LLM-Assisted Forensic Timeline Analysis
Abstract
Compares reading a forensic file-activity timeline from The Sleuth Kit on its own with having an open-source LLM, Falcon-7B-Instruct, interpret it. Tested against simulated malware activity, the model flagged files being suspiciously modified and encrypted, along with a suspicious new .exe and .txt file, as possible ransomware, making the threat easier to understand.
Full title: Comparative Analysis between Timeline of File Activity by Sleuth Kit and LLM (Large Language Models) for Ease of Understanding/Interpretation of Possible Threats
The question
The Sleuth Kit can reconstruct a timeline of when every file on a disk was modified, accessed, changed or created. That timeline is one of the most useful things an investigator has, but it is dense: it can run to thousands of entries, and spotting the handful that matter takes time and experience.
This project asked whether an open-source large language model could make that timeline easier to understand, and point out possible threats in it, compared with reading the timeline on its own.
Tools
- The Sleuth Kit (TSK): a collection of open-source command-line forensic utilities (the engine behind Autopsy), used to parse the evidence and build the file-activity timeline.
- Falcon-7B-Instruct: an open-source, commercially licensed LLM from the Technology Innovation Institute (TII), used to interpret the timeline.
- JupyterLab: the environment the analysis ran in.
Method
- Prepare sample data containing simulated malware activity.
- Parse it with The Sleuth Kit into a timeline of file activity.
- Ask Falcon-7B-Instruct to interpret the timeline and explain any possible malicious activity.
- Compare the AI-assisted reading with a manual investigation of the same timeline.
Results
The model did more than restate events. It highlighted the implications of files being suspiciously modified and encrypted, a pattern that can signify ransomware, especially once a suspicious .exe and .txt file appeared in the timeline.
That met the project’s expected outcome: an open-source LLM can help investigators catch the implications of malicious activity and make a timeline easier to interpret.
Conclusion
The Sleuth Kit is already a powerful tool, and pairing it with an LLM let the timeline be understood at a deeper level. There is plenty still to refine, automation especially, but the results point to a promising direction for malware analysis and digital forensics.
Future work
The next step is an automated pipeline in JupyterLab:
- Python scripts and IPython magics: modular scripts for data extraction, processing and result generation, run from the notebooks with magics like
%run. - CI/CD: Jenkins or GitHub Actions re-running the notebooks, tests and validation whenever the code or data changes.
- Automated reports:
nbconvertturning executed notebooks into HTML, PDF and Markdown reports.
Selected references
- The Sleuth Kit (TSK) & Autopsy: open source digital forensics tools
- Creating a timeline with The Sleuth Kit , AA Forensics
- Scenarios , Digital Corpora
- nbconvert: convert notebooks to other formats
- papermill documentation
- Apache Airflow documentation
- Running notebook pipelines locally in JupyterLab , P. Titzler (2021)