google / timesketch

Collaborative forensic timeline analysis
Apache License 2.0
2.62k stars 589 forks source link

Support DFIQ #2781

Closed berggren closed 1 year ago

berggren commented 1 year ago

Support the upcoming DFIQ format to create Investigative Scenarios.

thinrope commented 1 year ago

A paragraph explaining how to import/setup https://github.com/google/dfiq/ into /etc/timesketch properly will be great here! Is simply copying data/* into /etc/timesketch/dfiq/ enough?

jaegeral commented 1 year ago

That will come soon (think weeks) with plenty of documentation, what it is, how to use it etc etc.