Agent skill

Building Super Timelines With Plaso

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then…

Apache-2.0Auto-check: notesSecurity

Install Building Super Timelines With Plaso

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-super-timelines-with-plaso -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills building-super-timelines-with-plaso --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/building-super-timelines-with-plaso .claude/skills/building-super-timelines-with-plaso && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
building-super-timelines-with-plaso
GitHub stars
34k
Token cost
~1.9k tokens
SKILL.md length
721 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then…

  • Works in 7 steps: Extract events into a storage file → Inspect the storage file → Export a filtered super timeline (CSV) → …
  • Reconstructing the full sequence of events on a compromised
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder; calls docker and apt-get

What it does

Building Super Timelines With Plaso is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then triage and filter the results in Timesketch. Use when reconstructing the full sequence of events on a compromised or forensically imaged host during a DFIR investigation.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security, covering Digital forensics. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Reconstructing the full sequence of events on a compromised
  • Forensically imaged host during a DFIR investigation

Example prompts

  • “/building-super-timelines-with-plaso”

Requirements

  • Python 3
  • Docker

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Extract events into a storage file
  2. Inspect the storage file
  3. Export a filtered super timeline (CSV)
  4. One-step extraction + export with psteal
  5. Import into Timesketch
  6. Triage in Timesketch
  7. Hunt for anti-forensics

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • docker
    • apt-get

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • plaso.readthedocs.io
    • timesketch.org
    • hub.docker.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Building Super Timelines With Plaso loads about 1.9k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 721 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:59
    sudo add-apt-repository ppa:gift/stable
  • NoteRuns commands with sudoSKILL.md:60
    sudo apt-get update && sudo apt-get install -y plaso-tools

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 721 words, ~1,916 tokens.

Download SKILL.mdSave it as .claude/skills/building-super-timelines-with-plaso/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
building-super-timelines-with-plaso
description
Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then triage and filter the results in Timesketch. Use when reconstructing the full sequence of events on a compromised or forensically imaged host during a DFIR investigation.
domain
cybersecurity
subdomain
digital-forensics
tags
digital-forensics, plaso, log2timeline, super-timeline, timesketch, dfir, timeline-analysis, incident-response
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
RS.AN-03
mitre_attack
T1070

Building Super Timelines with Plaso

Authorized Use Only: Build timelines only from evidence you are authorized to analyze. Work from forensic images/copies and preserve chain of custody.

Overview

Plaso (Plaso Langar Að Safna Öllu) is the open-source engine behind log2timeline, the standard for building forensic super timelines — a single chronological, normalized view fusing hundreds of artifact types (file-system MACB times, registry, EVTX, browser history, prefetch, LNK, $UsnJrnl, syslog, and more) into one timeline. Plaso has three core CLI tools:

  • log2timeline.py — extracts events from a source (disk image, mount point, directory, or device) into a .plaso storage file using its large parser/plugin set.
  • pinfo.py — reports on the contents and processing metadata of a .plaso file.
  • psort.py — post-processes, filters, deduplicates, time-zones, and exports the storage file to an output format (CSV, JSON-line, Elasticsearch, Timesketch, etc.).
  • psteal.py — convenience wrapper that runs extraction + export in one step.

The resulting timeline is enormous, so analysts triage it in Timesketch — a collaborative, web-based timeline analysis platform that ingests .plaso files (or CSV/JSONL) and supports filtering, tagging, starring, saved searches, and automated analyzers.

When to Use

  • Reconstructing the full sequence of events on a compromised host during incident response.
  • Correlating activity across many artifact sources on a single normalized timeline.
  • Investigating anti-forensic behavior such as timestomping or log clearing (which stands out against MACB and journal evidence).
  • Feeding a curated timeline into Timesketch for team triage.

Prerequisites

  • Install Plaso (Docker is the supported, reproducible method):
    bash
    docker pull log2timeline/plaso
    # Run a tool, mounting your evidence/output directory
    docker run -v /cases:/data log2timeline/plaso log2timeline.py --version
    Alternatively on Ubuntu via the GIFT PPA:
    bash
    sudo add-apt-repository ppa:gift/stable
    sudo apt-get update && sudo apt-get install -y plaso-tools
  • A Timesketch instance (docker-compose deployment from https://github.com/google/timesketch) for triage.
  • A forensic image (E01/raw) or mounted file system.

