System Combo Timeline

複数の入力ファイルから TLN形式のタイムラインを生成してくれるみたい。TLNは少しずつ拡がりを見せている…のかな?

http://www.cutawaysecurity.com/blog/system-combo-timeline

System Combo Timeline was developed to help with the quick generation of timeline information from a Windows system. This tool is currently in the development stages but is ready for active use during an incident response engagement. The tool is a python script that provides internal functionality and external communications with tools that perform parsing of specific Windows system artifacts to produce a TLN-based text file. The resulting file can be reviewed using your favorite text editor or, as I prefer, Mandiant’s Highlighter. Recommendations and functionality requests are welcome.