Skip to main content

log-timeline-correlator

星标15
分支4
更新时间2026年3月24日 16:06

Parse, normalize, and correlate forensic timelines from Plaso/log2timeline (l2tcsv, json_line), Hayabusa (CSV/JSONL), Chainsaw (JSON), and raw log files (syslog, auth.log, JSON-formatted logs, Windows XML event logs). Produces unified UTC timelines, detects attack sequences, and maps findings to MITRE ATT&CK. Use this skill whenever the user mentions timeline, plaso, log2timeline, supertimeline, l2tcsv, timeline correlation, log parsing, attack sequence, 'merge these logs', 'correlate events across sources', 'build a timeline', 'what happened between', or 'reconstruct the attack'. Also triggers for temporal analysis, time-window queries, and gap detection in forensic timelines.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
2 个文件
SKILL.md
readonly