← Research

Report Sheridan College · Graduation project

LLM-Assisted Forensic Timeline Analysis

Hashir Asad

Abstract

Compares reading a forensic file-activity timeline from The Sleuth Kit on its own with having an open-source LLM, Falcon-7B-Instruct, interpret it. Tested against simulated malware activity, the model flagged files being suspiciously modified and encrypted, along with a suspicious new .exe and .txt file, as possible ransomware, making the threat easier to understand.

Full title: Comparative Analysis between Timeline of File Activity by Sleuth Kit and LLM (Large Language Models) for Ease of Understanding/Interpretation of Possible Threats

The question

The Sleuth Kit can reconstruct a timeline of when every file on a disk was modified, accessed, changed or created. That timeline is one of the most useful things an investigator has, but it is dense: it can run to thousands of entries, and spotting the handful that matter takes time and experience.

This project asked whether an open-source large language model could make that timeline easier to understand, and point out possible threats in it, compared with reading the timeline on its own.

Tools

  • The Sleuth Kit (TSK): a collection of open-source command-line forensic utilities (the engine behind Autopsy), used to parse the evidence and build the file-activity timeline.
  • Falcon-7B-Instruct: an open-source, commercially licensed LLM from the Technology Innovation Institute (TII), used to interpret the timeline.
  • JupyterLab: the environment the analysis ran in.

Method

  1. Prepare sample data containing simulated malware activity.
  2. Parse it with The Sleuth Kit into a timeline of file activity.
  3. Ask Falcon-7B-Instruct to interpret the timeline and explain any possible malicious activity.
  4. Compare the AI-assisted reading with a manual investigation of the same timeline.

Results

The model did more than restate events. It highlighted the implications of files being suspiciously modified and encrypted, a pattern that can signify ransomware, especially once a suspicious .exe and .txt file appeared in the timeline.

That met the project’s expected outcome: an open-source LLM can help investigators catch the implications of malicious activity and make a timeline easier to interpret.

Conclusion

The Sleuth Kit is already a powerful tool, and pairing it with an LLM let the timeline be understood at a deeper level. There is plenty still to refine, automation especially, but the results point to a promising direction for malware analysis and digital forensics.

Future work

The next step is an automated pipeline in JupyterLab:

  • Python scripts and IPython magics: modular scripts for data extraction, processing and result generation, run from the notebooks with magics like %run.
  • CI/CD: Jenkins or GitHub Actions re-running the notebooks, tests and validation whenever the code or data changes.
  • Automated reports: nbconvert turning executed notebooks into HTML, PDF and Markdown reports.

Selected references