Objectives

  • Extract events from an image into a .plaso storage file.
  • Inspect the storage file with pinfo.
  • Filter and export a focused super timeline with psort.
  • Import the timeline into Timesketch and triage it.

MITRE ATT&CK Mapping

IDOfficial Technique NameRelevance to this skill
T1070Indicator RemovalSuper timelines reveal indicator-removal behavior (log clearing, file deletion, timestomping) by exposing inconsistencies between MACB timestamps, the USN journal, and event logs.

Plaso is a defensive forensics engine; the mapping reflects the anti-forensic adversary behavior super timelines are well suited to detect.

Workflow

1. Extract events into a storage file

log2timeline.py writes a .plaso file from a source. --storage-file names the output; the source can be an .E01, raw image, mount point, or directory.

bash
log2timeline.py --storage-file timeline.plaso /cases/greendale/image.E01

Scope parsers for speed/relevance with --parsers (presets like win7, webhist, or explicit parser names):

bash
log2timeline.py --parsers "win7,!filestat" --storage-file timeline.plaso /cases/image.E01
2. Inspect the storage file

pinfo.py reports source, parsers used, event counts, and any warnings.

bash
pinfo.py timeline.plaso
Show full SKILL.md (308 more words)Show less
3. Export a filtered super timeline (CSV)

psort.py selects an output module with -o, writes with -w, normalizes the timezone with --output-time-zone, and accepts an event filter expression to scope a date range.

bash
psort.py --output-time-zone 'UTC' \
  -o l2tcsv \
  -w supertimeline.csv \
  timeline.plaso \
  "date > datetime('2026-01-01T00:00:00') AND date < datetime('2026-01-27T00:00:00')"

For Timesketch-friendly JSON lines, use the json_line output module:

bash
psort.py --output-time-zone 'UTC' -o json_line -w supertimeline.jsonl timeline.plaso
4. One-step extraction + export with psteal

psteal.py runs extraction and CSV export together for quick triage.

bash
psteal.py --source /cases/greendale/image.E01 -o l2tcsv -w supertimeline.csv
5. Import into Timesketch

Use the official timesketch_importer CLI to upload the .plaso (or CSV/JSONL) into a sketch. Timesketch chunks/reassembles and indexes the file.

bash
timesketch_importer \
  --host http://127.0.0.1:5000 \
  --username admin \
  --timeline_name "greendale-host01" \
  --sketch_id 1 \
  timeline.plaso
6. Triage in Timesketch

In the sketch UI:

  • Filter to a suspicious window or data_type (e.g. windows:evtx:record, fs:stat).
  • Star/tag events of interest and add comments for collaboration.
  • Save searches and run analyzers (e.g. browser timeframe, similarity, sigma) over the timeline.
  • Build a narrative from corroborating events across artifact sources.
7. Hunt for anti-forensics

Look for MACB timestamps that disagree with $UsnJrnl entries (timestomping), gaps or EventLog cleared (1102) records, and deleted-then-recreated files — all visible on the unified timeline.

Tools and Resources

ResourcePurposeLink
Plaso (log2timeline)Timeline engine + toolshttps://github.com/log2timeline/plaso
Plaso documentationTool usage and parsershttps://plaso.readthedocs.io/
TimesketchTimeline analysis platformhttps://github.com/google/timesketch
Timesketch docsDeployment, importer, analyzershttps://timesketch.org/
Plaso Docker imageReproducible runtimehttps://hub.docker.com/r/log2timeline/plaso

Key Commands

CommandPurpose
log2timeline.py --storage-file out.plaso <source>Extract events
log2timeline.py --parsers <preset> ...Scope parsers
pinfo.py out.plasoInspect storage file
psort.py -o l2tcsv -w out.csv out.plaso "<filter>"Filter + export CSV
psort.py -o json_line -w out.jsonl out.plasoExport JSONL
psteal.py --source <img> -o l2tcsv -w out.csvExtract + export in one step
timesketch_importer --host ... <file>Import into Timesketch

