Timeline & Artifact Analysis
intermediate Hands-on lab 40 min 3 tasksSubscription
Build a forensic super-timeline from Windows artifacts (MFT, Prefetch, event logs, registry) with Plaso, then read it to reconstruct the full attack from initial access to objective and map each step to MITRE ATT&CK.
This lab is available with a Purple Edge subscription. Sign in to view the full overview and start the lab.
Part of these paths
Unlock this lab
Launch the lab in your browser. Real Kali, Ubuntu and Windows targets, guided step by step. No setup, no VM downloads.
Updated 2026-06-15