Skip to main content

Automation of Report and Timeline-file based file and URL analysis

The objective of this paper is to describe the workings of a highly extensible, high-performance, automatic timeline report parsing tool. The proposed tool, Log:Mole, can process log2timeline CSV export files and mactime-based bodyfiles.The tool can process these file types from both online and offline systems. This capability enables the tool to provide an automated, up-to-date mechanism for weeding out files that are known good and known-bad. If the files that are referenced in the log2timeline report are accessible to Log:Mole, it is able to gather additional information on their nature by passing them to various analyzing modules and combining the results. Thus Log:Mole can provide additional information not available solely from the logfiles.The proposed tool will greatly reduce the overwhelming amount of data requiring in-depth analysis and it runs atop both Windows and Linux. Moreover, it supports very large input-based report files while remaining high-performance making it suitable for large investigations. Finally, this paper examines use cases, examples and provides a conclusion and possible future work to be carried out including implementing data visualization and metadata extraction capabilities.

34572 (PDF, 2.82MB)

6 May 2014
ByFlorian Eichelberger
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

Threat Intelligence-Driven Attack Surface Management

Research Paper

Defenders struggle to keep up with the pace of digital transformation in the face of an expanding...

  • 9 Aug 2022
  • Jonathan Matkowsky

How to Build and Use an Incident Response Playbook Effectively

Research Paper

An effective incident response playbook provides structure and clarity during high-pressure security events.

  • 25 Jul 2022
  • Andreas Seiler

Windows 10 vs. Windows 11, What Has Changed?

Research Paper

Windows 10 was released on July 29, 2015. It has since become the most installed desktop operating...

  • 25 Jul 2022
  • Andrew Rathbun

Malware Function-based encryption technique

Research Paper

Recent malware often uses techniques to evade detection by cybersecurity products. One of the...

  • 22 Jun 2022
  • Hirokazu Murakami

Detecting Unauthorized Behavior From Legitimate Accounts

Research Paper

Incident Responders face an almost insurmountable amount of log events, and the move to the Cloud...

  • 22 Jun 2022
  • Rodney Caudle

Recommendations for small/medium-sized businesses enabling incident response

Research Paper

Security incidents are inevitable. While large businesses can afford security teams to prepare and...

  • 17 Jan 2022
  • Luke Pearson

Cloud Forensics Triage Framework (CFTF)

Research Paper

Digital media forensic investigations come in multiple forms and span single assets - from thumb...

  • 28 Jul 2021
  • Michael Beck

EDR Evasion: Stranger Things In A Payload

Research Paper

Tackling enterprise security has many pitfalls. Yet, the emergence of Endpoint Detection and Response (EDR) products has paved a way for threat hunters to act at scale.

  • 28 Jul 2021
  • Christopher Watson

CIS CSC Controls vs. Ransomware: An Evaluation

Research Paper

Cybercriminals continue to develop and enhance both new and existing ransomware variants, exploiting...

  • 19 May 2021
  • Dylan Malloy

Missing SQLite Records Analysis

Research Paper

This article will specifically discuss the identification of missing records, within the SQLite...

  • 12 Mar 2021
  • Ian Whiffin, Shafik G Punja, Ian Whiffin

Insider Threat The Theft of Intellectual Property in Windows 10

Research Paper

The prevalence of the theft of intellectual property investigations has grown over the past years...

  • 11 Mar 2021
  • Eduard Du Plessis

A Forensic Analysis of the Encrypting File System

Research Paper

EFS or the Encrypting File System is a feature of the New Technology File System (NTFS). EFS...

  • 24 Feb 2021
  • Ramprasad Ramshankar

Tactical Linguistics: Language Analysis in Cyber Threat Intelligence

Research Paper

The capability to effectively collect and analyze data in strategic foreign languages when...

  • 15 Jan 2021
  • Jason Spataro

Practical Process Analysis - Automating Process Log Analysis with PowerShell

Research Paper

Windows event log analysis is an important and often time-consuming part of endpoint forensics. Deep...

  • 29 Dec 2020
  • Matthew Moore

Incident Response in a Security Operation Center

Research Paper

Cybercrime dates back to the late 1700s and remains a threat today. By observing current threats,...

  • 27 Aug 2020
  • Josh Higgason

Applying the Scientific Method to Threat Hunting

Research Paper

Threat hunting is a proactive approach to discover attackers within an organization. Without the use...

  • 28 May 2020
  • Jeremy Kerwin

Tips and Scripts for Reconnaissance and Scanning

Research Paper

Nowadays, information is the key to success. Pentesters' and bounty hunters' first step is to...

  • 12 Feb 2020
  • Zoltan Panczel

Threat Hunting and Incident Response in a post-compromised environment

Research Paper

If you give an attacker 100 days to move freely in your compromised environment, the evidence is...

  • 3 Dec 2019
  • Rukhsar Khan

Exploring the Human Fingerprints on Malware

Research Paper

Much of the focus of cyber threat intelligence is countering adversaries and the tools and...

  • 22 Nov 2019
  • SANS Institute

The Value of Contemporaneous Notes and Why They Are a Requirement for Security Professionals

Research Paper

Contemporaneous notes, or notes taken as soon as practicable after an event or action takes place, are invaluable to analysts in security roles performing activities such as digital forensics and incident response.

  • 30 Sep 2019
  • Seth Enoka

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.