SkillAgentSearch skills...

building-incident-timeline-with-timesketch

Build collaborative forensic incident timelines using Timesketch to ingest,

Install / Use

npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-timeline-with-timesketch

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

95/100

Category

Security

Supported Platforms

Universal

Our assessment of building-incident-timeline-with-timesketch

building-incident-timeline-with-timesketch scores 95/100 on our quality scale, 144th of 544 Security skills we index (top 27%).

Its SKILL.md is 9.3 KB long, well organised into 49 sections with 12 code examples: a thorough specification that gives an agent plenty to work with.

With 33,340 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
29/30
Structure
20/20
Description
12/15
Adoption
19/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 25 days ago, so building-incident-timeline-with-timesketch is actively maintained.
  • It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.

AI review by kimi-k2.7-code on 2026-09-25. Automated pattern scan on 2026-09-25. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

building-incident-timeline-with-timesketch compared with similar skills

All 4 of these similar skills score higher than building-incident-timeline-with-timesketch; compare them before choosing.

SkillScoreStarsUpdatedFormat
building-incident-timeline-with-timesketch (this skill)by mukul9759533.3k25d agoSKILL.md
algorithmic-artby anthropics100177.9k3d agoSKILL.md
pptxby anthropics100177.9k3d agoSKILL.md
designby nextlevelbuilder100130.2k4d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k4d agoSKILL.md

Frequently asked questions

How do I install building-incident-timeline-with-timesketch?
Run npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-timeline-with-timesketch. The install tabs above show the steps for each supported agent.
Which AI agents does building-incident-timeline-with-timesketch work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is building-incident-timeline-with-timesketch safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is Apache-2.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is building-incident-timeline-with-timesketch still maintained?
The repository was last updated 25 days ago, so building-incident-timeline-with-timesketch is actively maintained.

name: building-incident-timeline-with-timesketch description: Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation documentation. Use when reconstructing the sequence of events during an incident investigation or when multiple analysts need to jointly tag, annotate, and search a shared DFIR timeline. domain: cybersecurity subdomain: incident-response tags:

  • timesketch
  • timeline-analysis
  • forensic-timeline
  • plaso
  • dfir
  • incident-investigation
  • collaborative-forensics mitre_attack:
  • T1059.001
  • T1021.002
  • T1547.001
  • T1053.005
  • T1070.006 version: '1.0' author: mahipal license: Apache-2.0 d3fend_techniques:
  • Executable Denylisting
  • Execution Isolation
  • File Metadata Consistency Validation
  • Content Format Conversion
  • File Content Analysis nist_csf:
  • RS.MA-01
  • RS.MA-02
  • RS.AN-03
  • RC.RP-01

Building Incident Timeline with Timesketch

Overview

Timesketch is an open-source collaborative forensic timeline analysis tool developed by Google that enables security teams to visualize and analyze chronological data from multiple sources during incident investigations. It ingests logs and artifacts from endpoints, servers, and cloud services, normalizes them into a unified searchable timeline, and provides powerful analysis capabilities including built-in analyzers, tagging, sketch annotations, and story building. Timesketch integrates with Plaso (log2timeline) for artifact parsing and supports direct CSV/JSONL ingestion for rapid timeline construction during active incidents.

When to Use

  • When deploying or configuring building incident timeline with timesketch capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with incident response concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Architecture and Components

Core Components

  • Timesketch Server: Web application with REST API for timeline management
  • OpenSearch/Elasticsearch: Backend storage and search engine for timeline events
  • PostgreSQL: Metadata storage for sketches, stories, and user data
  • Redis: Task queue management for background processing
  • Celery Workers: Asynchronous processing of timeline uploads and analyzers

Data Flow

Evidence Sources --> Plaso/log2timeline --> Plaso storage file (.plaso)
     |                                           |
     v                                           v
  CSV/JSONL --> Timesketch Importer --> OpenSearch Index
                                           |
                                           v
                                    Timesketch Web UI
                                    (Search, Analyze, Story)

Deployment

Docker Deployment (Recommended)

# Clone Timesketch repository
git clone https://github.com/google/timesketch.git
cd timesketch

# Run deployment helper script
cd docker
sudo docker compose up -d

# Default access: https://localhost:443
# Admin credentials generated during first run

System Requirements

  • Minimum 8 GB RAM (16+ GB recommended for large investigations)
  • 4 CPU cores minimum
  • SSD storage for OpenSearch indices
  • Docker and Docker Compose installed

Data Ingestion Methods

Method 1: Plaso Integration (Comprehensive)

# Process disk image with log2timeline
log2timeline.py --storage-file evidence.plaso /path/to/disk/image

# Process Windows event logs
log2timeline.py --parsers winevtx --storage-file windows_events.plaso /path/to/evtx/

# Process multiple evidence sources
log2timeline.py --parsers "winevtx,prefetch,amcache,shimcache,userassist" \
  --storage-file full_analysis.plaso /path/to/mounted/image/

