ResearchBib Share Your Research, Maximize Your Social Impacts
Sign for Notice Everyday Sign up >> Login

Automated Windows-Based Timelining Tool for Memory and Disk Image Analysis: Leveraging Timsort Algorithm with WinPmem, FTK Imager, Volatility 3 and The Sleuth Kit

Journal: International Journal of Computer Science and Mobile Computing - IJCSMC (Vol.13, No. 8)

Publication Date:

Authors : ; ; ; ;

Page : 16-22

Keywords : Image Acquisition; Forensic Artifact Parsing; Timeline Generation; Timsort Algorithm;

Source : Downloadexternal Find it from : Google Scholarexternal

Abstract

As technology evolves, so does the threat of cyberattacks – making Digital Forensics crucial for damage control and prevention. This paper aims to address the inefficiencies faced by investigators in a forensic setting by automating the processes necessary for disk and memory image acquisition, forensic artifact parsing, and timeline generation. Leveraging publicly available tools such as: WinPmem, FTK Imager, Volatility 3 (VOL3), and The Sleuth Kit (TSK), the developed Python script is then able to provide for a clearer insight into the series of events that have transpired during a cyber incident through the generation of detailed and cohesively organized timelines, then using the Timsort algorithm for timeline analysis.

Last modified: 2024-08-06 02:52:54