Back to search

Article

Advancing Cyber Incident Timeline Analysis Through Retrieval-Augmented Generation and Large Language Models

2025-01-15

Abstract excerpt

Cyber timeline analysis or Forensic timeline analysis is critical in Digital Forensics and Incident Response (DFIR) investigations. It involves examining artefacts and events—particularly their timestamps and associated metadata—to detect anomalies, establish correlations, and reconstruct a detailed sequence of the incident. Traditional approaches rely on processing structured artefacts, such as logs a...

Topics

Open a Topic to create a Post that cites this publication.

Identifiers and source

Literature Corpus work
d709b5d6-a567-5486-88a0-47ce580e60ca
DOI
10.20944/preprints202412.2516.v2
Open publication

Related research

Semantic proximity does not establish scientific evidence.

Click a neighbor to travelStep 1 · 12 closest
Interactive article relationship graphSelect a related publication card to move it into the centre and load its closest explainable connections. Solid lines are source-backed structured connections. Dashed lines are semantic discovery signals and are not scientific evidence.
Advancing Cyber Incident Timeline Analysis Through Retrieval-Augmented Generation and Large Language ModelsDOI 10.20944/preprints202412.2516.v2
Select a neighboring publication to make it the new centre.