# Import Plaso file into Timesketch
timesketch_importer -s "Case-2025-001" -t "Endpoint-WKS01" evidence.plaso

Method 2: CSV Import (Quick Ingestion)

message,datetime,timestamp_desc,source,hostname
"User login detected","2025-01-15T08:30:00Z","Event Recorded","Security Log","DC01"
"PowerShell execution","2025-01-15T08:31:15Z","Event Recorded","PowerShell","WKS042"
# Import CSV directly
timesketch_importer -s "Case-2025-001" -t "Quick-Triage" events.csv

Method 3: JSONL Import (Structured Data)

{"message": "Suspicious logon from 10.1.2.3", "datetime": "2025-01-15T08:30:00Z", "timestamp_desc": "Event Recorded", "source_short": "Security", "hostname": "DC01"}

Method 4: Sigma Rule Integration

# Upload Sigma rules for automated detection
timesketch_importer --sigma-rules /path/to/sigma/rules/

Analysis Workflow

Step 1: Create Investigation Sketch

1. Log into Timesketch web interface
2. Create new sketch (investigation case)
3. Add relevant timelines to the sketch
4. Set sketch description and tags

Step 2: Run Built-in Analyzers

Timesketch includes analyzers that automatically identify:

  • Browser Search Analyzer: Extracts search queries from browser history
  • Chain of Events Analyzer: Links related events (download -> execute)
  • Domain Analyzer: Extracts and categorizes domain names
  • Feature Extraction Analyzer: Identifies IPs, URLs, hashes
  • Geo Location Analyzer: Maps events to geographic locations
  • Similarity Scorer: Finds similar events across timelines
  • Sigma Analyzer: Matches events against Sigma detection rules
  • Account Finder: Identifies user account activity patterns
  • Tagger: Applies labels based on predefined rules

Step 3: Search and Filter

# Search examples in Timesketch query language

# Find all events related to specific user
source_short:Security AND message:"john.admin"

# Find PowerShell execution events
data_type:"windows:evtx:record" AND event_identifier:4104

# Find lateral movement indicators
source_short:Security AND event_identifier:4624 AND xml_string:"LogonType\">3"

# Find events within specific time range
datetime:[2025-01-15T00:00:00 TO 2025-01-15T23:59:59]

# Find file creation events
data_type:"fs:stat" AND timestamp_desc:"Creation Time"

# Search with tags
tag:"suspicious" OR tag:"lateral_movement"

Step 4: Build Investigation Story

1. Create new story within the sketch
2. Add search views that support each finding
3. Annotate key events with investigator notes
4. Link events to MITRE ATT&CK techniques
5. Document the attack narrative chronologically
6. Export story for inclusion in incident report

Advanced Features

Collaborative Investigation

  • Multiple analysts work on the same sketch simultaneously
  • Comments and annotations persist on events
  • Saved searches shared across the team
  • Investigation stories document findings in context

API Automation

from timesketch_api_client import config
from timesketch_api_client import client as ts_client

# Connect to Timesketch
ts = ts_client.TimesketchApi(
    host_uri="https://timesketch.local",
    username="analyst",
    password="password"
)

# Get sketch
sketch = ts.get_sketch(1)

# Search events
search = sketch.explore(
    query_string='event_identifier:4624 AND LogonType:3',
    return_fields='datetime,message,hostname,source_short'
)

# Add tags to events
for event in search.get('objects', []):
    sketch.tag_event(event['_id'], ['lateral_movement'])

Integration with Dissect

# Use Dissect for faster artifact parsing (alternative to Plaso)
target-query -f timesketch://timesketch.local/case-001 \
  targets/hostname/ -q "windows.evtx" --limit 0

Key Data Sources for Timeline Building

| Source | Parser | Evidence Value | |--------|--------|---------------| | Windows Event Logs (.evtx) | winevtx | Authentication, process execution, services | | Prefetch Files | prefetch | Program execution history | | MFT ($MFT) | mft | File system activity | | Registry Hives | winreg | System configuration, persistence | | Browser History | chrome/firefox | Web activity, downloads | | Syslog | syslog | Linux/network device events | | CloudTrail Logs | jsonl | AWS API activity | | Azure Activity Logs | jsonl | Azure resource operations | | Firewall Logs | csv/jsonl | Network connections | | Proxy Logs | csv/jsonl | HTTP/HTTPS traffic |

MITRE ATT&CK Mapping

| Technique | Timeline Indicators | |-----------|-------------------| | Initial Access (TA0001) | First malicious event, phishing email receipt | | Execution (T1059) | PowerShell/CMD events, process creation | | Persistence (TA0003) | Registry modifications, scheduled tasks, services | | Lateral Movement (TA0008) | Remote logons, SMB connections, RDP sessions | | Exfiltration (TA0010) | Large data transfers, cloud storage uploads |

References

Related Skills

View on GitHub
GitHub Stars33.3k
CategorySecurity
Updated25d ago
Forks4.0k

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions