Introducing the official account for the Timesketch project. Timesketch is a Digital Forensic Timeline Analysis platform that helps #DFIR teams collaborate to resolve complex cases. Follow us to be the first to learn about new features and updates! https://t.co/pgmQo5famN
New Timesketch release (20230721)
Highlights:
- OpenSearch queries in DFIQ
- Preserve user defined filters
- Support event list sorting
- Rework comments
- Analyzer results in the CLI
- Sketch attributes in the CLI
https://t.co/gQyTB41SV9
#DFIR
✨ New Timesketch release.
Highlights:
SSH/Windows bruteforce analyzers, DFIQ support, Updated event tags UI, Verbose analyzer output and Restyled timeline chips.
Full changelog: https://t.co/NJoOS1KseC
Thanks to everyone who contributed to this release!
We have started to automatically tag releases to our official docker images. Use the release version when pulling the image. For example:
https://t.co/PmTa8Y95ya
GitHub releases: https://t.co/qw9CgsEse9
Changelog: https://t.co/Jvpcm6hqgH
We just merged a small change to the DB schema. If you are running bleeding edge (HEAD) you need to upgrade your database schema. See instructions here: https://t.co/smmP97Xsqt
For all command line heroes out there. The Timesketch CLI tool is out. Search your forensic timelines from the comfort of your terminal or do timeline analysis from your scripts! https://t.co/15FabScJ3u
For our developing-folks, last week we fixed all the end2end, linter and unit tests, so if you develop and create PRs, check for all the boxes to be green.
OpenSearch is now the default search backend for new Timesketch installations as well as the development environment. More details here: https://t.co/F8GHET5OSV #OpenSearch#dfir
Do you remember the time when you wanted to 𝗦𝘁𝗮𝗿 𝗔𝗹𝗹 the events in Timesketch but some were already starred, so you ended up accidentally unstarring them?🧐 No more! 💪🏻
https://t.co/zJNiG7984w
👁️🕰️Happy to share a new blog post connecting a few pieces: @virustotal + @TimesketchProj + @sigma_hq and DFTimewolf. How to use a new VT feature that allows Enterprise customers to download EVTX for a sandbox execution of submitted samples in DFIR. 🕰️👁️
https://t.co/e3sEvSLspQ
Σ Timesketch Sigma compose. You can now compose and parse your @sigma_hq rules straight in the UI, copy the search query and test it with your data set. https://t.co/9aK1PvhJmK Please test it and provide feedback. Written by @alexanderjaeger Σ
Did you know that Timesketch has support for Jupyter and Colab notebooks? This significantly lowers the bar for innovation in forensic timeline research. Get started: https://t.co/EvGtTCEYd7
If you want to use it for analysis, here is an intro:
https://t.co/4IIomyhosr
#dfir
This is your chance to influence the future of Timesketch and forensic timeline analysis! Take a look at our 2021 user survey here: https://t.co/QNgqGTnU0T
#DFIR
spun up our @velocidex to @TimesketchProj pipeline last night from scratch to test some new timesketch and sigma magic, kicked off some triages in velociraptor
and hour later, sketches automagically appeared 🌈🤓💙
deployment instructions here:
https://t.co/PWNsujALvB
We made it easier to change the color on your timelines as well as getting back basic information such as analyzer details etc, all while staying in context (no more extra pages to configure). h/t @BartInglot for your work on this!
We are excited to present the new innovative search history in Timesketch. Implemented as a tree with support for branching, annotations and intuitive navigation means you will never get lost in your searches again! #dfir
I spend quite some time on this feature and the underlying stack, so I am eager to hear feedback from people. Hope you like it @TimesketchProj@sigma_hq