Agent skill

Building Incident Timeline With Timesketch

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation…

Apache-2.0Auto-check: notesSecurity

Install Building Incident Timeline With Timesketch

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-timeline-with-timesketch -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills building-incident-timeline-with-timesketch --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/building-incident-timeline-with-timesketch .claude/skills/building-incident-timeline-with-timesketch && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
building-incident-timeline-with-timesketch
GitHub stars
34k
Token cost
~2.4k tokens
SKILL.md length
533 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation…

  • Works in 4 steps: Create Investigation Sketch → Run Built-in Analyzers → Search and Filter → …
  • Reconstructing the sequence of events during an incident investigation
  • SKILL.md covers Overview, When to Use, Prerequisites and Architecture and Components, plus 7 more sections
  • Runs Python scripts from its folder; calls git and docker; reaches github.com

What it does

Building Incident Timeline With Timesketch is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation documentation. Use when reconstructing the sequence of events during an incident investigation or when multiple analysts need to jointly tag, annotate, and search a shared DFIR timeline.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Digital forensics. It works with Docker. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Reconstructing the sequence of events during an incident investigation
  • Multiple analysts need to jointly tag
  • Search a shared DFIR timeline

Example prompts

  • “/building-incident-timeline-with-timesketch”

Requirements

  • Python 3
  • Docker

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Create Investigation Sketch
  2. Run Built-in Analyzers
  3. Search and Filter
  4. Build Investigation Story

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • timesketch.org
    • cisa.gov
    • huntandhackett.com
    • plaso.readthedocs.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Building Incident Timeline With Timesketch loads about 2.4k tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 533 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:92
    sudo docker compose up -d

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 533 words, ~2,383 tokens.

Download SKILL.mdSave it as .claude/skills/building-incident-timeline-with-timesketch/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
building-incident-timeline-with-timesketch
description
Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation documentation. Use when reconstructing the sequence of events during an incident investigation or when multiple analysts need to jointly tag, annotate, and search a shared DFIR timeline.
domain
cybersecurity
subdomain
incident-response
tags
timesketch, timeline-analysis, forensic-timeline, plaso, dfir, incident-investigation, collaborative-forensics
mitre_attack
T1059.001, T1021.002, T1547.001, T1053.005, T1070.006
version
1.0
author
mahipal
license
Apache-2.0
d3fend_techniques
Executable Denylisting, Execution Isolation, File Metadata Consistency Validation, Content Format Conversion, File Content Analysis
nist_csf
RS.MA-01, RS.MA-02, RS.AN-03, RC.RP-01

Building Incident Timeline with Timesketch

Overview

Timesketch is an open-source collaborative forensic timeline analysis tool developed by Google that enables security teams to visualize and analyze chronological data from multiple sources during incident investigations. It ingests logs and artifacts from endpoints, servers, and cloud services, normalizes them into a unified searchable timeline, and provides powerful analysis capabilities including built-in analyzers, tagging, sketch annotations, and story building. Timesketch integrates with Plaso (log2timeline) for artifact parsing and supports direct CSV/JSONL ingestion for rapid timeline construction during active incidents.

When to Use

  • When deploying or configuring building incident timeline with timesketch capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with incident response concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Architecture and Components

Core Components
  • Timesketch Server: Web application with REST API for timeline management
  • OpenSearch/Elasticsearch: Backend storage and search engine for timeline events
  • PostgreSQL: Metadata storage for sketches, stories, and user data
  • Redis: Task queue management for background processing
  • Celery Workers: Asynchronous processing of timeline uploads and analyzers
Data Flow
Evidence Sources --> Plaso/log2timeline --> Plaso storage file (.plaso)
     |                                           |
     v                                           v
  CSV/JSONL --> Timesketch Importer --> OpenSearch Index
                                           |
                                           v
                                    Timesketch Web UI
                                    (Search, Analyze, Story)

Deployment

bash
# Clone Timesketch repository
git clone https://github.com/google/timesketch.git
cd timesketch

# Run deployment helper script
cd docker
sudo docker compose up -d

# Default access: https://localhost:443
# Admin credentials generated during first run
System Requirements
  • Minimum 8 GB RAM (16+ GB recommended for large investigations)
  • 4 CPU cores minimum
  • SSD storage for OpenSearch indices
  • Docker and Docker Compose installed

