timescanner in SIFT...
 
Notifications
Clear all

timescanner in SIFT v2.1

5 Posts
4 Users
0 Reactions
715 Views
(@magicm)
Active Member
Joined: 16 years ago
Posts: 8
Topic starter  

I'm having a problem getting a complete timeline using SIFT v2.1. It appears that for some reason the results from timescanner are not being included in the final timeline. I'm following the steps Rob documented in his blog post regarding Super Timelines (http//computer-forensics.sans.org/blog/2010/03/19/digital-forensic-sifting-super-timeline-analysis-and-creation/). I've verified that there is output from timescanner by opening the bodyfile. However, if I then run mactime (instead of running it after the fls and regtime cmds), I get an empty file.

Has anyone else seen this problem, or am I just doing something stupid?

Thanks for the help!


   
Quote
(@twjolson)
Honorable Member
Joined: 17 years ago
Posts: 417
 

SIFT 2.1 includes a new 'do-it-all' utility called log2timeline-sift. It's quite cool, though I am not too experienced in it. Just run that against an image, it mounts it and creates the timeline all in one shot. It puts it in the Cases folder, I believe.


   
ReplyQuote
(@corey_h)
Eminent Member
Joined: 15 years ago
Posts: 43
 

By any chance, have you checked what the default output format for timescanner is? The Sift v2.0 comes with log2timeline version .6 and in the new version the default output was changed to csv instead of mactime. I don't use timescanner anymore so I'm not sure if the default output format was changed as well. If it was changed to csv then the mactime command won't work against it's output. (At the time when Rob's post came out the default file format was mactime)

There are also a few other changes in log2timeline and one important change is that log2timeline has replaced the functionality timescanner provided. The new -r switch will make log2timeline search recursively through directories on the system so you really don't need to use timescanner anymore. For more information you can check out the log2timeline man page http//log2timeline.net/man.html

If you need information on how to create a timeline using version .6 here are a few links showing how.

http//journeyintoir.blogspot.com/2011/09/building-timelines-tools-usage.html

http//thedigitalstandard.blogspot.com/2011/07/log2timeline-and-super-timelilnes.html

hth

Corey Harrell
"Journey into Incident Response"
http//journeyintoir.blogspot.com


   
ReplyQuote
(@magicm)
Active Member
Joined: 16 years ago
Posts: 8
Topic starter  

Thanks for the help guys!


   
ReplyQuote
(@kristinn)
New Member
Joined: 14 years ago
Posts: 2
 

there is also a quick "cheat sheet" for log2timeline in the latest SIFT version that you might want to check out. It provides some quick commands that might be helpful.

And make sure if you are using the debian package release to do an apt-get update && apt-get upgrade to make sure you´ve got the latest release. (as of now the latest release is 0.62)


   
ReplyQuote
Share: