Plaso
DFIR timeline generation engine that parses logs, disk images, and artifacts to create unified event timelines for incident investigations.
Technical Architecture & Overview
Plaso, also known as log2timeline, is an open-source DFIR tool that extracts timestamps and events from logs, disk images, and forensic artifacts to produce unified timelines. It automates the creation of super timelines used to reconstruct activity during investigations.
Targeted Technical Use Cases
Generating event timelines from forensic images, logs, and endpoint artifacts during incident response.
Evaluation & Trade-offs
Core Strengths
- +Parses a wide range of file systems, logs, and artifact formats.
- +Produces unified event timelines from heterogeneous forensic sources.
- +Actively maintained as part of the log2timeline project.
Trade-Offs & Limitations
- -Large timelines can be difficult to query and interpret without additional tooling.
- -Parsing speed and resource usage scale with the volume of input data.
Defensive Security Application
Reconstructing attacker activity, establishing a forensic timeline, and correlating events across evidence sources.
Frequently Asked Questions
What is Plaso?→
Plaso, also known as log2timeline, is an open-source DFIR tool that extracts timestamps and events from logs, disk images, and forensic artifacts to produce unified timelines. It automates the creation of super timelines used to reconstruct activity during investigations.
What is Plaso used for?→
Generating event timelines from forensic images, logs, and endpoint artifacts during incident response.
What are the strengths of Plaso?→
- +Parses a wide range of file systems, logs, and artifact formats.
- +Produces unified event timelines from heterogeneous forensic sources.
- +Actively maintained as part of the log2timeline project.
What are the limitations of Plaso?→
- +Large timelines can be difficult to query and interpret without additional tooling.
- +Parsing speed and resource usage scale with the volume of input data.
How is Plaso used defensively?→
Reconstructing attacker activity, establishing a forensic timeline, and correlating events across evidence sources.