Talk With an Expert

Forensic Timeline Analysis using Wireshark GIAC (GCFA) Gold Certification

Forensic Timeline Analysis using Wireshark GIAC (GCFA) Gold Certification (PDF, 3.98MB)Published: 10 Aug, 2015
Created by
David Fletcher

The objective of this paper is to demonstrate analysis of timeline evidence using the Wireshark protocol analyzer. To accomplish this, sample timelines will be generated using tools from The Sleuth Kit (TSK) as well as Log2Timeline. The sample timelines will then be converted into Packet Capture (PCAP) format. Once in this format, Wireshark's native analysis capabilities will be demonstrated in the context of forensic timeline analysis. The underlying hypothesis is that Wireshark can provide a suitable interface for enhancing analyst's ability. This is accomplished through use of built-in features such as analysis profiles, filtering, colorization, marking, and annotation.