Validation Criteria

  • .plaso storage file produced from the source image
  • pinfo confirms expected parsers ran and event counts are non-zero
  • Super timeline exported with UTC normalization and a scoped filter
  • Timeline imported into a Timesketch sketch and indexed
  • Suspicious window triaged with tags/stars/saved searches
  • Anti-forensic indicators (timestomping, log clearing) checked
  • Findings documented with corroborating cross-source events

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/building-super-timelines-with-plaso of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Building Super Timelines With Plaso next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Building Super Timelines With Plaso compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Building Super Timelines With Plaso this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: NotesApache-2.0
Oss ForensicsTommy-yw/RunbookHermes5463 repos~5kAutomated safety check: PassMIT
Ctf Malwareljagiello/ctf-skills3.4k—~2.1kAutomated safety check: NotesMIT
Dfirtransilienceai/communitytools563—~1.5kAutomated safety check: PassMIT
TShark Traffic AnalysisAgentSecOps/SecOpsAgentKit2201 repos~4.8kAutomated safety check: NotesCustom licence
Runtime Memory Sample Acquisitiondslsdzc/rev-skills135—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Oss Forensics

    Tommy-yw/RunbookHermes

    Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

    546 GitHub starsUsed in 3 repos~5k tokens
    SecurityAuto-check passed
  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 27 days ago
    SecurityAuto-check: notes
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    563 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • TShark Traffic Analysis

    AgentSecOps/SecOpsAgentKit

    Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

    220 GitHub starsUsed in 1 repo~4.8k tokens
    SecurityAuto-check: notes
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    135 GitHub stars~2k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Digital Forensics

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.

    41k GitHub starsUsed in 2 repos~389 tokens
    SecurityAuto-check: warnings

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Building Super Timelines With Plaso

What does Building Super Timelines With Plaso do?

Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then…. Building Super Timelines With Plaso is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then triage and filter the results in Timesketch.

When should I use Building Super Timelines With Plaso?

Building Super Timelines With Plaso fits situations like: reconstructing the full sequence of events on a compromised; forensically imaged host during a DFIR investigation.

How do I install Building Super Timelines With Plaso in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-super-timelines-with-plaso -a claude-code`. Or copy the skill folder (skills/building-super-timelines-with-plaso in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/building-super-timelines-with-plaso in your project. Claude Code loads it when a task matches its description.

How do I install Building Super Timelines With Plaso in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-super-timelines-with-plaso -a codex`. Or copy the skill folder (skills/building-super-timelines-with-plaso in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/building-super-timelines-with-plaso in your project. Codex loads it when a task matches its description.

Can I use Building Super Timelines With Plaso in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-super-timelines-with-plaso -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/building-super-timelines-with-plaso, .gemini/skills/building-super-timelines-with-plaso, .github/skills/building-super-timelines-with-plaso and .opencode/skills/building-super-timelines-with-plaso in your project.

What does Building Super Timelines With Plaso need to run?

Going by SKILL.md and its folder, Building Super Timelines With Plaso needs Python for the scripts in its folder and the command-line tools its instructions call (docker and apt-get). Our summary lists: Python 3; Docker.

Does Building Super Timelines With Plaso access the network?

SKILL.md names 4 domains. As links in the text: github.com, plaso.readthedocs.io, timesketch.org and hub.docker.com. This is read from the text; nothing was executed.

Is Building Super Timelines With Plaso safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Building Super Timelines With Plaso use?

Building Super Timelines With Plaso is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Building Super Timelines With Plaso use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 826 tokens, read only when the agent opens those files.

What are the alternatives to Building Super Timelines With Plaso?

Skills that share tags, products or a category with Building Super Timelines With Plaso: Oss Forensics (Tommy-yw/RunbookHermes, 546 stars), Ctf Malware (ljagiello/ctf-skills, 3.4k stars), Dfir (transilienceai/communitytools, 563 stars) and TShark Traffic Analysis (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Building Super Timelines With Plaso?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.