Top Cybersecurity Training Protects Your Assets - Learn From the BEST and Apply New Knowledge Immediately!


To attend this webcast, login to your SANS Account or create your Account.

This webcast has been archived. To view the webcast login into your SANS Portal Account or create an account by clicking the "Get Registered" button on the right. Once you register, you can download the presentation slides below.

Forensic Timeline Analysis Using Wireshark

  • Wednesday, October 25, 2017 at 10:30 AM EDT (2017-10-25 14:30:00 UTC)
  • David Fletcher

You can now attend the webcast using your mobile device!



Forensic timelines performed on captured hard disk images create a large volume of output. Organizing and analyzing this information can be challenging for an investigator. Colorization of the timeline can make this task easier but often relies on inflexible single-purpose tools. As an alternative, use of the Wireshark protocol analyzer will be investigated for this purpose. Useful features such as through put statistics, colorization profiles, packet comments, and packet marking will be applied to forensic analysis to illustrate the power of leveraging a mature and flexible application to replace single purpose tools.

Speaker Bio

David Fletcher

David Fletcher is a security analyst with Black Hills Information Security (BHIS). In his current role, he performs a wide array of different penetration testing activities to assist customers in improving their security posture. Before moving to BHIS, David worked for the United States Air Force for twenty-three years. During this time, he worked in a wide array of disciplines including system administration, vulnerability management, boundary defense, web application programming, database programming/administration, installation level network operations, and offensive cyber research and development.

David is a candidate for the Master of Science degree in Information Security Engineering from the SANS Technology Institute.

The SANS Technology Institute is the only graduate program that combines SANS technical training, recognized as the industry's best, with leadership and management curriculum specifically developed for the unique needs of aspiring leaders. Learn more at

Need Help? Visit our FAQ page or email

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.