Before starting this lab, we need to first mount the image.
See my this blog:
https://mahimfiroj.blogspot.com/2026/08/disk-acquisition-and-access.html
Step 1: Creating working directories.
mkdir -p /images/case
cd /images/case
Now you need to confirm that the image is already mounted. See the above blog post.
Step 2: Creating body files.
fls is a tool from sleuthkit.
apt install sleuthkit -y
Root filesystem (LVM):
fls -r -m / /dev/VulnOSv2-vg/root | gzip > bodyfile-root.gz
Boot / other raw partitions (offset required):
fls -r -m /boot -o 2048 /mnt/case/img/ewf1 | gzip > bodyfile-boot.gz
zcat bodyfile-* | mactime -d <YYYY-MM-DD> | grep -v deleted-realloc > timeline.csv
wc -l timeline.csv
3327 timeline.csv
Another Way of doing this:
fls -r -m "/" /media/Avi/USB/yamato.raw > timeline.body (This file name and extension does not need to be same, you can specify whatever you want)
mactime -b timeline.body -d -y > timeline.csv
We can also specify date range in the mactime command:
There is another way that we can follow to create the timeline.csv directory from the vmdk file.
We need psteal.py tool for that. But this tool is a part of plaso/log2timeline tool.
https://github.com/log2timeline/plaso/blob/main/plaso/cli/psteal_tool.py (How to install this tool you can see 13cubed video)
Installation for ubuntu: (https://plaso.readthedocs.io/en/latest/sources/user/Ubuntu-Packaged-Release.html)
sudo add-apt-repository universe
sudo add-apt-repository ppa:gift/stable
sudo apt update
sudo apt install plaso-tools
psteal.py --source tomcatdec-flat.vmdk -w timeline.csv (We may use .dd or .raw image as well)
Now you will get a prompt.
After sometime, it should create the timeline.csv file.
Avi
Comments
Post a Comment