google / timesketch

Collaborative forensic timeline analysis
Apache License 2.0
2.62k stars 589 forks source link

Evidence Completeness Workflow #1223

Open binglot opened 4 years ago

binglot commented 4 years ago

Details

It would be great if Timesketch could warn the user that the evidence they loaded into Timesketch appears to be incomplete and explain why it thinks so.

This could be done after Timesketch completed all the processing of the uploaded evidence. The "analyzer" would check what evidence is available and only run checks if the right evidence is available (including any dependencies).

Example checks:

Detailed example:

Mock-up Solution

Initial warning

Warning details

Reasoning

Helps:

jaegeral commented 1 year ago

DFIQ?