Advancing cyber incident timeline analysis through retrieval-augmented generation and large language models
Cyber timeline analysis or forensic timeline analysis is critical in digital forensics and incident response (DFIR) investigations. It involves examining artefacts and events---particularly their timestamps and associated metadata---to detect anomalies, establish correlations, and reconstruct a deta...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI
2025
|
Subjects: | |
Online Access: | https://repository.londonmet.ac.uk/10080/7/computers-14-00067.pdf |