SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Last Month at the SANS360, I promised the release of the Timeline Template to be used to automatically colorize your timelines.
The EXCEL TEMPLATE can be downloaded here.
To use the template you must currently use MS EXCEL 2007 or higher. Hopefully we can get other formats of this created, but think this is a start to help out with analysis of log2timeline data.
To learn how to create timelines: Read these articles
Your chart should now look like this once you start filtering your data to the elements you are looking for.

Another Example

This chart will also help you with analysis of the colorized artifacts from our FOR408 Windows In-Depth Course

To select specific artifacts of interest you can select them from the source, sourcetype, type, or short columns. Below is an example of FILTERING using the drop down filter for the Sourcetype column. If you wanted look for specific data types and eliminate others, this is a great place to start.

More articles on analysis techniques are coming, but the color spreadsheet needs some polish still.


Rob T. Lee is Chief AI Officer and Chief of Research at SANS Institute, where he leads research, mentors faculty, and helps cybersecurity teams and executive leaders prepare for AI and emerging threats.
Read more about Rob T. Lee