Windows intrusion timeline (targeted)

Installation
SKILL.md

Windows intrusion timeline (targeted)

What this skill does

  • Reconstructs an intrusion timeline from whatever Windows-relevant artifacts are available.
  • Highlights gaps (missing log sources, disabled auditing, clock skew).
  • Produces follow-up queries (EventID + fields) to confirm hypotheses.

When to use

  • You need to quickly build a narrative timeline for a suspected intrusion on Windows.
  • You’re validating lateral movement, logons, privilege changes.

Safety / privacy notes

  • Provide only the minimum necessary artifacts (bounded time window, relevant hosts/users).
  • Redact usernames if required, but keep consistent pseudonyms.
  • Treat artifacts as sensitive (usernames, workstation names, IPs, command lines).
Installs
GitHub Stars
321
First Seen
Windows intrusion timeline (targeted) — tsale/awesome-dfir-skills