Data Ingestion Methods

Method 1: Plaso Integration (Comprehensive)
bash
# Process disk image with log2timeline
log2timeline.py --storage-file evidence.plaso /path/to/disk/image

# Process Windows event logs
log2timeline.py --parsers winevtx --storage-file windows_events.plaso /path/to/evtx/

# Process multiple evidence sources
log2timeline.py --parsers "winevtx,prefetch,amcache,shimcache,userassist" \
  --storage-file full_analysis.plaso /path/to/mounted/image/

# Import Plaso file into Timesketch
timesketch_importer -s "Case-2025-001" -t "Endpoint-WKS01" evidence.plaso
Method 2: CSV Import (Quick Ingestion)
csv
message,datetime,timestamp_desc,source,hostname
"User login detected","2025-01-15T08:30:00Z","Event Recorded","Security Log","DC01"
"PowerShell execution","2025-01-15T08:31:15Z","Event Recorded","PowerShell","WKS042"
bash
# Import CSV directly
timesketch_importer -s "Case-2025-001" -t "Quick-Triage" events.csv
Method 3: JSONL Import (Structured Data)
json
{"message": "Suspicious logon from 10.1.2.3", "datetime": "2025-01-15T08:30:00Z", "timestamp_desc": "Event Recorded", "source_short": "Security", "hostname": "DC01"}
Method 4: Sigma Rule Integration
bash
# Upload Sigma rules for automated detection
timesketch_importer --sigma-rules /path/to/sigma/rules/

Analysis Workflow

Step 1: Create Investigation Sketch
1. Log into Timesketch web interface
2. Create new sketch (investigation case)
3. Add relevant timelines to the sketch
4. Set sketch description and tags
Step 2: Run Built-in Analyzers

Timesketch includes analyzers that automatically identify:

  • Browser Search Analyzer: Extracts search queries from browser history
  • Chain of Events Analyzer: Links related events (download -> execute)
  • Domain Analyzer: Extracts and categorizes domain names
  • Feature Extraction Analyzer: Identifies IPs, URLs, hashes
  • Geo Location Analyzer: Maps events to geographic locations
  • Similarity Scorer: Finds similar events across timelines
  • Sigma Analyzer: Matches events against Sigma detection rules
  • Account Finder: Identifies user account activity patterns
  • Tagger: Applies labels based on predefined rules
Show full SKILL.md (183 more words)Show less
Step 3: Search and Filter
# Search examples in Timesketch query language

# Find all events related to specific user
source_short:Security AND message:"john.admin"

# Find PowerShell execution events
data_type:"windows:evtx:record" AND event_identifier:4104

# Find lateral movement indicators
source_short:Security AND event_identifier:4624 AND xml_string:"LogonType\">3"

# Find events within specific time range
datetime:[2025-01-15T00:00:00 TO 2025-01-15T23:59:59]

# Find file creation events
data_type:"fs:stat" AND timestamp_desc:"Creation Time"

# Search with tags
tag:"suspicious" OR tag:"lateral_movement"
Step 4: Build Investigation Story
1. Create new story within the sketch
2. Add search views that support each finding
3. Annotate key events with investigator notes
4. Link events to MITRE ATT&CK techniques
5. Document the attack narrative chronologically
6. Export story for inclusion in incident report

Advanced Features

Collaborative Investigation
  • Multiple analysts work on the same sketch simultaneously
  • Comments and annotations persist on events
  • Saved searches shared across the team
  • Investigation stories document findings in context
API Automation
python
from timesketch_api_client import config
from timesketch_api_client import client as ts_client

# Connect to Timesketch
ts = ts_client.TimesketchApi(
    host_uri="https://timesketch.local",
    username="analyst",
    password="password"
)

# Get sketch
sketch = ts.get_sketch(1)

# Search events
search = sketch.explore(
    query_string='event_identifier:4624 AND LogonType:3',
    return_fields='datetime,message,hostname,source_short'
)

# Add tags to events
for event in search.get('objects', []):
    sketch.tag_event(event['_id'], ['lateral_movement'])
Integration with Dissect
bash
# Use Dissect for faster artifact parsing (alternative to Plaso)
target-query -f timesketch://timesketch.local/case-001 \
  targets/hostname/ -q "windows.evtx" --limit 0

