timesketch icon indicating copy to clipboard operation
timesketch copied to clipboard

Collaborative forensic timeline analysis

Results 342 timesketch issues
Sort by recently updated
recently updated
newest added

What the title says. * How to get intelligence added (new IOC) * Update screenshots * How the weighting / coloring works

Documentation

**Bug Description** The submission of a CSV with missing mandatory headers fals on the server side. However, even if the clients are notified with an error, they will try to...

Bug
Needs triage

It would be good if the caller to the intelligencen view could provider richer chats (e.g. with weight, color, etc.) - [ ] Frontend changes - [ ] Documentation update

Feature request
Frontend

**Is your feature request related to a problem? Please describe.** I'm always frustrated when I upload a timeline via the web UI and it times out. **Describe the solution you'd...

Feature request
Good first issue
UI/UX
Small effort

**Describe the bug** Unit tests for the frontend involving certain components can't be run because of the following **To Reproduce** Try adding a unit test file in `timesketch/frontend/tests/` that imports...

Bug
Needs triage

**Describe the bug** When using the deploy_timesketch.sh Skript, creating an investigation results in 404 errors being shown. When trying to upload timelines, the psort-processes crash because of "TypeError: 'NoneType' object...

Bug
Needs triage

First iteration would be to check if the four columns `message,datetime,timestamp,timestamp_desc`are missing. If one of them is missing, give an error message.

Feature request
Good first issue
UI/UX
Frontend
data_upload

Following yml files were added to to the blocklist cloud/azure/azure_aad_secops_signin_failure_bad_password_threshold.yml web/web_multiple_susp_resp_codes_single_source.yml

conflicts

A lot more scenario based stuff to be discussed with jbn - system_information - wlan_history - persistence

When facing a famous error 500, all a user has is the Sketch_id. Yet most of our logging is based on the index_id which is different, so returning the searchindex...

Feature Request