector 2. BUILD the timeline Double-click Run-TimelineBuilder.bat, pick a collection Or: Run-TimelineBuilder.bat "path\to\collection" "mimikatz,psexec" 3. REVIEW summary in the console output Total events, date range, per-source breakdown, keyword-flagged count 4. CHOOSE a viewer when prompted Excel: pre-colored rows, ready to analyze immediately Timeline Explorer: powerful forensic CSV viewer (manual color setup) Both: side by side for maximum flexibility 5. TRIAGE in your chosen viewer Filter EventType to SecurityAlert for AV detections and tampering Filter Flagged column to TRUE for keyword hits Sort by Timestamp for chronological review Group by EventType for category analysis (hide Snapshot rows to see only real events) 6. INVESTIGATE Pivot on timestamps: what else happened +/- 5 minutes? Pivot on users: what else did this account do? Pivot on processes: where else does this executable appear? Check Browser entries for downloads preceding suspicious execution 7. REFINE if needed Re-run with -StartDate/-EndDate to zoom into a timeframe Re-run with additional -Keywords based on findings Re-run with -Sources to focus on specific artifact types ## Known Limitations and Expected Warnings - USN journal size -- All USN rows are kept by default. On a very busy system the timeline can exceed Excel's row limit (see above); use -MaxUsnEntries N to keep only the newest N rows. The log says how many older rows were dropped. - "Could not load Amcache hive: ..." -- Usually a dirty hive: it needs its transaction logs (Amcache.hve.LOG1/.LOG2). Older versions of the triage collector dropped these hidden files by mistake, so collections made with them often hit this warning and Amcache parsing is skipped. Re-collect with the current collector to get the logs. - "No service data found" -- Appears for mounted-image collections, which have no services.csv (it needs live queries). Scheduled tasks of mounted images are parsed from the collected task XML files instead. - "N IFEO/SilentProcessExit key(s) could not be opened (access denied)" -- A collected hive keeps the key permissions of the system it came from. Keys that deny Administrators (e.g. IFEO\DefenderAgentScan.exe on Windows 11) are skipped and named in the warning. - Hidden scheduled tasks -- A task is reported as hidden when its TaskCache\Tree key has no SD value, so the check relies on Windows keeping SD values there. Hidden task folders are only reported when other folders in the same hive have an SD value; otherwise the log says "N TaskCache\Tree folder(s) without an SD value not reported". - TaskCache times -- "Scheduled task registered" / "last run" rows from Registry-TaskCache are only added for tasks that scheduled_tasks.csv or the task XML files do not already cover. With -Sources Registry but not ScheduledTasks they are added for every task (a few hundred Microsoft tasks on a normal system). - Mark of the Web -- Only Zone.Identifier text stored inside the MFT record (resident, almost always the case) can be read. A non-resident stream still gives a row, with "zone unknown" and no URL. curl.exe and Invoke-WebRequest usually set no Mark of the Web, and copies through FAT/exFAT drives and Unblock-File remove it. - Third-party antivirus in the Application log -- Of the event source names read, only Symantec AntiVirus, McLogEvent and Sophos Anti-Virus are documented; the others are the products' names as they register them, not verified against real logs. Events under any other source name are not read. - Old browser databases -- Each browser query uses the columns the database has. A Chromium store too old to have the key columns (e.g. a History downloads table without target_path, an autofill table without date_created) is skipped with "0 row(s) added" in the log. - Collections from older collector versions -- Still supported, with less precise times: no collection_info.json (the time zone and collection time are read from collection_log.txt), no original file times in the manifest, no bam_entries.csv / run_keys.csv / startup_folders.csv / usb_storage_devices.csv (BAM is read from the SYSTEM hive; run keys and startup items become Snapshot rows), and only setupapi.dev.log is collected (it may be missing if Windows rotated it). - Snapshot rows -- Services, drivers, network state, DLLs and items with no recorded time are shown at the collection time with EventType Snapshot. Their Timestamp is when the state was observed, not when it was created. - Local-time sources -- USN and setupapi times are local-time text. Times inside the hour that repeats when daylight saving time ends cannot be told apart and may be off by one hour. - Excel row limit -- Timelines over 1,048,575 rows are written to CSV only. - Excel "Repaired Records" or recovery prompt -- Known ImportExcel/EPPlus library issue. Click Yes to proceed. Data and color-coding are intact. The CSV file contains the complete unmodified data. See "CSV vs Excel differences" above. - "windows.netscan: 0 entries" -- Volatility 3's netscan plugin may return no results on Windows 11 Build 26200+ due to kernel structure changes. This is a Volatility compatibility issue, not a script bug. ## Limitations vs. Full Tools (plaso/log2timeline) Feature | timeline-builder.ps1 | log2timeline/plaso -----------------+--------------------------------+---------------------------- Se
Scan report · 2026-10-08
- ✓ Prohibited terms or links
- ✓ Repository eligibility
- ✓ slopscore.md paperwork
- ✓ Content policy
- ✓ Risk review — +25 binaries at repo root (Run-TimelineBuilder.bat, timeline-builder.ps1)
From the balcony · 1 of 4 clapped
- Crusoeclapped
Forensic parser with zero dependencies, no telemetry, reads only from local triage collections without querying the system or requesting credentials.
Schnitzel, Cap'm Slop and Princess read it and passed. Their reasons are on the balcony, with every other verdict.
Critics are accounts on this site with no GitHub account behind them. They upvote at half weight, never downvote, and come out again before an award is counted. Who they are.
0 comments
log in to comment.