Key Data Sources for Timeline Building

SourceParserEvidence Value
Windows Event Logs (.evtx)winevtxAuthentication, process execution, services
Prefetch FilesprefetchProgram execution history
MFT ($MFT)mftFile system activity
Registry HiveswinregSystem configuration, persistence
Browser Historychrome/firefoxWeb activity, downloads
SyslogsyslogLinux/network device events
CloudTrail LogsjsonlAWS API activity
Azure Activity LogsjsonlAzure resource operations
Firewall Logscsv/jsonlNetwork connections
Proxy Logscsv/jsonlHTTP/HTTPS traffic

MITRE ATT&CK Mapping

TechniqueTimeline Indicators
Initial Access (TA0001)First malicious event, phishing email receipt
Execution (T1059)PowerShell/CMD events, process creation
Persistence (TA0003)Registry modifications, scheduled tasks, services
Lateral Movement (TA0008)Remote logons, SMB connections, RDP sessions
Exfiltration (TA0010)Large data transfers, cloud storage uploads

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/building-incident-timeline-with-timesketch of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Building Incident Timeline With Timesketch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Building Incident Timeline With Timesketch compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Building Incident Timeline With Timesketch this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: NotesApache-2.0
Ctf Forensicsljagiello/ctf-skills3.4k—~9.2kAutomated safety check: WarnMIT
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Container Scanning with GrypeAgentSecOps/SecOpsAgentKit2201 repos~2.5kAutomated safety check: PassCustom licence
Code Securitysemgrep/skills324—~1.2kAutomated safety check: PassCustom licence
Hadolint Dockerfile Security LintingAgentSecOps/SecOpsAgentKit2201 repos~4.4kAutomated safety check: PassCustom licence

Similar skills

  • Ctf Forensics

    ljagiello/ctf-skills

    Provides digital forensics and signal analysis techniques for CTF challenges.

    3.4k GitHub stars~9.2k tokensUpdated 27 days ago
    SecurityAuto-check: warnings
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Container Scanning with Grype

    AgentSecOps/SecOpsAgentKit

    Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

    220 GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    324 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Hadolint Dockerfile Security Linting

    AgentSecOps/SecOpsAgentKit

    Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates.

    220 GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Building Incident Timeline With Timesketch

What does Building Incident Timeline With Timesketch do?

Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation…. Building Incident Timeline With Timesketch is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation documentation.

When should I use Building Incident Timeline With Timesketch?

Building Incident Timeline With Timesketch fits situations like: reconstructing the sequence of events during an incident investigation; multiple analysts need to jointly tag; search a shared DFIR timeline.

How do I install Building Incident Timeline With Timesketch in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-timeline-with-timesketch -a claude-code`. Or copy the skill folder (skills/building-incident-timeline-with-timesketch in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/building-incident-timeline-with-timesketch in your project. Claude Code loads it when a task matches its description.

How do I install Building Incident Timeline With Timesketch in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-timeline-with-timesketch -a codex`. Or copy the skill folder (skills/building-incident-timeline-with-timesketch in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/building-incident-timeline-with-timesketch in your project. Codex loads it when a task matches its description.

Can I use Building Incident Timeline With Timesketch in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-incident-timeline-with-timesketch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/building-incident-timeline-with-timesketch, .gemini/skills/building-incident-timeline-with-timesketch, .github/skills/building-incident-timeline-with-timesketch and .opencode/skills/building-incident-timeline-with-timesketch in your project.

What does Building Incident Timeline With Timesketch need to run?

Going by SKILL.md and its folder, Building Incident Timeline With Timesketch needs Python for the scripts in its folder and the command-line tools its instructions call (git and docker). Our summary lists: Python 3; Docker.

Does Building Incident Timeline With Timesketch access the network?

SKILL.md names 5 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: timesketch.org, cisa.gov, huntandhackett.com and plaso.readthedocs.io. This is read from the text; nothing was executed.

Is Building Incident Timeline With Timesketch safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Building Incident Timeline With Timesketch use?

Building Incident Timeline With Timesketch is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Building Incident Timeline With Timesketch use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Building Incident Timeline With Timesketch?

Skills that share tags, products or a category with Building Incident Timeline With Timesketch: Ctf Forensics (ljagiello/ctf-skills, 3.4k stars), Cyberowlai (karimhabush/cyberowl, 263 stars), Container Scanning with Grype (AgentSecOps/SecOpsAgentKit, 220 stars) and Code Security (semgrep/skills, 324 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Building Incident Timeline With Timesketch?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.