Glossary
Super Timeline
A super timeline merges timestamps from filesystem metadata, logs and application artifacts into one chronological view, typically built with Plaso.
A super timeline is a single chronological list of events extracted from many sources at once: filesystem MAC(B) times, syslog and journald entries, login records, shell history with timestamps, package manager logs, container logs and more. Where a filesystem timeline only answers "which files changed when", a super timeline places a login, a package install and a new cron file side by side so the sequence of an intrusion becomes visible.
The standard open source tool is Plaso. log2timeline.py parses an image or directory into a Plaso storage file, and psort.py filters, deduplicates and exports it, for example to CSV or into Timesketch for collaborative review.
log2timeline.py --storage-file case.plaso /mnt/evidence
psort.py -o l2tcsv -w timeline.csv case.plaso "date > '2026-09-27 00:00:00' AND date < '2026-09-28 00:00:00'"
Super timelines are large, so the usual method is to start from an anchor event (a suspicious login or a malware file's timestamp) and examine a narrow window around it. Normalise everything to UTC, remember that some sources record local time without a zone, and treat missing periods as a finding rather than an absence of activity. See building a Linux super timeline with Plaso.