Forensic timelines performed on captured hard disk images create a large volume of output. Organizing and analyzing this information can be challenging for an investigator. Colorization of the timeline can make this task easier but often relies on inflexible single-purpose tools. As an alternative, use of the Wireshark protocol analyzer will be investigated for this purpose. Useful features such as through put statistics, colorization profiles, packet comments, and packet marking will be applied to forensic analysis to illustrate the power of leveraging a mature and flexible application to replace single purpose tools.