Forensic Timeline
A time-ordered reconstruction of relevant filesystem, operating-system, application, and user events used to analyze activity and sequence of actions.
Digital-Forensics Context
A forensic timeline orders filesystem, operating-system, application, and user artifacts to reconstruct sequences of activity. MACB-style timestamps and other time sources must be normalized with their timezone, clock skew, timestamp semantics, and source reliability in mind.
Evidence Boundary
One timestamp rarely proves that a particular user action occurred at exactly that time. Modification rules differ among filesystems and applications, so timeline events should be corroborated with independent artifacts.
Related Digital-Forensics Concepts
- Master File Table
- USN Journal
- Chain of Custody
- Timeline Analysis